Product Description for Users

d.velop AG, Schildarpstraße 6-8, 48712 Gescher, Germany ("provider," "d.velop," "we," "us"), provides a web-based platform ("d.velop postbox," "platform" or "system") that can be used by registered members ("users" or "recipients").

1 General product features

The use of d.velop postbox is free of charge for users. With the platform, users can digitally receive documents and send them to registered companies and organizations. Once delivery is completed, responsibility for backing up and archiving the document lies with the recipient. Documents can be accessed via a browser-based web portal at https://postbox.eu and via the "postbox.eu" mobile applications for iOS and Android.

In addition, users can digitally store, structure, search, export, delete and manage their own documents within the platform.

With the d.velop eIDAS postbox, the existing d.velop postbox product will be expanded to include the functionality of a qualified electronic delivery service (QERDS) in accordance with the eIDAS Regulation (Regulation (EU) No. 910/2014, as amended); this is expected to be available from summer 2026. The qualified delivery service documents the relevant delivery events with electronic evidence and makes this available to the parties involved.

This product description outlines the features of the delivery platform for sending and receiving documents. Where the qualified electronic delivery service is used, the product description also covers the features of the d.velop eIDAS postbox (QERDS).

Note: The publicly available principles concerning the use, security, proof logic and role distribution of the qualified service are documented in the QERDS Public Policy (policy identifier: https://mobile-services.d-velop.de/policy/qerds/v1).

2 Terms and roles

The following definitions of terms serve to clarify the further explanations.

Sender

Company, organization, authority or other entity that delivers documents to users via d.velop postbox or – where applicable – receives documents from the user.

Subscription

Mechanism for establishing a 1:1 delivery relationship between the sender and user. Activation takes place via activation information, in particular a subscription code and PIN. The subscription code and the corresponding PIN are transmitted by the sender to the user in a secure manner outside the platform (e.g. by traditional mail). Once the service is activated by the user, it appears in the user's account.

Account

Personal access of the user to the platform via the web client or mobile app.

Recipient

A recipient ("user," "end user") is a private participant who possesses a registered account and receives documents via the platform and – where activated – returns them to a sender.

QERDS

Qualified electronic delivery service pursuant to Article 44 of the eIDAS Regulation in the form of the d.velop eIDAS postbox.

Proof of delivery

For qualified delivery, users can access a proof of delivery via the properties of a document. This constitutes a comprehensive, user-friendly representation of the qualified delivery, which clearly summarizes the qualified events as well as the outcome.

Evidence export

With an evidence export, the recipient can verify the delivery-relevant information regarding the sender, recipient, time of posting by the sender, immutability of the content and time of opening by the recipient in a legally admissible manner, for example, in the context of court proceedings.

Part A – standard service: d.velop postbox

3 Standard scope of services

3.1 Basic function: digital document receipt and optional return channel

d.velop postbox allows users to receive digital documents from connected senders. If the respective sender provides a return channel, and has activated it, the user can also send documents back to this sender. Whether and to what extent a return channel is available depends on the specific usage scenario of the sender.

3.2 Account, registration and delivery relationships

Use of the product requires a user account. An account can either be created by the user free of charge or prepared by a sender and subsequently activated by the user.

If an account already exists, a user can regularly establish additional delivery relationships by entering activation information (in particular, a subscription code and PIN). A subscription code can only be used once and is provided to the user by the sender.

If a delivery relationship is terminated – for example, if the subscription is canceled by the user or the sender – no further delivery is possible via this delivery channel. Documents that already exist in the account remain unaffected.

3.3 Access options

The service is accessed via a browser-based web portal at https://postbox.eu or via the "postbox.eu" mobile applications for iOS and Android. JavaScript and cookies must be activated to make use of all functionalities in the web portal. Access generally requires entry of a user name or e-mail address and password. Additional authentication methods may be required.

3.4 Document receipt, document storage and processing

Received documents are made available in the user account, where they can be viewed, downloaded and managed by means of the available functions. In addition, users can upload their own documents to the platform and save them in personal document storage.

The platform also supports structured storage in folders, the assignment of document properties or keywords, searches for document, the export of individual documents or folders and the deletion of documents via a recycle bin mechanism.

Storage of the user's own documents may be subject to storage limits. If the available storage limit is reached, the upload of further own documents may be rejected. The receipt of deliveries from connected senders generally remains unaffected by this.

Users have the option of sending documents to their personal d.velop postbox as e-mail attachments. This function enables simple digital storage of documents that are received via e-mail from external sources. The documents are sent to an individual e-mail address that is provided to the user in the portal. Documents received in this way are automatically saved in the personal document storage and are subject to the same conditions as other uploaded documents with regard to storage space, format support and processing.

