1. WHO WE ARE The data controller for personal data processed through WatchProject B2B is Penta Lucent S.L. ("WatchProject B2B", "we", "us"), with registered address at Calle Nicaragua, 85, Local 3, Despacho B, 08029 Barcelona, Spain, Tax ID (CIF) B88788252. You can contact us on any privacy matter, or to exercise the rights described in Section 7, at info@watchproject-b2b.com. This Privacy Policy explains how we collect, use, share and protect personal data when you visit our website, create an account, or use the Service, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Data Protection and Digital Rights Guarantee (LOPDGDD). 2. WHAT DATA WE COLLECT Depending on how you use the Service, we process the following categories of personal data: Account and profile data: email address, password (stored as a salted hash, never in plain text), first and last name, handle, phone number, profile picture, business name, business description and website URL (for merchant accounts), preferred language, and address details you choose to add to your profile. Visibility preferences: your choices as to whether your phone number, WhatsApp number and address are shown publicly on your profile. Listing data: watch descriptions, photographs, prices, brand, model and reference information, and other content you submit when creating or managing a listing. Communications: messages, offers and attachments you exchange with other users through our chat feature. Message content is encrypted at rest. Notification preferences and delivery data: your channel opt-ins (email, WhatsApp, push, SMS where offered), and records of notifications sent to you and their delivery/read status, including status updates we receive from WhatsApp when you have opted in to that channel. Technical and usage data: IP address, device and browser information, log data, and cookies strictly necessary to operate the website (see Section 8). Risk and moderation signals: internal risk indicators (such as an automatically computed fraud score) and moderation flags associated with your account, generated from your activity on the Service, used to protect users and the marketplace from fraud, abuse and prohibited listings. Reports: if you report a listing or a user, we process the report reason and details you provide, and if you are reported, the report and any related decision are processed as part of moderation. We do not intentionally collect special categories of personal data (e.g. health, religion, political opinions) and ask that you do not include such data in your profile, listings or messages. 3. PURPOSES AND LEGAL BASES We process personal data for the following purposes: To create and administer your account, and to provide the core marketplace functionality (publishing and browsing listings, messaging, offers) - necessary for the performance of the contract between you and us (Article 6(1)(b) GDPR). To operate features you opt into, such as WhatsApp, push or SMS notifications, and to send you the notifications you have configured - performance of the contract and, for optional channels, your consent (Article 6(1)(a) and (b) GDPR). To detect and prevent fraud, abuse, counterfeit or stolen-item listings, and other violations of our Marketplace, Moderation and Visibility Rules, including through automated risk scoring described in Section 10 - our legitimate interest in keeping the marketplace safe and trustworthy, and that of other users (Article 6(1)(f) GDPR). To restrict visibility of certain listings to Verified Merchant accounts, and to notify eligible merchants of matching supply and demand ("dealer matching") where that feature is enabled for your account - performance of the contract with merchant accounts and our legitimate interest in operating a functioning B2B marketplace segment (Article 6(1)(b) and (f) GDPR). To send you service and security communications (e.g. account activation, password reset) - necessary for the performance of the contract and our legitimate interest in account security (Article 6(1)(b) and (f) GDPR). These transactional messages are sent regardless of your marketing notification preferences, because they are necessary to operate your account. To send non-transactional notifications by email (e.g. activity digests, marketing-style updates) - your consent, which you can withdraw at any time using the unsubscribe link included in every such email or from your notification settings (Article 6(1)(a) GDPR). To comply with legal obligations, including responding to lawful requests from public authorities, tax and accounting obligations, and to establish, exercise or defend legal claims (Article 6(1)(c) and (f) GDPR). To maintain the security, integrity and availability of the website, including through essential cookies and technical logs (Article 6(1)(f) GDPR). 