Privacy Policy
Last Updated
This Privacy Policy explains how Bold and Code, Inc. ("Patentia", "we", "us"), a Delaware corporation at 1111B S Governors Ave, STE 23343, Dover, DE 19904, United States, handles personal data when you visit patentia.online, use the Patentia service, or contact us.
Invention disclosures are governed separately. The confidentiality of the technical content you submit, and our obligations over it, are set out in section 4 of our Terms of Service, which is stricter than anything required by data protection law. This Policy covers personal data. The two work together and neither reduces the other.
Summary
Question | Answer |
|---|---|
Do you use my content to train AI models? | No. Not by us, and not by our AI provider. See section 4 |
Which AI providers see my invention? | Google only. No other AI provider is used to process your disclosures. See section 4 |
Is my inventor identity sent to the AI provider? | Not by us. Inventor details are stored separately and are never added to the prompt. See section 4 |
Do you sell my personal data? | No, never. We also never disclose invention disclosures, or anything derived from them, for advertising. Our marketing website carries advertising measurement tags you can switch off; see section 3 |
Where is my data processed? | United States |
Do you collect sensitive personal data? | We do not request or require it |
Can I get my data deleted? | Yes. See section 8 |
1. What we collect
Information you give us
Category | Examples |
|---|---|
Account data | Name, email address, password (stored only as a salted hash, never in readable form), organisation, role |
Billing data | Billing contact and address, and a reference identifier from our payment processor. We never receive or store card numbers |
Customer Content | Invention disclosures, technical descriptions, drawings, documents and claim text, together with the reports, analyses, drafts and other data generated from them |
Inventor details | Where you choose to provide them: the names and contact details of inventors associated with a disclosure |
Support communications | Messages you send us, and our replies |
Information collected automatically
Usage and device data (features used, actions taken, session dates and duration, time zone, country, browser and device information), server logs, and cookies as described in our Cookie Policy.
Information from third parties
We do not enrich or supplement your account data from third-party sources. Separately from the Services, we may collect publicly available business contact information about prospective customers for outbound sales. We delete prospect contact data twenty-four months after the last interaction, or on objection, keeping only the minimum record needed to ensure we do not contact you again.
Is any of this required? Account data is required to enter into and perform our contract with you, so without a name, an email address and a valid payment method we cannot create an account or provide the Services. Everything else, including inventor details and anything you tell us in support, is optional, and its absence only limits the features that depend on it.
Sensitive data. We do not request, require or solicit special category data under GDPR Article 9, or data relating to criminal convictions under Article 10, and please do not submit it deliberately. Where an invention disclosure incidentally contains such data, we process it only as necessary to deliver the Services you have requested and on your instruction as controller, under the same protections as all other Customer Content, and you remain responsible for the Article 9(2) condition that permits it.
2. How we use it, and on what legal basis
The table below covers processing for which we are the controller: your account, billing, support and website use. Where you upload Customer Content, and where you enter inventor details, we process the personal data in that material on your behalf. For that processing you are the controller and we are the processor, and it is governed by our Data Processing Agreement rather than by the legal bases below. Delivering the reports and analyses you request, and keeping them available in your account, is part of that processor processing and is covered by the same agreement.
Purpose | Legal basis (GDPR Art. 6) |
|---|---|
Creating and administering your account | Performance of a contract |
Processing payments and issuing invoices | Performance of a contract; legal obligation |
Sending service messages (verification, password reset, billing) | Performance of a contract |
Securing the Services, preventing abuse, investigating incidents | Legitimate interests |
Improving and developing the Services using usage data only | Legitimate interests |
Marketing communications and non-essential cookies | Consent |
Contacting prospective business customers about our services | Legitimate interests, being our interest in marketing a business service to the business contacts responsible for it |
Retaining records required by United States tax and accounting law | Legitimate interests, being our interest in meeting the record-keeping rules that apply where we are established |
We do not use Customer Content to improve the Services. Product development and quality measurement are performed exclusively on publicly available patent literature and on inventions we author ourselves. Usage data, which never includes Customer Content or anything derived from it, is the only customer-derived input to product improvement.
