Privacy Statement
This statement explains which personal data IPG ClearCheck processes, why, how long we keep it, and what rights you have. We process as little personal data as possible: there are no accounts, and a free scan is not stored on our servers. Only when you order a full report do we keep that scan for a limited time.
1. Controller
The controller is PS Not Just Another Agency B.V., trading as IPGateway and operating the IPG ClearCheck service, Laan van Kronenburg 14, 1183 AS Amstelveen, Chamber of Commerce number 55023533. For privacy questions, contact info@ipgateway.io.
2. Which data we process
- Search terms: the brand name, company name or Chamber of Commerce number you enter. This can be the name of a sole trader or another natural person.
- Photos for text recognition: if you use the camera, the text is read entirely in your browser. The photo is not uploaded to us.
- Scan results: the result of a scan is cryptographically signed and sent to your browser, where it stays during your visit (and temporarily in the tab's session storage during payment). For a free scan we do not keep a copy on our servers.
- Scans for a full report: when you start the payment for a full report, we store that scan — the search term, the trademark owner found, the results of the checks and the sources consulted, including any personal data from public registers — so that you can download the report again and so that we can show which sources were consulted.
- Temporary search cache: to limit the load on public trademark registers, we briefly keep the answers of the European trademark overview to a search (the search term and the public trademark data, including holder names).
- Payment data: when you order a full report, Stripe processes your payment details, email address and billing details (including your VAT number if you provide one). We receive the payment status and the billing details needed for the invoice — never your full card details. The invoice describes the report ordered, including the brand name, and contains a link and a reference to your report.
- Watermark in the report: every page of the report you download carries a light footer with the report reference, the date and your email address in masked form (for example f***@example.com), so that a shared report stays traceable to the purchase. The report itself is not otherwise protected: you can read, print, copy and forward it.
- Technical data: IP address, browser type, time of request and error messages in server logs, needed to run and secure the service. To prevent misuse, your IP address is also kept briefly in the server's working memory to limit the number of scans per visitor.
- Quality reports: if a scan contains contradictory or incomplete outcomes, an internal report with the search term and the outcomes is created for our team, so that we can investigate the error.
- Personal data from public registers: a report can contain personal data published in public registers, such as names of sole traders, insolvent debtors, court-appointed administrators, beneficial owners or persons on the EU sanctions list.
3. Purposes and legal bases
- Running a scan and delivering a report you ordered, including downloading it again later — performance of a contract (Article 6(1)(b) GDPR).
- Handling payments, invoicing and keeping financial records — legal obligation (Article 6(1)(c) GDPR).
- Showing on request which sources a report is based on, and handling complaints about a report — legitimate interest (Article 6(1)(f) GDPR).
- Adding a report reference and a masked purchaser identifier to the report, to discourage uncontrolled distribution and to investigate misuse — legitimate interest (Article 6(1)(f) GDPR).
- Securing the service, preventing misuse, limiting the load on public registers and solving errors — legitimate interest (Article 6(1)(f) GDPR).
- Including personal data from public registers in reports, so that businesses can assess the risks of a deal — legitimate interest (Article 6(1)(f) GDPR). We only consult registers that are public for this purpose and only show data relevant to the assessment. The registers we consult are trademark, company, insolvency and sanctions registers; we do not consult criminal or judicial records.
4. Automated analysis and scoring
ClearCheck automatically analyses the information from the sources consulted and produces an advisory score. Where the result concerns a natural person, such as a sole trader, this can amount to profiling. ClearCheck does not take decisions that have legal effects or similarly significant effects on a person: the user reads the underlying results, verifies every possible match and decides.
5. If you appear in a report
A report can contain personal data about you that we did not get from you but from a public register — for instance as a sole trader, trademark holder, beneficial owner, insolvent debtor, court-appointed administrator, or a person on the EU sanctions list.
We do not notify each of those people individually. We hold no contact details beyond what the register publishes, a report is seen only by the one business that ordered it, and tracing and writing to everyone named would take disproportionate effort. We rely on the exception in Article 14(5)(b) GDPR, and this statement is the public notice that goes with it.