4. WHO WE SHARE DATA WITH Other users: your handle, profile information you choose to make public, listing content, and messages you send are visible to the users you interact with, to the extent you make them public or address them to that user. Service providers acting on our behalf (data processors), under a data processing agreement and only to the extent necessary to perform their service: hosting and infrastructure providers; cloud/object storage providers for listing photographs and profile pictures; error-monitoring and diagnostics tooling used to keep the Service reliable; email delivery providers; and WhatsApp Business Platform, operated by Meta Platforms, Inc. / Meta Platforms Ireland Ltd, used to deliver notifications to users who have opted into WhatsApp notifications. Public authorities, regulators, courts or law enforcement, where we are required to disclose data by law, to comply with a legal obligation, or to protect our rights, property or safety, or that of our users or the public. Professional advisers (e.g. legal, accounting) where necessary for their services, under confidentiality obligations. We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes. 5. INTERNATIONAL TRANSFERS We aim to process personal data within the European Economic Area (EEA) wherever possible. Some processors we use, including the WhatsApp Business Platform (Meta), may process data outside the EEA, including in the United States. Where this occurs, we rely on the safeguards recognised under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision, to ensure your data receives an equivalent level of protection. You can request more information about these safeguards at info@watchproject-b2b.com. 6. RETENTION We retain personal data for as long as your account is active and the data is necessary to provide the Service. When you close your account, we delete or anonymise personal data within a reasonable period, except data we must keep for longer to comply with a legal obligation (e.g. tax and accounting records), to resolve disputes, to enforce our agreements, or to protect against fraud and abuse (for example, moderation and risk records may be retained after account closure where necessary to prevent repeat abuse). Messages remain available to the participants of a conversation for as long as their accounts and the conversation exist, or until deleted in accordance with our data retention practices. Notification delivery logs are retained for a limited period sufficient to diagnose delivery issues and to demonstrate consent for non-transactional communications. 7. YOUR RIGHTS Subject to the conditions set out in applicable data protection law, you have the right to: access the personal data we hold about you; request rectification of inaccurate or incomplete data; request erasure of your data; request restriction of processing; object to processing based on our legitimate interest, including profiling for risk-scoring purposes; request portability of data you provided to us in a structured, commonly used, machine-readable format; and withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing before withdrawal. Many of these rights can be exercised directly from your account settings (profile data, notification channel opt-ins, listing and message deletion). For anything else, contact us at info@watchproject-b2b.com. We will respond within the time limits set by applicable law. You also have the right to lodge a complaint with a supervisory authority, in particular the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD, www.aepd.es), or the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. 8. COOKIES We use cookies and similar technologies that are strictly necessary to operate the website, including a secure, HTTP-only session cookie used to keep you signed in. These essential cookies cannot be disabled without affecting the functioning of the Service and are not used to track you across other websites. We do not currently use analytics or advertising cookies; if this changes, we will update this section and request your consent where required by law before setting non-essential cookies. 9. CHILDREN The Service is not directed at, and is not intended to be used by, individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at info@watchproject-b2b.com so we can take appropriate action. 10. AUTOMATED PROCESSING AND RISK SCORING We use automated indicators, including an internally computed risk/fraud score based on account and platform activity, to flag accounts and listings that may require review for potential fraud, abuse or violations of our Marketplace Rules. Flagging is a signal for our moderation team, not an automatic decision: actions that materially affect your account, such as suspension or restriction, are subject to review by our team before being applied, and you may contact us to request human review of a moderation decision that affects you. 11. SECURITY We apply technical and organisational measures appropriate to the risk, including encryption of chat messages at rest, storage of authentication tokens in secure, HTTP-only cookies rather than in a form accessible to client-side scripts, and hashing of passwords with a dedicated password hasher. No system is completely secure; if we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent authority and, where required, affected users, in accordance with Articles 33 and 34 GDPR. 12. CHANGES TO THIS POLICY We may update this Privacy Policy to reflect changes in our processing activities or applicable law. We will publish the updated version on the website and update the effective date; for material changes, we will provide additional notice (for example by email or an in-product notice) where required by law. 13. CONTACT For any question about this Privacy Policy or your personal data, contact Penta Lucent S.L. at info@watchproject-b2b.com or at Calle Nicaragua, 85, Local 3, Despacho B, 08029 Barcelona, Spain. Last updated: 18 July 2026.