3. We do not sell your data
We do not sell personal data. We never have and we will not.
We never disclose Customer Content for advertising. Your invention disclosures, the reports and analyses generated from them, and anything derived from them are never used for advertising, never sent to an advertising platform, and never leave the processing described in section 5. That is the commitment that matters, and it is absolute.
Separately, our marketing website carries advertising measurement tags from Google and LinkedIn, listed individually with their cookies and durations in our Cookie Policy. They exist to measure whether an advertisement led to a sign-up. Depending on how an advertising platform uses the identifiers such tags set, activity of this kind can meet the definition of "sharing" for cross-context behavioural advertising under the California Consumer Privacy Act. We would rather describe it than hide behind a definition. You can switch those tags off at any time through Cookie settings in the footer, and app.patentia.online, where you sign in and where invention disclosures are handled, loads no advertising tags and no session-recording technology, and no analytics unless you have separately accepted it there. Sign-up conversions are attributed to advertising through a measurement parameter on inbound links, described in our Cookie Policy. Nothing in that measurement sees a disclosure, a report, or any field you complete.
4. Artificial intelligence
This is the section most customers care about, so it is stated plainly.
Your content is never used to train, fine-tune or improve any AI or machine learning model. Not by us, and not by any AI provider we use.
Google is the only AI provider we use to process your disclosures. Large language model processing runs through Google's enterprise AI service, under contractual terms that prohibit Google from using prompts or responses to train or improve its models. No disclosure is sent to any other AI provider for processing.
We never add inventor identity to what we send the AI provider. When we process a disclosure, we send the technical description. The inventor names, contact details and other identifying information you enter as inventor details stay in our database and are never included in the prompt by us. What we cannot do is remove a name you have written into the body of a document you upload, so if you would rather a name never reach the AI provider, take it out before uploading.
Similarity search runs on our own infrastructure. Your disclosure text is never sent to any third party for it.
AI output is informational patent intelligence. It is not legal advice and not a substitute for a qualified patent attorney. See section 1 of our Terms of Service.
5. Who processes data on our behalf
These four subprocessors have access to Customer Content or to personal data in the course of delivering the Services:
Subprocessor | Purpose | Location | Access to invention disclosures |
|---|---|---|---|
Google LLC | Cloud infrastructure and AI inference | United States | Yes, the technical content you submit. We never add inventor identity to it |
Cloudflare, Inc. | Edge network and DNS | United States | In transit only, as the network path |
Stripe, Inc. | Payment processing | United States | No |
ActiveCampaign LLC (Postmark) | Transactional email: account verification, password reset, billing notifications | United States | No |
We will give at least thirty (30) days' written notice before adding or replacing any subprocessor on this list, except where a change is needed urgently to protect the security or availability of the Services, in which case we notify you as soon as we can. Where you are covered by our Data Processing Agreement, the thirty-day notice period applies without that exception. Customers under a Data Processing Agreement may object. Each subprocessor is bound by written confidentiality and data protection obligations appropriate to the service it provides, and we remain fully responsible to you for their acts and omissions.
Our trust center at trust.patentia.online publishes our full vendor list, which is broader than the table above because it also covers corporate service providers that support how we run the business rather than deliver the Services to you. Those providers are not subprocessors of Customer Content and the thirty-day notice commitment above does not apply to them.
Our own personnel access production systems to operate, support and troubleshoot the Services, using internal engineering and support tooling. That access is limited to personnel who strictly require it, is logged, and is bound by written confidentiality obligations.
