Terms of Service
Draft, version 2026-08-03-draft-0.4 (last revised 3 August 2026) — these terms govern use of the Quovalis API and console operated by Thomas Braun, trading as Quovalis (Einzelunternehmen), Oskar-von-Miller-Ring 20, 80333 München, Germany(“we”). The service is offered exclusively to businesses and professionals (Unternehmer within the meaning of § 14 BGB), not to consumers. By creating an account you confirm that you act as a business and that you are authorised to bind the account holder.
1. The service
The service validates X.509 certificates (in particular QWAC and QSealC) against the European Commission’s List of Trusted Lists and the national trusted lists it references: certificate-chain building to a listed trust anchor, qualified-status mapping, revocation checking (OCSP/CRL), and parsing of qcStatements including PSD2 attributes. Results are returned as structured documents with a tri-state verdict (VALID / INVALID / INDETERMINATE) and stored for retrieval subject to the retention windows in the Privacy Policy.
2. What the service does not claim
- A verdict is a technical assessmentof the presented certificate against the published trust-list and revocation data identified in the result document, including their source timestamps. It is not legal advice and no guarantee of the certificate holder’s identity or conduct.
- Revocation data is cached. A VALID verdict normally reflects revocation data that is current at the time of the request; during temporary unavailability of OCSP/CRL infrastructure, however, the service may rely on a previously obtained revocation response for up to 24 hours past its scheduled update time. The result document identifies the revocation method and source, the timestamps at which the revocation data was produced and checked, and whether a cached response was used. Customers whose regulatory or risk requirements demand current revocation confirmation must evaluate these fields and treat results accordingly.
- Results carry no qualified or court-grade attestation: v1 produces no signed evidence records and no qualified timestamps. We are not a qualified trust service provider within the meaning of eIDAS, and the service is not a qualified validation service or qualified evidentiary service.
- Certificate validity is not proof of a live regulatory authorisation. PSD2 attributes are read from the certificate; we do not cross-check national competent authority or EBA registers.
- An INDETERMINATE verdict means the service could not obtain sufficient data (e.g. revocation infrastructure unreachable and no usable cached response, trust list stale) — it is deliberately never coerced to VALID.
- QSCD status is not assessed.Qualified-status mapping evaluates the trusted-list Qualifications (Sie) overrides of the matched service — including qualification granted or withdrawn only through that extension — but the QSCD/SSCD axis of those qualifiers is not evaluated or reported, and service-history entries are not consulted: the assessment reflects the service’s current list entry at validation time. Where an applicable override cannot be fully evaluated, the service never falls back to a best-effort answer: the certificate is not reported as qualified and the verdict is INDETERMINATE, unless the certificate already fails outright on a stronger ground (e.g. revoked or expired).
3. Accounts, members and API keys
An account (tenant) can have multiple members with different roles (owner, admin, viewer), managed on the console’s Team page. The account holder is responsible for its members’ use of the service and for keeping credentials and API keys confidential; keys can be revoked at any time in the console. Passwords are stored only as salted argon2id hashes; API key secrets and sign-in tokens are stored only as one-way hashes of high-entropy random values — never in plain text.
4. Plans, prices, quotas and rate limits
Each plan carries a monthly validation quota and request-rate limits as published on the pricing and plan pages. The prices, quotas and limits applicable to your plan are those published when the plan is ordered; they remain fixed for the running billing period, and price changes take effect only for future billing periods. All prices are exclusive of value-added tax and other applicable transaction taxes, unless expressly stated otherwise. We announce price changes and material quota reductions at least 30 days before they take effect; if such a change is detrimental to you, you may terminate as of its effective date.
Free-tier requests beyond quota are rejected; paid tiers proceed with metered overage up to a configurable overage cap that is enabled by default — requests beyond the cap are rejected (HTTP 429, overage-cap-reached) until the cap is raised or a new calendar month begins. Paid plans are invoiced; invoices are payable within 14 days by bank transfer (SEPA). If payment is late, the statutory consequences for commercial transactions apply (default interest of 9 percentage points above the base rate and the statutory lump sum of €40, § 288 BGB). Plan changes are handled manually in v1. We may throttle or shed traffic that threatens platform stability (HTTP 429/503 with Retry-After).
5. Acceptable use
- No attempts to circumvent authentication, quotas, rate limits or signup protections.
- No probing, scanning or disrupting the service or other tenants.
- No automated account creation; one account per legal entity unless agreed otherwise.
- Only submit certificates you are entitled to process.
- Do not submit private keys, credentials, secrets or personal data unrelated to certificate validation.
We may suspend accounts violating these rules; where practicable we give prior notice and an opportunity to remedy before suspending.
6. Availability and changes
We operate the service with reasonable care on a best-effort basis. A specific availability level is not guaranteed in v1 (no SLA); maintenance windows are announced in advance where practicable, and urgent security maintenance may be performed without notice. We may change or discontinue features with at least 30 days’ notice for material reductions; if a change materially reduces the service you have ordered, you may terminate as of its effective date. The versioned API (/v1) only changes in backwards-compatible ways, except where an urgent security, legal or regulatory requirement makes an incompatible change unavoidable; in that case we give as much advance notice as the circumstances permit.
7. Liability
We are liable without limitation for damage caused intentionally or by gross negligence, for injury to life, body or health, in the case of fraudulent concealment of a defect, to the extent we have given a guarantee as to quality, and under the Produkthaftungsgesetz (Product Liability Act).
In all other cases (simple negligence) we are liable only for the breach of essential contractual obligations (Kardinalpflichten — obligations whose fulfilment makes the proper performance of the contract possible in the first place and on whose fulfilment you may regularly rely), and only up to the damage foreseeable at contract formation and typical for this kind of contract. This limitation applies equally to indirect damage, consequential loss and lost profit: such damage is recoverable only to the extent that it was foreseeable at contract formation and typical for this kind of contract. In these cases of simple negligence — and only in these cases — liability for loss of data is limited to the recovery effort that would have been required had you performed regular, risk-appropriate backups.
These limitations also apply in favour of our employees, representatives and vicarious agents (Erfüllungsgehilfen).
Decisions taken in reliance on validation results remain your responsibility (see section 2).
8. Data protection
Processing of personal data is described in the Privacy Policy; for business customers a data processing agreement is available. For the contents of certificates you submit and the resulting validation records we act as your processor under that agreement.
9. Termination
The account owner may close the account at any time in the console settings; closure revokes all keys and erases the data of the account and of all its members as described in the Privacy Policy. Stored validation records can be exported via the API or console before closure. Data whose retention is required by statutory retention duties (in particular invoicing, accounting and tax records, including the monthly settlement records of amounts owed) is retained for the statutory periods and erased thereafter. We may terminate accounts for cause, in particular for violations of section 5.
10. Governing law and jurisdiction
German law applies, excluding the CISG. If you are a merchant (Kaufmann), a legal person under public law or a special fund under public law, or if you have no general place of jurisdiction in Germany, the exclusive place of jurisdiction for all disputes arising from this contract is Munich, Germany; mandatory statutory venues remain unaffected. In all other cases the statutory venues apply. Should individual provisions of these terms be or become invalid, the validity of the remaining provisions remains unaffected.