Legal Center
Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).
This Data Processing Agreement (“DPA”) forms part of the SaaS Agreement between the Customer as controller and Heritage Timepieces AB as processor where the Provider processes Customer Personal Data on the Customer's behalf. Capitalised terms not defined here have the meaning in the SaaS Terms. GDPR terms have their GDPR meanings.
Klocktech AB is under registration and is not the processor until a valid transfer of the SaaS Agreement and this DPA takes effect. A transfer notice must identify the registered processor and preserve all obligations and safeguards.
“Customer Personal Data” means personal data contained in Customer Data that the Provider processes on the Customer's behalf. This DPA does not govern processing for which the Provider is an independent controller under the Privacy Notice.
The Provider will process Customer Personal Data only on documented Customer instructions, including the Agreement, configured product actions, authorised support requests and written instructions consistent with the Service. If EU or Member State law requires other processing, the Provider will inform the Customer before processing unless legally prohibited.
The Provider will immediately inform the Customer if, in its opinion, an instruction infringes applicable data-protection law. It may suspend the affected processing while the parties resolve the issue. The Provider does not determine the Customer's purposes and must not combine Customer Personal Data with another dealer's data or use it for its own advertising or general model training.
The Customer is responsible for lawful instructions, transparency, legal bases, rights handling, data accuracy, minimisation and configuration. It must not submit special-category data, criminal-offence data, government identifiers, payment-card data or identity documents unless the Service expressly supports them and the parties document the necessary safeguards.
| Item | Description |
|---|---|
| Subject matter | Hosting and operating Klocktech inventory, media, publication, reservation, reporting, support and enabled AI or connector functions |
| Duration | The subscription term, approved transition and retrieval period, followed by deletion under this DPA and the Retention Policy |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, transformation, generation, translation, transmission to Customer-selected destinations, backup, restriction and deletion |
| Purposes | Delivering, securing, supporting and troubleshooting the contracted Service on the Customer's instructions |
| Data subjects | Customer personnel and users; dealer buyers, prospects, sellers, consignors and reservation contacts; supplier and partner contacts; people incidentally appearing in authorised Customer content |
| Data types | Identity and business contact data; account roles; communications; reservation and transaction references; watch reference and full or partial serial numbers; watch ownership or provenance notes; device and audit data; images and attachments; AI inputs and outputs; Customer-selected channel identifiers |
| Sensitive data | Not intended. Special-category, criminal-offence, identity-document and payment-card data are prohibited unless expressly agreed with documented safeguards |
| Frequency | Continuous or event-based according to Customer use |
| Controller rights | Determine purposes and instructions; configure users and retention; access and export data; request assistance, return or deletion; audit compliance |
The Provider will ensure that every person authorised to process Customer Personal Data is bound by confidentiality, receives appropriate privacy and security training, and accesses only what is necessary for assigned duties. Access is removed promptly when no longer required.
Support access to a tenant should be Customer-approved where practicable, time-limited, role-scoped and logged. Emergency access needed to contain a serious incident may occur without advance approval but must be documented and notified as soon as reasonably possible.
The Provider will implement and maintain measures appropriate to risk under Article 32 GDPR. The minimum launch commitments are:
| Control area | Minimum measure |
|---|---|
| Governance | assigned security responsibility, policies, risk review, asset and vendor register, documented incident and continuity procedures |
| Identity and access | unique accounts, least privilege, role-based access, administrator MFA, periodic access review, secure credential and token handling |
| Tenant isolation | tenant identifier and authorisation enforced in storage, APIs, jobs, caches, analytics and support tools; automated cross-tenant tests |
| Encryption | current industry-standard encryption in transit; encryption at rest for production data and backups; managed keys and restricted key access |
| Sensitive watch data | full serial numbers field-level access-controlled and encrypted; backend-only or masked public derivative showing no more than three original characters; immutable original preserved; access, redaction and changes audited |
| Serial containment | no full serial in public text, media, metadata, filenames, URLs, notifications or routine logs; masked logs and restricted administrator exports; no AI, reference or market-data vendor receives a full serial; a destination-required private API field is used only after a separate per-destination Customer instruction, when strictly necessary and protected from public display, and is unavailable while backend-only mode is selected |
| Logging and monitoring | security, administrative, authentication, export, connector and privileged-access events logged, protected and reviewed proportionate to risk |
| Secure development | code review, dependency and secret scanning, environment separation, change control, security testing and remediation prioritised by risk |
| Vulnerability management | supported software, patching based on severity, responsible disclosure route and periodic independent testing appropriate to scale |
| Availability | monitored production service, protected backups, restore tests, capacity controls and documented recovery responsibilities |
| Incident response | triage, containment, evidence preservation, communication, lessons learned and corrective action |
| Data lifecycle | minimisation, configurable retention where available, controlled export, secure deletion and backup expiry |
| Vendors | due diligence, written security and data terms, least data access, subprocessor register and continuing review |
| AI and integrations | approved vendors only; no competitor browsing; no vendor training on Customer Data; Customer Data scoped to tenant and authorised destination; originals, segmentation and provenance retained |
| Physical and personnel | reputable data-centre controls through hosting vendors; confidentiality, onboarding and offboarding for Provider personnel |
The Provider may update measures to address technology and risk, provided overall protection is not materially reduced. This table is a contractual target and must be verified by the CTO before publication; it is not a claim of certification.
