Legal Center

B2B SaaS Subscription Terms

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. Agreement and business eligibility

These terms form an agreement between Heritage Timepieces AB, as current provider, and the business identified in an Order Form (“Customer”). “Klocktech” means the service and brand. Klocktech AB is under registration and is not a party unless and until a valid transfer has taken effect.

The Service is offered only for business use. The person accepting an Order Form represents that the Customer is acting in its trade, business or profession and that the person has authority to bind it. No consumer may subscribe under these terms.

The Agreement consists only of the Order Form and documents it expressly incorporates by title, version and date. The exhaustive list, subject-matter limits and priority rules in the Legal Centre apply. An Order Form may vary ordinary commercial terms but cannot override the DPA for Customer Personal Data or unmodified Standard Contractual Clauses.

2. Definitions

Authorised Dealer Data means watch records, media, listings and related information concerning inventory the Customer owns, physically holds, or is expressly authorised to market on consignment or agency terms, provided through the Customer's own upload, system or authenticated account. It does not include an automated feed, account, database or catalogue belonging to another dealer, even where that dealer has given permission.

Authorised User means an individual whom the Customer permits to use the Service for the Customer.

Connected Account means the Customer's own authenticated account with a website, marketplace or other Third-Party Service.

Customer Data means data, media, credentials, prompts, text, records and other material submitted to, stored in, generated through or transmitted from the Service on the Customer's behalf. It excludes Provider technology and properly anonymised statistical information that cannot identify the Customer, a person, a watch, a listing or another dealer.

Documentation means the current user and technical documentation supplied for the Service.

Order Form means an accepted ordering document, electronic order or other written commercial schedule identifying the Customer and subscription.

Permitted Reference Data means manufacturer- or model-level specifications from an approved manufacturer source or licensed catalogue. It must not contain or reveal a dealer or seller, listing, listing URL, individual watch, item-level price, availability, photograph, description, serial number or other item-level dealer information. A licence, consent or technically accessible interface alone does not bring another dealer's data within the commercial product.

Prohibited Third-Party Dealer Data means another dealer's watches, stock feed, listings, photographs, descriptions, titles, serial numbers, prices, seller identity, availability, customer data or other non-authorised dealer information.

Service means the Klocktech hosted software, enabled modules, Documentation and support identified in an Order Form.

Third-Party Service means a platform, marketplace, website, AI model, data provider, payment service or other service not controlled by the Provider.

3. Service scope and hard product boundary

The Service is intended to help the Customer manage its Authorised Dealer Data, prepare dealer-uploaded images, create and translate draft content, configure prices, select publication destinations, publish through authorised connectors, manage reservations and sale status, and report on the Customer's own operations.

The Service does not give the Customer a right or function to scrape, crawl, search, discover, monitor, import, copy, aggregate or expose Prohibited Third-Party Dealer Data. It does not provide a partner-stock or competitor-listing database. Authorised consignment or agency inventory must be entered through the Customer's own upload or system and never through another dealer's feed, account, database or catalogue. Authenticated retrieval of the Customer's own known listings, orders and status events from a Connected Account is permitted. Product reference suggestions may use the Customer's verified data or Permitted Reference Data. Market insights may use the Customer's own history or a licensed, non-identifiable aggregate index subject to the safeguards in section 8. If a compliant source is unavailable, that feature must be disabled; web scraping is not a fallback.

4. Subscription right and accounts

Subject to the Agreement and payment of fees, the Provider grants the Customer a limited, non-exclusive, non-transferable and non-sublicensable right during the subscription term for Authorised Users to access and use the Service for the Customer's internal business operations. The Customer may not resell, time-share or provide the Service to another organisation unless an authorised reseller agreement says otherwise.

The Order Form controls enabled modules, locations, users, storage, API capacity, markets and other plan limits. The Customer appoints account administrators, maintains accurate user information, assigns least-privilege roles, protects credentials and promptly removes access when no longer required. Accounts may not be shared between individuals. The Customer must notify the Provider promptly of suspected compromise.

