Legal Center
Status: Draft v0.9 — 11 August 2026 — legal and operational review required before publication. Current provider: Heritage Timepieces AB, org. no. 559491-1157, VAT SE559491115701, Kungsgatan 2C, 223 50 Lund, Sweden. Entity notice: Klocktech AB is under registration and is not the current contracting party. Registration alone does not transfer an agreement. Contacts: legal@heritagetp.com (legal/privacy) · info@heritagetp.com (general).
This draft does not yet identify production hostnames. No asset is authorised for security testing under this draft. Before publication, Klocktech must list exact in-scope web and API hostnames and any test environment. Third-party platforms, customer systems, marketplaces, employee devices, social accounts and Heritage Timepieces' watch-commerce systems are out of scope unless expressly listed.
To request written permission or report an accidental finding, contact legal@heritagetp.com with “Klocktech security” in the subject. Do not include passwords, unnecessary personal data or a large data sample.
After scope is published, a researcher must:
The Provider will not pursue a civil claim for activity it determines was performed in good faith and in strict compliance with the published scope and rules. This statement cannot bind customers, third parties or public authorities and is subject to Swedish counsel approval before publication.
No permission is given for denial of service, high-volume automation, credential stuffing, phishing, social engineering, malware, destructive testing, physical intrusion, spam, extortion, public disclosure before coordination, testing a third-party platform, accessing a real Customer account without that Customer's written permission, or downloading data as “proof”.
If another tenant's or dealer's information becomes visible, stop immediately. Do not browse further, enumerate, download, retain, contact the dealer or test other accounts. Report only the minimum detail needed to locate the issue and follow secure deletion instructions.
A useful report includes the authorised asset, issue type, date and time, minimal reproduction, impact, relevant request identifiers, and safe remediation ideas. After the security team and workflow are staffed, publish achievable acknowledgement, triage and update targets. Until then, no response-time or bounty promise is made. No monetary reward exists unless a separate bounty programme expressly states one.
Coordinated public disclosure requires written agreement on timing and content. The Provider may credit a researcher only with permission.