We collect only what an order needs, we never sell your data, and you can have it deleted at any time by writing one e-mail.
watchexclusive.eu is run by I&M Montres s. r. o., a company based in Slovakia, inside the European Union. That means the EU General Data Protection Regulation (GDPR) applies to every customer we serve – wherever in the world you live. This page explains, in plain language, what we hold, why, who else sees it and how to get it back or removed.
The four things worth knowing before you read the detail
Everything below is explained in full further down the page – these are the commitments that matter most.
We never sell your data
Your name, address and order history are not for sale, not rented out and not passed to data brokers. They go only to the people who physically need them: the courier, the payment provider and our accountant.
Tracking only if you say yes
Analytics and advertising cookies load only after you accept them in the consent banner. Refuse them and the shop works exactly the same – you can change your mind at any moment.
Encrypted end to end
The whole site runs over HTTPS and card details never touch our servers – Stripe and PayPal process them under PCI-DSS certification. We see only the last four digits and the transaction ID.
Deleted on request
Ask us to erase your data and we do it within 30 days, apart from invoices that Slovak tax law forces us to archive for ten years. One e-mail is enough – no form, no fee.
1. Who is responsible for your data
The controller – the company that decides what happens to your data and answers for it – is the same company that sells you the watch.
| Controller | I&M Montres s. r. o. |
| Registered office | Na križovatkách 18, 821 04 Bratislava, Slovakia (EU) |
| Showroom | Karpatská 18, 811 05 Bratislava, Slovakia |
| Company ID (IČO) | 47 218 061 |
| Commercial register | Commercial Register of the City Court Bratislava III, Section: Sro, Insert No. 90094/B |
| VAT number | SK2023803793 |
| E-mail for privacy matters | [email protected] |
| Telephone | +421 911 591 937 |
| Supervisory authority | Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava – dataprotection.gov.sk |
We are a small company and do not process data on a scale that requires a formal Data Protection Officer under Article 37 GDPR. Privacy questions are handled directly by the management team at the e-mail address above, normally the same working day.
2. What we collect, why, and how long we keep it
Every processing operation needs a purpose and a legal basis. This is the complete list – there is nothing else running in the background.
| Purpose | Data | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Handling your order | Name, delivery and billing address, e-mail, telephone, order contents | Art. 6(1)(b) – performance of a contract | For the duration of the order, then archived with the invoice |
| Invoicing and accounting | Invoice data, payment method, transaction reference, VAT details | Art. 6(1)(c) – legal obligation (Slovak Accounting Act) | 10 years from the end of the accounting year |
| Your customer account | E-mail, encrypted password, order history, wish list, saved addresses | Art. 6(1)(b) and Art. 6(1)(a) – contract and consent | Until you delete the account, or after 3 years of inactivity |
| Returns, complaints and guarantee claims | Order number, description of the fault, photographs, bank details for the refund | Art. 6(1)(b) and Art. 6(1)(c) | 4 years from the end of the claim |
| Newsletter and offers | E-mail address, record of your consent, whether the message was opened | Art. 6(1)(a) – consent, withdrawable at any time | Until you unsubscribe, then 3 years for proof of consent |
| Analytics and advertising | IP address (shortened), device and browser, pages viewed, session recordings | Art. 6(1)(a) – consent given in the cookie banner | Up to 14 months, or until you withdraw consent |
| Security and fraud prevention | IP address, order pattern, payment provider risk signals | Art. 6(1)(f) – our legitimate interest in preventing fraud | 12 months |
| Verifying identity for bank transfers | Date of birth or an identity document, only for high-value transfers when the law requires it | Art. 6(1)(c) – anti-money-laundering obligation | As long as that law requires, then deleted |
| Review invitations | E-mail address, order number | Art. 6(1)(f) – legitimate interest in customer feedback | Sent once after delivery; you can opt out in the e-mail |
We do not use your data for automated decision-making or profiling that has a legal effect on you. We do not knowingly process special categories of data – health, beliefs, biometrics – and we ask you not to send them to us. Cookies are described in detail on the Cookies page.
4. Who else sees your data
We share data only where an order genuinely cannot be completed without it, and every recipient works under a written processing agreement.
| Recipient | What they receive | Why |
|---|---|---|
| Carriers – DHL Express, UPS, Packeta, national postal operators | Name, address, telephone, e-mail | To deliver the parcel and let you track it. Carriers per country are listed on our Shipping page. |
| Stripe Payments Europe (Ireland) | Payment data, order amount | Card processing. Card numbers go straight to Stripe – we never see them. |
| PayPal (Europe) S.à r.l. (Luxembourg) | E-mail, order amount | PayPal payments, under PayPal’s own privacy terms. |
| VÚB banka, a. s. (Slovakia) | Name, payment reference, amount | Bank transfers and refunds. |
| Our accountants and tax advisers | Invoice data | Statutory bookkeeping and tax returns. |
| Cookiebot – Usercentrics A/S (Denmark) | Consent record, anonymised IP | Proof that consent was properly obtained. |
| Google Ireland Ltd | Cookie identifiers, usage data | Analytics and advertising – only with your consent. |
| Microsoft Ireland Operations Ltd | Cookie identifiers, session recordings | Clarity and Microsoft Advertising – only with your consent. |
| Contentsquare SA (France) | Anonymised interaction data | Understanding how pages are used – only with your consent. |
| Trustpilot A/S (Denmark) | E-mail address, order number | Sending you a single invitation to review your purchase. |
| Our hosting and IT support provider | Technical access to the store database | Running and maintaining the website. |
5. Sending data outside the European Union
Your data is stored on servers inside the European Union. Some of the providers above are part of international groups, so limited transfers to the United States can happen – for example when Google or Microsoft process analytics data. Those transfers are covered by the European Commission’s Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework.