What we do instead: we use only registers that are public for this purpose, we show only what is relevant to assessing a trademark or a counterparty, we keep the data for 90 days, and we never publish a report. You can ask us what we hold about you, object to the processing, or ask for a correction — see “Your rights”. If the register itself is wrong, only the register can correct the source, so we recommend contacting it as well.
6. Processors and recipients
- Vercel Inc. — hosting and private storage of scans for full reports and of the temporary search cache. The application runs in Vercel's Frankfurt (EU) region. Vercel is a United States company; it and its subprocessors can process technical data, metadata and support data outside the EEA. See “International transfers”.
- Stripe — payment processing and invoicing. For payment data, Stripe also acts as an independent controller under its own privacy policy.
- jsDelivr (cdn.jsdelivr.net) — delivers the text-recognition program and language files to your browser when you use the camera. That provider sees your IP address, not your photo.
- Public registers and their operators — receive the search term, or the name of the trademark owner found, when a scan consults them.
- Internal message channel — our quality and error reports go to our own server logs. If we route them to an external channel as well (Slack or Microsoft Teams, for example), we will name that provider here before we switch it on.
We have data processing agreements with our processors. We do not sell personal data.
7. International transfers
Vercel and Stripe are part of groups with entities in the United States. Where personal data is transferred outside the European Economic Area, we rely on the EU–US Data Privacy Framework for suppliers certified under it, and otherwise on the European Commission's standard contractual clauses. We check per supplier which entity we contract with and which of the two applies.
8. Retention
- Free scans: not stored on our servers; they remain in your browser until you close or clear it.
- Scan for a full report, payment not completed: deleted after one day.
- Scan for a paid full report: kept in full for 90 days, so you can download the report again and we can show which sources were consulted. After 90 days we delete the search term, trademark owner, results, sources and all personal data from public registers, and the report can no longer be downloaded.
- What remains after those 90 days: the report reference, the scan date and the score. Those belong to the invoice, so we keep them for as long as the invoice — seven years — and then delete them too.
- Payment and invoice data (at Stripe and in our records): seven years, as Dutch tax law requires. The invoice names the report you ordered, including the brand name you searched for. That brand name therefore stays in our financial records for seven years, even though the scan itself is deleted after 90 days.
- Temporary search cache: at most 24 hours.
- IP address for limiting scans: at most 10 minutes, in working memory only.
- Server logs and internal quality reports: at most 30 days, unless needed longer to investigate an incident.
Deletion and reduction after these periods happen automatically every day. We only keep personal data longer if we need it for a complaint, a dispute or a legal claim, and then only for as long as that takes.
9. Cookies
We set no cookies for ordinary visitors: the site is in one language, there are no accounts, and we use no tracking or advertising cookies and no analytics. No cookie consent is therefore needed. On a trade-fair device we can switch on a demonstration mode, which sets one functional cookie (clearcheck-demo) on that device. During payment, Stripe's own pages set their own cookies, described in Stripe's privacy policy. If we ever add analytics, we will update this statement first.
10. Your rights
You have the right to access, rectify and erase your personal data, to restrict processing, to data portability and to object to processing based on legitimate interest. If a report contains your personal data from a public register, you can object or ask for correction; we will assess this, and we recommend also contacting the register concerned. For a stored scan, please mention the report reference printed at the bottom of the report.
Send your request to info@ipgateway.io. We respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your country.
11. Security
Connections are encrypted (HTTPS). Scan results are cryptographically signed, so we can tell whether a result has been altered, and a payment belongs to exactly one scan. Stored scans are kept in private storage that is not publicly accessible, and a report is only produced after we have verified with Stripe that this scan was paid for.
The download link on your invoice works as a key: anyone who has that link can download the report until the 90 days are up. Treat it as confidential. Access to stored scans, logs and payment data is limited to authorised IPG staff.
12. Changes and contact
We may update this statement; the current version and its date are always on this page. Questions: info@ipgateway.io.