Last updated: 16 September 2026. This notice covers objectid.io and the ObjectID services operated by SDV Consulting SRLS. The data involved depends on the features and infrastructure you use.
At a glance
We use customer information to deliver the requested functions, secure the service, provide support and administer purchases. We do not sell customer content or reuse documents, telemetry or operational data for advertising, commercial profiling or training general-purpose AI models. This does not mean that the service processes no data: authentication, routing, storage and displaying information are processing operations too.
Service data and payment data have different purposes. Stripe collects payment and billing information through its checkout. ObjectID receives the references and status information needed to supply credits or subscriptions and can access billing records for administration and legal obligations. Customer operational content is not sent to Stripe as part of payment processing.
1. Who is responsible
SDV Consulting SRLS, Via della Conciliazione 13, 20862 Arcore (MB), Italy, VAT IT13168650961, is the controller for website operation, customer relationships, service administration, security and our billing obligations. Contact: info@objectid.io.
When a business customer uses hosted ObjectID functions to process personal data about its own staff, customers or other people, that customer determines the purpose of that processing. ObjectID acts as a processor to the extent it processes those data on the customer's instructions. That processing requires the applicable Article 28 GDPR agreement; this notice does not replace it. Infrastructure operated independently by the customer or its chosen provider is subject to their responsibilities and notices.
2. Information used by the ObjectID service
- Access and authorisation: DID, public wallet address, signatures and authentication challenges, sessions, tenant and asset identifiers, permissions and service entitlements. We use these to verify access, associate operations with the correct identity and enforce permissions and plan limits.
- Customer content: documents, files, metadata, lifecycle events, integrity references, telemetry, device readings, location and commands that you submit or make available through a configured integration. We process the information needed for the functions you request, such as verification, display, routing, storage, evidence export and authorised command delivery.
- Hosted configuration: integration endpoints, access credentials, private locations and decryption settings where you save them in the hosted service. These enable the connections and private views you configure. Saved private configuration is encrypted at rest; this does not imply that data cannot be decrypted by the service when needed to perform its functions.
- Technical and security data: IP addresses, request times, browser or client information, request metadata, errors and operational logs, used to deliver connections, diagnose failures and prevent abuse.
- Contact and support: your name, email, organisation and information you include in messages, used to answer your request and manage the relationship. Please send only information needed for the request.
Purely industrial data that cannot be linked to a person are not personal data. Wallet addresses, identifiers, hashes and location can nevertheless be personal data when they can be linked to an individual; we do not treat them as automatically anonymous.
3. Where customer content goes
Customer-controlled infrastructure: documents and operational datasets can remain in your own storage, broker or Integration Server. ObjectID does not require every underlying dataset to be copied into a central repository. However, when you use a hosted ObjectID gateway or webview to retrieve, relay, decrypt or display that information, the requested content may pass through our servers. Storage under your control does not by itself mean that ObjectID never processes it.
ObjectID-hosted functions: data you send to hosted storage or integration services are processed there to provide the selected features, according to the plan, configuration and applicable service agreement. Access for support or maintenance is limited to what is needed for those tasks.
Public IOTA records: transactions can publish wallet addresses, identifiers, selected metadata, events and integrity references. Public records can be read and copied worldwide by network participants and other third parties. Do not put personal or confidential content on-chain. Deleting hosted data or closing access does not erase blockchain history; we cannot promise deletion of public ledger records or third-party copies. Requests concerning personal data still receive an individual assessment.
4. Stripe: payments, subscriptions and billing
Collected by Stripe: checkout can collect name, email, billing address, tax identifiers and payment-method details. The credit-purchase flow also supports Italian invoicing fields such as tax code, recipient code and PEC. Stripe processes technical and transaction information for payment security and fraud prevention. Full card numbers and card security codes are entered into Stripe's payment interface, not stored in ObjectID's application databases.
Sent by ObjectID: product or plan, amount, currency and purchase references. For credit purchases, Stripe metadata also includes the DID, recipient wallet address, network, package and credit quantity; a mint transaction reference may be added after fulfilment. For Digital Twin subscriptions, checkout uses a purchase-intent reference and plan, with the association to the customer's DID maintained by ObjectID.
Received or accessible by ObjectID: Stripe customer, checkout, payment, invoice and subscription identifiers; payment and renewal status; plan, billing period, cancellation status and fulfilment references. Stripe webhook messages can also carry billing information. In the credit flow, our server reads supplied Italian invoicing fields and copies them into Stripe customer metadata for the electronic-invoicing connector. Our application stores focus on service and transaction references rather than duplicating the checkout billing profile; authorised administration can still access relevant billing information through Stripe.
