Validity: March 2026

Data privacy notice

1 General information

1.1. Controller

We, d.velop AG, take your privacy and our legal obligations to protect your personal data very seriously. Legal regulations require us to be completely transparent in how we process your personal data. In order for you, as the data subject, to understand how we process your data, you need to be sufficiently informed about the necessity, purpose and scope of the processing. This privacy statement explains which personal data we process when you use the SaaS & app solution (“d.velop postbox”, “platform” or “system”).

The “controller” within the meaning of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and other data protection regulations is

d.velop AG
Schildarpstrasse 6-8, 48712 Gescher, Germany
+49 (0) 2542 9307-0
info@d-velop.de
www.d-velop.de

hereinafter referred to as “we,” “us” or the “controller.”

You can contact the data protection officer at:

Nils Möllers
Keyed GmbH, Siemensstrasse 12, 48341 Altenberge, Germany
datenschutz@d-velop.de

We are not responsible for any data processing by the operators of the app stores (Apple App Store® and/or Google Play®) via which you download our app. Information can be found in the data privacy notices of the app store operators.

Please also note that links in our SaaS solution and/or apps may take you to third-party websites. These links are either clearly marked or can be identified by the address bar of your browser. We are not responsible for data processing on these pages.

1.2 Definitions

1.2.1 From the GDPR

This privacy statement uses the terms of the GDPR. The corresponding definitions (Art. 4 GDPR) can be found, for example, at https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32016R0679.

1.2.2 Cookies

Cookies are text files that are stored on or read from your end device by a SaaS solution or a website. They can be used, for example, to recognize you on subsequent visits, save settings, allow you to remain logged in or analyze specific user behavior.

1.2.3 Categories of data

When we specify in this privacy statement which categories of data we process, we are referring in particular to the following data: Master data (e.g. name, address, date of birth), contact details (e.g. e-mail address, telephone number, messenger services), content data (e.g. text entries, photographs, videos, contents of documents and files), contract data (e.g. subject of the agreement, terms, customer category), payment data (e.g. bank details, payment history, use of other payment service providers), usage data (e.g. history on our platform, use of certain content, access times), connection data (e.g. device information, IP addresses, URL referrer) location data (e.g. GPS data, IP geolocation, access points) and diagnostic data (e.g. crash logs, performance data for the website/app, other technical data for analyzing malfunctions and errors).

1.3. Information about data processing

We process personal data only to the extent permitted by law. We only pass on personal data in the cases described below. To protect your data, we use appropriate technical and organizational measures (e.g. pseudonymization, encryption).

Unless we are legally obliged to store or pass on personal data to third parties (in particular law enforcement agencies), the type, scope and duration of processing depend on which functions you use in each individual case.

If we use service providers (in particular, an affiliated company of the d.velop Group as the operator), this is done – where applicable – within the framework of commissioned data processing according to Art. 28 GDPR.

When senders (e.g. companies or authorities) transmit documents and messages to recipients, the sender is generally responsible for the content and selection of the personal data transmitted. We process this content to technically carry out delivery and to make the content available in the mailbox. Depending on the specific arrangements, this may occur on behalf of the sender (Art. 28 GDPR) or under the sender’s own responsibility. The respective contractual provisions are decisive.

When a sender initiates a digital delivery, the sender can, in particular, establish during the delivery process whether a user account exists (e.g. as a hit in the delivery process) and whether the delivery was successfully completed (delivery status). Content is only transmitted to the sender to the extent necessary for delivery and verification purposes, and in accordance with the respective roles/contracts.

1.4. Duration of storage

We delete personal data as soon as the purpose for which it was processed no longer exits or a prescribed retention period expires. Continued storage may be necessary if data is required for concluding or fulfilling a contract. In the case of non-essential cookies, we will inform you about their functional duration at the end of this privacy statement.

Data from the user agreement (e.g. user account and contact data) is generally deleted upon termination of the agreement or when it has been established that no agreement will be concluded. Exceptions apply where data must continue to be stored due to legal obligations or for the establishment, exercise or defense of legal claims. In this case, the data will be deleted upon expiry of the respective retention period, or processing of this data will be limited to the necessary extent (e.g. blocking/restriction).

Data processed on the basis of granted consent will be deleted after this consent is withdrawn, unless further processing is permitted by other legal bases.

