Privacy Policy

Last updated: 25.02.2026

Important Notice: We take the protection of your personal data very seriously. This privacy policy informs you about how we process your personal data within the scope of our website and services. Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Data Controller

The data controller within the meaning of the GDPR is:

Antonio Blago
Email: service@tmpilot.ai
Website: www.tmpilot.ai

For data protection inquiries, you can contact us at any time at the email address listed above.

2. General Information on Data Processing

2.1 Scope of Processing

We only process personal data of our users to the extent necessary to provide a functional website and our services. Processing is regularly carried out only with the user's consent or when permitted by legal provisions.

2.2 Legal Bases

The processing of personal data is based on the following legal bases of the GDPR:

  • Art. 6 Abs. 1 lit. a DSGVO: User consent
  • Art. 6 Abs. 1 lit. b DSGVO: Performance of contract or pre-contractual measures
  • Art. 6 Abs. 1 lit. c DSGVO: Compliance with legal obligations
  • Art. 6 Abs. 1 lit. f DSGVO: Legitimate interests of the controller

2.3 Data Deletion and Storage Duration

Personal data is deleted as soon as the purpose of storage no longer applies. Storage may continue beyond this if required by legal provisions (e.g., tax retention periods of 6-10 years).

3. Collection and Processing of Personal Data

3.1 Registration and User Account

Data collected:

  • Email address (required)
  • Password (encrypted using pbkdf2:sha256)
  • First and last name
  • Company name (optional)
  • IP address at registration
  • Registration date

Purpose: Provision of user account, authentication, security

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

Storage duration: Until account deletion plus 30 days backup period

3.2 Trademark Search

Data collected:

  • Entered brand name
  • Product Description
  • Identified Nice classes
  • Search results and risk analysis

Purpose: Conducting trademark searches in EUIPO and DPMA registers

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

Storage duration: As long as the account is active; 30 days after account deletion

3.3 Payment Data

Data collected:

  • Payment information (processed via Stripe)
  • Email address from Stripe Checkout
  • Transaction history

Purpose: Processing of one-time payment for the premium report (EUR 29)

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

Storage duration: 10 years (tax retention obligation)

Payment processing: Payment processing is handled exclusively by Stripe. We do not store complete credit card data. stripe.com/privacy

Automatic account creation. When you make a purchase, we create a user account using the email address you provide during checkout. The legal basis is Art. 6 (1)(b) GDPR: the account is the access route to the report you purchased. We store your email address, name and the origin of the order. You can have the account deleted at any time.

3.4 Server Log Files

Each time our website is accessed, the following data is automatically stored in server log files:

  • IP address of the accessing computer
  • Date and time of access
  • Name and URL of the accessed file
  • Browser type and version
  • Operating system

Purpose: Ensuring system security, error diagnosis

Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest)

Storage duration: 7 days, then automatic deletion

3.5 Email Communication

Data collected:

  • Email address
  • Message content
  • Timestamp

Purpose: Communication, support, delivery of premium reports and payment confirmations

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

3.5a Email categories and cancellation options

We send emails in different categories. Transactional emails (invoices, payment confirmations, cancellation and security notices, client inquiries to law firms) are legally or contractually required and cannot be unsubscribed from. All promotional and informational emails (e.g. review requests, cart reminders, monthly reports, attorney recommendations) can be unsubscribed individually at any time via the following methods:

  • Click on "Unsubscribe" at the bottom of each promotional email (One-click unsubscribe as per RFC 8058)
  • Manage all categories under /einstellungen (logged-in users) or /anwalt-dashboard/einstellungen (law firms)
  • Email to service@tmpilot.ai requesting unsubscription

Legal basis for promotional emails: Art. 6 Abs. 1 lit. a DSGVO (Consent) bzw. Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in an existing business relationship according to § 7 para. 3 UWG).

Duration of storage for cancellation decision: Unlimited, as long as the account exists, so that the cancellation is respected permanently.

3.6 Lawyer Referral (Legal Consultation Leads)

Data collected:

  • First and last name
  • Email address (required)
  • Phone number (optional)
  • Free-text message (optional)
  • Linked trademark search results

Purpose: Referral to specialized trademark attorneys

Legal basis:

  • Art. 6 Abs. 1 lit. a DSGVO (Consent) - for sharing with partner law firm
  • Art. 6 Abs. 1 lit. b DSGVO (Performance of contract) - for the referral service itself

Shared data: Name, email, phone, summary of the trademark search, to the assigned partner law firm

Storage duration: Until referral completion plus 6 months, unless consent is withdrawn earlier

Right to withdraw: At any time via email to service@tmpilot.ai

3.7 Lawyer Network (Firm Registration)

Data collected:

  • Firm name, contact person, email, phone
  • Address (street, ZIP code, city, country)
  • Website URL, specializations, firm description

Purpose: Operation of the lawyer network, public firm profile, lead referral

Legal basis:

  • Art. 6 Abs. 1 lit. b DSGVO (Performance of contract) - for the subscription
  • Art. 6 Abs. 1 lit. a DSGVO (Consent) - for the publication of the firm profile

Published data: Law firm name, description, areas of expertise, website URL (Dofollow link), logo, on the public law firm page

Storage duration: Duration of subscription plus 30 days; profile removed on cancellation

Payment data: see section 3.3 (Stripe)

4. Cookies

4.1 Use of Cookies

Our website uses cookies. Cookies are small text files stored on your device.

