Privacy Policy
Last updated: 10 September 2026. This policy explains how we collect, use, and protect your personal data.
1. Data controller
Trademark Dashboard is operated by Decentralised Finance Software Ltd, a company registered in England and Wales (Company No: 16838716).
Registered address: Moxon House, Moxon Street, London, W1U 4EY.
We are registered with the UK Information Commissioner's Office as a Data Controller. Our ICO Registration Number is ZC110187. You can verify our entry on the public ICO Register of Data Controllers.
If you have questions about this policy or your personal data, contact us at [email protected].
2. What data we collect
We collect the following categories of personal data:
- Account and contact data: email address provided when you sign up, subscribe to our newsletter, or purchase a report.
- Search queries: the trademark names, classes, and filters you enter when using our search tools. We use these to provide results and improve the service. Temporary ChatGPT research snapshots are described in Section 5d.
- Usage data: pages visited, features used, browser type, device type, and IP address. Collected via Google Analytics 4 only with your consent.
- Payment data: processed securely by Stripe. We do not store your card details on our servers. Stripe acts as an independent data controller for payment processing.
- Cookie data: see our Cookie Policy for full details.
3. Lawful basis for processing
Under the UK General Data Protection Regulation (UK GDPR), we process your data on the following bases:
- Consent: for analytics cookies (Google Analytics 4), marketing communications, and remarketing / retargeting cookies (Google Ads, LinkedIn Insight Tag) — the latter two only when you explicitly select “Accept All” on our cookie banner. You can withdraw consent at any time by clearing the banner choice in your browser.
- Contract: to provide the services you have requested, including search results, clearance reports, and account management.
- Legitimate interests: to improve our services, detect fraud, maintain security, and to promote our services through advertising — including building advertising audiences with Google (Customer Match) and improving the accuracy of our conversion measurement (Google Enhanced Conversions). Where we share data with Google on this basis it is cryptographically hashed beforehand, and you have the right to object at any time (see Section 5). We balance these interests against your rights and freedoms.
- Legal obligation: where we are required to retain data by law (e.g. financial records for HMRC).
4. How we use your data
- To provide and improve our trademark search and clearance tools
- To send our newsletter and service notifications (with your consent)
- To process payments for premium reports
- To analyse usage patterns and improve the platform (anonymised data only, with consent)
- To query the public-availability of brand names across third-party platforms (see Section 5b) and surface those results to you within our tools
- To measure the performance of our advertising and to build advertising audiences with Google, using hashed contact data (see Section 5)
- To comply with legal obligations
5. Data sharing
We do not sell your personal data. We share data only with the following third-party processors, each of which is bound by data processing agreements:
- Google Analytics (Google LLC): anonymised usage analytics. Only activated with your cookie consent. Data may be transferred to the US under Standard Contractual Clauses.
- Stripe (Stripe, Inc.): payment processing. Stripe acts as an independent data controller for payment data.
- Hetzner Online GmbH: server hosting (Germany). All UK trademark data and application data is hosted within the EU.
- Clerk (Clerk, Inc.): account authentication and identity management (your email address and name). Data may be transferred to the US under Standard Contractual Clauses.
- Mailing Pigeon: delivery of our service, account and lifecycle emails (your email address and name, and the email-preference / consent status you set). Marketing emails are sent only on the lawful basis described in this policy and every one includes an unsubscribe link; you can opt out at any time.
- Google Ads (Google LLC): to measure the effectiveness of our advertising and to build advertising audiences, we may share a limited set of your contact details — your email address, and where available your name, phone number, and country — with Google. This data is cryptographically hashed (SHA-256) on our systems before it is transmitted, so Google does not receive these details in readable form. It is used for Google’s “Customer Match” (recognising existing customers, building similar audiences, and where we choose excluding existing customers from prospecting campaigns) and “Enhanced Conversions” (improving the accuracy of our conversion measurement). Google processes this data in accordance with its Ads Data Processing Terms, and data may be transferred to the US under Standard Contractual Clauses. You can object to this sharing or request deletion at any time by contacting us at [email protected].
- Meta, LinkedIn, X (Twitter) and Reddit advertising platforms: to build matched advertising audiences (“Custom Audiences” / “Matched Audiences”) and measure ad performance, we may share a limited set of contact details — your email address, and where available your name and country — with these platforms. As with Google, this data is cryptographically hashed (SHA-256) on our systems before it is transmitted, so the platform does not receive it in readable form; it is used only to recognise whether you already hold an account so we can include or exclude you from a campaign. Each platform acts under its own advertising data-processing terms, and data may be transferred outside the UK under appropriate safeguards. You can object to this sharing or request deletion at any time at [email protected].