For qualified electronic deliveries, legal requirements to ensure the preservation of evidentiary value will apply as soon as this function is available. In this case, proofs of delivery and corresponding evidence are stored for the period defined for this purpose, even if a user account is closed. In the context of the d.velop eIDAS postbox, a retention period of seven years is defined. Further details can be found in section 2.3.

1.5. Automated individual decision-making including profiling

We do not use automated individual decision-making including profiling to reach decisions pursuant to Art. 22 Para. 1, 4 GDPR.

1.6. Rights of the data subject

As the data subject, you have the right of access pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restrict processing pursuant to Art. 18 GDPR and the right to data portability pursuant to Art. 20 GDPR. The restrictions from Sections 34, 35 BDSG apply to the right of access and the right to erasure. You have the right to lodge a complaint with a supervisory authority for data protection matters (Article 77 GDPR in conjunction with Section 19 BDSG). The supervisory authority to which we are subject is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestrasse 2-4, 40213 Düsseldorf, Germany. However, you are free to lodge a complaint with any supervisory authority for data protection matters of your choosing.

1.7. Notification obligations of the controller

We will notify all recipients to whom your personal data has been disclosed of any rectification or deletion of your personal data or any restriction of processing pursuant to Art. 16, Art. 17 Para. 1 and Art. 18 of the GDPR, unless such notification is impossible or involves disproportionate effort. Upon your request, we will inform you of who received this notification.

1.8. Obligation to provide information

Unless otherwise explained below in the legal bases under 2 or 3, you are not obliged to provide personal data. However, in the cases described in Art. 6 Para. 1 Lit. b) of the GDPR, the personal data is necessary for the performance or conclusion of a contract. If you do not provide this personal data, it is not possible to fulfill or conclude the contract. If you do not provide personal data in the cases described in Art. 6 Para. 1 Lit. a) and f) of the GDPR, it is not possible to use the parts of our SaaS solution in question.

To use the services described here on your device (notebook, smartphone, tablet), you may also be required to grant us access to the following interfaces, functions and data on your device: system functions (e.g. camera or microphone), stored content (e.g. documents or photos). You are not required to grant this access. However, if you do not, you may not be able to use the functions and services or your use may be restricted.

1.9. Right to object and revoke consent

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6 Para. 1 Lit. f) of the GDPR. Where personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing.

Pursuant to Art. 7 Para. 3 Clause 4 of the GDPR, you also have the right to revoke your consent to future processing at any time. Such a revocation does not affect the lawfulness of any processing carried out before the revocation. You can revoke your consent by mail or e-mail without the need for a specific form. If you object, we will cease to process your personal data unless another (legal) basis permits the processing. If, however, you revoke your consent and there is no other basis that permits the processing, the personal data must be deleted immediately pursuant to Art. 17 Para. 2 Lit. b) of the GDPR.

No specific form is required to lodge an objection or revoke consent. Such communications should be addressed to:

d.velop AG
Schildarpstrasse 6-8, 48712 Gescher, Germany
+49 (0) 2542 9307-0
info@d-velop.de

You can also revoke certain consent(s) in the app’s settings or on your device by disabling the functions in question (see examples under the functions in 2).

2 Data processing in connection with use of the SaaS & app solution

Your use of the SaaS & app solution and its functions requires us to process certain personal data. In the following, we explain how we process your personal data.

2.1 Operation of the SaaS & app solution

Purpose of processing: Provision, functionality and optimization of our service; ensuring the security of our information technology systems. This also constitutes our legitimate interest pursuant to Art. 6, Para. 1, Lit. f) GDPR.

Legal basis: Art. 6, Para. 1, Lit. b) and f) GDPR

Categories of data: Contact details, master data, content data, usage data, connection data, diagnostic data

Recipients of the data: Affiliated company of the d.velop Group as the operator of the platform (commissioned data processing); IT service providers, other affiliated companies of the d.velop Group (where necessary for operation and support).

Intended transfer to third countries: None. The processing takes place within the European Economic Area (EEA). Data is processed and stored in a data center in Germany and a second data center in Austria (geo-redundant operation).

Does providing your consent mean that we store or read personal information on your device? No

2.2 Registration (user account)

Purpose of processing: Creation of a user account for the use of the d.velop postbox.

Legal basis: Art. 6, Para. 1, Lit. b) GDPR

Categories of data: Master data, contact details, content data (if applicable)

Recipients of the data: Affiliated company of the d.velop Group as the operator of the platform (commissioned data processing); IT service providers, other affiliated companies of the d.velop Group (where necessary for operation and support).

