ObjectID General Terms and Conditions
Effective Date: 23 August 2026
Welcome to ObjectID.io, a service provided by SDV Consulting SRLS, via della Conciliazione 13, 20862 Arcore (MB) – Italy (VAT IT13168650961). By accessing or using this Website or any associated Service, you agree to these Terms. If you do not agree, you must not use the Website or the Services.
1. Definitions
“Website” means ObjectID.io and its subdomains.
“Service” means any ObjectID functionality, including user interfaces, APIs, smart-contract interactions, credit-based operations and the ObjectID Digital Twin service.
“Digital Twin Service” means the ObjectID Digital Twin webview, the hosted integration services made available by ObjectID, and the related identity, lifecycle, telemetry-routing and command functions.
“Digital Twin” or “Twin” means an on-chain ObjectID Twin identity together with any associated public metadata, off-chain operational data, configuration and lifecycle evidence.
“Integration Server” or “DTIS” means the ObjectID Digital Twin Integration Server used to connect devices, MQTT brokers, storage and the Webview. A DTIS may be operated by ObjectID, by the User, or by a third party selected by the User.
“Subscription” means a recurring service plan associated with an authorized ObjectID DID and its applicable limits and features.
“Credits” means consumable, non-transferable units required for specified ObjectID operations.
“User”, “You” or “Client” means any person or entity accessing or using a Service.
“We”, “Us” or “Our” means SDV Consulting SRLS.
2. Authorized Access and Credit-Based Use
Functions that create, update or delete on-chain objects, or that use hosted operational resources, may require authentication through an ObjectID DID, an active Subscription, Credits, or all of these.
Credits and Subscriptions are associated with the authorized User or DID and may not be transferred, resold or shared unless expressly permitted in writing.
Purchasing Credits or a Subscription does not grant any right in ObjectID trademarks, software, smart contracts, documentation or other intellectual property.
The User is responsible for the accuracy of the DID, signer address, ownership and authorization information used with the Service.
2-bis. ObjectID Digital Twin Service
2-bis.1 Service scope and architecture
The Digital Twin Service separates identity and verifiable lifecycle evidence from operational data. Selected identity, authority, revision and integrity references may be recorded on the IOTA public blockchain. High-frequency telemetry, files and commercially sensitive operational data are not required to be stored on-chain and may remain in an ObjectID-hosted environment or in infrastructure controlled by the User.
The Service may include a public or authenticated Webview, on-chain Twin creation and lifecycle operations, QR-linked public views, private configuration, MQTT telemetry display, storage routing and signed command workflows. Feature availability depends on the selected plan, network, configuration and connected infrastructure.
2-bis.2 Public and private information
Information intentionally written to a public blockchain or configured as public Twin metadata may be visible to anyone and may be indexed, copied and retained by third parties. Private geolocation, Integration Server credentials, decryption secrets and other private configuration stored by the hosted Webview are intended to remain off-chain and are encrypted at rest. The User remains responsible for choosing which information is public and for ensuring a lawful basis for every disclosure.
Blockchain anchoring proves the existence, ordering or integrity of a reference at a point in time; it does not prove that the underlying operational statement is true, complete, legally valid or suitable for a particular purpose.
2-bis.3 Integration Server, MQTT and customer infrastructure
Realtime telemetry and commands are available only when the Webview can securely reach a correctly configured Integration Server. The User may use the hosted DTIS where included in the applicable plan or deploy a private DTIS, MQTT broker and storage under the User’s control.
When the User selects private or third-party infrastructure, the User is responsible for its deployment, security, certificates, network exposure, firewall rules, availability, backups, monitoring, updates, lawful data processing and compatibility. We do not control and do not warrant customer-operated or third-party MQTT brokers, DTIS instances, networks, devices or storage.
2-bis.4 Credentials and configuration files
Tenant credentials, Twin configuration files, recovery files, API tokens, MQTT credentials, private keys, seeds and decryption passwords are security-sensitive. The User must download, verify, store and back them up securely, restrict access to authorized personnel and rotate or revoke them after suspected compromise. Some secrets may be displayed or made available for download only once. We may be unable to recover lost credentials or restore access to independently controlled infrastructure.
2-bis.5 Telemetry, retention and storage
The User remains the controller and owner of operational data submitted by its devices, subject to applicable law and any separate data-processing agreement. Retention for hosted operational data is determined by the selected Subscription, the configuration displayed by the Service or a separate written service-level agreement. Data may be automatically pruned after the applicable retention period. The User must export or back up any data it is required to preserve.
For private or customer-selected storage, the User is solely responsible for capacity, durability, encryption, retention, deletion, recovery and regulatory compliance. The Digital Twin Service does not require indiscriminate storage of telemetry on a public blockchain.
2-bis.6 Industrial commands and safety boundary
The command channel is intended for authenticated, policy-controlled operational instructions. It is not an emergency-stop channel, safety instrumented system, protective control, medical device control or other safety-certified mechanism. The User must implement independent physical and logical safety controls, local interlocks, authorization policies, validation, rate limits, fail-safe states and human oversight appropriate to the asset and risk.
The User is solely responsible for defining permitted commands, confirming the authority of signers, testing device behavior and ensuring that every command complies with applicable law, machinery rules, workplace-safety requirements and manufacturer instructions. ObjectID may reject or suspend commands that fail technical or policy checks, but such checks do not replace the User’s safety engineering.
