Operated by
IT CPO SARLU
SIREN
897 603 296
Registered
Montlignon, France
Rights holder enquiries →

Policies

An enforcement service should be willing to state its own rules in public. These are ours: who we will act for, what we require before we file anything in a client’s name, how someone who receives a request from us can challenge it, and what we do with personal data.

Last updated 27 July 2026 · Published by IT CPO (SIREN 897 603 296) · These policies are governed by French law

Read this first

BrandNameGuardians is a trading name of IT CPO. We are not a law firm. Nothing on this page or elsewhere on this site is legal advice, and no legal professional privilege attaches to correspondence with us. Where a matter requires legal advice or a formal proceeding, instruct qualified counsel — we will prepare the evidence file and work alongside them.

01 Terms of engagement

Applies to all client engagements from 27 July 2026.

1.1 What we supply

We supply monitoring, detection, evidence capture, assessment and the preparation and submission of enforcement requests through the published rights-holder or abuse procedures of third-party platforms. The precise marks, channels, geographies, volumes and reporting cadence of an engagement are set out in a written service order agreed with the client. Anything not in that service order is out of scope.

1.2 What we do not supply

  • Legal advice, legal representation, or any service reserved to a regulated legal profession.
  • Trademark registration, prosecution or portfolio management before an IP office.
  • Any guarantee that a platform, registrar, host or third party will act on a request.
  • Removal of lawful content. See Acceptable use & refusals.

1.3 Client obligations

The client warrants, for the whole duration of the engagement, that it:

  • holds the trademarks and other rights it puts in scope, or is duly authorised to act for the holder;
  • has authority to grant us the mandate described in section 2 and that the signatory is authorised to bind the client;
  • will tell us promptly if a right lapses, is assigned, is challenged, or if a licence, distribution or settlement agreement makes a particular use permitted; and
  • will not use our reports or evidence to pursue conduct that is unlawful in the relevant jurisdiction.

We rely on these warranties. If a filing is later reversed because the underlying right did not exist or the use was in fact licensed, responsibility for that sits with the client.

1.4 Service levels

We commit to what is within our control — the quality and the speed of our own work — and to nothing that is not:

  • Filing time. A confirmed infringement is filed within two business days of confirmation; same business day where it involves phishing, malware or payment fraud using the client’s identity.
  • Assessment. Every detection receives human analyst review before any filing. No filing is generated automatically.
  • Reporting. A written report each calendar month covering detections, filings, confirmed outcomes and open items, unless a different cadence is agreed.
  • Response time. Client correspondence answered within two business days.

We do not commit to removal rates, removal times or any particular decision by a third party, because those are not ours to give.

1.5 Fees, term and termination

Fees, billing period and minimum term are set out in the service order. Either party may terminate for convenience on 30 days’ written notice, and either party may terminate immediately for material breach that is not remedied within 15 days of written notice. On termination we stop monitoring, withdraw nothing that has already been correctly filed, and hand over the client’s case files on request. Sums due for work already performed remain payable.

1.6 Liability

Our obligations are obligations of means, not of result. To the fullest extent permitted by French law, our aggregate liability arising out of an engagement is limited to the fees paid by the client under that engagement in the twelve months preceding the event giving rise to the claim. We are not liable for indirect or consequential loss, loss of profit, loss of revenue or loss of opportunity. Nothing in these terms excludes liability for fraud, wilful misconduct, gross negligence (faute lourde) or any liability that cannot lawfully be excluded.

1.7 Governing law and jurisdiction

These terms and any engagement are governed by French law. The parties will first attempt to resolve any dispute amicably. Failing that, the competent courts of France have exclusive jurisdiction. Where the client is a consumer, the mandatory protections and jurisdiction rules of the client’s country of residence are unaffected.

02 Client verification & authorisation

The policy that governs whether we can act at all.

We file requests that can take another party’s advert, listing, account or domain offline. That power is only legitimate if it is exercised by, or genuinely on behalf of, the person who owns the right. So this is the one policy we do not make exceptions to.