If your watch is delivered outside the EU, the carrier and the customs authority of the destination country receive the name, address and contents of the parcel – that is unavoidable, it is what a customs declaration is. Those authorities process the data under their own national law, not under this policy.
6. Your rights – and how to use them in one e-mail
The GDPR gives you eight rights over your data. You do not need a form, a reason or a lawyer to use any of them.
- Access
Ask what we hold about you and get a copy of it, free of charge. - Rectification
Have anything wrong or incomplete corrected – a misspelt street, an old telephone number. - Erasure
Have your data deleted, except invoices that tax law obliges us to keep for ten years. - Restriction
Freeze the processing while a dispute about accuracy or legitimate interest is resolved. - Portability
Receive the data you gave us in a machine-readable file, or have it sent to another company. - Objection
Object to anything based on our legitimate interest. For direct marketing the objection is absolute – we stop immediately. - Withdrawal of consent
Withdraw consent to the newsletter or to cookies at any time. That does not affect what was lawful before. - Complaint
Complain to a data protection authority if you believe we have got something wrong.
How to exercise them. Write to [email protected] from the address you used for your order, or use the contact form. Tell us what you want – a copy, a correction, deletion – and we answer within 30 days, free of charge. If a request is unclear or we cannot match it to a customer, we may ask one question back to confirm it is really you; we never demand a copy of an identity document just to answer a routine request.
Newsletter and cookies without writing to us. Every marketing e-mail has an unsubscribe link at the bottom that works instantly. Cookie consent is changed on the Cookies page. Registered customers can edit their address book and personal details directly in their account.
Where to complain. If you are not satisfied with our answer, you can complain to the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk. If you live elsewhere in the EU, you may complain to the authority in your own country instead.
7. How your data is protected
The whole site is served over HTTPS with a valid certificate, passwords are stored hashed and never in readable form, and access to the order system is limited to the few people who handle orders, each with their own account. Backups are encrypted and kept inside the EU.
Card details are never stored by us. They are entered on Stripe’s or PayPal’s own PCI-DSS certified infrastructure and we receive only a transaction identifier and the last four digits. No system is perfectly secure, but if a breach ever put your rights at risk we would notify the supervisory authority within 72 hours and tell you directly, as Article 34 GDPR requires.
8. Children
The shop is intended for adults. We do not knowingly collect data from anyone under 16, and an order can only be placed by someone with the legal capacity to enter into a contract. If you believe a child has given us personal data, write to us and we will delete it without delay.
9. If you are shopping from outside the EU
We apply the same GDPR standard to every customer. A few national rules are worth adding.
California residents. Under the CCPA and CPRA you may ask what categories of personal information we collected in the past twelve months, ask for a copy, ask for deletion, and be free from any discrimination for doing so. We do not sell or share personal information for cross-context behavioural advertising in the sense of the CCPA, and we have never done so, so there is nothing to opt out of – but you are welcome to confirm that with us. Send any CCPA request to [email protected]; we answer within 45 days.
Canada, Australia, New Zealand and elsewhere. Your national privacy law may give you further rights. In practice the GDPR rights listed in section 6 are broader than most of them, and we apply those rights to you as well – simply write to us.
Customs. Deliveries outside the EU require an export and import declaration containing your name, address and the contents of the parcel. That declaration goes to the customs authority of your country and we cannot avoid or restrict it.
10. Changes to this policy
We update this page when we add a tool, a carrier or a payment method, or when the law changes. The current version always sits at this address and the date of the last change is shown below. If a change materially affects how we use data you have already given us, we tell registered customers by e-mail before it takes effect.
This policy sits alongside our Terms & Conditions, the Refunds & Returns policy and the Cookies page, which together describe your relationship with us.
In force from 4 September 2026. This English version is the reference text; translations are provided for convenience.
Privacy – frequently asked questions
The questions customers actually ask about their data.
Do you sell my data to anyone?
No. We do not sell, rent or trade personal data, and we never have. It goes only to the courier, the payment provider, our accountant and – with your consent – the analytics tools listed in section 4.
Can I order without creating an account?
Yes. Guest checkout collects only what is needed to deliver and invoice the order. An account is optional and simply stores your addresses and order history so you do not retype them.
How do I delete everything you hold about me?
Send one e-mail to [email protected] from the address on your order. We delete your account, your marketing data and your contact history within 30 days. Invoices stay in our accounts for ten years because Slovak tax law requires it – that part cannot be deleted on request.
Do you see my card number?
No. Card details are entered directly on Stripe’s or PayPal’s systems. We receive a transaction reference and the last four digits, which is what appears on your invoice.
What happens if I refuse cookies?
The shop works normally. Only essential cookies run; analytics, session recording and advertising stay switched off. You can change your mind on the Cookies page at any time.
How long do you keep my order?
The invoice for ten years, because the Slovak Accounting Act says so. Everything else is shorter: an inactive account is deleted after three years, analytics data after at most fourteen months, fraud-prevention logs after twelve months.
A question about your data?
Write to us and a person – not a ticketing system – will answer, usually the same working day. Access, correction and deletion requests are free and need no special form.
I&M Montres s. r. o. · Na križovatkách 18, 821 04 Bratislava, Slovakia · [email protected] · +421 911 591 937