01
Who we are#
"IPkit" (also "we," "us," or "our") refers to Four Birds Limited, a New Zealand company with its registered office at 566A Cove Road, RD2, Waipu 0582, New Zealand. We are the data controller for personal data processed through IPkit's consumer-facing surfaces. Where IPkit acts as a data processoron behalf of a customer (for example, where a customer's application sends end-user queries to api.ipkit.ai), the customer is the controller and our Data Processing Addendum governs that relationship.
02
Scope#
This policy applies to all IPkit properties:
- ipkit.ai — the website and customer portal (account, keys, billing, dashboards).
- api.ipkit.ai — the programmatic API.
This policy does not apply to third-party sites that IPkit links to. The official intellectual-property registers and similar public sources we draw data from have their own privacy notices governing their collection and publication of that data; IPkit's own processing of personal data contained in those sources is covered by this policy — see the section "Personal data from public IP registers" below.
03
Information we collect#
3.1 Information you provide
- Account information. Email address, display name, and (optionally) company name when you sign up at ipkit.ai. If you sign in with Google or GitHub, we receive the email and avatar associated with that account.
- Billing information.Plan selection and billing identifiers. Card details are handled by Stripe and never reach IPkit's servers — we receive only a customer identifier, the last four digits, and the card brand.
- Support and waitlist correspondence. The email address and any content you send to
hello@ipkit.ai,privacy@ipkit.ai, or via a waitlist form on the apex. - Search queries and content.Brand names, descriptions, classes, jurisdictions, and any other text or file you submit through IPkit's search, monitoring, or analysis tools.
3.2 Information collected automatically
- Authentication state. A Supabase-issued session cookie on ipkit.ai (see our Cookie Policy).
- API usage telemetry. For each call to api.ipkit.ai we record the authenticated key, request path, response status, latency, byte counts, IP address, and a timestamp. We use this for rate-limiting, billing, abuse detection, and product improvement.
- Server logs. Standard request logs (IP, user-agent, path, status, timestamp) generated by our hosting providers for security and operational diagnostics.
- Fraud-prevention signals.During checkout, Stripe collects device and network signals (described in Stripe's own privacy notice).
We do not run analytics cookies, advertising trackers, or session-replay tools on the apex (ipkit.ai). See the Cookie Policy for the full breakdown.
3.3 Information from third parties
We receive limited identity information from OAuth providers (Google, GitHub) when you choose to sign in with them, and operational data from our sub-processors (e.g., Stripe sends events about subscription state). We do not buy personal data from data brokers. We also obtain records from official intellectual-property registers, which can include personal data of parties named in those registers — see "Personal data from public IP registers" below.
04
How and why we use information#
Each purpose below maps to a lawful basis under the EU/UK General Data Protection Regulation. Comparable bases apply under the California Consumer Privacy Act ("CCPA") and other regional laws.
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Provide the service you requested (search, monitoring, analysis) | Account, queries, usage | Contract (Art. 6(1)(b)) |
| Authenticate sessions and protect accounts | Account, session cookie, IP | Contract; legitimate interest in security |
| Bill paid plans and prevent payment fraud | Billing identifiers, usage counts | Contract; legal obligation (tax records) |
| Enforce rate limits and detect abuse | Usage telemetry, IP, key metadata | Legitimate interest (Art. 6(1)(f)) |
| Improve the product (aggregate analysis, debugging) | Usage telemetry, error logs | Legitimate interest |
| Send service emails (security, billing, material changes) | Email address | Contract; legal obligation |
| Send product updates and waitlist follow-ups | Email address | Consent — withdrawable at any time |
| Comply with legal requests and enforce our Terms | As needed | Legal obligation; legitimate interest |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. IPkit's analyses are presented for human review — they do not auto-file, auto-oppose, or auto-reject anything on your behalf.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA.
