Privacy Policy
Last updated: 6 September 2026
1. Controller
Trabos Digital Matrix
Owner: Astrid Trabos
Hänkelbodenstrasse 1, 8173 Neerach, Switzerland
Email: [email protected]
2. Data collected & purposes
2.1 User account
When you register we collect your email address and a hashed password (bcrypt). This data is stored on our database server: at Contabo GmbH (Lauterbourg, France/EU) for EU customer data and at Infomaniak Network SA (Geneva, Switzerland) for data of Swiss customers. Purpose: authentication, service delivery, invoicing.
2.2 Trademark checks (search queries)
Signed in: Every trademark check you run while signed in is stored and linked to your account — the name checked, the target markets chosen, the industry, the Nice classes as well as the score and risk indicator of the result. The purpose is the delivery of the service: your check history is a promised part of the product (the “Search history” page with re-run, CSV export and score trend). Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention: 12 months from creation, then automatic deletion (section 4). You can delete individual entries or your entire history yourself at any time (“Search history” page) and download your checks in full via the data access request (section 5).
Without signing in: We store nothing. Checks run by visitors who are not signed in remain solely in the memory of the running session. Without an account there would be nobody the checked name could be attributed to — and therefore neither a purpose for storing it nor a way to provide access or deletion.
Your checks are not evaluated for training or analytics purposes. The former consent for such a data corpus (“consent gate”) was decommissioned on 6 September 2026; nothing is collected and nothing is evaluated.
2.3 Payment data
Payments are processed exclusively via Stripe, Inc. We do not store card data. Stripe is PCI-DSS certified. The transfer of data to the USA takes place on the basis of EU standard contractual clauses (SCCs).
2.3a Domain registration (optional)
If you register a domain through LegalBrandCheck, you provide registrant data (name, email, phone number, postal address) — this is legally required for registration with the competent registry (mandatory WHOIS details). We work with two registrar partners, Cloudflare, Inc. and Dynadot Inc.; which of them actually registers your domain depends automatically on the chosen domain ending (for example “.ch” is handled exclusively via Dynadot). Payment is made via Stripe as described under 2.3. Purpose: performance of a contract (Art. 6(1)(b) GDPR). Retention: for the duration of the domain registration plus statutory retention periods.
2.4 Server logs
IP address (anonymised after 24 hours), user agent, timestamp and the URL requested are processed for the operation and the security of the service.
2.5 Cookies
Technically necessary and set without consent: one httpOnly/Secure cookie that protects sign-in via an external provider against forged requests (<code>lbc_oauth_state</code>, SameSite=Lax, lifetime 10 minutes). Your sign-in itself does not depend on a cookie: session token (<code>legalname_token</code>), the session ID of our own statistics (<code>lbc_session_id</code>, see 2.6.1), your language choice and your cookie decision (<code>lbc_ga4_consent</code>) are stored as first-party localStorage items in your browser and are not transmitted to third parties. Only if you give explicit consent in the cookie banner does Google Analytics additionally set its own analytics cookies (<code>_ga</code> and others, see 2.7); without consent none of them is set. No advertising cookies, no retargeting.
Also technically necessary and set without consent: your display choice (light, dark or system) in the cookie trabos_theme (lifetime one year, SameSite=Lax, no tracking) and in your browser's local storage (trabos-theme). Stored only on your device as well: the selected customer type (lbc-customer-type), the state of the introduction dialog (lbc-onboarding) and, when signed in, the session token (legalname_token). These entries are only transmitted to us when you are signed in and save your settings to your account; you can delete them at any time in your browser settings.
2.6 Our own usage statistics (first-party, cookieless)
To analyse search volume, traffic sources and conversion (free checks vs. subscription) we collect usage events via components we operate ourselves (first-party). No cookies are set and no data is transferred to third parties. There are two separate collections using different techniques — we describe them individually because they must be assessed differently under data protection law.
2.6.1 Events from the browser (localStorage session ID)
We record: a random session ID that cannot be traced back to the person (localStorage), coarse origin data (country, via server-side IP-to-country resolution — the IP address itself is not stored), plus the referrer domain and UTM parameters on the first page view. Legal basis: legitimate interest in improving the service (Art. 6(1)(f) GDPR).
2.6.2 Server-side funnel measurement (derived session key)
In addition, the server itself counts at which point of the flow (home page → check → result → pricing page → checkout → payment) visitors drop off. This measurement works without JavaScript; it is triggered by the calls to our own interface and by a 1×1 pixel image from our own server (/api/funnel/px.gif). For each event we store:
- the step and the timestamp,
- the language identifier derived from
Accept-Language(e.g. “de-ch”), - the country from the IP-to-country resolution (the IP address itself is not stored),
- a coarse device class from the user agent (crawler / mobile / tablet / desktop) — the user agent itself is not stored,
- a session key: a non-reversible hash value (HMAC-SHA256) derived from IP address and user agent with a random key drawn afresh every day.
