Product Description for Users

1. General product features

d.velop AG, Schildarpstraße 6-8, 48712 Gescher, Germany ("provider", "d.velop", "we", "us"), provides a web-based platform ("platform", "system", "d.velop trust spaces") that can be used by registered members ("users").

The platform offers solutions for cross-organizational collaboration and connects organizations with their business partners, private end customers and employees. The individual functions according to the chosen tariff are listed later in this document.

2. Definition of terms

The following definitions of terms serve to clarify the further explanations.

2.1. User

A user is a private or business participant who uses the platform to collaborate with other users of the platform, for example, by sending or receiving documents. The user receives an account on the platform for this purpose.

2.2. Account

An account allows the user to access to the platform. By registering with their user name, e-mail address and password, the user receives a user ID and access to their own personal account, e.g. to receive or save their documents.

2.3. Sending of documents

Documents are sent electronically via the platform.

2.4. Space

Within the platform, the user assigns documents to spaces. These represent the highest administrative level. The documents contained in this space can be organized at lower levels using additional structuring options, such as folders. Each user has a personal space ("My Space") and, if applicable, team spaces, which they share with other users within or outside their own organization, depending on the configuration. Each space has a designated owner, whose tariff determines and enforces any usage limits, such as the total amount of storage space available.

3. Information security

The security of data on the platform is ensured by a number of technical and organizational measures.

3.1. Data location

To provide the platform, d.velop uses data center services of an external, German IT service provider, the data centers of which are located within Germany. The data centers of this external IT service provider are certified according to the following standards, among others:

ISO 9001
ISO 27001
ISO 27017
ISO 27018
C5

User authentication is carried out via an external, German IT service provider, the data centers of which are located within Germany and are certified according to ISO 9001 and ISO 27001, among others.

3.2. Encryption of content (data at rest)

All data and content that is saved and processed by the platform is stored in encrypted form according to current industry standards. This applies to content provided by the customer, metadata for the content as well as content created or derived for the purpose of providing the service (e.g. full-text information, preview graphics). Separate keys are used to encrypt the data in different storage media (databases, hard drives). An access log records access to the keys. Currently, the Advanced Encryption Standard (AES) is used for encryption via the XTS method with 256-bit encryption keys. d.velop reserves the right to regularly reassess this in accordance with the current recommendations of the German Federal Office for Information Security, and to make any necessary adjustments.

3.3. Transport encryption ("data in transit")

Transport encryption according to current industry standards is used for communication between the application components. This is re-evaluated at regular intervals to ensure compliance with any new requirements and recommendations of the Federal Office for Safety in Information Technology. At the time this document was created, this means at least TLS version 1.2 for HTTPS connections. For other connections (depending on the application), either TLS or comparable transport encryption is used.

4. Included services

Unless the user has explicitly opted for a paid tariff during the subscription process, they are automatically assigned the platform's free tariff after registration, which provides the basic functionality of the system. d.velop provides the services described below within the scope of existing technical and operational capabilities. The availability of the respective scope of services and functions depends on the user's selected tariff. The user can expand the associated scope of services by switching to a different (paid) tariff. d.velop reserves the right to make new functions available to the customer for testing purposes, in addition to the functions covered in this product description. d.velop also reserves the right to remove these additional functions from the product.

4.1. Sending and receiving documents

Users are able to receive documents from and send documents to other users of the platform. If the recipient does not yet have an account, they have the option of creating an account when receiving documents. Any limitations on the maximum number of sending operations in a given period are determined by the selected tariff.

4.2. Document storage and collaboration

4.2.1. Personal space

Each user receives a personal space. The documents contained in this space are accessible only to the respective authorized user.

4.2.2. Collaboration via team spaces

Team spaces can be created to enable collaboration with other users, such as colleagues, business partners, customers or family members. An authorized user can create their own space and invite both registered and unregistered users to join this space, for example, via e-mail. Documents in these team spaces are available to the registered and authorized members of the corresponding team space (referred to as the "team"). The user who created the team space is considered the owner of the space. Any limitations on the maximum number of own spaces, i.e. the spaces for which the respective user is the owner, are determined by the selected tariff.