2.1 Before an engagement starts

We verify, and record, all of the following:

  • The legal entity. Registered name, company or register number, registered address, and the jurisdiction of incorporation.
  • The signatory’s authority. Evidence that the person instructing us can bind that entity — a register extract naming them, a board authority, or a delegation from someone who is named.
  • Title to the rights. Registration numbers, register, classes, jurisdictions and status of every mark put in scope; and, where the client is not the registered proprietor, the licence, assignment or power of attorney that connects them to it.
  • The mandate. A signed Letter of Authorisation naming IT CPO / BrandNameGuardians as the client’s authorised representative for enforcement filings relating to the listed marks, with a stated scope and expiry.
  • Where counsel instructs us for an underlying client, confirmation from counsel that they hold their own authority from that rights holder.

2.2 Scope of the mandate

A mandate is specific, not general. It names the marks, the channels and the territories. It does not authorise us to act on marks that are not listed, to act against parties outside the agreed channels, or to make legal claims beyond trademark and related rights enforcement. Extending scope requires a written amendment.

2.3 Keeping it current

Mandates and rights status are re-checked at least annually and on any renewal. A mandate lapses automatically on its expiry date, on termination of the engagement, or on notice from the client. Once a mandate has lapsed we file nothing further under it. If we learn that a right in scope has been revoked, invalidated, abandoned or assigned, we suspend filings on that right and tell the client the same day.

2.4 If verification fails

We decline the engagement. We do not accept “we will send the paperwork later” as a basis for beginning to file, and we do not act on the strength of a claimed relationship we cannot document.

Why this is public

A party that receives a request from us is entitled to know what we had to prove before it was sent. Publishing the standard also means our clients know exactly what will be asked of them at onboarding, before they spend time on it.

03 Enforcement & evidence standards

What has to exist before we file.

3.1 Evidence required for every filing

  • The full URL, and the domain, seller, advertiser or account identifier where one is available.
  • A capture of the material as it appeared — screenshot and, where possible, the page source or the served response.
  • A timestamp in UTC and the geography and device profile the content was served to. Ads in particular are targeted; where something was seen matters.
  • The specific mark relied on, with its registration number, register and class.
  • The analyst’s written reasoning for why this use is infringing rather than lawful.
  • An identifier linking the item to its case file and to the client mandate it was filed under.

Captures are stored unmodified with a hash and an append-only access log, so the file can be relied on later if the matter escalates.

3.2 Assessment before filing

Automated monitoring produces candidates, never filings. An analyst classifies each candidate as infringing, lawful, ambiguous or out of scope. Ambiguous items are escalated to a second reviewer and, where the client wants that decision, referred to the client and its counsel. Nothing in the lawful or out-of-scope categories is ever filed.

3.3 Proportionality

Where a lighter step is likely to resolve the matter, we take it first — a direct approach to a seller, affiliate or advertiser who is probably unaware of the rules, before a platform complaint that may cost them their account. Enforcement is meant to stop the use, not to maximise the damage.

3.4 Accuracy and correction

We do not knowingly submit a materially inaccurate statement to any platform. If we discover after filing that a request was wrong — wrong party, lapsed right, licensed use, misidentified content — we withdraw it in writing to the platform, tell the affected party, and tell the client, without waiting to be asked.

04 Counter-notices & disputes

For anyone who has received a request from us.

If we have asked a platform, registrar or host to act against something you published and you believe that is wrong, you can challenge it directly with us. You do not need a lawyer to do so, and you do not need to go through the platform first.

4.1 How to challenge a request

Write to [email protected] with NOTICE in the subject line, and include:

  • the reference number on the request, or the platform’s case number;
  • the URL, listing, account or domain concerned;
  • who you are and in what capacity you are writing; and
  • why you believe the use is lawful or the request mistaken — for example an authorised reseller agreement, a licence, exhaustion of rights, comparative advertising that meets the legal conditions, descriptive or nominative use, or simply that you are not the party we identified.

4.2 What we do with it

  • We acknowledge receipt within three business days.
  • The review is carried out by someone who was not involved in the original filing.
  • We reach a reasoned decision within ten business days, and tell you if a matter genuinely needs longer and why.
  • If we agree with you in whole or in part, we withdraw or narrow the request in writing to the platform, send you a copy of that withdrawal, and record the outcome against the case file.
  • If we maintain the request, we tell you the specific right and the specific reasoning we rely on, so that you can take it further.