We may also disclose personal data where required to comply with a subpoena, warrant, court order or other legal obligation; to establish or defend legal claims; to protect the vital interests of a person; or in connection with a merger, financing or sale of our business, in which case the acquirer assumes the obligations in this Policy and in section 4 of the Terms of Service. Customer Content is not disclosed during diligence or negotiation. It transfers only on completion, and only to an acquirer that has assumed our obligations under section 4 of the Terms of Service in full.
6. Cookies and tracking
We use cookies and similar technologies on our marketing website, as described in our Cookie Policy. That Policy is the authoritative list and it is more detailed than this section.
The product application is stricter than this website. app.patentia.online, where you sign in and where invention disclosures are handled, loads no advertising and no session-recording technology, and loads analytics only if you have explicitly accepted it there. There is no regional default: if you have made no choice, nothing loads. Nothing loads at all on pages reached through a link that carries a credential, such as password reset and account verification.
On the marketing website we offer a single accept-or-reject choice covering all non-essential technologies. We do not currently offer per-category selection. Two limits are worth stating here as well as in the Cookie Policy:
Outside the EEA and the UK, consent defaults to granted before you interact with the banner. Inside the EEA and the UK, no non-essential cookie or similar technology is written or read until you accept, with two exceptions we would rather state than have you find: the record of your own choice, and the third parties listed in section 6 of our Cookie Policy that are page elements rather than tags, one of which may set its own cookies if you interact with it. We determine your region from your browser's time zone rather than your IP address, so a device reporting a non-European time zone receives the default-granted experience wherever its owner happens to be. The Cookie Policy explains this and how to override it.
Four third parties load regardless of your choice, because they sit outside the consent gate rather than behind it: our demo scheduler (app.cal.com), our website platform's own analytics (events.framer.com), Google Fonts (fonts.gstatic.com) and Google Tag Manager (googletagmanager.com), which loads the consent framework itself and writes no cookies and reads no identifiers until you accept. Each receives your IP address and browser user-agent. None of them receives anything you type on our pages, although the demo scheduler receives what you enter into its own booking form if you choose to use it.
The marketing website's analytics and advertising providers are Google (Analytics and Ads), Microsoft (Clarity, session recording on marketing pages only), LinkedIn (advertising measurement), Cal.com (demo scheduling) and Framer (website hosting and page analytics). None of them has access to Customer Content. Of that list, only Google Analytics also runs on the product application, and only where you have accepted it there. The rest run on the marketing website alone. They are distinct from the Services subprocessors in section 5.
7. International transfers
We are established in the United States, and the production infrastructure for the Services runs in the United States on Google Cloud Platform. All personal data we hold as controller or processor is stored there. Our marketing website is hosted separately, as described in section 6, and Cloudflare operates a global edge network, so website traffic may pass through a point of presence outside the United States in transit.
Transfers from the European Economic Area, the United Kingdom or Switzerland rely on the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum. A Data Processing Agreement incorporating both is published at patentia.online/legal/dpa and applies where you are a controller of personal data that we process on your behalf. Our principal infrastructure subprocessors, Google, Cloudflare and Stripe, are additionally certified under the EU-US Data Privacy Framework.
On GDPR status. We process personal data in accordance with the GDPR and maintain the supporting machinery: a Record of Processing Activities under Article 30, a published subprocessor register, a documented data subject request process, breach notification procedures, and enforced multi-factor authentication on administrative and production access, with quarterly access reviews.
We are not GDPR certified, and we say so plainly. Compliance with the GDPR is a legal obligation that applies to us whether or not anyone certifies it. A voluntary certification route does exist under Article 42, through approved schemes such as the Europrivacy European Data Protection Seal issued by bodies accredited under Article 43, and we have not obtained it. Our security controls are continuously monitored and independently evidenced through our SOC 2 Type II audit, which is available under NDA. That report covers security controls rather than the whole of the GDPR, and we do not present it as a substitute for certification.
We will give at least thirty (30) days' notice before processing data in an additional jurisdiction.