Not stored are: IP address, user agent in plain text, email address, customer identifier, search term, URL parameters and referrer.
An honest assessment: As long as a given day's random key exists, a session key could be recomputed if the IP address and the browser are known. We therefore treat the rows of the current day as personal (pseudonymous) data, not as anonymous data. At the change of day (00:00 UTC) the previous day's random key is deleted; from that moment no row can be attributed to a person any more — not even by us. Older rows are therefore anonymous.
Your rights in this respect: For the current day you can view your own rows without signing in (GET /api/funnel/me) and delete them (DELETE /api/funnel/me). The request only returns rows belonging to your own IP address and your own browser; other people's rows cannot be reached this way. For rows from earlier days there is nothing left to attribute, which is why access and erasure are moot there (Art. 11 GDPR). Retention: 400 days (see section 4). Storage location: our public database at Contabo (Lauterbourg, France / EU) — it contains no customer data. Legal basis: legitimate interest in a robust measurement of the reach of, and drop-off from, our own offering (Art. 6(1)(f) GDPR). Since no cookies are set and no information is read from your device, no consent under Art. 5(3) of the ePrivacy Directive / Section 25 TDDDG is required for this.
2.7 Google Analytics 4 (only with your consent)
In addition to our own statistics (2.6) we optionally offer Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This service is loaded exclusively after explicit consent given via the consent banner — without consent there is no contact with Google whatsoever. If you consent, Google sets analytics cookies (among others _ga, _ga_<Container-ID>) and processes pseudonymous usage data (client ID, page views, device and browser information). A transfer to Google LLC (USA) takes place on the basis of the EU standard contractual clauses (SCCs). Withdrawal: your decision itself is not stored in a cookie but as the entry lbc_ga4_consent in your browser's localStorage — deleting cookies alone therefore does not withdraw consent. The consent banner no longer appears once a decision has been made. To withdraw, use the button at the end of this section or clear the site data (localStorage) in your browser settings. Where consent has been given, certain events (e.g. completed purchases) may additionally be transmitted to Google server-side via Google's Measurement Protocol using the same client ID (_ga cookie), in order to increase the reliability of measurement across page navigations — this happens exclusively after consent and never for users who have declined. Legal basis: consent (Art. 6(1)(a) GDPR, Art. 31(1) revFADP).
Current state in this browser: no decision yet. Without a decision nothing is loaded.
2.8 Handover to legal representation (filing / legal review)
If you commission a trademark filing or a legal review from a check result, we hand your details over to a legal representative by machine. LegalBrandCheck does not review anything itself and does not take on a mandate — we merely transmit. Transmitted are: your name and email address, the trademark name checked, the Nice classes and jurisdictions requested, your free-text message to the representative as well as a link to the full check report and its verification hash.
The recipient is either the representative you name yourself or — if you do not name one — a partner firm we have on file. In both cases the firm is an independent controller within the meaning of the GDPR, not our processor: it is bound by professional secrecy and decides on further processing itself. Its own privacy policy applies to the processing there. If no representative can be determined, no transfer takes place and we tell you so explicitly.
Legal basis: performance of the order you initiated (Art. 6(1)(b) GDPR). Retention of the handover record with us: until your account is deleted or until an erasure request — the self-service deletion below removes handover records both via your account ID and via your contact email address, and therefore also if you placed the order without an account. We cannot retrieve the email already sent to the representative; please contact the firm for that.
3. Sub-processors & third parties
The following service providers process personal data on behalf of Trabos Digital Matrix or receive anonymised search queries. With all providers outside Switzerland / the EEA, EU standard contractual clauses (SCCs) are in place as the legal basis for the data transfer.
