Back to home
Trademark SDK

Privacy Policy

Information obligations under Art. 13 and 14 General Data Protection Regulation (GDPR) · Effective: 21/07/2026

We provide a software platform and API (the "Service") that enables developers, agencies and businesses to search, monitor and file trademarks across multiple jurisdictions. In the following we inform you about the processing of personal data ("data") when you use our website, dashboard and API.

1. Who is responsible for data processing and how can you contact us?

Controller for data processing is: Trademark SDK, Vienna, Austria. If you have any questions or concerns regarding the processing of your data, you can contact us at: privacy@trademarksdk.com.

2. What data is processed, for what purpose and for what duration?

We process your data in the manner described below. If we process your data for any other purpose, we will inform you separately before processing begins. Required fields are marked with (*). Providing all other data is voluntary; if you do not provide required data we will generally not be able to deliver the requested service.

2.1 Data processing when visiting our website

Processed data:IP address*, date and time of the request*, time zone difference to GMT*, content of the request*, HTTP status code*, transferred data volume, referrer URL, browser type and version*, operating system*, device identifier.
Purpose:Delivering the website, ensuring stability and security, protecting against attacks (e.g. DDoS, bot traffic).
Legal basis:Our legitimate interest (Art. 6(1)(f) GDPR) in providing a secure and stable website.
Duration:Server log data is stored for a maximum of 30 days, longer only in case of a security incident.
RecipientPurposeLocationBasis for third-country transfer
Cloudflare, Inc.Edge hosting, CDN, DDoS protection, WAFUSA / global edgeStandard Contractual Clauses (SCC)
Lovable ABApplication hosting and deployment platformSweden / EUWithin the EEA

2.2 Data processing when creating and using an account

Processed data:Email address*, password (stored as a salted hash)*, full name, company name, billing address, VAT ID, customer number*, date and time of registration*, login timestamps, IP address, device and browser information, user role.
Purpose:Creating and managing your account, authentication, providing access to the dashboard and API, customer communication, fraud prevention.
Legal basis:Performance of contract (Art. 6(1)(b) GDPR) and our legitimate interest in account security (Art. 6(1)(f) GDPR).
Duration:For the duration of the contractual relationship. After deletion of the account, data is kept only as long as required by statutory retention obligations (in particular § 132 BAO – 7 years for tax-relevant documents).
RecipientPurposeLocationBasis for third-country transfer
Supabase, Inc. (as part of Lovable Cloud)Database, authentication, file storageEU (Frankfurt)Within the EEA
Cloudflare, Inc.Serverless backend execution, edge networkUSA / global edgeStandard Contractual Clauses (SCC)

2.3 Data processing when using social sign-in

We offer a "Continue with Google" sign-in option. Legal basis is your consent (Art. 6(1)(a) GDPR), which you can revoke at any time by deleting your account or revoking access in your Google account. When you sign in, Google transmits your name, email address, profile picture URL and Google account ID to us. The provider may also process this transaction on its own servers, including in the USA, on the basis of Standard Contractual Clauses.

RecipientPurposeLocationBasis for third-country transfer
Google Ireland Ltd. / Google LLCOAuth authentication ('Sign in with Google')Ireland / USAStandard Contractual Clauses (SCC)

2.4 Data processing for payments and invoicing

Processed data:Billing name*, billing address*, country*, VAT ID (for EU B2B reverse charge), email address*, purchased plan / amount*, invoice number*, payment status*, last 4 digits of the card / payment method type, IP address used during checkout. Full card data is collected and stored exclusively by our payment processor – we never see or store full card numbers.
Purpose:Processing payments, issuing invoices, complying with Austrian tax law (UStG, BAO), fraud prevention, accounting.
Legal basis:Performance of contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR, in particular § 132 BAO).
Duration:7 years from the end of the year in which the transaction took place (§ 132 BAO).
RecipientPurposeLocationBasis for third-country transfer
Stripe Payments Europe, Ltd.Payment processing, subscription management, invoicingIrelandWithin the EEA (sub-processing in USA under SCC)
Austrian tax authority (Finanzamt)Statutory tax reportingAustriaWithin the EEA
External tax advisor / accountantBookkeeping, year-end accounts, auditAustriaWithin the EEA

