Global compliance

Privacy and business law, handled country by country

Ascen Mark operates across borders, so we apply the strictest applicable standard in each region rather than a single home-country rulebook. This page is the register of what we comply with, why we process data, and who you can complain to.

Register version 2026-08-20 · Ascendum Corporate Advisory LLC, 10124 N McKinley Ave, Kansas City, MO 64157, United States

Privacy regimes we operate under

RegionLawRegulatorYour rightsCross-border transfersResponse time
European Union / EEAGDPR (EU) 2016/679 + ePrivacy DirectiveLead supervisory authority of your member state (EDPB network)Access, Rectification, Erasure, Restriction, Portability, Objection, Withdraw consent, No solely automated decisionsEU Standard Contractual Clauses (2021/914) + transfer impact assessment; registry publication is a legal obligation1 month (extendable by 2 months)
United KingdomUK GDPR + Data Protection Act 2018 + PECRInformation Commissioner's Office (ICO)Access, Rectification, Erasure, Restriction, Portability, Objection, Withdraw consentUK International Data Transfer Agreement / UK Addendum to the EU SCCs1 month
IndiaDigital Personal Data Protection Act 2023 + IT Rules 2011Data Protection Board of IndiaAccess summary, Correction & completion, Erasure, Nominate, Grievance redressalTransfers permitted except to restricted territories notified by the Central Government; verifiable consent notice given at collection in English and available regional languages30 days (grievances acknowledged within 72 hours)
United States (state laws)CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA and successor state statutesCalifornia Privacy Protection Agency and state Attorneys GeneralKnow / access, Delete, Correct, Portability, Opt out of sale, sharing and targeted advertising, Limit use of sensitive data, Non-retaliationService-provider contracts restricting secondary use; we do not sell personal data45 days (extendable by 45)
CanadaPIPEDA and substantially similar provincial laws (Quebec Law 25)Office of the Privacy Commissioner of Canada; CAI (Quebec)Access, Correction, Withdraw consent, Challenge compliance, Quebec: portability and de-indexingComparable-protection contracts; cross-border processing disclosed before collection30 days
AustraliaPrivacy Act 1988 + Australian Privacy Principles + Notifiable Data Breaches schemeOffice of the Australian Information Commissioner (OAIC)Access (APP 12), Correction (APP 13), Anonymity where practicable, Opt out of direct marketing, Complain to the OAICAPP 8 accountability — overseas recipients bound by contract to APP-equivalent handling30 days
SingaporePersonal Data Protection Act 2012 (as amended 2020)Personal Data Protection Commission (PDPC)Access, Correction, Withdraw consent, Data portability, Do Not Call registrationTransfer Limitation Obligation satisfied by contractual comparable-standard clauses30 days
United Arab EmiratesFederal Decree-Law No. 45 of 2021 (PDPL); DIFC DP Law 2020 and ADGM DP Regulations 2021 where applicableUAE Data Office; DIFC and ADGM CommissionersAccess, Rectification, Erasure, Restriction, Portability, Objection, Withdraw consentAdequacy decision or appropriate contractual safeguards; explicit consent where neither applies30 days
Rest of worldBrazil LGPD, Japan APPI, South Korea PIPA, South Africa POPIA, Switzerland revFADP, Nigeria NDPA and similarThe competent authority of your country of residenceAccess, Correction, Deletion, Objection, Complaint to your regulatorWe apply the strictest applicable standard — EU SCCs plus local consent where a law requires it30 days unless local law is shorter

Why we process data, and for how long

Preparing and lodging IP applications

Data
Applicant identity, brand/specification content, specimens, priority documents
Lawful basis
Performance of contract; legal obligation of the receiving registry
Retention
Life of the right + 7 years statutory limitation

Identity, sanctions and anti-money-laundering checks

Data
Name, country, entity details, screening results
Lawful basis
Legal obligation (AML/CFT, sanctions and export-control law)
Retention
5 years from end of relationship (7 in some jurisdictions)

Payments, tax and invoicing

Data
Billing name, address, tax IDs, payment processor tokens (no card numbers stored)
Lawful basis
Contract and legal obligation (tax, VAT/GST records)
Retention
7–10 years per local tax law

Document scanning and platform security

Data
File hashes, scan verdicts, hashed IP addresses, access logs
Lawful basis
Legitimate interests in securing the service; legal obligation to report breaches
Retention
24 months

AI assistance for drafting and office-action responses

Data
Matter text you submit to the assistant
Lawful basis
Contract; never used to train third-party foundation models
Retention
Matter lifetime; prompts purged after 30 days

Marketplace, valuation and escrow activity

Data
Listing details, offers, valuation opinions, settlement receipts
Lawful basis
Contract; legal obligation for financial record keeping
Retention
7 years from closing or withdrawal

Marketing communications

Data
Email address, engagement metrics
Lawful basis
Consent (opt-in), withdrawable at any time
Retention
Until withdrawal + 12 months proof of consent

Business-law compliance

Unauthorised practice of law & agent licensing

Ascen Mark is a technology platform, not a law firm or IP agency in any country.