5b. Third-party platform availability checks
To support brand-name availability checks within our tools, we query the official public APIs of major online platforms to determine whether a proposed name is already in use as a public handle, page, or domain. These checks return only a public availability status (such as “available”, “taken”, or “not found”). We do not collect, store, or share any personal data, post content, follower data, media, or private profile information belonging to any user of those platforms.
The platform APIs we may query include, without limitation:
- Instagram Graph API(Meta Platforms Inc.) — for the public availability of Instagram usernames
- X / Twitter API(X Corp.) — for the public availability of X handles
- YouTube Data API(Google LLC) — for the public availability of YouTube channel handles
- GitHub REST API(GitHub, Inc.) — for the public availability of GitHub usernames
- WHOIS / domain registry lookups— for the public availability of domain names
- Companies House (UK) and Charity Commission for England and Wales— for the public availability of company and charity names
Where a platform requires authenticated access for an anonymous availability lookup, we use the minimum-scoped credentials issued to us by that platform and do not access user-level data. Each third-party platform processes lookup requests in accordance with its own terms and privacy policy.
Use of the Instagram Graph API is subject to Meta's Privacy Policy and the Meta Platform Terms.
5c. Where we obtain your data
Most personal data we hold is provided by you directly. In addition, for our business-to-business outreach we obtain limited contact information — such as a trade-mark owner’s name, business address and, where available, company number — from public trademark registers, including the UK Intellectual Property Office register and the United States Patent and Trademark Office register. Where we also hold an email address for such a contact, we may use it for the advertising-audience matching described in Section 5, on the lawful basis set out in Section 3. If you are a trade-mark owner contacted on this basis, you have the right to object at any time at [email protected], and we will stop contacting you and remove you from any advertising audiences.
5d. ChatGPT trademark research
When you use our ChatGPT app, we receive the search names, selected registers, classes and filters, record identifiers or goods/services descriptions sent to the app tools. We return the requested register evidence to ChatGPT. Public register evidence can include names of individual trademark owners. We do not receive your full conversation merely because you connect the app.
V2 searches create temporary snapshots containing the search inputs and returned records so that you can reopen the same research on our website. Anyone with a research link can view that snapshot. Links expire after one hour and may expire earlier if the cache is full; expired files are cleared during later searches. Link expiry and physical file deletion are separate. Do not put confidential material in a search you intend to share.
A shortlist is held in the app view and, where supported, in the conversation's saved widget state. Selecting records sends that selection to ChatGPT as context. Choosing “Discuss with ChatGPT” sends a follow-up containing the search scope and selected or returned record identifiers. OpenAI processes this information under its own terms, privacy policy and your settings.
To operate and protect the service, our MCP diagnostics record tool names, timestamps, outcomes, timings, result counts, selected classes, query lengths, pseudonymous query and IP hashes, and request metadata such as user-agent and referrer. These hashes are not a guarantee of anonymity. Server access logs also contain request metadata. The V2 research workspace does not use advertising pixels, enrol you in marketing, or create an account. Opening another website page may bring you to that page's normal cookie and account controls.
6. Data retention
- Waitlist emails: retained until you unsubscribe or request deletion, or for 24 months from collection if no account is created.
- Account data: retained for the duration of your account plus 12 months after deletion, unless longer retention is required by law.
- Search queries: except for the temporary ChatGPT snapshots described in Section 5d, anonymised after 30 days. Aggregated analytics retained indefinitely.
- Payment records: retained for 7 years as required by HMRC.
7. Your rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing: request limitation of processing in certain circumstances.
- Right to data portability: receive your data in a structured, commonly used format.
- Right to object: object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email [email protected]. We will respond within one month.
8. Complaints
If you have a concern about how we have handled your personal data, please contact us first at [email protected] or [email protected]. You may also write to us at our registered address (Section 1) or reach us through any channel we use to communicate with you, including email and social media.
We will acknowledge your complaint within 30 calendar days and aim to provide a substantive outcome within 3 months of receipt. If we need longer, we will explain why and keep you informed of progress.
Under the Data (Use and Access) Act 2025 (in force from 19 June 2026), you must raise a complaint with us before escalating to the ICO, unless the ICO agrees there are exceptional circumstances.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
9. International transfers
Your data is primarily stored within the European Economic Area (Hetzner, Germany). Where data is transferred outside the EEA (e.g. Google Analytics, Stripe), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Information Commissioner.
10. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (TLS 1.2+), secure server infrastructure, access controls, and regular security reviews.
11. Children
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email (if you have an account) or by a prominent notice on our website. The “last updated” date at the top of this page indicates when the policy was last revised.