5. Customer data, provenance and authority

The Customer retains its rights in Customer Data. It grants the Provider and its approved subprocessors a worldwide, non-exclusive right during the Agreement to host, copy, process, transform, transmit, display, back up and delete Customer Data only as necessary to provide, configure, secure, troubleshoot and support the contracted Service for that Customer in accordance with the Agreement and documented instructions. Identifiable Customer Data may not be used for general or cross-customer product improvement. General improvement may use only irreversibly anonymised and sufficiently aggregated statistics under the safeguards below.

The Customer represents and warrants that it has the rights, permissions, notices and lawful basis needed to submit and use Customer Data and to instruct the Provider. In particular, the Customer must:

  • use the Service only for watches it owns, physically holds or is expressly authorised to market on consignment or agency terms, and supply them only through its own upload, system or authenticated account;
  • maintain evidence of ownership, consignment or marketing authority where appropriate;
  • upload only media and content it owns or may lawfully use;
  • ensure product, condition, provenance, service, warranty and included-accessory information is accurate;
  • protect full serial numbers, credentials, costs and customer information through appropriate roles;
  • comply with sales-channel rules, advertising, intellectual-property, privacy, tax, sanctions, customs and consumer obligations applicable to its own sales; and
  • not list counterfeit, stolen, pledged, embargoed or otherwise unlawful goods.

The Provider does not acquire ownership of Customer Data and will not use one Customer's identifiable inventory, images, prompts, serials, prices, listings or commercial information to serve another dealer, train a general-purpose or cross-customer AI model, or create cross-dealer benchmarking. This prohibition applies even if an individual Customer offers to opt in. The Provider may use only irreversibly anonymised and sufficiently aggregated operational statistics that cannot identify or single out a Customer, person, watch, listing or confidential commercial pattern.

6. Inventory, publication and sales responsibility

The Customer makes the final decision to create, approve, publish, price, translate, reserve, sell, withdraw or archive a watch. Connecting a sales channel does not publish all watches automatically; the Customer must select destinations for each watch unless it has deliberately configured an approved automation.

Klocktech performs channel preflight checks where supported, but a third party may reject, delay, alter or remove a listing. The Customer must review publication results and exception notices. Where a connector reports an uncertain or failed update, the Customer must verify the live channel before relying on Klocktech. Simultaneous external transactions can still create a conflict or double sale; no software can eliminate that risk where a platform lacks timely official controls.

Unless an Order Form expressly says otherwise, Klocktech does not contract with the Customer's buyers, take title to watches, process buyer payments, provide escrow, arrange carriage, authenticate watches, insure shipments, issue invoices to buyers or administer returns. The Customer remains responsible for its buyers, listings and transactions.

7. Images, content and AI-assisted output

Original dealer-uploaded photographs must be preserved immutably. Generative processing is permitted only outside the watch segmentation mask. Narrowly constrained, non-generative tonal corrections may affect watch pixels only where they do not invent, erase, repair, beautify or obscure condition evidence. Cropping must not omit relevant damage or included components. The watch itself—including dial, hands, bezel, case, bracelet, engravings, patina, scratches, damage and other condition evidence—must not be generated, replaced, concealed or materially altered.

A distinct privacy-redaction tool may create an audited public derivative that blur- or opaque-masks the serial region without synthesising replacement characters or modifying the immutable original. The Customer must choose backend-only display or a masked public display showing no more than three original characters. The full serial must not appear in public image metadata, filenames, text or public channel fields. A destination-required private API field may receive the full serial only after a separate per-destination Customer instruction, through a non-public field, where strictly necessary and contractually protected. This exception is unavailable while the Customer has selected backend-only mode and cannot enable public display.

Descriptions, histories, translations, attribute suggestions, price suggestions and image outputs can be inaccurate, incomplete or non-unique. They are drafts requiring qualified human review. The Customer must compare processed photographs with originals and verify all factual claims before publication. AI output is not authentication, valuation, investment, legal, tax or condition advice. The AI Features and Image Integrity Policy applies.

