Privacy Policy
Information on data protection in accordance with Art. 13/14 GDPR
Last updated: March 2026
Data Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Legal basis: Art. 6 (1) GDPR
No data protection officer has been appointed, as the requirements under Art. 37 GDPR are not met.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — You can request information about the personal data we hold about you at any time.
- Right to rectification (Art. 16 GDPR) — You can request the correction of inaccurate data or the completion of incomplete data.
- Right to erasure (Art. 17 GDPR) — You can request the deletion of your personal data, provided no legal retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR) — You can request that the processing of your data be restricted, e.g. if you contest the accuracy of the data.
- Right to data portability (Art. 20 GDPR) — You can request that we provide your data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21 GDPR) — You can object to the processing of your data at any time if it is based on Art. 6 (1) lit. f GDPR.
- Right of withdrawal (Art. 7 (3) GDPR) — You can withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
To exercise your rights, you can contact us at any time by email at <email/>.
You also have the right to lodge a complaint with a supervisory authority. The responsible authority is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin, email: <emailBerlin/>.
Hosting & Security
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Our website is hosted by Hetzner. When you visit our website, server log files are automatically collected containing the following data: IP address, date and time of the request, page/URL accessed, referrer URL, browser and operating system used, amount of data transferred, and the HTTP status code.
Server log files are stored for a period of 14 days and then automatically deleted. Storage is necessary to ensure trouble-free operation and to detect misuse.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stable and secure operation).
A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Hetzner. Data processing takes place exclusively in Germany/EU.
SSL/TLS Encryption
This website uses SSL/TLS encryption for security reasons. This ensures that data you transmit to us is encrypted and cannot be read by third parties.
Data Collection When Using Our Service
Use Without Registration
When using the free trademark search without registration, the following data is processed:
- Search term (brand name) — transmitted to our backend for similarity research and to OpenAI for embedding generation
- IP address — to enforce the daily limit (max. 3 searches per day) and for bot detection via Cloudflare Turnstile
- Language preference — stored as a cookie (NEXT_LOCALE) for 1 year
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the service and protection against abuse).
Use With Registration
For registered users, the following additional data is processed:
- Clerk user ID — links your account with our data. Your email address, name, and password are stored and processed exclusively by Clerk.
- Search queries — search term, optionally selected Nice classes and brand description
- Saved searches — search term, timestamp, and user ID are stored on our backend so you can retrieve your research
- Quota and billing data — number of searches used, plan type, expiry date, and purchase ID
- Consent records — which usage notices you accepted and when
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest).
You can delete your saved searches at any time. For complete deletion of all personal data, please contact us by email at <email/> (Art. 17 GDPR). Payment data is retained for up to 10 years in accordance with statutory retention periods (§ 147 AO, § 257 HGB). The provider reserves the right to delete all user data after 180 days of inactivity. Affected users will be notified by email in advance.
https://clerk.com/legal/privacyThird-Party Services
Authentication — Clerk
Clerk, Inc. (USA) — DPF certified
We use Clerk for user authentication and management. The following data is processed: email address, name, IP address, session cookies, and device information.
Clerk is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an adequacy decision by the EU Commission pursuant to Art. 45 GDPR, which ensures an adequate level of data protection at certified US companies.
Clerk sets the following cookies: __session (session token for authentication), __client_uat (timestamp to verify session freshness).
Legal basis: Art. 6 (1) lit. b GDPR (contract performance) and Art. 6 (1) lit. f GDPR (legitimate interest).
https://clerk.com/legal/privacyPayment Processing — Stripe
Stripe Payments Europe Ltd., Dublin, Ireland — DPF certified
We use Stripe for payment processing. Name, email address, payment data, and transaction data are processed. Payment data (credit card numbers, bank details) is processed directly by Stripe and is never stored on our servers.
Stripe is PCI-DSS Level 1 certified — the highest security standard in the payment card industry.
Legal basis: Art. 6 (1) lit. b GDPR (contract performance).
https://stripe.com/privacyData Processing — OpenAI
OpenAI Ireland Ltd. (for EEA users)
For generating embeddings, only brand names and search terms are sent to the OpenAI API. No personal data such as IP addresses, names, or email addresses is transmitted to OpenAI.
