Privacy Policy

Your data protection is our priority

📅 Last updated: October 11, 2025 • Version: 1.0

1. Introduction

At Morpheus Mark, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our AI-powered trademark enforcement platform.

As a legal technology service operating in the trademark enforcement domain, we handle sensitive information with the utmost care and comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Data Controller Information

The data controller responsible for your personal information is:

Company: Hucke & Sanker PLLC

🇺🇸 US Office: 43 West 43rd Street, Suite 363, New York, NY 10036

🇩🇪 EU Office: Zusestraße 40, 50858 Cologne, Germany

🇬🇧 UK Office: 15-17 Middle Street, Brighton BN1 1AL, United Kingdom

Email: [email protected]

Phone (US): +1 201 228 0455

Phone (DE): +49 221 650 88 272

Phone (UK): +44 1 273 035 374

3. Types of Personal Data We Collect

3.1 WhatsApp Inquiry Data

When you submit an inquiry via WhatsApp, we collect:

  • WhatsApp phone number
  • Your inquiry message content
  • Timestamp of your request
  • Any additional information you voluntarily provide

3.2 Portal Authentication Data

For client portal access, we collect:

  • Email address and password
  • Two-factor authentication codes
  • Login timestamps and IP addresses
  • Session information and authentication tokens

3.3 Trademark Enforcement Data

As part of our trademark enforcement services, we process:

  • Trademark registration details and documentation
  • Evidence of trademark infringement
  • Seller and marketplace information
  • Legal case files and correspondence
  • Settlement agreement details
  • Payment information for settlements

3.4 Technical Data

We automatically collect certain technical information:

  • IP address and geolocation data
  • Browser type and operating system
  • Device information
  • Pages visited and time spent on our platform
  • Referral source

5. Your Data Rights

5.1 Right to Access

You have the right to request access to your personal data that we hold, including information about how we process it and who we share it with.

5.2 Right to Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

5.3 Right to Erasure

You may request deletion of your personal data, subject to legal retention requirements for evidence and compliance purposes.

5.4 Right to Restrict Processing

You can request that we limit the processing of your personal data in certain circumstances.

5.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format.

5.6 Right to Object

You can object to processing of your personal data based on legitimate interests, unless we can demonstrate compelling legitimate grounds for the processing.

📧 How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days of receipt.

6. Security Measures

We implement robust security measures to protect your personal data:

🔐 Encryption

End-to-end encryption for data transmission and AES-256 encryption for data storage

🛡️ Access Control

Multi-factor authentication and role-based access control

🔍 Regular Audits

Quarterly security assessments and penetration testing

📋 Compliance

ISO 27001 and SOC 2 Type II certified infrastructure

7. Cookies and Tracking

We use a privacy-first approach to cookies and tracking technologies:

7.1 Essential Cookies

  • Authentication tokens for secure portal access
  • Session management and security features
  • Language and preference settings

7.2 Audience measurement — always on, without cookies

We measure how our pages are used with Plausible Analytics, which we host ourselves on our own server in Frankfurt am Main, Germany. Plausible sets no cookies and assigns no identifier that recognises you across visits; your IP address is not stored, but combined with a daily-changing random value into a hash that cannot be reversed and becomes meaningless after 24 hours. The measurement data never leaves our server and is not passed to any analytics provider. Legal basis: Art. 6(1)(f) GDPR. Consent under § 25 TDDDG is not required because nothing is stored on or read from your device. You may object under Art. 21 GDPR.

7.3 Advertising measurement — only with your consent

If you accept in the consent dialog, we additionally load the Google Ads conversion tag (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) and the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). Both set cookies and recognise whether a click on one of our ads led to a visit here. Both providers build a profile of your behaviour and link it to data they already hold; if you are signed in with them, this visit can be attributed to your account. We have no influence over how far that linking goes.

Legal basis: § 25(1) TDDDG and Art. 6(1)(a) GDPR — your consent, and nothing else. Third-country transfers: both providers also process data in the United States, on the basis of the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework. Retention: cookie lifetimes are set by Google and LinkedIn, not by us; according to their own information they range from a few days to 24 months depending on the cookie. Their notices govern: Google and LinkedIn.

🍪 Our Cookie Policy

Without your consent, nothing on this site sets an advertising cookie and no advertising service is loaded — the scripts are present in the page source but disabled (type="text/plain") and only run once you accept. A tracking pixel that cannot be switched off is deliberately not included. We do not sell your data.

The button deletes your stored decision and reloads the page. You will then be asked again, and no advertising service loads until you make a new choice. Withdrawal takes effect for the future; the lawfulness of processing carried out beforehand is unaffected. Cookies already set by Google and LinkedIn can additionally be removed in your browser settings.

8. International Data Transfers

Your personal data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework: Certified for EU-US data transfers
  • Standard Contractual Clauses: EU-approved contractual provisions
  • UK Extension: Recognized for UK-EU data transfers
  • Binding Corporate Rules: Internal data protection policies

Our servers are located in secure data centers in the United States, Germany, and the United Kingdom, ensuring compliance with regional data protection requirements.

9. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected:

Data Type Retention Period Legal Basis
Inquiry Data 2 years Legal compliance
Case Files 10 years Statute of limitations
Financial Records 7 years Tax requirements
Authentication Logs 1 year Security purposes

10. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or for other operational reasons. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending email notifications to our clients
  • Displaying prominent notices in the client portal
  • Updating the "Last updated" date at the top of this policy

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:

Email: [email protected]

Phone (US): +1 201 228 0455

Phone (DE): +49 221 650 88 272

Phone (UK): +44 1 273 035 374

🇺🇸 US Address: 43 West 43rd Street, Suite 363, New York, NY 10036

🇩🇪 EU Representative: Zusestraße 40, 50858 Cologne, Germany

🇬🇧 UK Office: 15-17 Middle Street, Brighton BN1 1AL, United Kingdom

🏛️ Regulatory Authorities

If you believe our processing of your personal information infringes on applicable data protection laws, you have the right to lodge a complaint with a supervisory authority.

This Privacy Policy is part of our commitment to transparency and data protection.