8. Pricing, currencies and market insights

The Service may apply Customer-configured base prices, foreign-exchange conversions, channel adjustments, fee estimates and rounding rules. The rate source and timestamp should be displayed where relevant. A conversion or automated suggestion is not a guarantee of executable price, fee, margin or market value. Live prices do not change merely because an exchange rate changes unless the Customer expressly enables and approves that behaviour.

The Customer is responsible for final prices and taxes. Market insight, if enabled, is limited to the Customer's own data or licensed aggregate information that cannot identify or single out another dealer, listing or individual watch. Outputs must use risk-based minimum cohort thresholds, suppress rare model/region/time combinations, prevent repeated or overlapping queries from reconstructing underlying records, and exclude underlying rows, seller identity, listing URL, image, description, serial number and availability. The Provider does not warrant the completeness, representativeness or future accuracy of an aggregate index.

9. Integrations and third-party services

The Customer authorises the Provider to access each Connected Account using the permissions the Customer grants and to send or receive the Customer's own listing, inventory, order and status data as described in the Integration Terms. The Customer is responsible for third-party accounts, fees, policies and credentials.

Third-Party Services are outside the Provider's control. Their APIs, policies and availability may change. The Provider may change or discontinue a connector where necessary for law, security, feasibility or third-party restrictions. It will not replace an unavailable official interface with scraping or unauthorised access.

10. Fees, invoicing and tax

Fees, billing currency, invoicing frequency, subscription term and usage limits are stated in the Order Form. Unless stated otherwise, invoices are due 30 days from invoice date, fees exclude VAT and similar taxes, and the Customer is responsible for taxes other than taxes on the Provider's net income. Overdue undisputed amounts accrue interest under the Swedish Interest Act and may incur reasonable recovery costs.

The Customer must raise a good-faith invoice dispute within 15 days of receipt and pay undisputed amounts on time. Except where the Agreement gives a termination refund or mandatory law requires otherwise, fees are non-refundable.

An Order Form controls renewal. If it is silent, the subscription continues month-to-month after the paid period and either party may terminate on 30 days' written notice. The Provider may change fees for a renewal or future monthly period on at least 30 days' notice. No change applies retroactively.

11. Privacy, data processing and security

For Customer Data processed on the Customer's behalf, the Customer is normally controller and the Provider processor. The Data Processing Agreement applies. For website, account administration, billing, direct business communications and protection of the Service, the Provider may act as an independent controller as described in the Privacy Notice.

The Provider will maintain appropriate technical and organisational measures proportionate to the risk, including access control, tenant isolation, logging, secure development, incident handling, backup and encryption measures described in the DPA. The Customer is responsible for secure user configuration, lawful instructions, appropriate endpoint security and timely review of account access.

No certification is promised unless it is expressly identified in a current Security Overview or Order Form.

12. Confidentiality

Each party may receive non-public information that a reasonable person would understand to be confidential, including business plans, pricing, source code, security information, unpublished inventory, full serial numbers, acquisition costs, customer lists, credentials and personal data. The recipient will use it only for the Agreement, protect it with at least reasonable care, and disclose it only to personnel, advisers and subcontractors who need it and are bound by confidentiality.

Confidential information excludes information the recipient can show was lawfully known without restriction, independently developed, lawfully received from a third party, or public without breach. If disclosure is legally compelled, the recipient will, where legally permitted, give prompt notice and reasonable assistance.

These duties continue for five years after disclosure and for trade secrets for as long as they remain protected as trade secrets. The DPA governs personal data and survives as stated there.

13. Intellectual property

The Provider and its licensors retain all rights in the Service, software, APIs, interface, Documentation, templates, models, methods, improvements, branding and aggregated statistics that do not identify a Customer, person, watch, listing or dealer. The Customer retains Customer Data and its marks.

The Customer may use AI output and processed media produced from its Customer Data for its business, subject to applicable law and third-party rights. The Provider does not guarantee that output is protectable, exclusive or free from similarity to other material.

