Privacy
Your details, kept simple.
This policy explains how Borso handles personal data under the EU General Data Protection Regulation (GDPR). We collect as little as we need, never sell it, and never publish it.
Who is responsible
The controller of your data is Borso (see the Legal notice). For any privacy question, email getwatch@borso.shop.
What we collect
- Contact form: your name, WhatsApp number, approximate budget, the watch you are looking for (brand, model or reference, condition, timeframe), and your preferred city.
- Messages: what you send us by email, WhatsApp, or Telegram.
- Transactions: if a sale goes ahead, the details needed to complete it and to meet legal duties, which may include proof of identity, address, and source of funds.
- Technical data: our hosting provider records standard server logs (such as IP address and browser type) to keep the website secure and running.
Why we use it, and on what legal basis
- To reply to your request and look for your watch: steps taken at your request before any agreement (GDPR art. 6(1)(b)).
- To keep a record of requests and follow up on them: our legitimate interest in running the service (art. 6(1)(f)).
- To carry out identity, anti-money-laundering, tax, and accounting duties: legal obligation (art. 6(1)(c)).
- To protect the website against abuse: legitimate interest (art. 6(1)(f)).
The contact form fields are needed so we can reply; without them we cannot handle your request. We do not use automated decision-making or profiling.
Who we share it with
Because we connect buyers and sellers, a seller may need some of your details to complete a sale. We share your name or contact details with a seller only after telling you first, and only what is needed.
We also use trusted service providers who process data on our behalf: website hosting (Vercel), our request database (Supabase), and our email provider. If you message us on WhatsApp or Telegram, those services process your messages under their own privacy terms. We may disclose data where the law requires it, for example to public authorities.
Some providers are based outside the European Economic Area, for example in the United States. Where data is transferred there, it is protected by the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
How long we keep it
Requests that do not lead to a sale are kept for up to 24 months after our last contact, then deleted. Records of completed transactions and compliance checks are kept for as long as the law requires, typically 5 to 10 years. You can ask us to delete a request sooner at any time.
Your rights
You can ask to access, correct, or delete your data, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time. Email getwatch@borso.shop and we will respond within one month.
You can also complain to a data protection authority: in the Czech Republic, the Office for Personal Data Protection (uoou.gov.cz); in Spain, the Agencia Española de Protección de Datos (aepd.es); or the authority where you live.
Cookies
The public website uses no advertising, analytics, or tracking cookies, so there is nothing to accept or decline. Our staff-only admin area uses strictly necessary sign-in cookies, which do not apply to visitors. If this ever changes, we will update this page and ask for your consent first.
Changes
We will update this policy when our practices change. The date below shows the latest version.
Last updated 1 October 2026.