The Embedding API operates under a zero-retention policy — data is not stored. According to OpenAI's API Data Usage Policy, data submitted via the API is not used to train models.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in service functionality).
https://openai.com/policies/row-privacy-policy/Web Analytics — Google Analytics
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
This website uses Google Analytics to analyze user behavior. Cookies are used and your IP address is collected in anonymized form (IP anonymization). The following data is collected: page views, time on page, device type and screen resolution, operating system and browser, approximate location (country/city), referrer (referring page), and interaction events (e.g. clicks, scroll depth).
The retention period for Analytics data is set to 14 months. After this period, the data is automatically deleted.
Legal basis: Art. 6 (1) lit. a GDPR (consent). Google Analytics is only activated with your explicit consent.
You can object to data collection by Google Analytics at any time by adjusting your cookie settings or installing the browser add-on to disable Google Analytics: https://tools.google.com/dlpage/gaoptout
https://policies.google.com/privacyEmail & Domain — Strato
STRATO AG, Pascalstraße 10, 10587 Berlin
Our email communication (<email/>) and domain registration are operated through Strato. During email communication, the following data is processed: sender and recipient address, subject, date and time of sending, IP address of the sending mail server, and the content of the message.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in reliable email communication) and Art. 6 (1) lit. b GDPR (pre-contractual measures when making contact).
A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Strato. Data processing takes place exclusively in Germany.
https://www.strato.de/datenschutz/Bot Protection — Cloudflare Turnstile
Cloudflare, Inc. (USA) — DPF certified
To protect against automated requests, we use Cloudflare Turnstile. This transmits your IP address, browser type, operating system, and interaction data to Cloudflare to distinguish human users from bots. Turnstile is only used for unauthenticated users.
Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse protection).
https://www.cloudflare.com/privacypolicy/Cookies
This website uses the following cookies:
Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be disabled. They are used for user authentication and session management (Clerk).
Analytics Cookies
These cookies are only set with your explicit consent and are used to analyze user behavior (Google Analytics).
| Cookie | Purpose | Duration |
|---|---|---|
| __session | Clerk — Authentication token for user login | Session end |
| __client_uat | Clerk — Timestamp to verify session freshness | Session end |
| NEXT_LOCALE | Language preference — stores the selected language (de/en) | 1 year |
| _ga | Google Analytics — Unique user distinction across sessions | 2 years |
| _ga_* | Google Analytics — Associates page views with a session, calculates time on page and page counts | 2 years |
| __stripe_mid | Stripe — Fraud prevention and unique device identification | 1 year |
| __stripe_sid | Stripe — Session identifier for payment processing | 30 minutes |
| cf_clearance | Cloudflare Turnstile — Proof of passed bot challenge | max. 30 minutes |
A cookie consent mechanism will be implemented shortly. Analytics cookies will only be set after your explicit consent.
Without cookies: The strictly necessary cookies are required to use the service. Without them, login is not possible. If you decline analytics cookies, the website will function without restrictions — no usage analysis will take place.
Data Transfers to Third Countries
Some of the services we use process data in the USA: Clerk (authentication), OpenAI (embedding generation), and Cloudflare (bot protection). All three companies are certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is based on an adequacy decision by the EU Commission pursuant to Art. 45 GDPR, which ensures an adequate level of data protection at certified US companies.
All other services (Hetzner, Strato, Stripe, Google Analytics) process data exclusively within the EU or Germany.
Automated Decision-Making
No automated decision-making within the meaning of Art. 22 GDPR takes place. The similarity analysis serves exclusively informational purposes and has no legal effect on users.
Contact & Updates
If you contact us by email, your details (name, email address, content of your inquiry) will be stored to process your request. This data will be deleted once your inquiry has been fully processed, but no later than 6 months after the last contact, unless legal retention obligations apply.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in processing inquiries) and Art. 6 (1) lit. b GDPR (pre-contractual measures).
We reserve the right to update this privacy policy to reflect changes in the legal situation or changes to our service.