lcp
Privacy & data protection · GDPR · Updated 4 September 2026

We collect only what an order needs, we never sell your data, and you can have it deleted at any time by writing one e-mail.

watchexclusive.eu is run by I&M Montres s. r. o., a company based in Slovakia, inside the European Union. Because we sell into the United Kingdom, both the EU GDPR and the UK GDPR apply to your data. This page explains, in plain language, what we hold, why, who else sees it and how to get it back or removed.

EU controller  ·  No data selling  ·  Consent-based tracking  ·  Deletion on request
The policy at a glance
ControllerI&M Montres s. r. o., Bratislava, Slovakia (EU)
Law that appliesEU GDPR and UK GDPR
What we collectContact, order, payment and website-usage data
WhyTo deliver your order, meet tax law, and – with consent – improve the shop
Sold to anyone?Never. We do not sell or rent personal data
Kept for10 years for invoices, less for everything else
Your rightsAccess, correction, deletion, portability, objection

The four things worth knowing before you read the detail

Everything below is explained in full further down the page – these are the commitments that matter most.

We never sell your data

Your name, address and order history are not for sale, not rented out and not passed to data brokers. They go only to the people who physically need them: the courier, the payment provider and our accountant.

Tracking only if you say yes

Analytics and advertising cookies load only after you accept them in the consent banner. Refuse them and the shop works exactly the same – you can change your mind at any moment.

SSL

Encrypted end to end

The whole site runs over HTTPS and card details never touch our servers – Stripe and PayPal process them under PCI-DSS certification. We see only the last four digits and the transaction ID.

30

Deleted on request

Ask us to erase your data and we do it within 30 days, apart from invoices that Slovak tax law forces us to archive for ten years. One e-mail is enough – no form, no fee.

1. Who is responsible for your data

The controller – the company that decides what happens to your data and answers for it – is the same company that sells you the watch.

Controller I&M Montres s. r. o.
Registered office Na križovatkách 18, 821 04 Bratislava, Slovakia (EU)
Showroom Karpatská 18, 811 05 Bratislava, Slovakia
Company ID (IČO) 47 218 061
Commercial register Commercial Register of the City Court Bratislava III, Section: Sro, Insert No. 90094/B
VAT number SK2023803793
E-mail for privacy matters [email protected]
Telephone +421 911 591 937
Supervisory authority Office for Personal Data Protection of the Slovak Republic – dataprotection.gov.sk. UK customers may also contact the Information Commissioner’s Office (ICO).

We are a small company and do not process data on a scale that requires a formal Data Protection Officer under Article 37 GDPR. Privacy questions are handled directly by the management team at the e-mail address above, normally the same working day.

2. What we collect, why, and how long we keep it

Every processing operation needs a purpose and a legal basis. This is the complete list – there is nothing else running in the background.

Purpose Data Legal basis (GDPR) Retention
Handling your order Name, delivery and billing address, e-mail, telephone, order contents Art. 6(1)(b) – performance of a contract For the duration of the order, then archived with the invoice
Invoicing and accounting Invoice data, payment method, transaction reference, VAT details Art. 6(1)(c) – legal obligation (Slovak Accounting Act) 10 years from the end of the accounting year
Your customer account E-mail, encrypted password, order history, wish list, saved addresses Art. 6(1)(b) and Art. 6(1)(a) – contract and consent Until you delete the account, or after 3 years of inactivity
Returns, complaints and guarantee claims Order number, description of the fault, photographs, bank details for the refund Art. 6(1)(b) and Art. 6(1)(c) 4 years from the end of the claim
Newsletter and offers E-mail address, record of your consent, whether the message was opened Art. 6(1)(a) – consent, withdrawable at any time Until you unsubscribe, then 3 years for proof of consent
Analytics and advertising IP address (shortened), device and browser, pages viewed, session recordings Art. 6(1)(a) – consent given in the cookie banner Up to 14 months, or until you withdraw consent
Security and fraud prevention IP address, order pattern, payment provider risk signals Art. 6(1)(f) – our legitimate interest in preventing fraud 12 months
Verifying identity for bank transfers Date of birth or an identity document, only for high-value transfers when the law requires it Art. 6(1)(c) – anti-money-laundering obligation As long as that law requires, then deleted
Review invitations E-mail address, order number Art. 6(1)(f) – legitimate interest in customer feedback Sent once after delivery; you can opt out in the e-mail

We do not use your data for automated decision-making or profiling that has a legal effect on you. We do not knowingly process special categories of data – health, beliefs, biometrics – and we ask you not to send them to us. Cookies are described in detail on the Cookies page.

