Last updated: October 5, 2026
Privacy Policy
How notolens collects, handles, and protects information when you use our monitoring service.
1. Overview and Scope
Sebastian Graef LLC, operating as notolens (“notolens,” “we,” “us,” or “our”), provides automated brand intelligence and monitoring software designed to detect potential brand conflicts across domain registries, official trademark registers, and mobile app stores. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, submit brand queries through our check tools, register for an account, or subscribe to our monitoring service.
This Privacy Policy applies to personal information collected through our website, application interfaces, customer dashboards, and related services (collectively, the “Service”). It does not apply to third-party websites or services that may be referenced, linked, or surfaced within match records and action guides.
2. Data Controller and Roles
For the purposes of the General Data Protection Regulation (GDPR), the UK Data Protection Act, and applicable data privacy laws, Sebastian Graef LLC operates as an independent Data Controller with respect to:
- Account details, credentials, and contact information collected from our customers and authorized users.
- Payment and billing metadata associated with active subscriptions.
- Technical telemetry, device identifiers, and server access logs generated by interactions with our platform.
With respect to publicly available domain registration records (such as RDAP or WHOIS data), trademark register filings, and app store listings ingested across public sources, notolens processes such records as an independent controller pursuant to legitimate interests in delivering brand conflict intelligence and intellectual property defense.
3. Information We Collect
We collect information in three primary ways: information you provide directly, information collected automatically through your use of the Service, and information gathered from public registries and registers.
A. Information You Provide Directly
- Account and profile details: When you create an account, we collect your name, email address, and a secure cryptographic representation of your password handled by our authentication systems.
- Monitor configurations: When you configure a monitor, you submit the brand names, marks, official domains, trademark offices, and app store listings that you designate for ongoing surveillance.
- Search and preliminary check queries: Brand keywords submitted to our preliminary check tool are processed to compute detection counts across indexed records.
- Billing information: When you subscribe to a paid tier, our third-party payment processor collects payment details (such as credit card information, billing address, and tax identifiers). We retain only transaction tokens, card brand and expiration, and payment status; we do not store raw card numbers on our servers.
- Communications: If you contact us directly, we collect the content of your message, email address, and any attachments you provide.
B. Public Registry and Store Records
To provide brand monitoring and suggest relevant abuse reporting channels, our automated systems ingest and analyze publicly accessible records from external directories:
- Domain registries: Public zone files, domain registration metadata (RDAP/WHOIS), public DNS records, and published registrar or hosting abuse contacts surfaced in action guides.
- Trademark registers: Public trademark filing records, applicant names, application numbers, filing dates, correspondence addresses, and goods and services classifications published by official trademark authorities.
- Mobile app stores: Public application listings, developer names, published developer emails, bundle identifiers, and store catalog information published on public storefronts.
C. Information Collected Automatically
- Device and network logs: Internet Protocol (IP) addresses, browser user agent strings, operating system characteristics, referring URLs, request timestamps, and language preferences.
- Operational telemetry: Diagnostic event logs, API request latencies, error states, and session identifiers necessary to maintain platform stability and detect malicious traffic.
4. Legal Bases for Processing (EEA and UK Users)
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we collect and process your personal data only when we have a lawful basis under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)): To create and manage your account, authenticate your login, process subscription payments, execute scheduled monitoring scans, and deliver match records.
- Legitimate interests (Art. 6(1)(f)): To operate, safeguard, and improve our brand monitoring platform; to prevent fraud, credential stuffing, and abuse; to protect intellectual property rights; and to generate risk assessments based on public records.
- Compliance with legal obligations (Art. 6(1)(c)): To comply with applicable statutory tax, accounting, anti-money laundering, and legal reporting obligations.
- Consent (Art. 6(1)(a)): Where you have provided express consent for specific optional communications, which you may withdraw at any time.
5. How We Use Collected Information
We use the information we collect strictly for the following business and operational purposes:
- Operating, provisioning, and maintaining the automated monitoring platform.
- Executing scheduled scans against domain feeds, trademark registers, and app store catalogs.
- Evaluating potential brand conflicts, computing informational risk scores and match records, and generating suggested next steps with public reporting channels.
- Authenticating user sessions and enforcing multi-tenant security boundaries.
- Delivering match summaries, critical service alerts, and administrative billing notices.
- Investigating, preventing, and mitigating fraudulent transactions, security incidents, or violations of our Terms of Service.
- Analyzing aggregate platform performance to improve system reliability and scan throughput.
6. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. We do not share your personal data with third parties for cross-context behavioral advertising.
No automated third-party reporting: notolens does not submit reports, dispute filings, or communications to third parties (such as domain registrars, hosting providers, trademark offices, or app stores) on your behalf. External links and contact addresses surfaced in action guides (such as abuse forms, mailto links, or phone numbers) are provided solely for your direct, manual use. Any communication or evidence you share with an external party is subject to that third party’s privacy policy and terms.