  • Representation before a registry is performed only by locally qualified attorneys or registered agents where local law requires it.
  • Self-file preparation is offered only in jurisdictions that permit an applicant to file on their own behalf.
  • No advice, opinion or legal representation is given by Ascendum staff; jurisdiction-specific disclaimers are shown at every point of use.

Anti-money-laundering, sanctions & export control

Onboarding is screened before any payment is accepted or work allocated.

  • Customer identification and beneficial-ownership checks on entities using the marketplace, escrow and valuation services.
  • Screening against OFAC, UN, EU, UK HMT and local sanctions lists; blocked parties are refused and records retained.
  • No services to jurisdictions or persons subject to comprehensive sanctions or US export controls.
  • Suspicious activity escalated to the compliance officer and reported where a filing duty applies.

Consumer protection & distance selling

Transparent pricing and statutory cancellation rights.

  • All-in indicative pricing in USD with taxes and official fees identified separately before checkout.
  • EU/UK 14-day distance-contract withdrawal right, with the express-consent waiver disclosed where work starts immediately.
  • Australian Consumer Law, Indian Consumer Protection Act 2019 and US FTC standards observed for advertising claims and refunds.
  • No dark patterns: cancellation is as easy as sign-up and renewals are notified in advance.

Payments, tax & financial records

All client money flows to Ascendum Corporate Advisory LLC and is settled onward on receipts.

  • PCI-DSS handled by the payment processor; no card data touches our systems.
  • Automatic tax determination for VAT, GST, sales tax and reverse-charge based on seller and customer country.
  • Invoices and receipts issued automatically; e-invoicing formats supported where mandated.
  • Escrow milestones released only against documented deliverables and official receipts.

Electronic signatures & records

Signatures are captured with evidence that stands up in each jurisdiction.

  • US ESIGN/UETA, EU eIDAS, UK ECA 2000, India IT Act 2000, Australia ETA 1999, Canada PIPEDA Part 2, Singapore ETA and UAE Electronic Transactions Law alignment.
  • Timestamped audit trail with signer identity verification, IP hash and document hash.
  • Wet-ink, notarised, apostilled or consularised execution enforced where the destination registry does not accept e-signature.

Anti-bribery, ethics & professional conduct

Country law first, then professional body rules; the stricter standard always prevails.

  • US FCPA and UK Bribery Act 2010 compliance; no facilitation payments to registry officials.
  • Panel members must maintain local qualification, insurance and good standing, and follow their professional body's code.
  • Conflicts checked before allocation; work is allocated automatically and non-exclusively.

Competition, marketplace & non-circumvention

Fair, transparent operation of the Brand Exchange and panels.

  • No price fixing between panel members; each sets its own wholesale fee.
  • Listing, offer and dispute rules published and applied uniformly; audit trail retained for every action.
  • NDA and no-direct-dealing terms enforced contractually, not by restricting a client's freedom to choose counsel.

Security, breach notification & data localisation

Encryption, least privilege and regulator-ready incident response.

  • PDF-only uploads with malware scanning, quarantine and appeal workflow.
  • Encryption in transit and at rest; role-based access limited to staff assigned to your matter.
  • Breach notification within 72 hours to the EU/UK/UAE regulators, without unreasonable delay under the OAIC NDB scheme, PDPC, DPDP and applicable US state laws.
  • Data residency options honoured where a jurisdiction mandates local storage.

Accessibility & non-discrimination

The portal is built to be usable by everyone.

  • WCAG 2.2 AA targets for contrast, focus states, keyboard navigation and ARIA labelling.
  • Alignment with the EU Accessibility Act, US ADA/Section 508 guidance and equivalent local standards.
  • Service is offered without discrimination on any protected ground.

AI governance

AI assists people; it never decides your matter.

  • AI output is labelled, reviewable and always subject to human sign-off by the preparer, reviewer and approver chain.
  • EU AI Act transparency duties observed for generated content and assistant interactions.
  • No solely automated decision with legal effect; you may request human review at any time.

Contact and escalation

Privacy: privacy@ascenmark.com · Grievance officer (India DPDP): grievance@ascenmark.com · Compliance officer: compliance@ascenmark.com · Post: 10124 N McKinley Ave, Kansas City, MO 64157, United States. You may also complain directly to your own regulator listed above.

Ascen Mark is a technology platform operated by Ascendum Corporate Advisory LLC. It is not a law firm, not an IP agency, not a valuer, not a broker and not a financial adviser, and provides no legal, tax, financial or investment advice in any country. All professional work is performed by independent, locally qualified practitioners engaged on their own terms. Ascendum Corporate Advisory LLC gives no guarantee of registration, outcome, valuation, sale price or business, and accepts no responsibility or liability for the acts, omissions, advice, fees or opinions of any practitioner, registry, counterparty or third party.