Privacy Policy
Last updated: 12 March 2026
PatentAuditor ("we", "us", "our") operates www.patentauditor.com. This policy explains what personal data we collect, why we collect it, and how we protect it when you use our patent valuation and commercial intelligence services.
1. Data We Collect
Information you provide
| Data | Purpose |
|---|---|
| First name, last name | Report personalisation and order communications |
| Email address | Report delivery, order confirmation, and status updates |
| Company / firm name (optional) | Report personalisation |
| Patent number | Generating your patent valuation report |
Payment data
Card details are collected and processed entirely by Stripe (our payment processor). Card numbers, CVVs, and expiry dates never touch or pass through our servers. We receive only a transaction confirmation and a truncated card identifier from Stripe. See Stripe's Privacy Policy.
Automatically collected data
- Server logs — IP address, browser type, referring URL, pages visited, and timestamps. Retained for security and debugging.
- Analytics — We use Google Analytics (GA4) to understand how visitors interact with our site. This collects anonymised usage data such as pages visited, session duration, and approximate location. See Google's Privacy Policy.
- Cookies — We use essential session cookies for site functionality and analytics cookies (Google Analytics). We do not use advertising or tracking cookies for third-party marketing.
2. How We Use Your Data
- Processing and delivering your patent valuation report
- Sending order confirmation, status updates, and report delivery emails
- Responding to your contact messages
- Processing payments (via Stripe)
- Detecting and preventing fraud or abuse
- Improving service reliability and performance
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Third-Party Processors
We use a limited number of trusted service providers to operate our service:
| Provider | Role | Data shared |
|---|---|---|
| Stripe | Payment processing | Payment card details (collected directly by Stripe) |
| Brevo | Transactional email delivery | Name, email address, order details |
| Google Analytics | Website analytics | Anonymised usage data, IP address (truncated), cookies |
| Google reCAPTCHA | Spam protection | Usage patterns, device info — see Google's Privacy Policy |
Each provider processes data under their own privacy policy and in compliance with applicable data protection laws.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your data under the following legal bases:
- Contract performance — processing your order and delivering your report (Art. 6(1)(b) GDPR)
- Legitimate interest — fraud prevention, service security, and improving our platform (Art. 6(1)(f) GDPR)
- Legal obligation — complying with tax, accounting, or legal requirements (Art. 6(1)(c) GDPR)
5. Data Retention
- Order records — retained for 7 years to comply with financial and tax record-keeping obligations.
- Generated reports — retained for 12 months after delivery to allow re-delivery if requested.
- Server logs — retained for up to 90 days, then deleted.
- Contact messages — retained until the query is resolved, then deleted within 12 months.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention requirements)
- Portability — receive your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interest
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
7. Data Security
We implement appropriate technical and organisational measures to protect your data:
- All connections are encrypted via TLS 1.3
- Payment processing is PCI DSS Level 1 compliant (handled by Stripe)
- Access to customer data is restricted to authorised personnel only
- Database backups are encrypted at rest
8. International Transfers
Your data may be processed by our service providers in countries outside your jurisdiction (including the United States). Where such transfers occur, they are safeguarded by Standard Contractual Clauses or equivalent mechanisms as required by applicable law.
9. Children's Privacy
Our service is intended for business professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected such data, please contact us for immediate deletion.
10. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page. Continued use of our service after changes constitutes acceptance of the updated policy.
11. Contact
If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.