| Provider | Purpose | Jurisdiction | Data transferred | Legal basis |
|---|---|---|---|---|
| Contabo GmbH | App server (processing of all accounts, including the Swiss ones) & database hosting of the EU accounts | Lauterbourg, France (EU) | Database content: customer data of the EU region (PII, search queries). In addition, all requests and admin evaluations run through this server — in doing so, data of Swiss accounts is also processed temporarily in memory without being stored there. Furthermore: the public database with the funnel measurement (section 2.6.2) | Data processing agreement (GDPR Art. 28) |
| Infomaniak Network SA | Database hosting of Swiss customer data | Geneva, Switzerland | Customer data of the CH region (PII, search queries) | Data processing agreement (FADP Art. 9) |
| Stripe, Inc. | Payment processing | USA (EU establishment Dublin, IE) | Email, subscription status — no card data on our side (card data is processed exclusively by Stripe) | SCCs (EU standard contractual clauses) |
| Resend, Inc. | Transactional emails (registration, notifications) | USA | Email address, message content | SCCs |
| TrabosLex (Trabos Digital Matrix) | Trademark law engine (internal API) | Contabo (FR/EU) or Infomaniak (CH) | Search term (no PII) | Intra-group assignment (same controller) |
| Legal representation / partner firm (only if commissioned, see 2.8) | Trademark filing or legal review — either the representative you name yourself or a partner firm on file | Various (worldwide, depending on the firm commissioned) | Name, email, trademark name, Nice classes, jurisdictions, free text, link to the check report | Performance of a contract (Art. 6(1)(b) GDPR) — not processing on our behalf: the firm is an independent controller |
| Cloudflare, Inc. | DNS / CDN | USA (EU PoPs) | IP address (transit, no logging enabled) | Legitimate interest (Art. 6(1)(f)) / SCCs |
| RDAP registrars (various) | Domain availability queries | Various (global) | Search term (no PII) | Anonymous — no PII transferred |
| TMview / WIPO / EUIPO / USPTO | Trademark register queries | EU / CH / USA | Search term (no PII) | Anonymous — no PII transferred |
| OpenCorporates Ltd. | Company register queries (global search) | UK | Search term (no PII) | Anonymous — no PII transferred |
| Apify Technologies s.r.o. | Company register fallback when OpenCorporates is unreachable (uses UK Companies House, French INSEE SIRENE and global GLEIF LEI data internally) | EU/Czech Republic | Search term (no PII) | Anonymous — no PII transferred |
| Official company registers (Norway Brønnøysund, Finland PRH/YTJ, Ireland CRO) | Direct company register queries for these countries | Norway / Finland / Ireland / EEA | Search term (no PII) | Anonymous, open government data — no PII transferred |
| Google Ireland Limited (Google Analytics 4) | Optional usage statistics — only after consent | Ireland (transfer to Google LLC, USA) | Client ID, pseudonymous usage data | Consent (Art. 6(1)(a) GDPR) + SCCs |
| Cloudflare, Inc. (for domain registration) | Domain registration as registrar partner (tier 1, depending on the domain ending) | USA | Name, email, phone, postal address (mandatory WHOIS details) | Performance of a contract (Art. 6(1)(b) GDPR) + SCCs |
| Dynadot Inc. (for domain registration) | Domain registration as registrar partner (fallback, e.g. .ch) | USA | Name, email, phone, postal address (mandatory WHOIS details) | Performance of a contract (Art. 6(1)(b) GDPR) + SCCs |
| Anthropic PBC (Claude API) | AI name generation, multilingual meaning check of the generated candidates and their brand-fit scoring; also a fallback path for transliterating foreign-language search terms when the European translation engine is unavailable | USA | Your product/business description verbatim (free text, up to 500 characters) and the industry you state; the name candidates generated from it; in the fallback case, the brand name you entered. No account, contact or payment data, no IP address. The free-text field is not filtered — please do not enter personal data there. | Legitimate interest (Art. 6(1)(f) GDPR) + SCCs |
| Microsoft Ireland Operations Ltd. (Azure Cognitive Services) | Machine translation: legal statements at runtime and foreign-language search terms; first engine — queried first, DeepL only as a fallback | Switzerland or EU/EEA, depending on the configured Azure region | Search term (no PII) | Legitimate interest (Art. 6(1)(f) GDPR) |
| DeepL SE | Machine translation of foreign-language search terms and of legal content statements at runtime; second engine — queried only when Azure is not configured or fails | Germany (EU) | Search term (no PII) | Legitimate interest (Art. 6(1)(f) GDPR) |
4. Retention periods
- Account data: until the account is deleted. Deletion via the self-service below is an immediate hard delete — there is no grace period and no restore.
- Payment data: card data is held exclusively by Stripe (see 2.3). When an account is deleted we delete your subscription records; records subject to the Swiss accounting obligation (paid domain purchases, commission-bearing affiliate clicks) are kept for 10 years — with the reference to your account removed.
- Trademark checks (search queries) of signed-in customers: 12 months from the date of creation, then deleted automatically (legal basis: performance of a contract, Art. 6(1)(b) GDPR). Checks without signing in are not stored in the first place (see 2.2)
- Stored check reports, first-use certificates and shared report links: until the account is deleted. A shared link additionally expires 7 days after it was created and is no longer served after that; the stored record itself remains until the account is deleted. There is no time-based deletion for this data — stated explicitly here, because a promised period that nothing carries out would be worse than none at all. A share link can be revoked at any time.
- Handover records to a legal representative (see 2.8): until the account is deleted or until an erasure request
- Funnel measurement (see 2.6.2): 400 days from collection. The daily random key with which a row could be attributed to a person at all is already deleted at the change of day (00:00 UTC)
- Server logs (IP): anonymisation after 24 hours
5. Your rights (Swiss FADP & GDPR Art. 15–22)
- Access to the data stored
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability (machine-readable format)
- Withdrawal of a consent given (Google Analytics, see 2.7) at any time without giving reasons — via the button in section 2.7
- Complaint to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or the competent EU data protection authority
Please send requests to: [email protected]
6. Legal bases
Personal data is processed on the basis of the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR Art. 6(1)(a), (b), (c), (f)).
Exercise your rights
You can export your data or delete your account right here — no email needed.