Legal
Terms of Service
Draft of 26 September 2026 [[to confirm: D15 effective date]]
These Terms of Service govern the relationship between ZadQ, a seller-verification service for x402 endpoints operated by Conectia OÜ, registry code 16847069, registered address [[to confirm: A1]], and, on one side, the vendors that register their endpoints with it and, on the other, anyone who checks an attestation.
They reflect the standard contractual structure we apply. The particular conditions of the operator agreement signed with each vendor prevail, in case of discrepancy, over these general terms. The Privacy Policy forms part of these terms.
1. Definitions
- ZadQ: the seller-verification service described on this website, operated by Conectia OÜ. Contact: hello@zadq.net [[to confirm: A2]].
- Vendor (or Registered Operator): the legal entity, or the accountable person, that registers an x402 endpoint with ZadQ and passes identity verification. The word seller names the same party in its x402 role.
- Endpoint: the exact selling surface named in an x402 challenge (the payTo address and the resource URL) to which an attestation is tied.
- MintID identity network: the identity network ZadQ is built on, where attestations are issued and their status is published under rules any party can verify on its public record.
- Issuer: the issuer on the MintID identity network that verifies vendors and signs attestations. Conectia OÜ operates it under the same published admission, deposit and status rules as any issuer of the network.
- Attestation: a digitally signed statement, carried in the vendor’s 402 Payment Required responses, tying an Endpoint to a verified, accountable operator at a stated assurance grade.
- Verdict: the result of checking an attestation, expressed as verified, not verified or unknown, re-checked on a published cadence.
- Checking Party (or Buyer): any person, agent or platform that reads an attestation and obtains a Verdict.
- Guarantee Deposit: the deposit the Issuer holds on the MintID identity network under its published rules, forfeitable, which stands behind every attestation it signs. [[to confirm: C7 whether a vendor-side deposit is added, and its terms]]
- Assurance Grade: the published level that ties the depth of identity verification to what the attestation claims and to its re-verification cadence.
- Trust perimeter: the set of vendors and agents whose accountability is verified. Reading who is inside it is free to everyone, always.
- Agent Operator: the accountable party behind an agent that pays. Agent attestation opens with v1; nothing in these terms offers it before.
- Confidential Information: all technical, commercial, financial, strategic or operational information to which either party has access under the agreement.
2. Description of the Service
ZadQ verifies that an accountable operator stands behind an x402 endpoint, without revealing who. At onboarding, the Vendor proves control of its payTo address with its wallet, is verified (KYB for a company and its representatives, KYC for a person) by the identity-verification provider inside the Issuer’s boundary, acknowledges these terms with its wallet, and receives an attestation issued on the MintID identity network. Its middleware attaches the attestation to its 402 responses; ZadQ’s verifier re-checks it on the published cadence and publishes the Verdict.
The Verdict states three things and nothing more: that a verified, accountable operator at or above the named Assurance Grade runs the Endpoint; that the Guarantee Deposit behind the attestation is at or above the published minimum; and that the attestation is current. It says nothing about the quality of what is sold.
ZadQ operates over the open x402 standard and is independent of it. x402 payments are processed by the parties’ own x402 tooling; ZadQ adds an optional verification layer and takes no part in the payment itself. Should no Verdict be available, integrations keep working: the status reads unknown, and nothing waits on ZadQ.
3. Eligibility and segment
The Service is intended for operators with meaningful commercial activity and regulated business counterparties: API and data providers, publishers and content sites charging machine readers, payments and financial infrastructure. Marketplaces, explorers and agents read Verdicts free of charge and are not customers. Registration is open to legal entities and, where the assurance grade admits it, to accountable persons.
ZadQ may decline, suspend or withdraw a registration when identity verification cannot be completed, when the information provided is inaccurate, when the Endpoint is used for unlawful purposes, or when the Vendor breaches these terms.
4. Onboarding and identification
The Vendor provides its Endpoint identifiers and the information the Assurance Grade requires. Identity verification is performed by the identity-verification provider inside the Issuer’s boundary: ZadQ receives outcome metadata only (an opaque session handle, the grade, the validity window) and never the documents or results themselves.
The Vendor warrants that all information provided is accurate and complete, that it controls the Endpoint it registers, and that it will notify ZadQ without delay of any change in its corporate identity, representatives or Endpoint.