2.5 Data processing for trademark search, monitoring and filing

Processed data:Trademark text / wordmark*, logo files, goods and services description (Nice Classification)*, jurisdictions of interest*, applicant name and address*, applicant legal form, representative details (if any), priority claims, prior registrations, correspondence with trademark offices, application and registration numbers, status of proceedings, opposition data.
Purpose:Performing trademark availability searches, providing monitoring of trademark registers, preparing and submitting applications to the competent trademark offices on behalf of the applicant, handling office actions.
Legal basis:Performance of contract (Art. 6(1)(b) GDPR). Where data is processed on behalf of your end customers, you act as controller and we act as processor under a separate Data Processing Agreement (Art. 28 GDPR).
Duration:For the duration of the trademark right plus statutory retention obligations (§ 132 BAO – 7 years).
RecipientPurposeLocationBasis for third-country transfer
EUIPO (European Union Intellectual Property Office)Filing and prosecution of EU trade marksSpainWithin the EEA
WIPO (World Intellectual Property Organization)Filing and prosecution of international (Madrid) trademarksSwitzerlandAdequacy decision
USPTO (United States Patent and Trademark Office)Filing and prosecution of US trademarksUSAArt. 49(1)(b) GDPR (necessary for the performance of the contract)
Other national trademark officesFiling and prosecution in the selected jurisdictionWorldwide depending on jurisdictionArt. 49(1)(b) GDPR (necessary for the performance of the contract) or SCC
Cooperating trademark attorneys / local agentsLocal representation where legally requiredWorldwide depending on jurisdictionArt. 49(1)(b) GDPR, where applicable SCC

2.6 Data processing for API usage, logging and abuse prevention

Processed data:API key identifier*, request timestamps*, endpoint called*, response code, request and response payload metadata, IP address*, user agent, rate-limit counters, error stack traces.
Purpose:Operating the API, metering usage for billing, rate limiting, debugging, security monitoring, abuse and fraud prevention.
Legal basis:Performance of contract (Art. 6(1)(b) GDPR) and our legitimate interest in the security and stability of the Service (Art. 6(1)(f) GDPR).
Duration:Detailed logs up to 90 days, aggregated usage metrics for the duration of the contract plus statutory retention periods.
RecipientPurposeLocationBasis for third-country transfer
Cloudflare, Inc.Edge logs, WAF, bot managementUSA / global edgeStandard Contractual Clauses (SCC)
Supabase, Inc. (as part of Lovable Cloud)Application database and structured logsEU (Frankfurt)Within the EEA

2.7 Data processing for transactional and product email

Processed data:Email address*, name, account ID*, email content (e.g. verification link, password reset, filing status update, invoice receipt), delivery, bounce and complaint events.
Purpose:Sending transactional emails required for the contractual relationship (account verification, security notifications, billing receipts, status updates on trademark filings).
Legal basis:Performance of contract (Art. 6(1)(b) GDPR) and our legitimate interest in secure, reliable operation (Art. 6(1)(f) GDPR).
Duration:Email logs and suppression data up to 12 months, longer where required by law.
RecipientPurposeLocationBasis for third-country transfer
Mailgun Technologies, Inc. (Sinch)Delivery of transactional emails, bounce and complaint handlingEU (where available) / USAStandard Contractual Clauses (SCC)

