Legal Center

API and Developer Terms

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. When these terms apply

These terms apply when the Provider grants a Customer, integration partner or developer access to a Klocktech API, webhook, software development kit, sandbox, schema or technical documentation. API access is not granted merely because an endpoint is discoverable.

2. Licence and credentials

The Provider grants a limited, revocable, non-exclusive right to use the authorised API for the approved internal integration during the applicable subscription. Credentials are confidential, must be stored securely, must not be embedded in public code, and may not be shared across customers. The developer must rotate and revoke credentials promptly when compromised or no longer needed.

3. Tenant and data scope

Every request must be scoped to the authorised tenant and purpose. A developer must not access, infer, enumerate or test another tenant. API access may process only the Customer's Authorised Dealer Data and its own Connected Accounts. The API must not be used to:

  • build a crawler, scraper, generic URL importer or marketplace search;
  • collect or monitor another dealer's watches, listings, images, prices or availability;
  • perform external duplicate, serial or image matching, provided that matching confined to the same Customer tenant and its own authenticated records is permitted;
  • combine Customer Data into a cross-dealer database; or
  • evade the AUP through an external service.

4. Technical rules

Developers must follow Documentation, authentication, encryption, versioning, pagination, webhook validation and rate limits. They must use reasonable retry and idempotency controls and must not create excessive traffic. The Provider may throttle or block harmful or anomalous use.

The developer must validate all output, handle partial failures, protect secrets and personal data, keep audit logs appropriate to risk, and notify the Provider promptly of a suspected incident. Production personal data must not be copied to an insecure development environment.

5. Changes and continuity

The Provider may introduce compatible changes and deprecate a version with reasonable notice. Urgent security or legal changes may occur sooner. Unless an Order Form states otherwise, preview and sandbox APIs have no availability commitment. The Provider does not guarantee that a third-party platform will maintain its API.

6. IP, restrictions and publication

The Provider owns the API, schemas, Documentation and sample code except identified open-source or third-party material. The developer may use them only for the authorised integration. Public benchmarking, security findings, use of Klocktech marks or publication of confidential API details requires written permission, except where mandatory law provides otherwise.

7. Termination

API rights end with the subscription or earlier revocation. The developer must stop calls, delete credentials and Provider Confidential Information, and return or delete personal data under the DPA. The Provider may immediately revoke credentials for security, cross-tenant access, scraping or other material abuse.