Intended transfer to third countries: None. The processing takes place within the European Economic Area (EEA). Data is processed and stored in a data center in Germany and a second data center in Austria (geo-redundant operation).

Does providing your consent mean that we store or read personal information on your device? No

2.3 Qualified electronic delivery (QERDS) – planned

With the d.velop eIDAS postbox, the existing d.velop postbox product will be extended to include the functionality of a qualified electronic delivery service (QERDS) in accordance with the eIDAS Regulation (Regulation (EU) No. 910/2014, as amended); this is expected to begin in summer 2026. A QERDS is a legally compliant means of digital delivery. It generates technical evidence of when a document was delivered and whether it was opened or the collection period has expired. This evidence serves as proof in legal contexts.

Purpose of processing: Completion of qualified electronic deliveries as well as generation, management, provision and retention of proofs of delivery/evidence (e.g. evidence of delivery and result of the delivery process: opening or expiry of deadline).

Legal basis: Art. 6, Para. 1, Lit. b) GDPR (contract/use of the service) and – where applicable and where retention of evidence is legally required – Art. 6, Para. 1, Lit. c) GDPR (legal obligation).

Categories of data: Identity data (e.g. from eID identification), authentication data (e.g. passkey, WebAuthn), delivery and verification data (evidence), log and time data (times and events), metadata for assigning delivery (recipient account, sender reference).

In the context of qualified deliveries, in particular information necessary for verification purposes is processed and stored. This includes, for example:

  • Information for identifying and authenticating the relevant parties (e.g. eID reference, passkey/WebAuthn reference)
  • Evidence of the handover/delivery of a document to the delivery service
  • Evidence of the result of the delivery process (e.g. opening or expiry of deadline)
  • Integrity/tamper protection information (e.g. cryptographic evidence, time data)
  • Assignment and log data (times/events)

Recipients of the data: affiliated company of the d.velop Group as the operator of the platform (commissioned data processing); where applicable, IT service providers and subcontractors for operation and security functions; senders receive information about the delivery status to the extent necessary for carrying out the delivery and for verification purposes. Furthermore, transmission to authorities/public bodies or other responsible bodies may occur if a corresponding legal obligation applies or if an official or court order exists. Insofar as the qualified delivery service is provided as a trust service, transmission to responsible bodies may take place, particularly under the conditions of the German Trust Services Act (VDG) (e.g. Section 8 Paragraph 2 VDG). Where legally permissible, data subjects will be informed about official/judicial data transmissions. The transmission will be documented and retained for a period of 12 months.

Intended transfer to third countries: None. The processing takes place within the European Economic Area (EEA). Data is processed and stored in a data center in Germany and a second data center in Austria (geo-redundant operation).

Duration of storage: Proofs of delivery and evidence are stored to ensure the preservation of evidentiary value in accordance with the legal requirements for qualified trust services. The duration of storage is determined by the trust service provider. In the context of the d.velop eIDAS postbox, a retention period of seven years is defined. Storage may also continue after the cancellation of a user account, insofar as this is necessary for the preservation of evidentiary value and/or legal obligations.

If the QERDS service is discontinued, a legally prescribed transfer of essential information and evidence to another qualified provider may be provided for, so that evidence remains usable as proof for the retention period.

2.4 Forwarding of e-mails to the postbox (after activation by the user)

Purpose of processing: Provision of the e-mail forwarding feature to enable users to send documents as e-mail attachments to their personal d.velop postbox. The e-mails are processed automatically and used exclusively for the technical forwarding to the user account. The content is not stored on a permanent basis.

Technical implementation: The processing takes place via the Amazon Simple Email Service (SES) and additionally via AWS Lambda functions for system-side forwarding.

Legal basis: Art. 6, Para. 1, Lit. a) GDPR

Categories of data: E-mail sender, recipient address (postbox address), subject line, e-mail content and attachments, metadata (e.g. timestamp, header information)

Recipient of the data:

Amazon Web Services EMEA SARL (Luxembourg) as a technical shipping and processing service provider within the scope of the order processing pursuant to Art. 28 GDPR; affiliated companies of the d.velop Group

Intended transfer to third countries: Yes, for technical reasons, the delivery may involve a transfer to the USA. Amazon Web Services is certified according to the EU-US Data Privacy Framework. Processing for our own purposes does not take place. The transfer of e-mails takes place on an encrypted basis (TLS).

Does providing your consent mean that we store or read personal information on your device? No.

