Privacy Policy
Last updated: 31 August 2026
At Rocketmark, we help you file trademark applications with Malta's Intellectual Property Registrations Directorate (IPRD) and the EU Intellectual Property Office (EUIPO). Doing that well means handling some of your personal data — and we want to be upfront about exactly what we collect, why, and what your rights are.
This policy applies to everyone who uses rocketmark.app and explains how we handle your data in line with the EU General Data Protection Regulation (GDPR) and Maltese data protection law.
1. Who we are
Rocketmark is operated by:
Oxide Ventures Ltd
Flat 4, De La Vallette Court, Triq Piscopo Macedonia, Xemxija, Malta SPB4234
Company registration number: C101739
Email: dpo@rocketmark.app
For privacy questions, you can also reach our privacy contact (our legal counsel): Dr. Matthew Galea Debono, GD Advocates — dpo@rocketmark.app
2. What we collect
About your brand and application
Your brand name, an optional website URL, and a description of what you sell. If you use our website-scan feature, we pull information from the site you point us to using Jina AI, which parses the page content for us. If you upload a logo, we store the image file. We also record which jurisdictions you're filing in (Malta and/or the EU) and which Nice classes you select. To generate our Nice class suggestions, we send your brand details, the parsed website content, and your goods/services description to OpenAI, which processes this on our behalf.
About you as the applicant
Your name, email, and postal address. If you're filing as an individual, we need your national ID details; if you're filing as a company, we need your company registration number. We keep a record of your application's status and any correspondence with us, the Malta IPRD, or the EUIPO.
About your account
The email address you use to sign in via magic link or one-time code, and basic login activity like timestamps.
About payments
Payments are handled by Stripe. We never see or store your full card number. Stripe holds the detailed payment data under its own security and retention practices — we only keep a lightweight accounting record (see Section 6).
About how you use our site
With your consent, we use PostHog (hosted in the EU) to understand how people use rocketmark.app — things like which pages you visit and where people drop off in the application form. See Section 8 for how to control this.
Anything else you send us
If you contact us directly — through a form, email, or support chat — we keep that correspondence too.
We don't intentionally collect sensitive categories of data (health, religion, biometric data, etc.). Please avoid including this kind of information in free-text fields, like your goods/services description, unless it's genuinely necessary.
3. Why we use your data
| We use your data to… | Which data | Why we're allowed to |
|---|---|---|
| Suggest Nice classes and run a preliminary clearance check against the EUIPO register | Brand details, website content (parsed by Jina AI), goods/services description (processed by OpenAI to generate suggestions) | It's necessary to deliver the service you asked for |
| Prepare and file your application with Malta IPRD and/or EUIPO | Applicant and brand details, mark type, logo, Nice classes | Necessary to deliver the service; also required by filing rules |
| Process your payment | Payment/transaction data (via Stripe) | Necessary to deliver the service; required for our tax records |
| Let you sign in and manage your application via your dashboard | Email, login activity | Necessary to deliver the service |
| Keep you updated on your application's progress | Applicant details, application reference | Necessary to deliver the service |
| Understand how people use the site and improve the application form | Usage data (via PostHog) | Only with your consent |
| Respond when you contact us | Contact details, correspondence | Our legitimate interest in supporting our customers |
| Keep the platform secure and prevent fraud | Account, transaction, and usage data | Our legitimate interest in running a safe service |
| Meet our accounting and tax obligations | Applicant and payment records | Required by law |
One thing worth flagging: our AI-assisted Nice class suggestions and clearance checks are a starting point, not the final word. A qualified IP lawyer reviews your filing before it goes anywhere, so no decision that affects you is made by the software alone.
4. Who we share your data with
- IP offices — Malta IPRD and/or EUIPO receive your application and applicant details, because that's literally what filing a trademark involves.
- Stripe — processes your payment. Stripe is a well-established, independently regulated payment company and handles your payment data under its own privacy terms.
- Jina AI — parses the website you give us so we can understand your brand.
- OpenAI — generates our Nice class suggestions, using your brand details, parsed website content, and goods/services description.
- Google reCAPTCHA — helps us detect automated abuse on our website-scan and class-recommendation features. Google may process your IP address and interaction signals; we use this for security, not marketing.
- PostHog — our analytics provider, and only if you've consented to analytics cookies.
- Our IP lawyers — the professionals who actually prepare and file your application.
- Behind-the-scenes service providers — things like hosting and the email service that sends your magic links and status updates. These providers only process data on our instructions and under contract.
- Authorities — if we're legally required to, or to protect our rights.
We do not, and will not, sell your data.
5. Where your data goes
Most of your data stays within the EU/EEA — our analytics (PostHog) are EU-hosted, and Malta IPRD and EUIPO are both within the EEA.
Stripe processes payments through Stripe entities in the United States. This is fully covered under GDPR: Stripe uses the European Commission's Standard Contractual Clauses and is certified under the EU-U.S. Data Privacy Framework, both of which are recognised, lawful ways to move data outside the EEA while keeping it protected to EU standards. You can read more in Stripe's privacy policy: https://stripe.com/privacy
Jina AI, which parses website content for us, is based in the EU (Berlin), and we've configured it to keep processing within the EU — so no data leaves the EEA for this step.