3.5 Data storage and encryption

All documents that are uploaded by the user or received from a sender are stored in encrypted form. The encryption and decryption is performed by the system as part of the provision and use of the documents. Where applicable, processing also includes functions for displaying, searching and structured management of documents.

3.6 File formats and sizes

Common file formats can be supported for the user's own uploads and the personal document storage. The specific scope of the supported formats depends on the current product specifications. The provider reserves the right to exclude individual file types from processing for security or operational reasons. Both the upload of individual documents and the simultaneous upload of multiple documents are supported. The file size for an upload is limited to 250 MB.

To the extent that documents are processed further in the platform, for example, for displaying previews or for search indexing, this depends on the respective file format and the specific product scope. Not every saved file format has to be fully displayable or searchable in the platform.

3.7 Export, deletion and account termination

Users can download or export documents within the scope of the provided functions. Before terminating the account, the user themselves must back up any data that they still require.

Deleted documents are first moved to a recycle bin and are only permanently removed from the recycle bin after their final deletion. Once permanently deleted, documents generally cannot be restored.

When the user account is deleted, access to the platform will be blocked and the account will be deleted in accordance with the General Terms of Use. Deletion can take up to 48 hours. The statutory obligations to retain records and provide documentary proof remain unaffected.

3.8 Support

Users have access to a free help center with frequently asked questions (FAQs), detailed tips and instructions. If users cannot find a suitable answer there, they can request support via the contact channels provided.

4 Technical requirements and security

Access to the platform requires the user to have an internet connection as well as suitable hardware and software. The provision of internet access and the required end device does not form part of the provider's service.

The platform is accessed via encrypted connections. Users must protect their access data and means of authentication – in particular passwords, passkeys as well as device protection mechanisms such as PINs or biometric authentication – from access by third parties.

The provider may further develop the platform within the scope of operational and technical possibilities. Planned maintenance and measures to ensure the security and integrity of the platform may lead to temporary restrictions.

5 Operation, data protection and data storage

Within the European Economic Area, d.velop postbox is operated and service-related data processed in accordance with the GDPR. The productive data processing takes place in Germany and Austria.

State-of-the-art technical and organizational measures are employed to safeguard confidentiality and integrity. Details regarding the handling of personal data are provided in the data protection information.

Part B – additional service: d.velop eIDAS postbox as a qualified electronic delivery service (QERDS)

6 Overview: qualified delivery

d.velop eIDAS postbox is designed as a qualified electronic delivery service (QERDS) in accordance with the eIDAS Regulation. The qualified proof logic is not simply linked to the provision of a document, but to the relevant events of the delivery process.

The result of the qualified delivery process is either the first opening of a document by the identified and authenticated user or the expiration of the collection period without opening of the document. Qualified evidence is generated for these events.

7 Participation requirements for users

Qualified delivery requires a one-off identification of the user based on a government-issued electronic identity (eID). As part of this identification, the user's identity data is verified. The postal address used for the qualified delivery is taken from the eID and stored in the user account.

For security-relevant user actions, particularly the first opening of a document received via qualified delivery, strong authentication is required. This takes the form of a passkey combined with successful local user verification on the registered end device, specifically via a PIN or biometric authentication.

Note: The first opening of a document received via qualified delivery is currently only possible via the mobile app. Previously activated documents can be accessed via the web client.

8 Qualified delivery process from the user's perspective

Following successful acceptance and validation, the document to be sent via qualified delivery is made available in the user account. Successful strong authentication is required for the first opening of the document.

If the document is opened for the first time within 14 days of being made available, a proof of opening is generated. If the document is not opened within this period, the delivery process is completed with the result "Deadline expired, unread," and a proof of deadline expiration is generated. The document remains available in the user account according to the general deletion rules.

9 Evidence and proof

For each qualified delivery, electronic proofs (evidence) are generated for the relevant events. Based on this information, a human-readable proof of delivery is made available to the user in PDF format.

For external evidentiary purposes, an evidence export can be provided. The evidence export takes the form of a sealed ASIC container that bundles the evidence for a delivery along with corresponding verification and validation information. The provision of this export may be subject to separate processes or fees.

10 Retention of qualified proofs

Evidence and qualified proofs are retained for a period of seven years. This also applies if the user account is deleted in the interim. These proofs are deleted only upon expiry of the retention period, provided that no conflicting legal obligations exist.

For long-term preservation of evidentiary value, renewed cryptographic securing of qualified sealed or time-stamped proofs may be necessary. In this respect, the policy and disclosure documents of the qualified trust service providers used are authoritative.

11 Final provisions

This product description describes the state of the service at the time of its publication. Further developments, particularly due to product changes, regulatory requirements or security requirements, are reserved; the applicable regulations and product information are authoritative.