Privacy Policy

Information on data protection in accordance with Art. 13/14 GDPR

Last updated: March 2026

Data Controller

The controller within the meaning of Art. 4 (7) GDPR is:

Legal basis: Art. 6 (1) GDPR

No data protection officer has been appointed, as the requirements under Art. 37 GDPR are not met.

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — You can request information about the personal data we hold about you at any time.
  • Right to rectification (Art. 16 GDPR) — You can request the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure (Art. 17 GDPR) — You can request the deletion of your personal data, provided no legal retention obligations apply.
  • Right to restriction of processing (Art. 18 GDPR) — You can request that the processing of your data be restricted, e.g. if you contest the accuracy of the data.
  • Right to data portability (Art. 20 GDPR) — You can request that we provide your data in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21 GDPR) — You can object to the processing of your data at any time if it is based on Art. 6 (1) lit. f GDPR.
  • Right of withdrawal (Art. 7 (3) GDPR) — You can withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

To exercise your rights, you can contact us at any time by email at <email/>.

You also have the right to lodge a complaint with a supervisory authority. The responsible authority is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin, email: <emailBerlin/>.

Hosting & Security

Hetzner Online GmbH

Industriestr. 25, 91710 Gunzenhausen, Germany

Our website is hosted by Hetzner. When you visit our website, server log files are automatically collected containing the following data: IP address, date and time of the request, page/URL accessed, referrer URL, browser and operating system used, amount of data transferred, and the HTTP status code.

Server log files are stored for a period of 14 days and then automatically deleted. Storage is necessary to ensure trouble-free operation and to detect misuse.

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stable and secure operation).

A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Hetzner. Data processing takes place exclusively in Germany/EU.

SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons. This ensures that data you transmit to us is encrypted and cannot be read by third parties.

Data Collection When Using Our Service

Use Without Registration

When using the free trademark search without registration, the following data is processed:

  • Search term (brand name) — transmitted to our backend for similarity research and to OpenAI for embedding generation
  • IP address — to enforce the daily limit (max. 3 searches per day) and for bot detection via Cloudflare Turnstile
  • Language preference — stored as a cookie (NEXT_LOCALE) for 1 year

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the service and protection against abuse).

Use With Registration

For registered users, the following additional data is processed:

  • Clerk user ID — links your account with our data. Your email address, name, and password are stored and processed exclusively by Clerk.
  • Search queries — search term, optionally selected Nice classes and brand description
  • Saved searches — search term, timestamp, and user ID are stored on our backend so you can retrieve your research
  • Quota and billing data — number of searches used, plan type, expiry date, and purchase ID
  • Consent records — which usage notices you accepted and when

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest).

You can delete your saved searches at any time. For complete deletion of all personal data, please contact us by email at <email/> (Art. 17 GDPR). Payment data is retained for up to 10 years in accordance with statutory retention periods (§ 147 AO, § 257 HGB). The provider reserves the right to delete all user data after 180 days of inactivity. Affected users will be notified by email in advance.

https://clerk.com/legal/privacy

Third-Party Services

Authentication — Clerk

Clerk, Inc. (USA) — DPF certified

We use Clerk for user authentication and management. The following data is processed: email address, name, IP address, session cookies, and device information.

Clerk is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an adequacy decision by the EU Commission pursuant to Art. 45 GDPR, which ensures an adequate level of data protection at certified US companies.

Clerk sets the following cookies: __session (session token for authentication), __client_uat (timestamp to verify session freshness).

Legal basis: Art. 6 (1) lit. b GDPR (contract performance) and Art. 6 (1) lit. f GDPR (legitimate interest).

https://clerk.com/legal/privacy
Payment Processing — Stripe

Stripe Payments Europe Ltd., Dublin, Ireland — DPF certified

We use Stripe for payment processing. Name, email address, payment data, and transaction data are processed. Payment data (credit card numbers, bank details) is processed directly by Stripe and is never stored on our servers.

Stripe is PCI-DSS Level 1 certified — the highest security standard in the payment card industry.