06
Sub-processors#
The following providers process personal data on our behalf:
| Provider | Purpose | Primary region |
|---|---|---|
| Vercel | Hosting | US / global edge |
| Supabase | Authentication and database | EU/UK (Ireland / London) |
| Neon | Database for register-data store | EU/UK (London) |
| Fly.io | API application hosting | EU/UK (London) for register-data systems |
| Stripe | Billing, payments, fraud prevention | US / EU |
| Resend | Transactional email and waitlist messaging | US |
| Tinybird | Aggregated usage analytics | EU |
| Upstash | Caching and operational data store | Global edge |
| Cloudflare | DNS, DDoS protection, edge security | Global edge |
| Cloudflare R2 | Object storage (register documents and images) | EU |
The systems that store personal data drawn from public IP registers (see "Personal data from public IP registers") are hosted with EU- and UK-resident providers and regions.
We engage each sub-processor under a written contract with data-protection terms at least as protective as those in this policy. Material changes to this list will be reflected here and notified to account holders by email at least 30 days in advance — see our Data Processing Addendum.
07
International transfers#
IPkit is operated by Four Birds Limited, a New Zealand company. New Zealand benefits from an adequacy decision of the European Commission (and equivalent UK adequacy regulations), so personal data may flow from the EEA and UK to IPkit in New Zealand without additional safeguards. The systems storing personal data drawn from public IP registers are EU/UK-resident (see the sub-processors section). Where personal data is otherwise transferred out of the EEA, UK, or Switzerland — for example to US-based sub-processors for hosting, email, or billing — we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures (encryption in transit and at rest) as applicable.
08
Retention#
| Category | Retention |
|---|---|
| Account profile | While your account is open; deleted within 30 days of account closure. |
| Billing records (invoices, tax-relevant data) | 7 years after the transaction (legal obligation). |
| API usage telemetry (per-request) | 13 months, then aggregated and anonymised. |
| Search queries and inputs | While your account is open, or as set out in your enterprise agreement. |
| Public IP-register records (incl. any personal data) | While the record remains published in the source register and the source remains part of the service; suppressed records excluded on request; development-only copies deleted if a source is not launched. See "Personal data from public IP registers". |
| Server and security logs | 90 days, unless retained longer to investigate an incident. |
| Waitlist email addresses | Until you unsubscribe or 24 months of inactivity, whichever comes first. |
| Support correspondence | 3 years after the ticket is resolved. |
Backups containing personal data are encrypted and aged out on the same schedules; in practice deletion from backups completes within 35 days of the live-system deletion.
09
Security#
We protect personal data with administrative, technical, and physical safeguards appropriate to its sensitivity. These include encryption in transit (TLS 1.2+) and at rest, least-privilege access controls with single sign-on for staff, mandatory two-factor authentication for production systems, structured logging and alerting, periodic vulnerability scanning, and an incident-response runbook. We follow a security-by-default model: raw API keys are shown to you exactly once at creation and stored on our side only as a keyed hash (HMAC-SHA256).
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator with jurisdiction as required by applicable law.
10
Your rights#
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (subject to legal-retention exceptions).
- Restrict or object to certain processing.
- Receive a portable copy of data you provided to us.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local supervisory authority (EU/UK residents) or the California Privacy Protection Agency.
Exercise any of these rights by emailing privacy@ipkit.ai. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice). We will not discriminate against you for exercising a privacy right.
California residentsmay designate an authorised agent to make requests on their behalf. We will verify both the agent's authority and your identity before responding.
If you are not an IPkit user but are named in a public IP-register record we process (for example as an applicant, owner, inventor, designer, or representative), see "Personal data from public IP registers" below for what we process, why, and how to object or request suppression.
11
Personal data from public IP registers#
This section is addressed to trademark, design, and patent applicants, owners, holders, representatives, inventors, and designers whose details appear in official intellectual-property registers — whether or not they are IPkit users. It is the information notice required by Article 14 of the EU and UK GDPR.
What we process, and where it comes from
IPkit obtains records from official, publicly available intellectual-property registers and data services, including those published by the European Union Intellectual Property Office (EUIPO), the United States Patent and Trademark Office (USPTO), the World Intellectual Property Organization (WIPO — including the Madrid and Hague systems), the European Patent Office (EPO), the Japan Patent Office (JPO), IP Australia, the Intellectual Property Office of New Zealand (IPONZ), the UK Intellectual Property Office, and the Canadian Intellectual Property Office. These records identify the parties connected with a registered right and can include: the name and correspondence address of an applicant, owner, or holder; the identity of representatives (agents or attorneys) of record; and the names of inventors or designers, together with the associated right, its classifications, goods-and-services text, and status and lifecycle dates.