3. Cookies, analytics and the consent banner

Nothing that is not strictly necessary runs before you agree to it. That is the rule, and it is enforced technically, not just written here.

How consent works. The banner is provided by Cookiebot. Until you make a choice, only essential cookies are set – the ones that keep your cart, your language and your login working. Analytics, session recording and advertising tags stay blocked. Your choice is stored for twelve months and you can change or withdraw it at any time from the Cookies page.

What we measure. With your consent we use Google Analytics 4 and Google Tag Manager to see which pages and which watches interest visitors, Microsoft Clarity and Contentsquare to see where a page confuses people, and Google Ads and Microsoft Advertising to measure whether an advertisement led to a sale and to show you our watches again on other sites. IP addresses are shortened before analysis and we do not receive your name from any of these tools.

Refusing changes nothing about the shop. You can browse, order, pay and return a watch with every optional cookie switched off. Refusing consent has no effect on prices, delivery or your rights – it only means we learn less about how the site is used.

4. Who else sees your data

We share data only where an order genuinely cannot be completed without it, and every recipient works under a written processing agreement.

Recipient What they receive Why
Carriers – DHL Express, UPS, Royal Mail (final delivery) Name, address, telephone, e-mail To deliver the parcel and let you track it. Carriers per country are listed on our Shipping page.
Stripe Payments Europe (Ireland) Payment data, order amount Card processing. Card numbers go straight to Stripe – we never see them.
PayPal (Europe) S.à r.l. (Luxembourg) E-mail, order amount PayPal payments, under PayPal’s own privacy terms.
VÚB banka, a. s. (Slovakia) Name, payment reference, amount Bank transfers and refunds.
Our accountants and tax advisers Invoice data Statutory bookkeeping and tax returns.
Cookiebot – Usercentrics A/S (Denmark) Consent record, anonymised IP Proof that consent was properly obtained.
Google Ireland Ltd Cookie identifiers, usage data Analytics and advertising – only with your consent.
Microsoft Ireland Operations Ltd Cookie identifiers, session recordings Clarity and Microsoft Advertising – only with your consent.
Contentsquare SA (France) Anonymised interaction data Understanding how pages are used – only with your consent.
Trustpilot A/S (Denmark) E-mail address, order number Sending you a single invitation to review your purchase.
Our hosting and IT support provider Technical access to the store database Running and maintaining the website.
We never sell, rent or trade personal data, and we do not share it with advertisers as a product. Beyond the list above, data leaves us only where a court, a tax authority or the police requires it by law, or where you ask us to send it somewhere yourself.

5. Sending data outside the European Union

Your data is stored on servers inside the European Union. Some of the providers above are part of international groups, so limited transfers to the United States can happen – for example when Google or Microsoft process analytics data. Those transfers are covered by the European Commission’s Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework.

If your watch is delivered outside the EU, the carrier and the customs authority of the destination country receive the name, address and contents of the parcel – that is unavoidable, it is what a customs declaration is. Those authorities process the data under their own national law, not under this policy.

6. Your rights – and how to use them in one e-mail

The GDPR gives you eight rights over your data. You do not need a form, a reason or a lawyer to use any of them.

  1. Access
    Ask what we hold about you and get a copy of it, free of charge.
  2. Rectification
    Have anything wrong or incomplete corrected – a misspelt street, an old telephone number.
  3. Erasure
    Have your data deleted, except invoices that tax law obliges us to keep for ten years.
  4. Restriction
    Freeze the processing while a dispute about accuracy or legitimate interest is resolved.
  5. Portability
    Receive the data you gave us in a machine-readable file, or have it sent to another company.
  6. Objection
    Object to anything based on our legitimate interest. For direct marketing the objection is absolute – we stop immediately.
  7. Withdrawal of consent
    Withdraw consent to the newsletter or to cookies at any time. That does not affect what was lawful before.
  8. Complaint
    Complain to a data protection authority if you believe we have got something wrong.