4.2 Types of Cookies

Cookie Type Purpose Storage duration
Session Cookies Authentication, login status Until end of browser session
Language settings Storage of preferred language (de/en) Up to 1 year
CSRF Protection Protection against Cross-Site Request Forgery Session or 24 hours
Referral cookie (tm_ref) Functional: stores the referral partner (?ref=) through which you reached us, for correct commission attribution. No profiling, no sharing with third parties. 30 days

All of the aforementioned cookies are technically necessary or functional and are set without consent on the basis of Art. 6 (1) (f) GDPR (legitimate interest in reach partnerships) or Section 25 (2) TDDDG. We do not use any marketing or advertising cookies.

4.3 No Use of Tracking Tools

Important: We do not use any third-party tracking tools such as Google Analytics, Facebook Pixel, or similar. There is no tracking for advertising purposes.

5. Integration of Third-Party Services

5.1 Stripe (Payment Processing)

For payment processing, we use the service Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA.

Data transmitted: Email, payment information, transaction data

Purpose: Secure payment processing for premium reports

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

Privacy Policy: stripe.com/privacy

5.2 OpenAI (AI Analysis)

For AI-powered Nice class mapping and risk analysis, we use the OpenAI API (GPT-4o-mini).

Data transmitted: Brand name, product description, search results (for analysis)

Purpose: AI-based Nice class mapping and premium risk analysis

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

Privacy Policy: openai.com/privacy

Training Opt-Out (OpenAI):
  • We use the OpenAI API. Your data will NOT be used to train AI models.
  • DPA (Data Processing Agreement) pursuant to GDPR Art. 28 concluded
  • OpenAI stores API requests for a maximum of 30 days for abuse detection

5.3 EUIPO API (EU Trademark Register)

For searching the EU trademark register, we use the REST API of the European Union Intellectual Property Office (EUIPO).

Data transmitted: Brand name (search query)

Purpose: Querying registered EU trademarks

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

5.4 DPMA (German Trademark Register)

For searching the German trademark register, we use the public search of the German Patent and Trademark Office (DPMA).

Data transmitted: Brand name (search query)

Purpose: Querying registered German trademarks

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

5.5 PythonAnywhere (Hosting)

Our website is hosted on servers of PythonAnywhere LLP (EU server).

Data transmitted: All data collected on the website

Purpose: Provision of website infrastructure

Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest)

5.6 Ionos SMTP (Email Delivery)

For sending emails (payment confirmations, premium reports), we use Ionos SMTP.

Data transmitted: Email address, email content

Purpose: Sending transactional emails

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (Performance of contract)

6. Data Transfer to Third Countries

Some of the services used (Stripe, OpenAI) are based in the USA.

Data transfer is based on:

  • Standard Contractual Clauses (SCC): Stripe, OpenAI
  • Adequacy decision: EU-US Data Privacy Framework (where applicable)

7. Your Rights as a Data Subject

You have the following rights under GDPR:

  • Right of access (Art. 15 GDPR): You can request information about your data stored with us
  • Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data
  • Right to erasure (Art. 17 GDPR): You can request the deletion of your data
  • Right to restriction (Art. 18 GDPR): You can request the restriction of processing
  • Right to data portability (Art. 20 GDPR): You can receive your data in a structured format
  • Right to object (Art. 21 GDPR): You can object to processing based on your particular situation

7.1 Exercising Your Rights

To exercise your rights, please contact: service@tmpilot.ai

We will respond to your request within 30 days.

7.1a Self-service account deletion

You can delete your user account yourself at any time - signed in at /en/account/delete .

Process:

  • Your login is locked immediately and your account is scheduled for deletion.
  • You receive a confirmation email with a cancel link.
  • You can cancel the deletion at any time within 30 days.
  • After the 30-day period your account is permanently deleted: personal master data, brand monitoring subscriptions and email preferences are removed; completed searches and payment data are anonymised (any reference to you personally is removed).
  • Invoice receipts are retained in anonymised form for tax reasons (10 years, German GoBD).

7.2 Right to Complain to Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.

8. Data Security

8.1 Technical Measures

We employ the following security measures:

  • SSL/TLS Encryption: All data transfers are encrypted (HTTPS)
  • Password Hashing: Passwords are hashed with pbkdf2:sha256, never stored in plain text
  • Session-based Authentication: Secure session management with CSRF protection
  • Access Control: Strict permission management for database access

9. AI Transparency and EU AI Act

Transparency notice pursuant to EU AI Act: TMPilot.ai uses AI systems (OpenAI GPT-4o-mini) to assist with Nice class assignment and risk analysis. The AI does not make independent decisions. All recommendations are for informational purposes only and do not replace legal advice.

9.1 AI Systems Used

  • OpenAI GPT-4o-mini: Nice class mapping (JSON mode) and premium risk analysis

9.2 Risk Classification

Our AI application falls under the "limited risk" category pursuant to the EU AI Act, as it does not make automated decisions with legal effect and serves exclusively for informational purposes.

9.3 No Training with User Data

User data is NOT used for training AI models. We have concluded a DPA with OpenAI pursuant to GDPR Art. 28.

10. Protection of Minors

Our services are intended exclusively for persons aged 18 and older. We do not knowingly collect data from minors.

11. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements or our services. The current version can always be found on this page.

Data Protection Contact

Controller:
Antonio Blago
Email: service@tmpilot.ai
Website: www.tmpilot.ai