Legal Center
Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).
This page describes Klocktech's minimum production security commitments and shared-responsibility model. It must be checked against the implemented architecture before publication. It does not claim ISO 27001, SOC 2, PCI DSS or another certification unless a current certificate is expressly listed.
Klocktech is designed around tenant isolation, least privilege, data minimisation, traceability and human control. The Customer's own or authorised inventory is the only inventory source. The architecture must not expose a generic crawler, arbitrary URL fetcher, marketplace search or cross-tenant analytics path.
Connectors authenticate only to the Customer's account and read only its own known listings, orders or events. An official API being unavailable does not authorise scraping. AI vendors must be approved, contractually restricted, listed where they process personal data, and contractually prohibited and technically configured from training on Customer Data.
The Provider maintains procedures to detect, triage, contain, investigate, recover from and learn from security incidents. Affected Customers receive notice under the DPA and Agreement. Public status and post-incident reporting will be proportionate to impact and security considerations.
Security issues should be reported under the Vulnerability Disclosure Policy. In an urgent suspected account compromise, contact legal@heritagetp.com and identify the affected organisation and account without emailing passwords or unnecessary personal data.
The Provider secures the Klocktech platform. The Customer must secure its devices, email, identity provider, users, permissions, connected accounts and internal processes; review access regularly; keep contact information current; verify suspicious output or connector errors; and maintain lawful copies or exports needed for its business continuity.
Before commercial launch, management should approve a documented risk assessment, vendor review, penetration test plan, recovery test, access review, incident exercise and security owner. Any future audit report or certification must be described accurately with scope and date.