How to exercise them. Write to [email protected] from the address you used for your order, or use the contact form. Tell us what you want – a copy, a correction, deletion – and we answer within 30 days, free of charge. If a request is unclear or we cannot match it to a customer, we may ask one question back to confirm it is really you; we never demand a copy of an identity document just to answer a routine request.

Newsletter and cookies without writing to us. Every marketing e-mail has an unsubscribe link at the bottom that works instantly. Cookie consent is changed on the Cookies page. Registered customers can edit their address book and personal details directly in their account.

Where to complain. If you are not satisfied with our answer, you can complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow SK9 5AF, or to the Office for Personal Data Protection of the Slovak Republic, dataprotection.gov.sk, as our lead authority.

7. How your data is protected

The whole site is served over HTTPS with a valid certificate, passwords are stored hashed and never in readable form, and access to the order system is limited to the few people who handle orders, each with their own account. Backups are encrypted and kept inside the EU.

Card details are never stored by us. They are entered on Stripe’s or PayPal’s own PCI-DSS certified infrastructure and we receive only a transaction identifier and the last four digits. No system is perfectly secure, but if a breach ever put your rights at risk we would notify the supervisory authority within 72 hours and tell you directly, as Article 34 GDPR requires.

8. Children

The shop is intended for adults. We do not knowingly collect data from anyone under 16, and an order can only be placed by someone with the legal capacity to enter into a contract. If you believe a child has given us personal data, write to us and we will delete it without delay.

9. UK-specific points

The UK left the EU, so two extra points apply to British orders.

UK GDPR and international transfers. Sending your data from the EU to the UK is permitted under the European Commission’s adequacy decision for the United Kingdom, so no additional safeguards are needed. Your rights under the UK GDPR are the same eight rights listed in section 6, and the ICO supervises how we handle them.

Customs. A parcel from Slovakia to the UK needs an export and import declaration containing your name, address and the contents of the parcel. That declaration goes to HM Revenue & Customs and to the carrier acting as your customs agent; we cannot avoid or restrict it. Import VAT and any duty are collected from you by the carrier on delivery.

10. Changes to this policy

We update this page when we add a tool, a carrier or a payment method, or when the law changes. The current version always sits at this address and the date of the last change is shown below. If a change materially affects how we use data you have already given us, we tell registered customers by e-mail before it takes effect.

This policy sits alongside our Terms & Conditions, the Refunds & Returns policy and the Cookies page, which together describe your relationship with us.

In force from 4 September 2026. This English version is the reference text; translations are provided for convenience.

Privacy – frequently asked questions

The questions customers actually ask about their data.

Do you sell my data to anyone?

No. We do not sell, rent or trade personal data, and we never have. It goes only to the courier, the payment provider, our accountant and – with your consent – the analytics tools listed in section 4.

Can I order without creating an account?

Yes. Guest checkout collects only what is needed to deliver and invoice the order. An account is optional and simply stores your addresses and order history so you do not retype them.

How do I delete everything you hold about me?

Send one e-mail to [email protected] from the address on your order. We delete your account, your marketing data and your contact history within 30 days. Invoices stay in our accounts for ten years because Slovak tax law requires it – that part cannot be deleted on request.

Do you see my card number?

No. Card details are entered directly on Stripe’s or PayPal’s systems. We receive a transaction reference and the last four digits, which is what appears on your invoice.

What happens if I refuse cookies?

The shop works normally. Only essential cookies run; analytics, session recording and advertising stay switched off. You can change your mind on the Cookies page at any time.

How long do you keep my order?

The invoice for ten years, because the Slovak Accounting Act says so. Everything else is shorter: an inactive account is deleted after three years, analytics data after at most fourteen months, fraud-prevention logs after twelve months.

A question about your data?

Write to us and a person – not a ticketing system – will answer, usually the same working day. Access, correction and deletion requests are free and need no special form.

I&M Montres s. r. o. · Na križovatkách 18, 821 04 Bratislava, Slovakia · [email protected] · +421 911 591 937

Product added to wishlist