2-bis.7 Standards and conformity statements
References in the Website or documentation to ISO, IEC, W3C, GS1, IOTA or other standards describe design objectives, mappings or technical alignment unless expressly stated otherwise. They do not constitute certification, accreditation, regulatory approval or a warranty that the User’s complete implementation is compliant. The User is responsible for its own conformity assessment and for obtaining any certification required for its product, facility or industry.
2-bis.8 Subscriptions, billing and cancellation
Paid Subscriptions are billed in advance at the price, currency, interval, limits and taxes shown at checkout. Unless the checkout or order form states otherwise, paid plans renew automatically until cancelled. Payments may be processed by Stripe or another disclosed payment provider under that provider’s terms and privacy policy.
A cancellation stops renewal but does not normally terminate access before the end of the already-paid billing period. Fees already paid are non-refundable except where mandatory law requires otherwise or We expressly agree in writing. At the end of the paid period, hosted limits, telemetry access, retention or other plan features may be reduced or disabled. The User is responsible for exporting required data before expiry.
Testnet plans, demonstrations, trials and promotional access may be activated without payment, may contain simulated or non-production data and may be changed or withdrawn at any time. They must not be used for production or safety-critical operations.
2-bis.9 Availability and service levels
Unless a separate written service-level agreement expressly applies, the Digital Twin Service is provided on an “as is” and “as available” basis without guaranteed uptime, latency, message delivery, command execution, data retention or disaster recovery. Availability may depend on IOTA networks, internet connectivity, DNS, MQTT brokers, cloud providers, storage providers and other third-party systems.
2-bis.10 Suspension and termination
We may suspend or restrict access where reasonably necessary to address non-payment, abuse, a security incident, unlawful activity, excessive resource consumption, risks to other users or infrastructure, or a material breach of these Terms. Termination of hosted access does not remove public blockchain records and may not remove data held in infrastructure controlled by the User or third parties.
2-ter. Experimental ObjectID Storage Service
The separate ObjectID Storage service at storage.objectid.io is an experimental, test-only component and has not been released on ObjectID mainnet. If used in a test environment, it is also subject to the ObjectID Storage Service Addendum. It must not be used for production workloads, business-critical files or data requiring guaranteed availability, durability or retention.
3. Intellectual Property
All Website content, software, documentation, designs and trademarks are the property of SDV Consulting SRLS or its licensors, except for components expressly distributed under an open-source licence. No additional right of reproduction, distribution or reuse is granted.
4. Service and Pricing Modifications
We may modify the Services, documentation, plan limits or pricing. Material changes affecting an active paid Subscription will apply from the next renewal unless an earlier change is required by law, security, third-party infrastructure or to prevent abuse. We may discontinue a Service and will provide reasonable notice where practicable.
5. Public Blockchain Disclaimer
Data and references submitted to a public blockchain may become public, immutable and impossible for Us to alter or delete.
The User must not place personal, confidential, unlawful or regulated operational data on-chain unless disclosure is lawful and strictly intended.
The User is responsible for compliance with GDPR and all other applicable data-protection, industrial, export-control and sector-specific laws.
Blockchain transactions may be irreversible and may fail or be delayed because of network, protocol, smart-contract, signer, authorization or gas conditions.
6. Decentralized Application Disclaimer
The User understands that ObjectID interfaces may interact directly with public blockchain smart contracts. We do not control the underlying blockchain and cannot guarantee its uninterrupted availability, transaction finality timing or future protocol behavior. The User must review transaction intent before signing and is responsible for actions authorized with its credentials.
7. Data Protection and Confidentiality
We process personal data in accordance with applicable law. Further information is available in our Privacy Policy. Where the User submits operational or personal data as an independent controller, the User is responsible for instructions, notices, lawful basis, data minimisation, retention and data-subject rights. Additional processor terms may be agreed where required.
Data Controller:
SDV Consulting SRLS
Via della Conciliazione 13, 20862 Arcore (MB) – Italy
VAT: IT13168650961
Email: info@objectid.io
8. Acceptable Use
The User must not use a Service to violate law or third-party rights; interfere with infrastructure; bypass technical or subscription limits; introduce malicious code; access assets without authority; issue unsafe or unlawful commands; or process data in a manner inconsistent with these Terms. The User is responsible for all activity performed through its credentials and connected systems.
9. Limitation of Liability
To the fullest extent permitted by applicable law, the Services are provided without warranties of uninterrupted availability, accuracy, fitness for a particular purpose, regulatory conformity or suitability for safety-critical operation. SDV Consulting SRLS shall not be liable for indirect, incidental, special, consequential or punitive damages, including loss of data, production, profit, opportunity or business continuity, arising from use or inability to use a Service, third-party infrastructure, blockchain behavior, device behavior or commands.
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited.
10. Governing Law and Jurisdiction
These Terms are governed by the laws of Italy. Unless mandatory law provides otherwise, disputes shall be subject to the competent courts of Monza and Brianza, Italy.
11. Contact
Questions about these Terms may be sent to info@objectid.io or to SDV Consulting SRLS, via della Conciliazione 13, 20862 Arcore (MB) – Italy.