4.3 What we will not do

We will not refuse to engage because you are on the other side. We will not require you to waive anything, or to agree to any commercial arrangement, as a condition of having your challenge reviewed. We will not disclose your identity or contact details to our client beyond what is necessary for them to instruct us on the matter, and we will tell you if that disclosure is necessary.

4.4 Your other routes

Nothing here limits your rights. You may use the platform’s own appeal or counter-notice mechanism, complain to a regulator, or take the matter to court, whether or not you contact us. Under the EU Digital Services Act you may also have access to the platform’s internal complaint-handling system and to a certified out-of-court dispute settlement body.

05 Acceptable use & refusals

Instructions we turn down.

Brand protection is straightforward to abuse. These are the instructions we refuse, regardless of the fee, and refusing them is a term of every engagement rather than a matter of goodwill:

  • Suppressing lawful criticism. Reviews, complaints, consumer forums, journalism, commentary, satire and parody are not trademark infringement, and we will not treat them as if they were.
  • Attacking lawful competition. Comparative advertising that meets the legal conditions, honest descriptive use, and legitimate keyword advertising that does not mislead as to origin are not filed against.
  • Acting against authorised parties. Licensees, distributors and resellers acting within their agreement, and genuine goods lawfully placed on the market in the relevant territory.
  • Rights we cannot document. No verified title and no valid mandate means no filing.
  • Trademark claims as a pretext. Where the real objective is to remove content for reasons unrelated to the mark.
  • Volume for its own sake. We do not accept engagements priced or measured per notice filed, because that incentive structure produces exactly the behaviour above.
  • Deanonymising individuals. We collect what is needed to identify the responsible commercial party. We do not run surveillance of private individuals, and we do not supply personal data for harassment.

If a client insists on an instruction that falls into any of these categories, we decline it in writing, and we treat continued insistence as a material breach that ends the engagement.

06 Privacy policy (GDPR)

Regulation (EU) 2016/679 · Last updated 27 July 2026

6.1 Who is responsible

The data controller is IT CPO (SARLU), 62 rue de Paris, 95680 Montlignon, France, SIREN 897 603 296, trading as BrandNameGuardians. For anything in this section, write to [email protected] or to the postal address above marked Data protection.

6.2 What we process, and why

Processing activities
DataPurpose and legal basis
Enquiry details — name, business email, company, role, message Responding to your enquiry and preparing a proposal. Legal basis: our legitimate interest in dealing with business enquiries, and steps preparatory to a contract.
Client contact and onboarding records — including verification documents and signatory identity Performing the engagement, and verifying authority to instruct us as required by section 2. Legal basis: performance of a contract, and our legitimate interest in not filing unauthorised requests.
Case data — URLs, captures, advertiser, seller, registrant and account identifiers, which may include personal data of the party complained about Detecting, documenting and enforcing against infringement. Legal basis: the legitimate interests of our client and of us in establishing, exercising and defending legal claims, balanced against the rights of the individual concerned.
Correspondence from parties who receive our requests Reviewing and deciding counter-notices under section 4. Legal basis: legitimate interest, and compliance with legal obligations.
Billing and accounting records Invoicing, tax and statutory bookkeeping. Legal basis: legal obligation under French commercial and tax law.
Server logs — IP address, request, user agent, timestamp Operating and securing this website. Legal basis: legitimate interest in security and availability.

We do not buy personal data, we do not sell it, and we do not use it for advertising or profiling. We do not knowingly process special categories of personal data, and we do not target this site at children.

6.3 No automated decisions about people

Our monitoring is automated, but its output is a candidate for review, never a decision. No enforcement request is generated, sent or maintained without a human analyst deciding it should be. You are therefore not subject to a decision based solely on automated processing within the meaning of Article 22 GDPR.

6.4 Who receives data

  • The platform, registrar, registry or host a request is filed with — necessarily, since that is the request.
  • Our client, in case reports relating to its own marks.
  • Legal counsel instructed by the client, where a matter escalates.
  • Service providers acting as processors under Article 28 contracts — hosting, email, storage and accounting.
  • Public authorities and courts, where we are legally required to disclose.