The Customer grants general written authorisation for subprocessors listed in the Subprocessor Register. The Provider will conduct due diligence, impose data-protection obligations no less protective than this DPA as applicable, and remain responsible for their performance.
The Provider will give at least 30 days' advance notice before any new or replacement subprocessor begins processing Customer Personal Data. The notice will identify the processor and intended processing. The Customer may object within 15 days on reasonable data-protection grounds. The parties will seek a reasonable alternative. If none is reasonably available, either party may terminate the affected feature or Service and the Customer will receive a pro-rata refund of prepaid unused fees for it.
If an urgent security or continuity event makes 30 days impracticable, the new processor still may not begin processing under the Customer's general authorisation until the Customer has been informed in advance and given a genuine opportunity to object. If advance objection time cannot safely be provided, the Provider must obtain the Customer's specific written authorisation or use an already authorised alternative; otherwise the new processor may not receive Customer Personal Data.
No production personal data may be sent to an unlisted AI, support or infrastructure vendor. Customer-selected sales channels acting as independent recipients are not subprocessors merely because Klocktech transmits data at the Customer's direction.
The Provider will not transfer Customer Personal Data outside the EU/EEA unless the transfer complies with Chapter V GDPR. Where an adequacy decision does not apply, the parties will use an appropriate mechanism, normally the applicable module of the European Commission Standard Contractual Clauses in Decision (EU) 2021/914, together with transfer assessment and supplementary safeguards where required.
If the Customer is an EU/EEA controller and the Provider transfers to a non-EEA subprocessor not directly subject to GDPR for the processing, the Provider will implement the appropriate processor-to-processor safeguards. The Subprocessor Register will identify countries and mechanisms.
Taking account of the nature of processing, the Provider will provide appropriate technical and organisational assistance for access, correction, deletion, restriction, portability, objection and other Chapter III requests. If a request is received directly and relates to Customer-controlled data, the Provider will forward it without undue delay and will not respond substantively unless instructed or legally required.
Assistance included in standard product functions is included in subscription fees. Exceptional manual work may be chargeable at agreed rates if permitted by law and caused by Customer configuration or volume.
The Provider will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and, where feasible, aims to provide an initial notice within 24 hours. The notice will include available information on nature, affected categories and approximate volume, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases.
The Provider will investigate, contain, remediate, preserve relevant records and reasonably assist the Customer with Articles 33–36 GDPR. Notification does not admit fault. The Customer remains responsible for notifying authorities and individuals unless the parties expressly agree otherwise.
The Provider will reasonably assist with data-protection impact assessments and prior consultation for the Service, considering the information available and nature of processing. The Customer remains responsible for deciding whether a DPIA is required and for the content of its assessment.
During the term and retrieval period, the Customer may export Customer Personal Data using available functions. At termination, the Customer may instruct return or deletion. The Provider will delete active-system copies after the agreed retrieval period and backup copies through normal expiry, unless EU or Member State law requires retention. Retained data will be isolated, protected and used only for the legally required purpose.
The proposed default is a minimum 30-day retrieval period, active-system deletion within 30 days after it ends, and backup expiry within 90 days after active deletion. The Customer may request written confirmation. The Data Act and Exit Policy apply where they require additional switching rights.
The Provider will make available information reasonably necessary to demonstrate Article 28 compliance, beginning with current policies, security documentation, subprocessor information, test summaries and written responses. No more than once per year, and additionally after a material incident or credible concern, the Customer may request a reasonable audit by itself or an independent auditor bound by confidentiality.
Audits must use existing evidence first, avoid disruption and other customers' data, occur during business hours with reasonable notice, and comply with security rules. The Customer bears its costs unless the audit identifies material non-compliance, in which case the Provider bears reasonable audit costs and promptly remediates. The Provider is not required to disclose another customer's data, penetration details that create risk, source code or protected trade secrets where equivalent evidence is available.
The Provider will assess requests for Customer Personal Data, verify authority and scope, challenge unlawful or disproportionate requests where reasonable, disclose only what is legally required, and notify the Customer before disclosure unless prohibited. It will document requests and apply the international-access safeguards described in the Subprocessor and Data Locations page.
Liability under this DPA is governed by the SaaS Terms without limiting rights of data subjects or regulatory powers under mandatory law. This DPA continues while the Provider processes Customer Personal Data. For all Customer Personal Data matters, it prevails over every inconsistent Agreement document; the European Commission's unmodified SCCs prevail where applicable.