Legal basis: Art. 6 (1) lit. b GDPR (contract performance).

https://stripe.com/privacy
Data Processing — OpenAI

OpenAI Ireland Ltd. (for EEA users)

For generating embeddings, only brand names and search terms are sent to the OpenAI API. No personal data such as IP addresses, names, or email addresses is transmitted to OpenAI.

The Embedding API operates under a zero-retention policy — data is not stored. According to OpenAI's API Data Usage Policy, data submitted via the API is not used to train models.

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in service functionality).

https://openai.com/policies/row-privacy-policy/
Web Analytics — Google Analytics

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

This website uses Google Analytics to analyze user behavior. Cookies are used and your IP address is collected in anonymized form (IP anonymization). The following data is collected: page views, time on page, device type and screen resolution, operating system and browser, approximate location (country/city), referrer (referring page), and interaction events (e.g. clicks, scroll depth).

The retention period for Analytics data is set to 14 months. After this period, the data is automatically deleted.

Legal basis: Art. 6 (1) lit. a GDPR (consent). Google Analytics is only activated with your explicit consent.

You can object to data collection by Google Analytics at any time by adjusting your cookie settings or installing the browser add-on to disable Google Analytics: https://tools.google.com/dlpage/gaoptout

https://policies.google.com/privacy
Email & Domain — Strato

STRATO AG, Pascalstraße 10, 10587 Berlin

Our email communication (<email/>) and domain registration are operated through Strato. During email communication, the following data is processed: sender and recipient address, subject, date and time of sending, IP address of the sending mail server, and the content of the message.

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in reliable email communication) and Art. 6 (1) lit. b GDPR (pre-contractual measures when making contact).

A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Strato. Data processing takes place exclusively in Germany.

https://www.strato.de/datenschutz/
Bot Protection — Cloudflare Turnstile

Cloudflare, Inc. (USA) — DPF certified

To protect against automated requests, we use Cloudflare Turnstile. This transmits your IP address, browser type, operating system, and interaction data to Cloudflare to distinguish human users from bots. Turnstile is only used for unauthenticated users.

Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse protection).

https://www.cloudflare.com/privacypolicy/

Cookies

This website uses the following cookies:

Strictly Necessary Cookies

These cookies are essential for the website to function and cannot be disabled. They are used for user authentication and session management (Clerk).

Analytics Cookies

These cookies are only set with your explicit consent and are used to analyze user behavior (Google Analytics).

CookiePurposeDuration
__sessionClerk — Authentication token for user loginSession end
__client_uatClerk — Timestamp to verify session freshnessSession end
NEXT_LOCALELanguage preference — stores the selected language (de/en)1 year
_gaGoogle Analytics — Unique user distinction across sessions2 years
_ga_*Google Analytics — Associates page views with a session, calculates time on page and page counts2 years
__stripe_midStripe — Fraud prevention and unique device identification1 year
__stripe_sidStripe — Session identifier for payment processing30 minutes
cf_clearanceCloudflare Turnstile — Proof of passed bot challengemax. 30 minutes

A cookie consent mechanism will be implemented shortly. Analytics cookies will only be set after your explicit consent.

Without cookies: The strictly necessary cookies are required to use the service. Without them, login is not possible. If you decline analytics cookies, the website will function without restrictions — no usage analysis will take place.

Data Transfers to Third Countries

Some of the services we use process data in the USA: Clerk (authentication), OpenAI (embedding generation), and Cloudflare (bot protection). All three companies are certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is based on an adequacy decision by the EU Commission pursuant to Art. 45 GDPR, which ensures an adequate level of data protection at certified US companies.

All other services (Hetzner, Strato, Stripe, Google Analytics) process data exclusively within the EU or Germany.

Automated Decision-Making

No automated decision-making within the meaning of Art. 22 GDPR takes place. The similarity analysis serves exclusively informational purposes and has no legal effect on users.

Contact & Updates

If you contact us by email, your details (name, email address, content of your inquiry) will be stored to process your request. This data will be deleted once your inquiry has been fully processed, but no later than 6 months after the last contact, unless legal retention obligations apply.

Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in processing inquiries) and Art. 6 (1) lit. b GDPR (pre-contractual measures).

We reserve the right to update this privacy policy to reflect changes in the legal situation or changes to our service.