4.2.3. Storage

The user is allocated a tariff-dependent storage volume for storing their documents on the platform. This is calculated from the sum of all documents stored in their personal space or in team spaces for which the respective user is the owner, regardless of which user uploaded the respective documents. Before each new document is uploaded, the system checks whether the storage limit has been exceeded. If the storage limit is exceeded, the upload of the new document is rejected, and the user receives a corresponding message. In this case, the user has the option of changing their existing tariff to a paid tariff with a higher storage volume or freeing up storage space by deleting documents already stored in the personal space so that the new document can be uploaded. Documents are not automatically deleted by the system. Receiving documents is possible to a certain extent even if the contractually agreed storage volume of the respective user has already been used up. However, to ensure permanent receipt, the user must either switch to a tariff with a higher storage volume or free up storage space by deleting documents already stored on the platform in their user account or their team spaces.

4.2.4. Folder management

The platform offers structured storage of documents within folders. Individual folder and subfolder structures are mapped within the account, in which the corresponding documents can be stored. The folders serve as a tool for the user to store their documents. Changing the folder structures defined by the user and assigning documents to other folders is also supported.

4.2.5. File upload

Documents that already exist in digital form can be uploaded by the user into corresponding folder structures. The file size per upload is limited to 2 GB.

4.2.6. Deletion of documents

The user can delete stored documents provided they have the appropriate authorization. This also includes the deletion of all associated data (document properties, preview images, etc.). The documents cannot be restored once they have been deleted.

4.2.7. File formats

The platform is used to store documents. Ultimately, almost any common file format can be stored. The options for further processing (e.g. preview images) depend on the respective file format and the chosen tariff.

4.3. Additional functions

4.3.1. Document export

It is possible to download and save individual documents to the user's end device (e.g. via the web client).

4.3.2. Account deletion

The user can choose to delete their account. This also includes the deletion of all documents and data stored in the personal space. The data cannot be restored once the account has been deleted. The deletion of user accounts can take up to 72 hours. During this time, it is not possible to create a new account with the previously used e-mail address.

4.3.3. Integration into other systems

d.velop trust spaces can be integrated into other systems of d.velop AG or other manufacturers via a corresponding API, provided that the manufacturer of the respective system supports this. The integration of d.velop trust spaces into other systems is subject to a fee and requires a corresponding paid tariff. If necessary, d.velop will provide the customer with technically limited means, such as access tokens with limited usability, so that the customer can try out the integration, exclusively for testing purposes, in the free tariff.

4.4. Access options

4.4.1. Access via desktop devices

The platform can be accessed via the latest version of the following browsers:

  • Google Chrome
  • Microsoft Edge (Chromium-based)
  • Safari on Apple devices

Access to the platform is only possible after logging in with a user ID and password.

4.4.2. Access via mobile devices

The platform can be accessed via the latest version of the following browsers:

  • Google Chrome
  • Safari on Apple devices

Access to the platform is only possible after logging in with a user ID and password.

5. Technical requirements

The user can access their user account with an up-to-date web browser, using both desktop and mobile devices. However, JavaScript and cookies must be enabled for the user to benefit from the platform's full functionality. Access to the platform requires user authentication with the corresponding login data, consisting of a user ID and password. Data and documents are accessed exclusively via encrypted connections (HTTPS). The provision and transfer of the necessary internet access, connections to the internet as well as the required equipment (hardware and software) are not covered by this product description.

6. Additional services

Depending on the selected tariff, additional functions are available to the user. Information on the available tariffs and their individual functions can be found on our website.

6.1. Tariffs and payment methods

The currently available tariffs can be viewed on the d.velop website and/or in the platform account after logging in. The user can upgrade to higher tariffs after logging into the platform, within the platform or in their account. If you have any questions about the scope of services, please contact us.

When upgrading to a higher tariff, the following payment methods are available to the user:

• Invoice with SEPA direct debit