8. How long we keep data, and how to have it deleted
We keep personal data while your account is active and for as long as needed to provide the Services, or longer where law requires it, for example tax and accounting records.
On termination of your account:
You have thirty (30) days to export your data, either yourself or by asking us for it in a structured, commonly used, machine-readable format.
After that period we delete it from our active systems within thirty (30) days and confirm in writing. A certificate of destruction is available on request.
Copies in backup archives are removed as those archives expire under their normal retention cycle, the longest of which does not exceed 400 days. Throughout, those copies remain isolated from further processing and remain subject to our confidentiality obligations.
Security audit logs are retained for 400 days under a retention lock that prevents early alteration or deletion. They contain no invention disclosures or report content.
Data we must retain by law is retained, isolated from further processing, and remains subject to our confidentiality obligations.
You can also request deletion at any time without closing your account. Contact privacy@patentia.online.
Account deletion removes all of it together, on the timetable set out above: what you submitted, the reports and analyses generated from it, and all data derived from either.
9. Security
Customer Content is encrypted in transit and at rest. Production systems are not directly reachable from the internet, network access is restricted, and unencrypted connections are rejected. Access to production is limited, requires two-factor authentication, and is reviewed. Security audit logging covers administrative reads, data reads and data writes.
Our current control set, policy library, standing security questionnaire and complete vendor list are published at trust.patentia.online. We hold SOC 2 Type II; the report is available under NDA through the access request flow there.
Incident notification. We will notify affected customers of a security incident involving their data without undue delay and in any event within 72 hours of becoming aware of it. Shorter notification periods are available under a negotiated agreement. Where we act as your processor, that notification is how we meet our obligation to inform you under GDPR Article 33(2). Where we act as a controller, we notify each supervisory authority whose Member State has affected individuals, within 72 hours where the breach is likely to result in a risk to those individuals, and where it is likely to result in a high risk to them we also communicate it to them directly and without undue delay. Notification covers the nature of the incident, the categories and approximate number of people and records affected, the likely consequences and the measures taken.
No system can be guaranteed impenetrable, and we do not claim otherwise. Report a security concern to security@patentia.online.
10. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access, rectify, erase, restrict processing of, object to processing of, and receive a portable copy of your personal data, and to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority.
If you are a California resident, you have the right to know what personal information we collect and how it is used and disclosed, to delete it, to correct it, to opt out of sale or sharing (we do not sell, and you can switch off the advertising measurement tags described in section 3 at any time through Cookie settings), to limit the use of sensitive personal information (we do not collect it for that purpose), and not to be discriminated against for exercising these rights. Comparable rights exist under other US state privacy laws.
You have an absolute right to object to direct marketing at any time. Tell us at privacy@patentia.online or use the unsubscribe link in any message, and we will stop and keep a suppression record so it does not restart.
How to exercise them. Email privacy@patentia.online. We will verify your identity using measures proportionate to the sensitivity of the data, and respond within one month for GDPR requests and 45 days for CCPA requests, extendable where the law permits and with notice to you. There is no charge for a reasonable request.
Where we act as a processor on behalf of a business customer, we will forward your request to that customer within three business days rather than acting on it ourselves, unless they instruct otherwise.
11. Children
The Services are not directed to anyone under 18 and we do not knowingly collect their personal data. If you believe we have, contact privacy@patentia.online and we will delete it.
12. Changes
We will post any revised version here with a new "Last updated" date. Material changes take effect thirty (30) days after posting. Changes that reduce our confidentiality obligations over Customer Content do not apply to existing customers without written agreement.
13. Contact
Purpose | Address |
|---|---|
Privacy and data subject requests | privacy@patentia.online |
Legal, agreements and DPAs | legal@patentia.online |
Security and vulnerability reports | security@patentia.online |
Support | support@patentia.online |
Bold and Code, Inc., 1111B S Governors Ave, STE 23343, Dover, DE 19904, United States.