2.8 Data processing when using AI-assisted features

Processed data:Prompts and context you submit (which may include trademark terms, goods and services descriptions, applicant data you provide), generated AI responses, model identifier, token usage.
Purpose:Generating classification suggestions, similarity assessments, drafting assistance and other AI-supported features of the Service.
Legal basis:Performance of contract (Art. 6(1)(b) GDPR). You are responsible for not submitting unnecessary personal data into prompts.
Duration:Prompts and responses may be retained for a limited period (typically up to 30 days) by the model provider for abuse monitoring; we do not use your prompt data to train models.
RecipientPurposeLocationBasis for third-country transfer
Lovable AI GatewayRouting AI requests to the selected model providerEUWithin the EEA
Google Ireland Ltd. / Google LLC (Gemini models)AI model inferenceIreland / USAStandard Contractual Clauses (SCC)
OpenAI Ireland Ltd. / OpenAI, L.L.C. (GPT models)AI model inferenceIreland / USAStandard Contractual Clauses (SCC)

2.9 Data processing for customer support

Processed data:Name*, email address*, account ID, content of your message*, attachments, timestamps.
Purpose:Answering your support requests and improving the Service.
Legal basis:Performance of contract / pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest (Art. 6(1)(f) GDPR).
Duration:As long as necessary to handle your request, plus statutory retention obligations.

2.10 Data processing for the assertion and defence of legal claims

Processed data:All data you have provided in the context of the contractual relationship.
Purpose:Assertion and defence of legal claims.
Legal basis:Our legitimate interest or that of third parties (Art. 6(1)(f) GDPR) in asserting and defending legal claims.
Duration:As long as necessary for this purpose, plus statutory retention obligations.
RecipientPurposeLocationBasis for third-country transfer
Courts and administrative authoritiesDefence and assertion of legal claims, compliance with legal obligationsWorldwide depending on jurisdictionArt. 49(1)(e) GDPR
Legal counsel and tax advisorsAdvisory services and defence and assertion of legal claimsWithin the EEAWithin the EEA

3. Is there automated decision-making, including profiling?

No. We do not use automated decision-making within the meaning of Art. 22 GDPR to establish or carry out our business relationship with you or to make other decisions that would significantly affect you in a similar way.

4. Data collected from other sources (Art. 14 GDPR)

In some cases we receive data not directly from you, but from the following sources:

Data / categorySourcePublicPurpose
Trademark register data (existing marks, owners, status)EUIPO, WIPO, USPTO and other national trademark officesYesSearch, monitoring and filing services
Company / VAT dataEU VIES, public commercial registersYesVAT validation, invoicing, reverse charge eligibility
Payment status, chargeback informationStripe Payments Europe, Ltd.NoPerformance of the contract, fraud prevention

5. End-customer data (processor role)

Where you use the Service to handle trademark matters for your own clients ("end customers"), you are the controller and we act as processor on your behalf within the meaning of Art. 28 GDPR. In this case our standard Data Processing Agreement (DPA) applies in addition to this Privacy Policy and governs the processing of end-customer personal data, the engagement of sub-processors and our technical and organisational measures.

6. Your rights regarding the processing of personal data

You have the right to (i) request information about whether and which personal data we hold about you and to receive copies of such data, (ii) request rectification, completion or erasure of personal data that is inaccurate or processed unlawfully, (iii) request that we restrict the processing of your personal data, (iv) object to the processing of your personal data under certain circumstances or withdraw any consent previously given, (v) request data that you have provided to us in a transferable format, and (vi) lodge a complaint with the Austrian Data Protection Authority (www.dsb.gv.at) or with another supervisory authority in the EU, in particular at your place of residence or work.

To exercise any of the above rights, please contact us by email at privacy@trademarksdk.com.

7. Security

We use industry-standard technical and organisational measures to protect your data, including TLS 1.2+ in transit, encryption at rest, hashed passwords, scoped API keys, row-level security in our database, least-privilege access controls and audit logs. No method of transmission or storage is 100% secure; you should keep your account credentials and API keys confidential.

8. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our processors or applicable law. The current version is always available at this URL with its effective date.

As of 21/07/2026