Billing remains our responsibility: using Stripe does not remove SDV Consulting's accounting and tax obligations. Relevant records may be processed by our accounting advisers, electronic-invoicing providers and tax authorities. The credit integration supports an A-Cube invoicing connector where activated.
Stripe's role: Stripe acts as a processor for certain activities performed on our instructions and as a controller for its own activities, including fraud prevention and legal compliance. Its separate practices, retention and international transfers are described in the Stripe Privacy Policy, Privacy Center and Data Processing Agreement. Optional Stripe services such as Link are governed by their own notices.
5. Purposes and legal bases
- Requested service, purchases and pre-contract enquiries: performance of a contract or steps requested before entering one (Article 6(1)(b) GDPR), where you are the contracting individual.
- Business contact administration, service security, abuse prevention and defence of claims: our legitimate interests in operating a secure service and managing business relationships (Article 6(1)(f)), balanced against your rights.
- Accounting, tax and legally required disclosures: compliance with legal obligations (Article 6(1)(c)).
- Optional marketing or non-essential tracking, if introduced: consent where required (Article 6(1)(a)); it can be withdrawn without affecting earlier lawful processing. Customer operational content is not used for these purposes.
You can browse public pages without purchasing. Data needed to authenticate, perform a requested operation or complete billing are necessary for that function; without them we may be unable to provide it. Optional fields are identified in the relevant interface. For customer-controlled processing, the customer determines the appropriate legal basis.
6. Recipients and international access
Access is limited to authorised personnel and providers needed for hosting, communications, support, payments and accounting, and authorities where legally required. Customer-selected infrastructure and public blockchain recipients are described above. Providers processing personal data on our behalf must be subject to appropriate contractual safeguards.
Where our providers process personal data outside the EEA, the applicable mechanism must be an adequacy decision or appropriate safeguards such as standard contractual clauses, with supplementary measures where needed. You can request information about the recipients and safeguards relevant to your service at info@objectid.io. Stripe describes its transfer arrangements in its own notice. Public blockchain publication is worldwide and is not equivalent to private storage with a contracted hosting provider.
7. Retention and deletion
- Hosted customer content: the selected plan, configured retention policy and service or processing agreement determine retention and deletion. Customer-operated storage follows the customer's own policy. Cancellation of billing does not itself delete all data.
- Access, configuration and service records: kept while needed to operate the requested service and then as needed to settle outstanding operations, meet legal duties or resolve claims. Retained records must be limited to those purposes.
- Technical logs and support: retention is determined by the time needed to investigate errors or incidents, complete support and resolve any related dispute; incident evidence can require longer retention than routine diagnostics.
- Accounting documents: generally ten years under Italian accounting rules, with longer retention where required for outstanding tax proceedings or legal obligations. Stripe separately determines retention for processing for which it is a controller.
- Public blockchain records: may remain indefinitely; ObjectID cannot set a deletion period for the public network.
Ask us for the retention settings applicable to your hosted service. No single automatic deletion period applies to all products, plans, backups and legal records.
8. Website cookies and external resources
The current public website does not use advertising pixels or audience-analytics scripts, and has no WordPress comment or Gravatar functions. Service applications can use browser storage or sessions for authentication and preferences. These functions are distinct from advertising tracking.
Some pages load images from external hosts, including StockSnap; those hosts receive the technical request, including your IP address. Following a social-network or other external link takes you to that provider's service. Stripe checkout uses its own technologies as explained in its Cookie Policy. Non-essential tracking, if added to our website, requires the applicable information and consent controls before activation.
9. Your rights and how to contact us
Subject to the GDPR conditions, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests and withdraw consent. Write to info@objectid.io. We may ask for proportionate identity verification and normally respond within one month; a permitted extension will be explained within that month. You can complain to the Italian Data Protection Authority (Garante) or your competent supervisory authority.
If your data were supplied by one of our business customers, contact that customer as controller; we assist with requests relating to processing on its behalf. For Stripe's own processing, its privacy notice provides direct rights-request channels. We do not use customer operational content to make solely automated decisions with legal or similarly significant effects about individuals. Automated access and payment-status checks are used to run the service; contact us if you need an access or billing outcome reviewed.
10. Legal framework and updates
This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), alongside the Italian Privacy Code (Legislative Decree 196/2003, as amended) and the Garante's guidelines on cookies and tracking. Material changes will be reflected here and communicated through appropriate service channels where required.