2.5 Matomo

Purpose of processing: Optimizing, designing and statistically evaluating our SaaS & app solution “d.velop postbox”.

Legal basis: Art. 6, Para. 1, Lit. a) GDPR

Categories of data: Usage data, connection data

Recipient of the data: IT service providers, affiliated companies within the d.velop group

Intended transfer to third countries: None

Does providing your consent mean that we store or read personal information on your device? Yes, see the list at the end of this privacy statement.

2.6 Contacting us (e-mail, telephone, contact form)

Purpose of processing: Replying to your inquiry in the contact form, your e-mail or your callback request.

Legal basis:  Art. 6 Para. 1 Lit. f) GDPR; Art. 6 Para. 1 Lit. b) GDPR (if your inquiry concerns the conclusion of a contract or an existing contract)

Categories of data: Master data, contact details, content data, usage data (if applicable), connection data, contract data (if applicable)

Recipients of the data: affiliated companies within the d.velop group, Inxmail GmbH, Wentzingerstr. 17, 79106 Freiburg, Germany

Intended transfer to third countries: None

Does providing your consent mean that we store or read information on your device? No

2.7 Payments (payment provider)

Purpose of processing: Processing payments for fee-based services in our SaaS solution.

Legal basis: Art. 6, Para. 1, Lit. b) GDPR

Categories of data: Master data, contact details, contract data, payment data

Recipient of the data: PAYONE GmbH, Lyoner Strasse 9, 60528 Frankfurt am Main, Germany, affiliated companies within the d.velop group, IT service providers

Intended transfer to third countries: None

Does providing your consent mean that we store or read personal information on your device? No

2.8 E-mail newsletter

Purpose of processing: Managing our distribution list and sending the newsletter you requested, personalizing our newsletter based on your usage behavior and documenting your consent to receive the newsletter.

Legal basis: Art. 6, Para. 1, Lit. a) GDPR

Categories of data: Contact details, master data, usage data, connection data

Recipients of the data: affiliated companies within the d.velop group, Inxmail GmbH, Wentzingerstr. 17, 79106 Freiburg, Germany

Intended transfer to third countries: None

Does providing your consent mean that we store or read information on your device? No

2.9 E-mail notifications from the platform

Purpose of processing: Sending contract-related notifications from the platform.

Legal basis: Art. 6, Para. 1, Lit. b) GDPR

Categories of data: Contact details, master data, usage data, connection data

Recipients of the data: affiliated companies within the d.velop group, Inxmail GmbH, Wentzingerstr. 17, 79106 Freiburg, Germany

Intended transfer to third countries: None

Does providing your consent mean that we store or read information on your device? No

2.10 Google Crashlytics and Firebase in the app

Purpose of processing: Keeping the platform and our other IT systems functioning properly

Legal basis: Art. 6, Para. 1, Lit. a) GDPR

Categories of data: Usage data, connection data

Recipients of the data: affiliated companies within the d.velop group, Google Ireland Ltd., Gordon House, Barrow Street Dublin 4 Ireland

Intended transfer to third countries: Yes (in accordance with EU standard contractual clauses/SCC)

Does providing your consent mean that we store or read information on your device? No

Transfer to third countries

The controller may transfer personal data to a third country. In principle, the controller may provide various safeguards to ensure that all processing is subject to an adequate level of protection. Data transfers may be initiated on the basis of an adequacy decision, internal data protection regulations, approved codes of conduct, standard data protection clauses or an approved certification mechanism pursuant to Art. 46, Para. 2, Lit. a) through f) GDPR.

If the controller intends to transfer data to a third country on the basis of Art. 49, Para. 1, Lit. a) GDPR, you will be notified at this point about the possible risks of transferring data to a third country.

There is a risk that the third country receiving your personal data may not provide a level of protection that is equivalent to the data protection required in the European Union. This may be the case, for example, if the EU Commission has not issued an adequacy decision for the third country in question or if certain agreements between the European Union and the third country are declared invalid. Specifically, surveillance laws in some third countries (for example, the USA) pose risks to certain EU fundamental rights. In such cases, it is the responsibility of the controller and the recipient to assess whether the rights of data subjects in this third country are protected to an equivalent level as in the European Union and can also be effectively enforced.

Pursuant to the General Data Protection Regulation, the level of data protection enjoyed by individuals within the European Union shall not be undermined when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organizations, including when personal data are further transferred from a third country or international organization to controllers or processors in the same or another third country, or to the same or another international organization.