If the Customer gives feedback, it grants the Provider a perpetual, worldwide, royalty-free right to use it without identifying the Customer. The Provider may use the Customer's name or logo in marketing only with prior written permission.

14. Acceptable use and compliance

The Customer and Authorised Users must comply with the Acceptable Use Policy. A breach by an Authorised User is a breach by the Customer. The Customer must not bypass technical limits, remove required AI or provenance markers, attempt cross-tenant access, build competitor-monitoring tools, or instruct staff, contractors, APIs or AI prompts to obtain Prohibited Third-Party Dealer Data.

Each party will comply with laws applicable to its performance. The Customer is responsible for export, sanctions, product, consumer and marketplace requirements relating to its watches and sales.

15. Suspension

The Provider may suspend affected access where reasonably necessary to address a material security threat, unlawful conduct, unauthorised dealer data, infringement complaint, harmful content, non-payment, third-party platform direction or material breach. Where safe and practicable, it will give notice and a chance to cure and will limit suspension to the affected account, feature or data.

The Provider may quarantine content while investigating provenance or rights. Suspension does not excuse undisputed fees. Lawful export and return rights remain subject to the Data Act, DPA and the need to protect security and third-party rights.

16. Limited warranties

Each party warrants that it has authority to enter the Agreement. The Provider warrants that during a paid production subscription the Service will materially conform to its Documentation and that Professional Services will be performed with reasonable skill and care. The Customer's exclusive remedy for a reproducible breach is correction or re-performance; if the Provider cannot remedy a material breach within a reasonable period, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees.

Except for those express warranties and mandatory law, the Service, beta features, AI output, market information and third-party integrations are provided without implied warranties. The Provider does not warrant uninterrupted operation, error-free output, third-party acceptance, a sale, margin, price, authenticity, provenance, translation, regulatory compliance of a Customer listing, or that an integration will remain available.

17. Indemnities

The Customer will defend and indemnify the Provider against a third-party claim arising from Customer Data, an unlawful or unauthorised listing, counterfeit or stolen goods, Customer instructions, breach of the AUP, or the Customer's violation of a connected platform's terms, except to the extent caused by the Provider's breach.

The Provider will defend the Customer against a third-party claim that the unmodified paid Service infringes an EU intellectual-property right. The Provider may obtain a right to continue, modify or replace the affected Service, or terminate it and refund prepaid unused fees. This obligation does not cover Customer Data, combinations not supplied by the Provider, unauthorised use or continued use after a reasonable instruction to stop.

The indemnified party must give prompt notice, reasonable cooperation and control of the defence, subject to the indemnified party's right to participate at its own cost and a prohibition on settlements admitting fault or imposing non-monetary obligations without consent.

18. Liability

Nothing excludes or limits liability that cannot lawfully be limited, or liability for fraud, wilful misconduct, gross negligence, death or personal injury caused by negligence. The Customer's payment obligations are not limited by this section.

Subject to the preceding paragraph, neither party is liable for indirect, incidental, special or consequential loss, or loss of profit, revenue, goodwill, anticipated savings or business opportunity. Reasonable costs to restore Customer Data following the Provider's breach are treated as direct loss.

Each party's aggregate liability arising from the Agreement is limited to fees paid or payable for the affected Service during the 12 months before the event giving rise to liability. For breach of confidentiality, the DPA or the Provider's security obligations, the aggregate cap is twice that amount. Service credits are the exclusive monetary remedy for an availability failure covered by an SLA, but not for a separate breach of confidentiality, data protection or security.

For claims arising from a free Beta Feature, the aggregate liability cap is SEK 5,000 and cannot be reduced below that amount by a zero-fee calculation, including for confidentiality, data-protection and security claims. It applies whether or not the Customer followed the prohibited-data rule; it does not authorise prohibited use, waive a Customer breach or expand the Service. A production pilot requires a signed pilot agreement with separately approved higher monetary floors and risk allocation. Liability caps and any insurance-backed floor remain a publication and executive-approval gate.

