01When these terms apply
These terms apply when a customer creates, publishes or administers an organisation workspace, enables a capability, connects an external service, or assigns a domain or Ident.ink subdomain to a private dashboard. They supplement the Terms of Service. If they conflict, an accepted order controls its commercial details, then these product terms, then the general Terms of Service.
02Customer control and responsibility
The project owner chooses the dashboard structure, members, roles, pages, data sources, workflows and visibility. Ident.ink supplies the tools and enforces configured access; it does not become the customer’s employer, director, accountant, agent or decision-maker.
Only authorised people may be invited. The customer must review access after role changes and remove people who no longer require it. Private dashboard content must not be made public merely to avoid access controls.
03Ident.ink OAuth and portal sessions
A published private workspace requires an Ident.ink account and an approved OAuth flow. Authorisation confirms identity but does not grant membership; the user must also hold current project access. Portal sessions are short-lived and may be revoked after logout, removal, suspension, risk detection or expiry.
The customer must not imitate the Ident.ink login screen, collect Ident.ink passwords, interfere with OAuth state or PKCE, or frame the authorisation flow. Customer domains receive no general access to Ident.ink cookies or APIs.
04Domains and publication
The customer must control each connected domain and publish the exact DNS records requested. Ident.ink may refuse deceptive, infringing, unsafe or technically invalid hostnames. One included subdomain or custom-domain allowance is subject to the product description; additional capacity may require payment.
DNS, certificate and registry changes can take time and depend on third parties. Removing a binding can make the workspace unavailable. A private workspace is not a public marketing website unless the customer deliberately builds and publishes a separate public site.
05Capabilities, bundles and charges
Capabilities can be included, purchased individually or supplied in a bundle. Recurring infrastructure, processing, communications, payments, storage and automation capabilities are normally monthly. A genuinely durable, low-cost deliverable may be sold once only when checkout says so.
The checkout page must identify the project, capability, billing interval, price and cancellation route. A capability is enabled only after confirmed payment or another recorded entitlement. Disabling a panel does not cancel its subscription.
06Workflows and high-impact actions
A workflow runs only after an authorised user saves and enables it. The customer must verify conditions, recipients, payment amounts, schedules and failure handling. Payment, payroll, legal, employment, security and deletion actions require the approvals shown by the product and must never rely on an unreviewed generated output.
Ident.ink may stop loops, duplicate triggers, excessive calls, unsafe destinations and actions that breach a provider rule or threaten the service. This safety action does not make Ident.ink responsible for the customer’s underlying instruction.
07Workspace governance and delegated authority
The project owner appoints administrators, defines roles and remains responsible for ensuring each person has authority for the actions assigned to them. A platform role records technical permission; it does not prove corporate office, employment authority, professional qualification or authority to bind another legal person.
Customers should use approval steps for payments, publication, deletion, exports, external disclosure and other high-impact actions. Ident.ink may offer maker-checker, audit, retention and policy controls, but the customer must configure them for its own governance and applicable law.
08Connected APIs and external providers
Only listed or explicitly approved HTTPS services may be connected. Connections exchange bounded data; they cannot download or execute code, address private networks, obtain platform secrets or control the host. Credentials must be stored only in designated encrypted fields.
The customer is responsible for authority to use the connected account, its lawful basis, provider terms, data accuracy and continuing security. Revoking a connection stops future exchange but does not retrieve data already lawfully sent to that provider.
09Portability, extension and customer-built systems
Where a feature provides export, import, templates, verified APIs or customer-supplied storage, the customer may use those interfaces to extend its workspace without transferring ownership of Ident.ink software. Imported material must be authorised, malware-free and compatible with the published format.
Customer-built panels, templates and workflows remain subject to tenant isolation, entitlement, review and resource limits. Ident.ink may approve additional verified integrations or enterprise controls, but will not permit an integration to download and execute untrusted code on platform infrastructure.
10Records, exports and retention
Dashboard records and exports reflect customer input and connected events. They may assist operations but are not audited accounts, statutory filings or professional advice. The customer must keep independent copies of records it is legally required to retain and reconcile financial information against the payment provider and bank.
Project deletion, account deletion or entitlement expiry may remove access and begin deletion under the published retention schedule. Audit, billing, fraud, backup and legal-hold records may remain for the periods explained in the Privacy Notice.
11Suspension, changes and support
Ident.ink may isolate a capability or connection where necessary to contain a security, legal, payment or reliability risk while leaving unrelated services available where reasonably possible. Material product changes follow the notice rules in the Terms of Service.
Report access errors, incorrect billing, unsafe automation or domain problems through Support with the project, time and non-secret error details. Do not send passwords, API secrets, complete payment details or private keys.
These product terms do not remove statutory consumer, employment, privacy or payment rights.