Legal Center

Data Portability, Switching and Exit Policy

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. Purpose

This policy explains how a Customer can export its data, terminate or switch from Klocktech, and request deletion. It is intended to satisfy the Agreement and, to the extent applicable to Klocktech as a provider of data processing services, Chapter VI of the EU Data Act.

2. Exportable Data

“Exportable Data” means the input and output data, including relevant metadata, directly or indirectly generated or co-generated by the Customer's use of the Service that the Customer is entitled to retrieve under the Agreement or applicable law. To the extent within the Provider's control and legally exportable, it includes:

  • structured watch inventory fields, tags, locations and status history;
  • original Customer-uploaded images and processed variants the Customer may use;
  • Customer-authored and AI-assisted descriptions and translations;
  • prices, currencies, Customer rules, rounding results and relevant timestamps;
  • the Customer's own connected listing identifiers and synchronisation state;
  • reservations, sales references and Customer-generated transaction records;
  • Customer-created users, roles and settings where appropriate;
  • relevant Customer-generated metadata and audit history; and
  • a data dictionary and available documentation needed to understand the export.

The proposed standard formats are CSV or JSON for structured data and a ZIP archive containing media in original or commonly used formats. Export must include the data and Customer-related digital assets required by applicable switching law; technical design choices may shape the documented format but do not remove a mandatory category. Actual schemas, size limits, interfaces and preparation times must be verified and published before launch in the online Data Structures and Export Formats Register on this page.

3. Exclusions

An export does not include another tenant's data; Prohibited Third-Party Dealer Data; third-party material the Customer has no right to receive; Provider source code, models, weights, algorithms or internal prompts; security-sensitive telemetry; destination credentials; or Provider trade secrets. An exclusion will not be applied so broadly that it prevents export of Customer input, output or relevant co-generated metadata required by law.

Licensed aggregate market data may be excluded or limited by its licence. The export should retain the Customer's own query and permitted aggregate result where legally and contractually allowed, but never underlying rows or a combination of results that defeats cohort thresholds, rare-combination suppression or overlapping-query controls and reveals a dealer, listing or individual watch.

4. Export during the subscription

The Customer may use available self-service export or send an authorised request to info@heritagetp.com. The Provider may verify administrator authority and deliver a large export through an encrypted or access-controlled channel. Export functions must not expose another tenant or secret credentials.

5. Switching process

The Customer may notify the Provider that it wishes to switch to another service, move to its own ICT infrastructure, or erase Exportable Data. To the extent the Data Act applies:

  • the maximum notice period to initiate switching will not exceed two months;
  • the mandatory transition will be completed without undue delay and within 30 calendar days after that notice period;
  • if 30 days is technically infeasible, the Provider will explain within 14 working days and identify an alternative period not exceeding seven months;
  • the Customer may extend the transition once, by notice, for a period that the Customer considers more appropriate for its own purposes;
  • service continuity and appropriate security will be maintained during the applicable transition while the Agreement remains in effect;
  • a retrieval period of at least 30 calendar days follows the transition; and
  • all Exportable Data and Customer-related digital assets that must be erased will be deleted after successful switching and expiry of retrieval, subject only to documented legal retention and any later deletion time validly agreed at the Customer's request.

To the extent the Data Act applies, the Agreement for the affected data processing service terminates when switching has been successfully completed. If the Customer requests erasure without switching, it terminates at the end of the applicable maximum notice period. Accrued payment rights, confidentiality, liability and legally required retention survive only as stated in the Agreement. The Provider will maintain contractual functions and continuity during the mandatory transition.

The Customer and destination provider must cooperate in good faith, supply destination details and protect credentials. Klocktech is responsible for making the export available; it is not responsible for rebuilding the Service or guaranteeing that a destination reproduces Klocktech functions.

6. Charges

Klocktech will not charge for a standard self-service or legally required switching export. Bespoke data cleansing, custom mapping, consulting, destination configuration or migration work beyond mandatory obligations may be charged only under a separately agreed Statement of Work. Standard subscription fees and proportionate fixed-term termination provisions are not described as switching charges.

7. Third-party channels

Exit from Klocktech does not automatically close a marketplace account or remove live listings held by a third party. The Customer must confirm channel status, revoke credentials and manage external records. The Provider will stop future synchronisation and delete stored tokens according to the Integration Terms.

8. Deletion and recovery

At the Customer's choice and subject to the DPA, the Provider returns or deletes Customer Personal Data. It will erase all required Exportable Data and Customer-related digital assets after the retrieval period, not only records labelled “Customer-generated”. The proposed default is at least 30 days for retrieval, active deletion within 30 days after retrieval ends, and backup expiry within 90 days after active deletion. Legal holds, accounting requirements and narrowly retained security evidence are exceptions and remain protected.

9. Open interfaces

Where Article 30(2) of the Data Act applies, Klocktech will make open interfaces available at no charge to the Customer and the Customer's authorised destination provider, with the same functions and service information made equally available to all customers and destination providers. Machine-to-machine interfaces will be supported where required for effective switching. Authentication, rate limits and security controls may be applied only where proportionate and must not frustrate switching.

10. Data Structures, Export Formats and Digital Assets Register

Before production contracting, Klocktech must publish and maintain an online, exhaustive register of categories of exportable data and Customer-related digital assets, their structures and formats, available interfaces, supported standards, preparation method, size or rate limits, known technical restrictions and retrieval process. The public register must explain any category excluded or protected for security, third-party rights or trade-secret reasons without disclosing the secret itself.

The Provider must also maintain an internal, exhaustive register of the specific data and digital-asset categories that risk exposing its trade secrets, the owner of each secret, the legal and technical basis for protection, and the least restrictive switching measure available. These registers, real export schemas and interface tests are publication blockers.

11. Infrastructure and international access information

The Subprocessor Register and Data Locations page must identify infrastructure jurisdictions and measures against unlawful third-country governmental access to EU-held non-personal data. The production contract must link to that current page. This is a publication blocker until actual hosting and vendor facts are confirmed.