We disclose personal information only in the limited circumstances described below:
- Infrastructure and service sub-processors: We engage trusted third-party service providers to support platform operations, including cloud hosting, managed database services, transactional email delivery, and payment processing. All service providers are bound by written data processing agreements requiring strict confidentiality, data security standards, and processing exclusively under our instructions.
- Compliance with legal process: We may disclose information if required by applicable law, regulation, valid subpoena, court order, or governmental demand, or when we determine in good faith that disclosure is necessary to protect the rights, property, or safety of notolens, our users, or the public.
- Business transfers: In the event of a merger, acquisition, corporate reorganization, financing, or sale of company assets, customer information may be transferred as a business asset, subject to standard confidentiality commitments.
7. International Data Transfers
notolens operates global cloud infrastructure. Information we collect may be transferred to, stored, and processed in jurisdictions outside your country of residence, including the United States.
When transferring personal data originating from the EEA, UK, or Switzerland to countries without an adequacy decision, we ensure appropriate safeguards are in place, including the execution of the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by technical security measures.
8. Data Security and Technical Safeguards
We implement robust technical and organizational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
- All web traffic and API communications are encrypted in transit using modern Transport Layer Security (TLS).
- Data at rest is stored in secure, logically isolated multi-tenant databases with strict access controls.
- User passwords are protected using industry-standard salted cryptographic hashing algorithms.
- Administrative access to production systems is restricted to authorized personnel on a least-privilege basis and protected by multi-factor authentication.
While we take rigorous measures to safeguard your information, no transmission over the Internet or electronic storage method can be guaranteed completely impenetrable.
9. Data Retention and Account Closure
We retain personal data for as long as your account is active or as necessary to provide the Service:
- Account data: Retained throughout the lifetime of your account. Upon account deletion, personal profile details are permanently removed or anonymized within thirty (30) days.
- Monitor configurations and match records: Retained while your monitor remains active or archived in your dashboard. If an account is deleted, associated match records are purged in accordance with our system retention schedules.
- Operational and security logs: Standard server and diagnostic logs are retained on rotating cycles, typically not exceeding ninety (90) days, unless extended for ongoing security investigations.
- Statutory records: Billing records, tax invoices, and transaction histories are retained for statutory retention periods mandated by applicable tax and accounting laws.
10. Your Privacy Rights
Depending on your jurisdiction of residence, you possess specific legal rights regarding your personal information.
A. European Economic Area and United Kingdom Rights
Under the GDPR and UK GDPR, you have the right to:
- Access: Request confirmation of whether we process your personal data and obtain a copy of that data.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure: Request the deletion of your personal data (“right to be forgotten”), subject to statutory exceptions.
- Restriction: Request that we restrict the processing of your personal data under certain circumstances.
- Data portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Objection: Object at any time to the processing of your data based on our legitimate interests.
- Lodge a complaint: File a complaint with your local supervisory data protection authority.
B. United States State Privacy Rights (California, Colorado, Virginia, etc.)
Under state privacy statutes, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to know and access: You may request disclosure of the categories and specific pieces of personal information collected, sources, business purposes, and categories of recipients.
- Right to delete: You may request deletion of personal information collected from you, subject to legal exceptions.
- Right to correct: You may request correction of inaccurate personal information.
- Right to non-discrimination: We will not discriminate against you, deny services, charge different prices, or provide a lower quality of service for exercising your statutory privacy rights.
- Sale and sharing opt-out: notolens does not sell personal information or share personal information for cross-context behavioral advertising, and has not done so in the preceding twelve (12) months.
To exercise any of these rights, please contact us at mail@notolens.com. We will verify your request using account credentials or email confirmation before fulfilling the request.
11. Cookies and Local Storage
notolens uses strictly necessary session cookies and local storage tokens required for platform operation, secure user authentication, session state management, and cross-site request forgery (CSRF) protection.
We do not deploy third-party advertising tracking cookies, behavioral profiling pixels, or cross-site commercial trackers on our platform. You may configure your browser settings to refuse cookies, though doing so may disrupt your ability to authenticate or access dashboard features.
12. Children’s Privacy
The Service is strictly intended for businesses, organizations, and individuals aged eighteen (18) and older. We do not knowingly solicit, collect, or process personal data from children under eighteen. If we become aware that an individual under eighteen has submitted personal information to us, we will take prompt steps to delete that information.
13. Modifications to This Privacy Policy
We may periodically update this Privacy Policy to reflect updates to our monitoring technology, operational procedures, or changes in legal standards. When modifications occur, we will revise the “Last updated” date at the top of this page.
If we make material revisions that substantially impact your privacy rights, we will notify you through a prominent notice in your account dashboard or via direct email communication prior to the changes taking effect.
14. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact Sebastian Graef LLC at mail@notolens.com.