Privacy policy
Last updated: 16 August 2026
Data controller
The data controller is Alaric Trullemans, publisher of the site.
For any request concerning your data, or to reach our privacy contact point: privacy@custoce.com.
What we process, why, and on what legal basis
We process your data for the following purposes, and for no other.
Keeping your vault and giving you access to it. Your email address, the name you choose to enter in the register, your display language and your vault number. Legal basis: performance of the service you request (Art. 6(1)(b) GDPR).
Establishing, preserving and passing on proof of ownership. The information relating to the pieces in your custody: brand, model, serial number, reference, photographs, date of certification, issuing house, together with the history of transfers, services and documents issued. Legal basis: performance of the service (Art. 6(1)(b)) and our legitimate interest in maintaining a reliable register of reference (Art. 6(1)(f)).
Securing access to your vault. Your personal code, of which we keep only a non-reversible fingerprint, the passkeys you register, of which we hold only the public part and never the secret held by your device, and the label of the enrolled device. Legal basis: performance of the service (Art. 6(1)(b)) and our legitimate interest in protecting vaults (Art. 6(1)(f)).
Giving you access back should you lose it. Your recovery email address, your recovery telephone number, and the fingerprints of your recovery codes and of the codes received by SMS. This data serves no other purpose. Legal basis: performance of the service (Art. 6(1)(b)).
Allowing you to write to the house, and the house to reply to you. The content of your messages and, if you choose to share it, the address at which the house may reply to you directly. Without that choice, the house never knows your address: we relay its reply. Legal basis: performance of the service (Art. 6(1)(b)) and, for the sharing of your address, your consent (Art. 6(1)(a)), which you may withdraw at any time.
Inviting you to open your vault, then reminding you of a service, on behalf of the house that certified your piece. We send these messages without ever disclosing your address to the house. They are capped: at most one activation reminder on day 1 and on day 7, and at most one service reminder per piece per month. Legal basis: our legitimate interest and that of the house in seeing a certified piece find its register and remain serviced (Art. 6(1)(f)). You may object at any time, with no reason to give, using the link included in every message: the objection takes effect immediately (Art. 21(2) GDPR).
Reporting a stolen piece and freezing its transfer. The account of the report, the piece concerned and the person making the declaration. Legal basis: our legitimate interest and that of victims in preventing a stolen piece from circulating (Art. 6(1)(f)), and performance of the service (Art. 6(1)(b)).
Securing the platform and preventing abuse. Your IP address, used only for the time needed to apply our rate limits and never stored in the database, together with a log of technical deeds: wallet creation, seal movements, email and SMS dispatches with the recipient masked. Legal basis: our legitimate interest (Art. 6(1)(f)) and the security obligation of Art. 32 GDPR.
Measuring the audience of the site. Aggregated statistics, without cookies and without any individual profile. Legal basis: our legitimate interest (Art. 6(1)(f)).
We never sell your data and never use it for advertising profiling. Custoce keeps no private key.
Where your data comes from
Some of your data does not reach us from you. When an accredited house or boutique hands you a piece, it passes us your email address, at the moment of handover or from its online boutique, so that we can invite you to open your vault. At that stage we receive only your email address and the piece concerned.
The first message you receive from us refers to this policy and carries an opt-out link. If you do not wish to open a vault, simply do not act on it: the invitation lapses of its own accord after thirty days. You may also ask for your address to be erased immediately by writing to privacy@custoce.com.
Recipients and processors
Accredited houses and boutiques. The house that certified your piece and, where applicable, the retailer that handed it to you see the piece and a masked vault number. Never your name, never your address, never your ownership history. There is a single exception, and it is yours to make: you may authorise, piece by piece, the retailer attached to that piece to see the name entered in the register. This authorisation is never pre-ticked or inferred, it may be revoked at any moment from your space, and the revocation takes effect immediately (Art. 7(3) GDPR). The issuing house never sees that name.
Our processors (Art. 28 GDPR), bound by a data-processing agreement and acting solely on our instructions: platform hosting (Vercel Inc., United States); database and authentication (Supabase Inc., United States); wallet signing and custody infrastructure (Turnkey, United States); service email delivery (Resend, United States); security SMS delivery (Twilio Inc., United States).
We disclose your data to no third party for commercial purposes. We may be required to respond to a competent judicial or administrative authority; where that happens, we inform you, unless the law forbids us from doing so.
Photographs
The photograph of the piece is visible on its public record: that is the very principle of verification by QR code, and it is the reason the register exists. So do not photograph anything you would not wish to make public, for example a document lying next to the watch.
The photograph of the paper certificate issued by the house, which often bears the name of the buyer, is never public. It is held in a closed space and may be consulted only by an authorised member of Custoce, in order to examine a dispute, through short-lived and logged access.
Transfers outside the European Union
Our processors Vercel, Supabase, Turnkey and Resend are established in the United States. These transfers are covered by the appropriate safeguards provided for by the GDPR: European Commission standard contractual clauses (Art. 46) or an applicable adequacy decision (Art. 45). You may obtain a copy of them by writing to privacy@custoce.com.
