23 september 2026

Privacy Policy

What personal data Worldwatch collects from dealers, their staff and the buyers whose orders reach us, why we process it, who receives it, how long we keep it, and the rights you have under the GDPR.

Version
1.1
Gäller från
23 september 2026

This policy applies when you use the Worldwatch platform, visit our websites, or interact with a dealer who uses Worldwatch. Worldwatch is a business-to-business platform for professional watch dealers. This policy is written for the people behind those businesses, for buyers and counterparties whose data reaches us through orders, and for website visitors. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Dutch law.

1.Who is responsible for your data

The controller for the processing described in this policy is Worldwatch.market B.V., Damsterdiep 10, 9711 SK Groningen, the Netherlands (Chamber of Commerce 98632329, VAT NL868577091B01). For privacy matters, email privacy@worldwatch.market.

Where a dealer stores its own customer or counterparty data in Worldwatch, or we synchronise it from a sales channel on the dealer's behalf, that dealer is the controller and we process the data as its processor. Section 5 explains this.

2.Whose data we process

  • Dealer owners, representatives and staff who register, operate or use a dealer account.
  • Buyers and counterparties whose details appear in orders, offers and transactions processed through the platform, typically because a dealer's sales on a connected channel are synchronised into it.
  • Prospective users and contacts: people who contact us, request a demo or sign up for updates.
  • Website visitors.
  • Beneficial owners and representatives verified during onboarding and compliance checks.

3.What we collect and where it comes from

Directly from you: account and profile data (name, business email, phone number, role, authentication data), business onboarding data (company details, trade register extracts, VAT numbers and, where verification is required, identity document data processed through our verification provider), and communications with us or through the platform.

From your organisation: a colleague may add you as a user, in which case we receive your name, email and role from your employer.

Generated by your use of the platform: listings, orders, offers, transaction records, activity logs and technical data such as IP address, device and browser information and error diagnostics.

From third parties: connected sales channels (order and buyer details for transactions on those channels, synchronised on the dealer's behalf), public registers and verification providers (for onboarding and compliance), and payment providers (payment confirmation and status data; we never receive full card numbers).

PurposeLegal basis (Art. 6 GDPR)
Providing the platform: accounts, listings, orders, marketplace, channel distribution, dealer networkPerformance of a contract
Onboarding, identity and business verificationContract; legal obligation where anti-money-laundering rules apply
Payments and payouts through our payment partnersContract; legal obligation
Tax and accounting record-keepingLegal obligation, including the 7-year retention under Dutch tax law
Platform security, fraud prevention, trust and safety, including reports, investigations and enforcementLegitimate interests; legal obligation under the Digital Services Act
Service diagnostics, error monitoring and improvement of the platformLegitimate interests
AI-assisted features of the platform (section 8)Legitimate interests
Aggregated, de-identified market data and the watch registerLegitimate interests
Product updates and commercial communications to business usersLegitimate interests, with an opt-out in every message
Responding to requests from competent authoritiesLegal obligation

Where we rely on legitimate interests, we have assessed that they are not overridden by your rights. You may object at any time (section 10).

5.Our role toward dealer data

Dealers use Worldwatch to manage their own customer, buyer and counterparty data, including data we synchronise from connected sales channels at the dealer's request. For that data the dealer is the controller and we are the processor, acting on the dealer's instructions under our Data Processing Agreement. The dealer is responsible for informing its customers, for the accuracy of the data it enters, and for its own use of it.

We process limited parts of that data as an independent controller only where we have our own purpose in law: security, fraud prevention, trust and safety, tax and accounting records, and other legal obligations.

If you are a buyer or counterparty and want to exercise your rights over transaction data, contact the dealer you dealt with. We assist dealers with requests and forward any request we receive directly.

6.Who receives your data

We use service providers, acting as processors under data processing agreements, in the following categories: cloud hosting and infrastructure (EU, Netherlands region); authentication and account management; search; image processing and delivery; error monitoring; email delivery; AI model providers; and payment and identity verification providers. The current list of sub-processors is set out in our Data Processing Agreement and available on request.

Independent recipients act as separate controllers under their own privacy policies: connected sales channels for buyer and order data on those channels, payment providers for their regulated activities, and competent authorities where we are legally required to provide data.

Our platform data is hosted in the European Economic Area. Where a provider processes data outside the EEA, we rely on the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses, with additional safeguards where appropriate.

7.How long we keep your data

DataRetention
Account and profile dataDuration of the account, then up to 6 months
Order and transaction records, including buyer details7 years, as required by Dutch tax law
Identity verification records5 years after the business relationship ends, as required by Dutch anti-money-laundering law
Trust and safety reports, investigations and enforcement recordsAs long as needed for accountability under the Digital Services Act and to defend legal claims
Support communications2 years
Technical logs and error dataUp to 1 year

When a retention period ends, or an erasure request is honoured, the data is deleted or anonymised. Backups are kept on a rolling schedule and overwritten in the ordinary course. Where the law requires us to keep records, erasure takes effect when that period expires.

8.Automated decision-making, profiling and AI

Trust and risk indicators. We maintain internal trust and risk indicators for accounts, derived from platform history, to prioritise reviews and protect the marketplace. Decisions with legal or similarly significant effects, such as suspension or removal, involve human review. Where automated tools contributed to a moderation decision, the statement of reasons you receive says so.

Fraud detection. Automated rules may flag activity for human investigation.

AI-assisted features. Parts of the platform use AI models, including models from third-party providers, to help dealers draft listing and advertisement text, create listings, suggest prices based on market data and translate content. These features work on listing and market data. We minimise the personal data sent to them, and our providers are contractually prevented from using it to train their own models.

Ranking. How listings are ranked in marketplace search is described in our Ranking Disclosure.

You have the right to obtain human intervention in respect of any automated decision that affects you, to express your point of view and to contest the decision.

9.How we protect your data

Platform data is hosted in the European Union. We apply encryption in transit and at rest, access controls and audit logging, and vulnerability management across our infrastructure. No system is perfectly secure. If a breach occurs that risks your rights, we notify the Dutch Data Protection Authority and, where required, you, in accordance with articles 33 and 34 GDPR.

10.Your rights

You have the right to access, rectify and erase your personal data, to restrict or object to processing, and to receive personal data you provided in a portable format. These rights apply to the personal data of natural persons. They do not extend to business data such as inventory, pricing or the sales records of a dealer account.

To exercise a right, email privacy@worldwatch.market. We verify your identity and respond within one month, extendable by two months for complex requests, in which case we tell you. A first request is free unless it is manifestly unfounded or excessive.

Data subject to a statutory retention period, such as transaction records under tax law, cannot be erased before that period expires; erasure is scheduled and takes effect when it ends.

You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the supervisory authority of your EU member state.

11.Cookies

Our websites set only cookies that are strictly necessary for authentication and security, plus preference cookies that remember your language choice. We set no advertising cookies, and our page analytics are cookieless and do not identify individual visitors. Details are in the Cookie Policy.

12.Changes to this policy

We may update this policy as the platform and the law evolve. Material changes are announced to account holders in advance through the platform or by email. The current version is always available at worldwatch.market/legal/privacy, with its effective date at the top.

13.Contact

Worldwatch.market B.V., Damsterdiep 10, 9711 SK Groningen, the Netherlands. privacy@worldwatch.market.