Legal Center
Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).
This notice explains how the current Klocktech provider handles personal data as an independent controller when people visit the Klocktech website, request a demo, subscribe on behalf of a business, administer an account, contact support, receive business communications, or interact with Klocktech personnel.
When Klocktech processes personal data contained in a Customer's inventory, reservation, sales, support or other records solely on the Customer's instructions, the Customer is normally the controller and the Provider is processor. That processing is governed by the Data Processing Agreement. The Customer must give its own notice to the affected people.
Until a valid entity transfer takes effect, the controller for the activities in this notice is Heritage Timepieces AB, organisation number 559491-1157, Kungsgatan 2C, 223 50 Lund, Sweden. Privacy requests may be sent to legal@heritagetp.com or the postal address above.
Klocktech AB is under registration. Its registration will not by itself transfer controller responsibility. Any future controller change will be communicated with the new entity's details, effective date and effect on existing processing.
Depending on the relationship, the Provider may process:
The public website and Service are not intended for children. The Provider does not knowingly offer accounts to anyone under 18.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Respond to enquiries and evaluate a business relationship | contact, message, employer | steps requested before a contract where the person is a party; otherwise legitimate interests in business development and communication |
| Create and administer business accounts | identity, account, role, organisation | performance of a contract where applicable; legitimate interests in delivering the Customer's contract |
| Provide support and service notices | contact, support, diagnostic data | contract and legitimate interests in operating and improving the Service |
| Invoice, collect and keep accounting records | commercial, billing and contact data | contract, legal obligation and legitimate interests in financial administration |
| Protect systems, prevent misuse and investigate incidents | technical, security and account data | legitimate interests in network and information security and, where applicable, legal obligation |
| Improve product usability and reliability | usage, diagnostic and feedback data | legitimate interests, using minimised or aggregated data where reasonably possible; consent where a non-essential cookie or similar technology requires it |
| Send product news, invitations and business marketing | business contact, interests and history | consent where required; otherwise legitimate interests, always subject to the right to object and Swedish electronic-marketing rules |
| Establish, exercise or defend legal claims | relevant account, contract, communication and security records | legitimate interests and legal obligation |
| Meet lawful authority requests | data specified in a valid request | legal obligation or applicable public-interest requirement |
Where legitimate interests are used, the Provider considers necessity, reasonable expectations, business context, sensitivity and safeguards. A person may object as described below. The Provider does not use consent where processing is necessary to perform a contract or comply with law.
To enter and administer a Klocktech contract, the Provider normally requires the Customer organisation's legal and billing details and an authorised representative's name, business contact details and authority. To create and protect a user account, it requires the user's name or identifier, business email, organisation, role and authentication/security events. Applicable invoice and VAT information is required to bill and keep legally required records.
If required contract or account information is not provided, the Provider may be unable to conclude the subscription, create or secure the account, provide support, issue a compliant invoice or perform the requested Service. Fields clearly marked optional—such as telephone number, marketing interests, feedback, profile preferences or non-essential analytics consent—may be withheld without losing the core Service, unless a particular optional feature cannot function without the stated field. A person may refuse direct marketing at any time.
Data is usually obtained directly from the person or the Customer organisation. It may also come from an account administrator, authorised integration, event organiser, referral, professional network or a public business source. The Provider will not scrape personal contact lists or another dealer's inventory or customer information. Where Article 14 GDPR applies, required information will be provided within the applicable period unless a lawful exception applies.
Personal data may be shared only as needed with:
The Provider does not sell personal data. Customer-selected marketplaces and websites may act under their own terms and privacy notices rather than as Klocktech subprocessors.
The production vendor and location register must be completed before launch. If personal data is transferred outside the EU/EEA, the Provider will use an applicable adequacy decision or another lawful safeguard such as the European Commission's Standard Contractual Clauses, assess the transfer circumstances, and implement supplementary measures where needed. The Subprocessor Register will identify the destination and transfer mechanism. A copy of relevant safeguards may be requested, subject to redaction of confidential information.
Personal data is retained only as long as necessary for its purpose, legal requirements, security and claims. The Data Retention and Deletion Policy contains the proposed schedule. Key examples include the subscription period and exit window for active account data, the statutory period for accounting records, limited periods for security logs and support history, and prompt honouring of marketing objections. A legal hold or dispute may require longer, restricted retention.
The Provider uses risk-appropriate technical and organisational safeguards, including access control, authentication, tenant separation, encryption, logging, backup, secure development, vendor oversight and incident procedures as described in the Security Overview and DPA. No internet service can be guaranteed absolutely secure. Users must protect credentials and promptly report suspected compromise.
The Provider does not use personal data in its controller activities to make a solely automated decision that produces legal or similarly significant effects on an individual. AI-assisted content, image and pricing features are subject to human review and are governed by the AI Features Policy. If a future use changes this position, the notice and product safeguards will be updated before deployment.
Subject to GDPR conditions and exceptions, a person may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting prior lawful processing. A person has an absolute right to object to direct marketing.
Requests should be sent to legal@heritagetp.com. The Provider may request the minimum additional information reasonably needed to verify identity and authority. It aims to respond within one month, subject to lawful extension for complexity or volume.
A person may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or another competent supervisory authority. The Provider welcomes an opportunity to address the concern first.
Material changes will be highlighted with an updated date and, where appropriate, direct notice. A new purpose incompatible with the original purpose will not be introduced without a valid legal basis and any required notice or consent.