OpenAI, which powers our Nice class suggestions, may also process your information outside the EEA — mainly in the US, via infrastructure including Microsoft Azure. This is covered by the Standard Contractual Clauses in OpenAI's Data Processing Addendum, contracted through OpenAI Ireland Limited for EEA/Swiss customers. By default, OpenAI doesn't use this data to train its models and only retains it briefly for abuse-monitoring purposes.
You might be wondering: since this information is often just what's already on your own website, or what you tell us yourself, does that change anything? Not the safeguard itself — GDPR treats it the same as any other personal data regardless of whether it's public or self-disclosed. But it does mean the information carries lower privacy risk than, say, sensitive personal data would, since it's information you've generally already chosen to make public about your own brand.
6. How long we keep your data
We don't keep data longer than we need to. Here's what that looks like in practice:
| What | How long | Why |
|---|---|---|
| Your application file (brand, applicant details, Nice classes, correspondence with IP offices) | Until your registration is complete, plus 10 years | Trademarks last 10 years and are renewable, so we keep your file around long enough to support a renewal or answer questions about the registration |
| Payment records — just the accounting essentials (invoice, amount, date, VAT details, and a reference to your Stripe transaction) | 10 years from the end of the relevant financial year | Maltese tax law requires businesses to keep accounting records for several years; 10 years covers both the VAT and income tax requirements comfortably. Your detailed payment/card data stays with Stripe under its own policies — we don't duplicate it. |
| Your account (email, login activity) | While your account is active, plus 2 years after your last activity | So we can support a dormant account if you come back, without holding onto it forever |
| Website analytics | 12–14 months | Standard practice for usage analytics — enough to spot trends, not so long that it becomes a permanent behavioral record |
| General inquiries not linked to a filing | 2 years from your last message | Enough time to handle any follow-up |
| AI clearance-check and class-recommendation logs | Tied to your application file, or 3 years if you didn't end up filing | Lets us review how the tool performed if a question ever comes up |
After these periods, we delete or anonymize the data, unless the law requires us to keep it longer.
7. Your rights
Your data is yours. You can ask us to:
- See it — get a copy of the personal data we hold about you
- Fix it — correct anything that's inaccurate or incomplete
- Delete it — ask us to erase your data, subject to some legal exceptions (e.g. we can't delete records we're legally required to keep)
- Pause how we use it — restrict processing in certain situations
- Take it with you — get your data in a portable, machine-readable format
- Object — push back on processing we base on our legitimate interests
- Withdraw consent — turn off analytics cookies at any time, no questions asked
To do any of this, just email us at dpo@rocketmark.app. We'll get back to you within a month.
If you're ever unhappy with how we've handled your data, you have the right to complain to Malta's Information and Data Protection Commissioner (IDPC) at https://idpc.org.mt, or to the data protection authority in your own EU country.
8. Cookies
We use two kinds of cookies:
- Essential cookies — keep you logged in and the site working. These don't need your permission.
- Analytics cookies (PostHog) — help us see how the site is used, but only if you say yes.
You can change your mind about analytics cookies anytime via the cookie settings link in our footer.
9. Keeping your data safe
We take reasonable technical and organisational steps to protect your data:
- Encrypted connections — All traffic to rocketmark.app is served over HTTPS (TLS), including sign-in, the filing form, checkout, and your dashboard.
- Passwordless sign-in — Accounts use Supabase Auth with magic links and one-time email codes. We do not store passwords. Session cookies are refreshed on each request, and /dashboard and /admin routes redirect unauthenticated visitors to login.
- Access controls — Applicant data is only returned by server-side code that checks your authenticated session and scopes queries to your linked customer record. Admin tools require an explicit admin role on your profile. Sensitive database operations use a server-only service key that is never sent to the browser.
- Database isolation — All application tables have row-level security enabled. Data is accessed through our application server rather than directly from client code.
- Payment security — Card details are entered and processed entirely by Stripe Checkout (a PCI-DSS Level 1 provider). We never see or store your full card number — only invoice references and transaction metadata. Stripe webhook events are verified with cryptographic signatures before we act on them.
- Private file storage — Uploaded logos and correspondence documents are stored in non-public Supabase Storage buckets. They are only served via time-limited signed URLs (typically one hour).
- Server-side secrets — API keys for OpenAI, Jina, Stripe, Resend, and Supabase are kept in server environment variables and are not exposed to client-side code.
- Webhook protection — Inbound Stripe webhooks require a valid signature. Our inbound email webhook supports an optional shared-secret check.
- Bot protection — Public website-scan and class-recommendation requests are protected with Google reCAPTCHA v3 before any AI or register lookups run.
- Analytics consent — PostHog only initialises after you explicitly opt in via the cookie banner; you can withdraw consent anytime from Cookies in the footer.
No system is 100% immune to risk, and we cannot promise perfect security — but we take these measures seriously.
10. Not for kids
Rocketmark is a business tool for adults filing trademark applications. We don't knowingly collect data from anyone under 16.
11. If this policy changes
We'll update the date at the top whenever we make changes. If something significant changes, we'll let you know — either on the site or by email.
12. Get in touch
Questions about your data or this policy? Reach out:
Oxide Ventures Ltd
Flat 4, De La Vallette Court, Triq Piscopo Macedonia, Xemxija, Malta SPB4234