Access to the dashboard is authenticated by proving control of the payTo address with the Vendor’s wallet; access to the service’s programmatic interfaces uses an API key or a short-lived session credential. The Vendor keeps such credentials confidential and is responsible for their use.
5. Fees and billing
Two tiers are offered to Vendors: Attested Vendor and Regulated / Compliance. Each carries an entry fee and an annual minimum, and a usage fee per settlement received at an attested Endpoint while its Verdict read verified, credited against the annual minimum and billed only above it. Amounts are set in the operator agreement [[to confirm: C13 whether amounts are published on the plans page after the counsel read]].
Invoicing runs on the billing provider’s hosted page, where the Vendor enters its legal and payment details; for the first contracts, invoices may also be settled by bank transfer as agreed in writing. Fees are payable in advance for the period they cover.
Checking an attestation and obtaining a Verdict is free of charge for the Checking Party, always. No fee is charged to buyers, agents or platforms for verification, and the Verdict is never sold.
Late payment may lead to suspension of renewal; a suspended attestation reads not verified once past its renewal deadline. Fees already paid are not refunded on termination, save as provided in the operator agreement.
6. The Guarantee Deposit
Every attestation is backed by the Guarantee Deposit the Issuer holds on the MintID identity network under the network’s published rules. While that deposit is below the published minimum, the positive Verdict is withheld and the status reads not verified or unknown; the Verdict says why.
[[to confirm: C7 a vendor-side deposit: whether it exists, who holds it, how it is sized, released and forfeited]]
7. Claims and recourse
The link between an attested party and the accountable operator behind it is sealed with the Issuer and readable by nobody at ZadQ. Release exists only through the dispute process of the MintID identity network, which is specified and not yet activated; until it is, every request for release is refused and recorded.
[[to confirm: C8 a contractual claims procedure of ZadQ’s own, if one operates before the network’s process: who may claim, within what period, what is provided, cure period, decision, what is paid and from what]]
A dispute escalation is the only stage at which identity information about the parties may be shared, and only to the extent needed to resolve the claim. Any decision by ZadQ on a claim is a contractual mechanism, not a judicial one, and leaves the parties’ legal actions intact.
8. Attestation lifecycle, renewal and revocation
Attestations are re-verified on the cadence published for their Assurance Grade. A Vendor re-verifies its identity before the verification’s reuse window ends; there is no grace period and nothing is extended. A re-verification completed in time keeps the attestation’s reference; an overdue one suspends the attestation until the re-verification is bound.
An attestation is invalid, and the Verdict drops accordingly, when the Issuer no longer holds a current registration on the network, when the attestation is past its renewal deadline, or when the Guarantee Deposit behind it is below the published minimum.
ZadQ may revoke an attestation when it has reasonable grounds to believe that the Endpoint is used for unlawful purposes, that the Vendor no longer controls it, that identity verification was obtained by fraud, or that these terms are materially breached. A Vendor that withdraws its consent to the service has every attestation it holds revoked; the withdrawal is final.
9. Obligations of the Vendor
- Keep the Endpoint under its control and deliver what it sells through it.
- Attach the attestation only to Endpoints it has registered, and not alter, transfer or lend it.
- Describe its verified status accurately, using the wording provided by ZadQ, and not imply that ZadQ endorses the quality of its goods or services.
- Re-verify its identity before the reuse window ends, and keep its dashboard state current.
- When it holds its own credential in its infrastructure, protect the key it lives next to and revoke the credential itself if that key is compromised.
- Comply with the laws applicable to its activity, including consumer, data-protection, tax and anti-money-laundering rules.
- Cooperate in good faith in any dispute escalation.
10. Checking Parties
Anyone may check an attestation free of charge. The Verdict is information for the Checking Party’s own decision. Whether to transact with an Endpoint, whatever its Verdict, remains the Checking Party’s decision and responsibility.
Integrations keep working when no Verdict is available: the status reads unknown, and the Checking Party applies its own policy. ZadQ is not liable for decisions taken on the basis of an unknown status, nor for losses arising from a transaction with an Endpoint, whatever its Verdict.
A Checking Party that relied on a verified status and suffered a loss has the recourse described in clause 7 [[to confirm: C8]]; that recourse does not create a contractual relationship with ZadQ.
11. Service levels
ZadQ operates the attestation, re-verification, key-publication and dashboard services with the levels of availability and support agreed in the operator agreement. The re-verification cadence is a published promise; a missed cycle is treated as an incident. Attestations are designed to be checkable against published keys so that a Checking Party never depends on the service being reachable at decision time.
