Legal Center

Subprocessor Register and Data Locations

Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).

1. Publication gate

This page is required before Klocktech handles production Customer Personal Data. No production subprocessor or infrastructure jurisdiction has been approved in this draft. Do not publish an empty or assumed register. The CTO and privacy owner must populate it from signed vendor agreements, configured regions and actual data flows.

2. Required production register

For every subprocessor, publish:

FieldRequired information
Legal vendorfull contracting entity, not only product name
Servicehosting, database, authentication, email, support, monitoring, AI, payments or other function
Datacategories processed and whether Customer Personal Data is involved
Data subjectsaffected categories
Processing locationcountry or region for storage and access
Transfer safeguardadequacy, SCC module or other mechanism where outside EU/EEA
Appointment datedate processing began
Vendor privacy/security linkcurrent public information where useful

Current production status: awaiting vendor selection and verification.

3. Customer-selected destinations

A marketplace, e-commerce platform or other destination selected and controlled by the Customer is normally an independent recipient under its own terms, not a Klocktech subprocessor merely because Klocktech sends the Customer's listing. If the same vendor separately provides infrastructure or another service on Klocktech's behalf, that processing must still be listed.

4. Change notice and objections

The Provider gives subscribed Customers at least 30 days' advance notice before any new or replacement subprocessor begins processing Customer Personal Data. Customers may object on reasonable data-protection grounds within 15 days, following the DPA process.

For an urgent security or continuity replacement, notice must still be given before processing begins. If the ordinary objection period cannot safely be provided, the Provider must obtain the Customer's specific written authorisation or use an already authorised alternative. It will not disclose Customer Personal Data first and notify later under the general authorisation.

5. ICT infrastructure jurisdiction and international government access

Before launch, this page must identify the jurisdiction to which the ICT infrastructure for each Klocktech service is subject. It must also describe, at a useful general level, the technical, organisational and contractual measures used to prevent third-country governmental access to or transfer of non-personal data held in the EU where that would conflict with EU or Member State law.

Minimum measures should include data-location controls, encryption, access restriction, request validation, challenge of unlawful requests, minimised disclosure, customer notice where lawful, transparency records and carefully selected vendors. The final SaaS Agreement must link to this up-to-date page.