Legal
Privacy Policy and Legal Notice
Draft of 26 September 2026 [[to confirm: D15 effective date]]
Website and service operator: Conectia OÜ, registry code 16847069, entered in the Estonian Commercial Register (registration department of Tartu County Court), registered address [[to confirm: A1 street, postal code, city, Estonia]], VAT number [[to confirm: A4]]. Contact for legal and data-protection matters: hello@zadq.net [[to confirm: A2 official mailbox and phone; A3 named contact, if any]].
Conectia OÜ is the controller of the personal data described here, under Regulation (EU) 2016/679 (GDPR) and the Estonian Personal Data Protection Act. This document is the Privacy Policy of the ZadQ website, its developer documentation and its seller dashboard, and the Legal Notice of the website.
1. Data-protection policy
The controller applies the principle of active responsibility: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality. The service is designed so that most of what it does needs no personal data at all, and this policy says plainly where it does.
The purpose of this document is to tell you what we do with your personal data, how it is collected, what it is used for, the rights you have, and the legal information current regulations require.
2. What we collect, and from whom
- Website visitors: usage data collected by Google’s analytics tag (pages visited, device type, approximate location), as described in section 9. Nothing else runs on the website.
- People who write to us: the address they write from and the content of the message.
- Seller dashboard users: the payment wallet address whose control they prove by signature (a pseudonymous identifier that is public on the payment rail), the short-lived session that proof opens, the endpoint identifiers they register, the state of their verification and attestations, and the signature with which they acknowledge the Terms of Service. The dashboard asks for no name, no identity document and no contact address.
- The register-interest form: which side you are on (vendor or agent operator) and, optionally, a resource URL or a fleet size band. The form has no field for a name or a contact address; submissions are counted, nothing more.
- Accountable operators in identity verification: the identity of the operator behind an endpoint and, for a company, of its representatives and beneficial owners, is verified by the identity-verification provider inside the issuer boundary of the MintID identity network. Those documents and results never enter ZadQ’s systems, logs or analytics: the service keeps attestation metadata only, that is, opaque session handles, assurance grades, validity windows and statuses. [[to confirm: C9 controller and processor roles for the identity check]]
- Billing: the legal name, address and payment details of a vendor are entered on the billing provider’s hosted page and processed there. ZadQ keeps the billing state, the name of the tier chosen and an opaque customer reference. [[to confirm: C10 name of the billing provider and its role]]
- Claimants: the recourse process of the MintID identity network is specified and not yet activated. [[to confirm: C8 what a claim collects, and from whom, once a claims procedure operates]]
Between the parties to an attested payment, no personal data changes hands unless a dispute is escalated. An attestation names an accountable operator through the issuer’s signature; a checking party obtains a verdict about an endpoint, never about a natural person.
3. Purposes and legal basis
- To answer messages sent to us (legal basis: your consent, and our legitimate interest in answering you).
- To operate the seller dashboard, issue and re-verify attestations and keep the record of each attestation’s lifecycle (legal basis: performance of the operator agreement).
- To keep the attestation record the assurance grade and the network’s published rules require (legal basis: compliance with legal obligations, and our legitimate interest in the integrity of the verification system).
- To invoice the service through the billing provider (legal basis: performance of the operator agreement, and accounting and tax obligations).
- To measure the use of this website (legal basis: your consent to the analytics tag [[to confirm: D16 consent control or a different legal basis]]).
- To defend our rights and comply with requests from competent authorities (legal basis: legal obligation and legitimate interest).
We do not use your data for advertising, and we do not sell it.
4. Recipients
- The identity-verification provider that runs the KYC and KYB checks inside the issuer boundary [[to confirm: C9 provider named, and its role]].
- The MintID identity network: the reference and the status of each attestation are recorded on the network’s public record. The record is pseudonymous; it names no person and no company.
- The billing provider, for invoicing and payment on its hosted page [[to confirm: C10 provider named]].
- Hosting providers of the website, the documentation, the dashboard and the service: Amazon Web Services, in regions of the European Union [[to confirm: C10 regions]].
- Google, for the website analytics tag (section 9).
- Competent authorities, on a lawful request.
Outside a dispute escalation, no personal data is shared between a vendor and a checking party in either direction.
We keep strict criteria for selecting processors and bind each of them contractually to data-protection obligations.
5. International transfers
Website analytics data may be processed by Google in the United States, under the EU-US Data Privacy Framework and the European Commission’s standard contractual clauses. Everything else stays in the European Union. Where a transfer outside the European Economic Area is ever needed, the controller applies the safeguards the GDPR requires.
6. Security
The service holds attestation metadata only: no identity documents, no results of identity checks, and none of your keys. A vendor’s credential lives in the vendor’s own infrastructure; the dashboard shows state, never secrets. Access to the service’s records is limited to authorised staff and logged, and the logging layer rejects known personal-data fields by construction.
7. Retention
- Messages sent to us: for the time needed to handle them.
- Dashboard records (wallet address, sessions, attestation metadata, the signed acknowledgement of the Terms): for the duration of the operator agreement and, after its end, for the period accounting, tax and anti-money-laundering law require, blocked and used only for those purposes [[to confirm: C10 retention of the wallet address and the signed acknowledgement]].
- Register-interest submissions: the optional details are cleared after twelve months; the count remains.
- Billing state and customer reference: for the duration of the agreement plus the legal periods; the billing provider applies its own retention to what it holds.
- Analytics data: for the retention period configured in Google Analytics.
8. Automated decisions
Verdicts are computed automatically from the standing of an attestation on the MintID identity network. They concern endpoints and organisations, not natural persons, and produce no legal effects on individuals. A verdict is information for the checking party’s own decision.
9. Cookies and analytics
The website and the developer documentation are static pages. The only code that runs on them is Google’s analytics tag (gtag.js), which sets Google cookies and reports usage to Google Analytics so that we can see how the site is used [[to confirm: D16 consent control, or a different legal basis]].
The seller dashboard runs its own code to talk to your wallet and to the service. It keeps the wallet session in your browser’s session storage and sets no analytics cookie [[to confirm: C10]].
10. Minors
This website and the service are not directed at minors. If we learn that we have inadvertently obtained personal data from a minor, we delete it as soon as possible.
11. Your rights
You may exercise your rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw consent at any time, by writing to hello@zadq.net [[to confirm: A2]], identifying yourself and the right you exercise. Where the service holds only a wallet address about you, we will need you to prove control of it.
If you consider that your rights have not been respected, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) [[to confirm: B5 primary supervisory authority]] or with the supervisory authority of the EU member state where you live or work.
12. Legal notice
Intellectual and industrial property. The design of this website, its source code, logos, marks and other distinctive signs belong to Conectia OÜ and are protected by the corresponding rights. Integration code published under the Apache-2.0 licence is governed by that licence.
Content liability. Conectia OÜ is not responsible for the legality of third-party websites linked from this website, nor for the use that third parties make of the information published on it.
Applicable law. The relationship between the user of this website and Conectia OÜ is governed by [[to confirm: B5 governing law]]. Conectia OÜ reserves the right to bring the actions it deems necessary for improper use of the website or its contents.
13. Changes to this policy
We may modify this policy when appropriate. The new version is published on this website with its date; when a change matters to a vendor’s privacy, the dashboard tells them [[to confirm: C11 notification channel]].
14. Contact
For any matter related to this policy, write to hello@zadq.net [[to confirm: A2]].