These allocations reflect a B2B service and should be read with any negotiated Order Form. Mandatory law and the Swedish Contracts Act remain applicable.

19. Term and termination

The Agreement begins when an Order Form is accepted. Either party may terminate for material breach not cured within 30 days after written notice. The Provider may terminate or suspend for an undisputed payment default not cured within 10 days after notice, or immediately where continued performance would be unlawful or create a serious security risk. Either party may terminate if the other enters insolvency proceedings that are not dismissed within 60 days, subject to mandatory insolvency law.

On termination, access ends except for an agreed transition. The Customer must revoke connected credentials and manage or remove live external listings. Amounts accrued remain due. The Customer may export data during the term and the applicable retrieval period. The Provider will return or delete personal data as instructed under the DPA and will delete other Customer Data under the Retention and Exit Policies, subject to legal holds, accounting law and protected backups.

Provisions that by nature should survive—including fees, confidentiality, IP, liability, disputes and data return/deletion—survive termination.

20. Data portability and switching

The Data Portability, Switching and Exit Policy is incorporated. Standard export of Exportable Data is available in structured, commonly used, machine-readable formats. The Provider will not impose a switching charge for standard legally required export. Additional mapping, implementation or migration work requested beyond legal and contractual obligations may be provided under a Statement of Work at an agreed price.

21. Changes to terms and service

The Provider may make non-material changes to clarify published standard terms, correct errors or improve presentation. Ordinary commercial changes apply at renewal or, for a rolling subscription, after at least 30 days' notice. A change required urgently by law or to address a specific security risk may take effect sooner, with an explanation and only to the extent necessary.

The Provider may not unilaterally amend an Order Form, DPA, Standard Contractual Clauses or signed Statement of Work. If another proposed standard-term or Service change would materially disadvantage the Customer and is not strictly required by law or security, the Customer may terminate the affected Service before it takes effect and receive a pro-rata refund of prepaid unused fees. This right applies to a materially adverse legal, data-use, liability or functionality change, not only a reduction in features.

Feature changes consistent with the Documentation do not amend negotiated commercial commitments. An Order Form can only be changed in writing by authorised representatives.

22. Transfer to registered Klocktech AB

Registration of Klocktech AB does not itself change the Provider. The Customer agrees that Heritage Timepieces AB may transfer the Agreement as a whole to Klocktech AB after registration if Klocktech AB assumes all Provider obligations, the transfer does not materially reduce Customer rights, and at least 30 days' written notice identifies the registered entity, organisation number, VAT number, address, effective date and updated contacts.

If applicable law or a negotiated Order Form requires a separate novation or consent, the transfer takes effect only when that requirement is met. Outstanding claims remain enforceable. If a proposed transfer would materially disadvantage the Customer, the Customer may object before the effective date and terminate the affected subscription with a pro-rata refund of prepaid unused fees. Counsel must confirm the final transfer mechanism before any notice is issued.

Neither party may otherwise assign the Agreement without the other's consent, not to be unreasonably withheld, except to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant business, provided the assignee can perform the obligations.

23. General terms

Neither party is liable for delay caused by events beyond reasonable control, except payment obligations, provided it mitigates and promptly informs the other. The parties are independent contractors; no partnership, employment, fiduciary or agency relationship is created.

Notices concerning breach, termination, transfer or claims must be sent by email to the addresses in the Order Form, with Provider legal notices copied to legal@heritagetp.com. Operational notices may be sent in the Service. Email is deemed received on the next business day unless a delivery failure is received.

Failure to enforce a right is not a waiver. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remainder continues. The Agreement is the entire agreement on its subject and supersedes prior proposals and discussions. Electronic signatures and acceptances are valid.

The Agreement is governed by Swedish law, excluding conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. The parties will first attempt in good faith for 30 days to resolve a dispute through executive negotiation. Unresolved disputes are subject to the Swedish courts, with the district court competent for the Provider's registered office as the first instance, unless the Order Form provides for arbitration or mandatory law requires otherwise.