Privacy policy.
1. Controller
Shio Ventures GmbH, Straßburger Straße 55, 10405 Berlin, Germany. Commercial register: HRB 82142 B, Charlottenburg local court. Contact: datenschutz@marqio.ai.
2. Data collected
- Account data (name, email address, authentication factors via Clerk, payment method via Stripe).
- File data (company ideas, candidate names, clearance results, domain status; in existing files additionally logo briefs and logo renders from the discontinued design module).
- Billing data (credit balance, internal booking ledger, purchases, Stripe transaction IDs).
- Technical logs (IP address, user agent, request timestamps, error stacks).
- Anti-abuse data (counters per hashed IP address for the fair-use limits of the free tools).
3. Purposes of processing
Provision of the service (name finding, clearance, domain comparison), billing of purchased full clearances and firm quotas, operational security, enforcement of the fair-use limits of the free tools, fulfilment of statutory obligations.
4. Legal bases
Art. 6(1)(b) GDPR (contract performance — name finding, clearance, domain comparison, billing), (c) (legal obligations — tax and commercial law), (f) (legitimate interest — operational security, error monitoring, enforcement of fair-use limits).
5. Recipients and processors
- Cloudflare, Inc. Hosting, edge compute, object storage (R2), database (D1), analytics. Storage location EU (Frankfurt).
- Clerk, Inc. Authentication, passkey management, session management.
- Stripe Payments Europe Ltd. Payment processing for full clearances and firm quotas.
- Anthropic, PBC AI inference for candidate names and classification in clearance. Anthropic does not use file data for model training.
- fal.ai (Featherless AI Labs, Inc.) Delivery of previously generated logo assets from existing files via the fal.ai CDN. No new logo generation takes place.
- Brandfetch B.V. Logo lookup service for reference-mark display in the file context.
- Functional Software, Inc. (Sentry) Error and performance monitoring.
Data-processing agreements per Art. 28 GDPR are in place with all processors. Current DPA versions are available on request from datenschutz@marqio.ai.
6. Affiliate outlinks to domain registrars
The domain module links via affiliate outlinks to Namecheap, Porkbun, IONOS and Gandi. These providers are not processors but independent controllers. Data processing at the registrar starts only when the outlink is clicked and follows the registrar’s privacy policy.
7. Third-country transfers
Cloudflare operates EU storage locations for Marqio (Frankfurt). US transfers occur with Clerk, Stripe, Anthropic, fal.ai and Sentry; Brandfetch processes in the Netherlands. US transfers rely on the EU standard contractual clauses (SCCs, Decision 2021/914) and, where available, on recipient self-certification under the EU-US Data Privacy Framework.
8. Retention period
File data is kept for the duration of the account and removed from live systems within 30 days after account deletion. Billing and ledger data are subject to statutory retention (10 years per § 147 AO and § 257 HGB). Technical logs are deleted after 90 days. Fair-use counters with hashed IP addresses are deleted after 30 days.
9. Rights of the data subject
You are entitled to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Complaints can be filed with the competent supervisory authority — for Shio Ventures GmbH this is the Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstraße 219, 10969 Berlin.
10. Cookies and similar technologies
Marqio uses strictly necessary cookies and browser storage: Clerk session cookies for sign-in, a napkin session cookie for anonymous naming drafts before login, and sessionStorage entries to restore file drafts. We use no marketing cookies and no third-party trackers. Cloudflare Analytics operates cookie-free.
11. Contact
Data protection inquiries, DPA provision and data-subject rights: datenschutz@marqio.ai. No external data protection officer has been appointed; under § 38 BDSG, Shio Ventures GmbH currently has no appointment obligation.