6.5 Transfers outside the EEA

Enforcement necessarily involves platforms established outside the EEA. Where we transfer personal data outside the EEA we rely on an adequacy decision of the European Commission where one covers the recipient, and otherwise on the Commission’s Standard Contractual Clauses together with a transfer impact assessment. A copy of the safeguards applied to a specific transfer is available on request.

6.6 Your rights

You have the right to request access to your personal data and to obtain rectification, erasure or restriction of processing; to object to processing based on legitimate interests; to data portability where applicable; and to withdraw any consent you have given. Requests go to [email protected] with GDPR in the subject line, and we answer within one month, extendable by two further months for complex requests, in which case we will tell you.

Two honest limits. Where personal data forms part of an evidence file needed to establish, exercise or defend a legal claim, we may retain it and restrict processing instead of erasing it, and we will explain that in our reply. And where we process data on behalf of a client as its processor, we will forward your request to that client and tell you we have done so.

You may lodge a complaint with the French supervisory authority, the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr — or with the authority in your own country of residence or work.

6.7 Security

Access to case data is role-based and logged. Data is encrypted in transit and at rest. Evidence captures are held write-once with integrity hashes. Access rights are reviewed when roles change and revoked on departure. We will notify the CNIL, and affected individuals where the threshold is met, within the deadlines set by Articles 33 and 34 GDPR.

07 Cookie policy

Short, because there is little to declare.

This website sets no advertising, analytics or tracking cookies, and at present sets no cookies at all. It loads no third-party fonts, scripts, tag managers, embedded videos, maps or social widgets, so no third party learns that you visited it. Nothing here requires consent under Article 82 of the French Data Protection Act.

Our web server keeps standard technical logs (see 6.2) for security and troubleshooting. If we later add anything that does require consent, we will publish a consent banner that allows you to refuse as easily as accept, and we will update this section before it goes live.

08 Data retention

Retention periods
Enquiries that do not become engagements12 months from last contact
Client onboarding and verification records5 years after the engagement ends
Case files and evidence captures5 years after the case closes, or until any related proceeding is finally concluded, whichever is later
Counter-notice correspondence and decisions5 years from the decision
Accounting and invoicing records10 years, as required by French commercial law
Web server logs12 months

At the end of a period, data is deleted or irreversibly anonymised. Clients may ask us to delete their case files earlier, subject to any legal-hold obligation and to the accounting periods above.

09 Confidentiality & conflicts of interest

9.1 Confidentiality

Client portfolios, enforcement strategy, case data and commercial terms are confidential. They are disclosed internally only to the people who need them for the engagement, and externally only where a filing requires it, where the client authorises it, or where the law compels it. Confidentiality survives the end of the engagement indefinitely.

We do not use one client’s case data for another client’s benefit. We do not publish client names or use them as references without written permission.

9.2 Conflicts

We check for conflicts before accepting an engagement and continuously afterwards. We will not act simultaneously for two parties in dispute with each other over the same or confusingly similar marks. If a conflict emerges mid-engagement, we disclose it promptly and either obtain informed written consent from both parties or withdraw from one matter — and if we withdraw, we say which and why.

We hold no interest in any monitored platform, marketplace, registrar or advertising network, and we receive no commission, referral fee or other payment from any of them.

10 Complaints & escalation

If any part of our work falls short — a wrong filing, a missed deadline, a report you cannot rely on, conduct you consider improper — we would rather hear it directly.

  1. Raise it. Email [email protected] with COMPLAINT in the subject line, plus what happened and any references. Acknowledged within three business days.
  2. Review. Handled by someone not responsible for the work complained of. Substantive written response within ten business days; if we need longer we tell you why and when.
  3. Outcome. Where we were wrong we say so plainly, set out what we are doing to correct it, and confirm what changes so it does not recur.
  4. If you are not satisfied. Reply to our response asking for it to be escalated to the gérant, who will review it personally. You also retain every legal and regulatory route open to you — including the CNIL for data protection matters and the competent French courts.

This procedure is open to clients and to parties who have received requests from us, on the same terms.

Question about any of this?

Policy questions, data protection requests and counter-notices all reach a person — the routes are on the contact page.