Legal

Privacy Policy and Cryptographic Data Protocols

Formal disclosures regarding the statutory basis for processing, cryptographic profile claims, and data minimization practices.

Statutory Basis for Processing

The processing of public federal registration records operates under the statutory basis of legitimate interest, pursuant to GDPR Article 6(1)(f) and applicable consumer privacy frameworks. The compilation and indexation of this data are necessary for the legitimate interest of ensuring structural transparency within the global intellectual property system. Furthermore, all baseline practitioner data processed by the Register is subject to the principle of intentional publicity, having been affirmatively disclosed and made public by the data subject via federal registration with the United States Patent and Trademark Office (USPTO).

Data Enrichment Transparency

To enhance structural discovery, baseline federal records are augmented via a deterministic, two-pass enrichment pipeline. Pass 1 cross-references public Cooperative Patent Classification (CPC) and International Patent Classification (IPC) data extracted from external public datasets (BigQuery). Pass 2 utilizes bulk data records from the Open Data Portal (ODP) to execute authoritative registration-keyed joins. Technical specialties assigned to practitioner profiles are exclusively derived from observed filing volumes and historical classification concentration. These assignments represent quantitative historical activity, not qualitative assessments of professional competence or skill.

Trustless Cryptographic Claims

The Register implements an asymmetric Ed25519 cryptographic architecture to govern profile ownership. When a practitioner asserts control over a profile, the authentication protocol executes a local-first keypair generation. The private key is generated and isolated entirely within the local browser storage sandbox; the Register never requests, receives, or stores private keys. By deploying a zero-password architecture, the infrastructure mathematically neutralizes the risk of centralized credential exfiltration and unauthorized profile hijacking.

Transactional Alerts & Metadata

The platform generates programmatic transactional alerts to notify practitioners of inbound profile visibility. To preserve data integrity and prevent programmatic syndication, these triggers are secured by strict behavioral gating; alerts are queued only when client-side interactions indicate verified human-driven gestures, effectively neutralizing bot-driven spam. In accordance with strict data minimization principles, the Register does not store or process IP addresses or identifying details of inbound viewers. The system exclusively records the country of origin to facilitate the delivery of the transactional alert.

The Erasure Protocol

Practitioners maintain an absolute, unconditioned right to demand the erasure of their public profile. Upon receipt of a removal request, the system executes a manual purge within a strict 24-hour processing window. To guarantee permanent exclusion and prevent inadvertent re-ingestion during daily USPTO roster synchronizations, the removed registration identifier is permanently appended to a deterministic suppression list.

U.S. Cloud Act & Sovereignty

The Register's public interface is distributed via a global edge network infrastructure. Recognizing that standard cloud environments located within United States jurisdiction—or operated by entities subject to the U.S. CLOUD Act—present severe sovereignty and professional secrecy hazards, the system dictates strict architectural separation. Practitioners managing unfiled, pre-grant disclosures are strongly advised to execute all specification drafting and flat-XML compilation locally utilizing the isolated Syntax workbench, thereby ensuring zero transmission of sensitive disclosures to extraterritorial cloud environments. The long-term infrastructure roadmap for the Register is anchored to certified Confidential Computing and Sealed Cloud architectures—utilizing hardware-level memory encryption standards such as Intel SGX and AMD SEV—and verified Sovereign Cloud networks (e.g., STACKIT, T-Cloud) to categorically eliminate the risk of compelled third-party data access.

Email privacy support