The entries in the public register described below are a different matter, and we would rather say so plainly: they are broadcast to a network of independent computers spread across the world, which nobody can identify or place under contract. No safeguard under Art. 46 can cover such a broadcast. We draw the only possible conclusion: to enter in that register nothing but technical elements, as few as the service allows, and to tell you before you open your vault.
Permanent entries in the public register
To guarantee the permanence and tamper-resistance of proof of ownership, certain technical elements attesting to the existence of a seal and of its transfers are recorded in a worldwide public register (the Polygon network): a seal number, digital fingerprints (one-way, non-reversible computations) and technical addresses specific to your vault.
These entries contain neither your name, nor your email address, nor any data identifying you directly. They nonetheless remain linkable to you by cross-referencing: your vault uses a single technical address, on which all your pieces are recorded. Anyone who knows that address, for example from a certificate you have shown them, can therefore see how many pieces are attached to it and on what dates they moved, without ever knowing who you are.
Once recorded, this data is permanent: nobody, not even we, can modify or erase it. That permanence is what gives the register its value, and it is also a real limit on your right to erasure (Art. 17(3)(b) GDPR). We tell you this beforehand, not afterwards.
Retention periods
Account data, your email address and your preferences, is kept for as long as your vault is open. Security data (code fingerprints, passkeys, recovery factors) is deleted as soon as you withdraw it.
Proof of ownership and the register's log of deeds are kept on a lasting basis: that is the very purpose of a register of reference.
The technical security log is kept for 24 months, then purged. Invitations that are not acted upon expire after thirty days. The list of people who have objected to our messages is kept for as long as is necessary in order not to write to them again: erasing it would amount to contacting them once more.
To close your vault: write to privacy@custoce.com. We then delete your account data, your security data and your messages. What remains, because we cannot do otherwise: the deeds already entered in the public register, described above, and the documents we have issued that stand as evidence for a third party, for example a certificate given to a buyer. We tell you precisely, case by case, what has been deleted and what remains.
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability (Art. 15 to 22 GDPR). Where processing rests on your consent, you may withdraw it at any time, without calling into question the lawfulness of earlier processing.
To exercise these rights: privacy@custoce.com. We reply within one month, extended to three months if the request is complex; we then inform you of this within the first month (Art. 12(3) GDPR). We may ask you to write to us from the address attached to your vault, so as not to hand your data to somebody else.
Objection to messages sent on behalf of houses: the link appears at the foot of each of those messages, and its effect is immediate. No reason will be asked of you (Art. 21(2) GDPR).
Certain erasure requests may be limited where retention is necessary for the purpose of the register, for a legal obligation, or where the element is recorded on a public register that cannot be changed. We then explain this to you precisely, rather than hiding behind a general formula.
You also have the right to lodge a complaint with the competent supervisory authority: the Belgian Data Protection Authority (Autorité de protection des données, APD), rue de la Presse 35, 1000 Brussels.
What is automatic, and what is not
Custoce takes no solely automated decision producing legal effects or significantly affecting you within the meaning of Art. 22 GDPR.
Several mechanisms are nonetheless automatic, and we would rather name them: after several incorrect personal codes, access to certain operations locks temporarily, for up to 24 hours; a piece reported stolen is frozen without delay, which prevents any transfer until the report has been examined; a request to recover access is carried out after a waiting period if you do not cancel it.
Above a value threshold, a recovery of access is examined by a person, and a sensitive decision in the administration console requires the approval of two separate people. In every case, you may write to us to obtain a human review.
Security
Access to your vault is partitioned at database level: a query can reach only your own rows. Secrets are never kept in the clear: the personal code and the recovery codes are reduced to a non-reversible fingerprint, and the links sent by email are stored hashed. Custoce holds no wallet private key.
The house console never receives your identity: this is not a masking on screen, it is what the server answers. Sensitive decisions in the administration console require two people.
No system is invulnerable. In the event of a data breach likely to result in a high risk to you, we inform you as soon as possible (Art. 34 GDPR).
Minors
The service is intended for adults. We do not verify age when a vault is opened, and we do not claim to: a vault is opened through a link sent to an email address.
If you find that a vault has been opened by a minor, write to us: we will close it. A piece passed to a minor heir is to be dealt with together with us, case by case, with their legal representative.
Cookies and local storage
The site uses no advertising cookie, no third-party tracker and no profiling. Audience measurement is aggregated and carried out without cookies.
Three cookies are set, all of them necessary for the site to work: your choice of language (one year), access to the private preview of the site where applicable (for the duration of the session) and the state of the opening page (for the duration of the session).
Your browser also keeps, in its local storage, your sign-in session, discreet mode, the collapsed state of the menu and the state of the inactivity lock. These elements never leave your device.
None of these elements requires your prior consent, because none of them serves to track you. That does not relieve us of the duty to tell you, and that is the purpose of this section.
Changes to this policy
We may change this policy. In the event of a substantial change affecting your rights or the purposes of processing, we inform you by email before it takes effect. The date of the last update appears at the top of the page.