Most register entries identify companies, which are not personal data. This section concerns the minority of entries that identify natural persons. We do not process special categories of personal data (Article 9), and we do not enrich register records with data from any other source.
Why we process it, and our lawful basis
We process this data to operate professional intellectual-property search, clearance, monitoring, and portfolio-analysis tools for IP attorneys, in-house counsel, brand owners, and researchers. Knowing who owns or applied for a right is intrinsic to those tasks — conflict clearance, freedom-to-operate analysis, opposition watching, and portfolio research cannot be performed without proprietor identity. Our lawful basis is Article 6(1)(f) GDPR (legitimate interests): IP registers are published precisely so that third parties can determine and clear rights, and our processing serves that same purpose for professional users. We have carried out and documented a legitimate-interest assessment; you may request a summary via privacy@ipkit.ai.
What we never do with this data
We do not use register personal data to market to, rate, score, or profile natural persons. We do not sell it. We do not use correspondence addresses for promotion. We do not combine register records with data from other sources to build profiles of individuals. Access for our customers is authenticated and rate-limited; we do not provide anonymous or bulk public access to personal data.
Processing during product development
Before a data source is made available to customers, we may hold a copy of its records — including any personal data they contain — in an isolated, EU/UK-resident development environment in order to build and evaluate our systems at realistic scale. During that phase the data is not disclosed to customers or any third party. If we do not proceed with a source, the development copy is deleted.
Who receives this data
When a source is live in the service, its records are available to authenticated IPkit customers — professional users bound by our Terms of Service, which prohibit using personal data from the service for direct marketing, profiling or rating of individuals, or bulk redistribution. We also disclose data to the sub-processors listed in this policy, who process it on our behalf.
Where it is stored, and international transfers
The register-data store and its sub-processors are EU/UK-resident. IPkit is operated by Four Birds Limited, a New Zealand company; access from New Zealand is covered by the European Commission's adequacy decision for New Zealand (and the equivalent UK adequacy regulations), so no additional transfer safeguards are required for that access.
How long we keep it
We retain a register record while it remains published in the source register and the source remains part of our service, refreshed from the source's own updates and corrections. Records suppressed at a data subject's request are excluded from our serving systems. Development-only copies are deleted if the source is not taken to launch.
Your rights
If you are named in a register record we process, you may object to our processing (Article 21) or request erasure (Article 17) by emailing privacy@ipkit.ai. Because the source register is a statutory public record, we cannot remove or change your entry in the register itself — corrections must be made with the issuing office, and we ingest the register's corrections. What we can and will do, on a well-founded request, is suppress the record or the personal-data fields from IPkit's own systems so we no longer serve them. You may also request access to the data we hold about you (Article 15), and you have the right to lodge a complaint with your data-protection supervisory authority.
Controller and contact
The controller for this processing is Four Birds Limited, 566A Cove Road, RD2, Waipu 0582, New Zealand — privacy@ipkit.ai.
12
Children#
IPkit is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@ipkit.ai and we will delete it promptly.
13
Do Not Track#
Because we do not run cross-site advertising trackers, IPkit treats "Do Not Track" and Global Privacy Control signals as a no-op: there is no third-party tracking to disable.
14
Changes to this policy#
We may update this policy as the product and our infrastructure evolve. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be announced by email to account holders and via an in-product banner. Continued use of IPkit after the effective date of a change constitutes acceptance.
15
Contact#
Privacy questions and rights requests: privacy@ipkit.ai.
Postal: Four Birds Limited, 566A Cove Road, RD2, Waipu 0582, New Zealand.
We will appoint a representative in the EU under Article 27 GDPR (and in the UK under the UK GDPR, as applicable) when those provisions apply to our processing, and will publish the representative's contact details in this section.