Planned maintenance is announced in advance on the dashboard. ZadQ may modify technical interfaces, giving reasonable notice and keeping published headers, SDKs and response formats stable wherever possible.
12. Intellectual property
ZadQ, its software, documentation, marks, badges and the design of this website belong to Conectia OÜ and are protected by intellectual and industrial property rights. Vendors receive a non-exclusive, non-transferable licence to use the wording and marks provided to describe their verified status, for the term of the agreement.
Integration code published by ZadQ under the Apache-2.0 licence is governed by that licence. Nothing in these terms limits the rights granted by it.
The Vendor keeps all rights over its own Endpoint, goods, data and services. Feedback and suggestions may be used by ZadQ to improve the Service without obligation.
13. Confidentiality
Each party keeps the other party’s Confidential Information in strict confidence and does not disclose it to third parties without prior written consent, save to the identity-verification provider, the billing provider and professional advisers bound by equivalent obligations, and where the law requires it.
The confidentiality obligation subsists during the agreement and after its termination. It does not cover information that is in the public domain through no fault of the recipient, was independently developed, or was lawfully received from a third party.
14. Personal data
ZadQ keeps attestation metadata only. Identity verification of a Vendor and its representatives is performed by the identity-verification provider inside the Issuer’s boundary; documents and results never enter ZadQ’s systems. The wallet address a Vendor proves control of, its sessions and the signature with which it acknowledges these terms are processed by Conectia OÜ as controller, under the Privacy Policy.
Where ZadQ processes personal data on behalf of a Vendor, the parties enter into a data-processing agreement in accordance with Regulation (EU) 2016/679. Billing details are processed on the billing provider’s hosted page under that provider’s own terms.
Between the parties to an attested payment, no personal data changes hands unless a dispute is escalated.
15. Limitation of liability
The total aggregate liability of ZadQ towards a Vendor arising from or related to the agreement is limited to the fees actually paid by that Vendor during the twelve months preceding the event giving rise to the claim [[to confirm: C14 counsel, inside the product-liability read]].
In no event shall either party be liable for indirect damages, lost profits, loss of business opportunities, reputational damages or other consequential damages, except in cases of wilful misconduct or gross negligence, or where the law does not allow such limitation.
ZadQ does not warrant the goods, data or services sold through any Endpoint, nor the conduct of any Vendor beyond what the Verdict states.
16. Term and termination
The operator agreement is entered into for an indefinite term unless a minimum period is agreed. Either party may terminate it with at least 30 calendar days’ written notice effective at the end of a calendar month. Attestations issued remain valid until their next renewal deadline unless revoked earlier.
Either party may terminate for material breach not cured within 15 calendar days of written notice. ZadQ may terminate immediately in the cases listed in clause 8 for revocation.
On termination, ZadQ revokes the Vendor’s attestations and disables its credentials. Attestation metadata is retained for the periods required by law [[to confirm: C7 release of any vendor-side deposit]].
17. Force majeure
Neither party is liable for breaches arising from events beyond its reasonable control, including natural disasters, armed conflicts, acts of terrorism, governmental restrictions, or generalised failure of telecommunications networks, for as long as the event lasts.
18. The network and subcontracting
Conectia OÜ operates the Issuer on the MintID identity network as the network’s first implementer, under the same published admission, deposit and status rules as any issuer, verifiable by anyone on the network’s public record; that relationship is disclosed wherever it is relevant. Identity verification is entrusted to an identity-verification provider inside the Issuer’s boundary, and invoicing to a billing provider, under written agreements that bind them to these terms. ZadQ remains responsible towards the Vendor for the Service.
19. Governing law and jurisdiction
These terms and the operator agreements are governed by [[to confirm: B5: Estonian law, with the Harju County Court in Tallinn / Spanish law, with the courts of Barcelona]], without prejudice to mandatory consumer-protection rules where they apply.
20. Modification of the terms
ZadQ may modify these terms, informing Vendors with at least 30 calendar days’ notice on the dashboard and on this website [[to confirm: C11 notification channel]]. A Vendor who does not accept the new terms may terminate without penalty within the notice period. Modifications required by law apply from their entry into force.
21. Contact
For any matter related to these terms, write to hello@zadq.net [[to confirm: A2]].