Legal Center

Data Retention and Deletion Policy

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. Principles

Klocktech retains data only for a defined purpose, then deletes, anonymises or restricts it. The Customer controls retention of Customer Personal Data to the extent the Service permits and remains responsible for its legal obligations. Legal holds, accounting rules, fraud prevention and security investigations can require restricted retention beyond an ordinary period.

The schedule below is a proposed launch default and must be confirmed against architecture, backups, vendor settings, claims periods and Customer requirements before publication.

2. Proposed schedule

Data categoryProposed defaultEnd-of-period action
Active Customer inventory, media, listings, reservations and Customer-controlled recordssubscription term plus switching and retrieval periodreturn/export and active-system deletion under DPA/Exit Policy
Deleted-item recycle bin30 dayspermanent active deletion unless restored or held
Post-termination retrieval copyat least 30 calendar days after transition/termination pointdelete active copy after retrieval period
Backups containing deleted Customer Dataexpire within 90 days after active deletionoverwrite through normal rotation; no restoration except recovery need
Account identity and role history not required for accountingsubscription plus 24 monthsdelete or anonymise, retaining limited audit evidence if needed
Security and authentication logs12 monthsdelete or anonymise; extend for an active incident or claim
Administrative audit trail for price, serial access, publishing and statussubscription plus 24 months, or longer if Customer configures lawfullydelete or anonymise; Customer export where supported
Support tickets and routine correspondencethree years after closure as a routine defaultdelete or minimise attachments; retain only selected evidence longer under a documented claims assessment
Contracts, invoices and accounting recordsthrough the seventh year after the calendar year in which the financial year ended, or longer for a documented legal requirement or selected claims evidencesecure deletion after the applicable legal and evidence period
Sales leads with no active relationship24 months after last meaningful interactiondelete or anonymise unless renewed basis exists
Marketing consent and objection evidenceconsent while used; minimal suppression record as long as needed to honour objectionrestrict to proof and suppression purpose
Cookie/device dataexact period in the verified Cookie Inventoryexpire or delete at stated time
Incident and legal-claim fileduration of matter plus applicable limitation and evidence periodrestricted archive then secure deletion
AI prompts and outputs in Customer recordsCustomer-configured record perioddelete with Customer record; external-vendor retention must be separately listed
Accidentally received Prohibited Third-Party Dealer Dataonly as long as necessary to block, contain and document the incident, normally no more than 30 days absent a legal holddelete the payload promptly; retain only minimised security or legal evidence where necessary

3. Deletion operation

Deletion from active production removes the data from normal user and support access. Backups are immutable or restricted and expire through documented rotation; deleted data is not intentionally restored except as part of disaster recovery, after which the deletion instruction is re-applied. Vendors must delete according to their agreements.

Anonymisation is used only where re-identification is not reasonably possible considering all means likely to be used. Merely removing a Customer name is not enough if a watch, serial, image or commercial pattern remains identifiable.

Swedish business claims may in some cases have a ten-year limitation period. This does not justify retaining all account or support data for ten years. The Provider must document which minimised contract, notice, payment, authority or security evidence is actually needed for a claim, restrict access to that evidence and delete unrelated content on the ordinary schedule.

4. Customer controls and requests

Customers should be able to export before deletion, configure eligible retention, delete individual records where lawful, and request a deletion confirmation. An authenticated GDPR erasure instruction or other verified permanent-deletion request bypasses an ordinary user recycle bin and promptly removes the data from normal user and support access, unless a documented legal exception applies; restricted backup copies then expire through rotation and are not returned to ordinary use. A deletion request may be refused or limited where retention is required by law, necessary for a legal claim, needed to protect security or would delete another person's data unlawfully. The reason will be documented.

5. Vendor and AI alignment

The subprocessor register must record vendor retention where it differs from Klocktech's active schedule. An AI vendor may not retain prompts or outputs longer or use them for training merely because its default terms permit it; Klocktech must select and contract the appropriate enterprise setting before production use.