Privacy policy
This policy explains what personal data the current References.watch public service may process, why it is used and the choices available to you.
1. Controller and privacy contact
The controller is the operator of the independent References.watch project described in the Legal notice. Privacy enquiries and rights requests can be sent to:
research@references.watchBecause the service is in a pre-launch phase, formal registered-operator details will be added to the Legal notice before commercial public launch.
2. Data that may be processed
| Category | Examples | How it arises |
|---|---|---|
| Technical and security data | IP address, request time, browser or device data, requested URL, security events | Generated when the site and its hosting infrastructure receive a request |
| Correspondence | Name, email address, message, cited sources and attachments | Provided when you contact the project |
| Assessment input | Watch photographs, selected image type and related request data | Submitted voluntarily through the identification or Condition Atlas beta tools |
| Preference data | Light or dark theme | Stored locally in your browser |
Please do not include faces, identity documents, serial numbers, location data or other personal information in watch photographs unless genuinely necessary and lawful.
3. Purposes and legal bases
- Delivering and securing the site: legitimate interests in operating a reliable service, preventing abuse and diagnosing failures.
- Responding to correspondence and correction requests: legitimate interests and steps taken at your request.
- Producing an optional photo identification or condition assessment: processing initiated by your affirmative submission of the photographs and required to return the requested result.
- Meeting legal obligations and defending claims: compliance with applicable law and legitimate interests where relevant.
Where consent is the appropriate legal basis, you may withdraw it for future processing. Withdrawal does not affect processing that was lawful before withdrawal.
4. Identification and Condition Atlas photographs
Images are resized in the browser before submission to the relevant endpoint. References.watch does not store uploaded watch photos. Uploaded images and shared information are processed only to return the requested identification or condition-assessment result.
Avoid sensitive content. Infrastructure providers may process transient request and security data under their own technical and contractual retention controls. Do not submit a photograph if you do not have the right to use it or if it contains information you do not want processed for this purpose.
6. Service providers, recipients and transfers
References.watch uses Cloudflare infrastructure for hosting, security, request handling and the beta AI assessment. Providers act under their applicable contractual and legal safeguards. Data may be processed outside your country; where GDPR transfer restrictions apply, an approved transfer mechanism or other lawful safeguard must be used.
We do not sell personal data. An external manufacturer or source website receives data only when you choose to follow its link, subject to that site's privacy policy.
7. Retention
- Submitted photographs are not intentionally retained in References.watch application storage by the current beta implementation.
- Correspondence and correction evidence are kept only as long as needed to answer, document the correction, protect the project or meet legal obligations.
- Technical and security logs are retained according to operational need and the hosting provider's configured controls.
- The theme preference remains in your browser until you change or clear it.
8. Your data-protection rights
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, portability or objection, and you may withdraw consent where processing relies on consent. We may need limited information to verify the requester before acting.
You may also complain to the Belgian Data Protection Authority or the competent authority where you live or work. The governing EU framework is the General Data Protection Regulation.
9. Security, children and policy changes
Reasonable technical and organisational measures are used, but no internet transmission is risk-free. The service is not directed to children and we do not knowingly request their data. Material policy changes will be published here with a new effective date.