Skip to content

Privacy Policy

PRIVACY POLICY Last Updated: 5 October 2026

  1. Introduction This Privacy Policy explains how Kryptonite Style LTD, trading under the brand name Nirius Brands (“Nirius Brands”, “we”, “us”, or “our”), collects, uses, stores and protects personal data when you visit or use our website. Nirius Brands operates as a luxury watch distributor. Our website provides information about available watches, private sourcing services and contact/enquiry facilities. We do not operate an online checkout on the website. Sales and payments are arranged privately between Nirius Brands and the customer. By using our website and submitting information through our enquiry, private sourcing or contact forms, you acknowledge that your personal data may be processed as described in this Privacy Policy.
  2. Data Controller The data controller responsible for your personal data is: Kryptonite Style LTD Trading as: Nirius Brands EIK: 207900723 VAT Number: BG207900723 ul. Kolednitsa №2, floor 1 Ruse, Bulgaria, 7002 Email: info@niriusbrands.com Telephone: +40 785 308 147 Alternative telephone: +39 377 390 3785 For privacy-related questions or requests concerning your personal data, please contact us at: info@niriusbrands.com
  3. Personal Data We Collect Depending on how you interact with our website, we may collect the following personal data: 3.1 Information submitted through forms When you submit a Product Enquiry, Private Sourcing request or Contact form, we may collect:
  • Full name
  • Email address
  • Telephone number
  • Country
  • Message or enquiry details
  • Information relating to the watch or watches you are enquiring about
  • Other information you voluntarily provide to us Please do not submit sensitive personal information through our website unless it is strictly necessary for the purpose of your request. 3.2 Information relating to business transactions Where you proceed with a private purchase or business relationship with Nirius Brands, we may process information necessary to manage the transaction, including customer identification, contact information, delivery information, invoicing information and communications relating to the transaction. Payment is arranged privately by bank transfer. We do not collect or store bank card details through an online checkout on our website. 3.3 Technical and security information When you access our website, technical information may be processed as necessary to operate, secure and maintain the website and its infrastructure. Depending on the technical circumstances, this may include information such as IP address, browser or device information, timestamps, request information and security-related logs. Such information is used for legitimate operational and security purposes and is not used by us for behavioural advertising.
  1. How We Use Personal Data We may use personal data to:
  • respond to enquiries submitted through our website;
  • respond to Private Sourcing requests;
  • respond to Contact requests;
  • communicate with potential customers and business partners;
  • provide information about watches and availability;
  • prepare and communicate private offers;
  • arrange and administer private sales;
  • arrange delivery and fulfilment;
  • issue and maintain transaction and accounting records;
  • comply with applicable legal, tax and accounting obligations;
  • maintain the security and integrity of our website and services;
  • prevent fraud, abuse or other unlawful activity;
  • establish, exercise or defend legal claims; and
  • otherwise operate our business in accordance with applicable law. We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
  1. Legal Bases for Processing We process personal data only where we have an applicable legal basis under data protection law. Depending on the circumstances, these legal bases may include: Performance of a contract or steps taken before entering into a contract We may process your information where it is necessary to respond to your request, prepare an offer, communicate with you about a potential transaction or perform a contract. Legal obligations We may process personal data where necessary to comply with applicable legal, tax, accounting, regulatory or other legal obligations. Legitimate interests We may process personal data where necessary for legitimate interests such as operating and securing our website, communicating with customers and potential customers, preventing fraud and abuse, maintaining business records, and establishing or defending legal claims, provided those interests are not overridden by your rights and freedoms. Consent Where consent is legally required, we will request it before carrying out the relevant processing. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  2. How We Receive Your Personal Data We may receive personal data:
  • directly from you when you complete a website form;
  • when you communicate with us by email or telephone;
  • during the course of a private enquiry or transaction;
  • when you voluntarily provide additional information in correspondence; or
  • automatically through technical and security systems necessary to operate the website.
  1. Service Providers and Data Processors To operate our website and business, we use selected third-party technology and service providers, which may process personal data on our behalf where necessary. These providers currently include:
  • Netlify — website hosting and deployment infrastructure;
  • Neon — database infrastructure;
  • Cloudflare R2 — storage infrastructure for website assets;
  • Resend — transactional email delivery. These providers are used to provide technical services necessary for the operation of the website and business. Where a service provider processes personal data on our behalf, we require appropriate contractual and technical safeguards as required by applicable data protection law. Resend states that it acts as a processor for customer data and that its stored service data is held in the United States, with international transfers covered by mechanisms including Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. resend.com Cloudflare provides Standard Contractual Clauses for applicable international transfers, and Netlify states that it maintains GDPR-related contractual and transfer safeguards and is currently certified under the EU-U.S. Data Privacy Framework. Cloudflare Where personal data is transferred outside the European Economic Area, we will rely on an applicable lawful transfer mechanism and appropriate safeguards as required by applicable data protection law.
  1. Data Retention We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy. The retention period may depend on:
  • the nature of the request or business relationship;
  • whether a transaction has taken place;
  • legal, tax and accounting requirements;
  • the need to maintain appropriate business records;
  • the establishment, exercise or defence of legal claims; and
  • applicable statutory limitation periods. When personal data is no longer required for these purposes, it will be deleted or otherwise securely disposed of, subject to applicable legal retention requirements.
  1. Data Security We take reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. However, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure.
  2. Cookies Our website uses cookies and similar technologies only as permitted by applicable law. Essential cookies may be used where necessary for website functionality, security, administration, authentication and the storage of cookie-consent preferences. Where non-essential cookies or similar technologies are introduced, we will request consent where required before using them. Our current website configuration does not use Google Analytics, Google Tag Manager, Meta Pixel or similar advertising/analytics tracking technologies. For additional information, please see our Cookie Policy.
  3. External Links Our website may contain links to external websites or services. When you follow an external link, the external website may process personal data independently of Nirius Brands. Such processing is governed by the privacy policy and terms of the relevant third party. We are not responsible for the privacy practices of external websites that we do not operate.
  4. Your Data Protection Rights Depending on the circumstances and applicable law, you may have the right to:
  • obtain information about how your personal data is processed;
  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to certain processing;
  • request portability of certain personal data;
  • withdraw consent where processing is based on consent; and
  • not be subject to a decision based solely on automated processing where the applicable legal conditions are met. These rights are subject to applicable legal conditions and exceptions. Autoritatea Europeană pentru Date To exercise your rights, contact: info@niriusbrands.com We may need to verify your identity before responding to certain requests.
  1. Complaints If you believe that your personal data has been processed unlawfully or that your data protection rights have been violated, we encourage you to contact us first so that we can attempt to resolve the issue. You also have the right to lodge a complaint with the competent data protection supervisory authority. For our Bulgarian establishment, the relevant supervisory authority is the: Commission for Personal Data Protection (CPDP) 2 Prof. Tsvetan Lazarov Blvd. Sofia 1592, Bulgaria Email: kzld@cpdp.bg Website: www.cpdp.bg The CPDP confirms that individuals may lodge complaints concerning violations of their rights under the GDPR and Bulgarian personal data protection legislation. Comisia GDPR
  2. Children's Privacy Our website is intended for adults and businesses and is not directed specifically at children. We do not knowingly seek to collect personal data from children.
  3. Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or business practices. When we make changes, we will update the “Last Updated” date at the top of this page. We encourage you to review this Privacy Policy periodically.
  4. Contact For any question concerning this Privacy Policy or the processing of your personal data, please contact: Kryptonite Style LTD Trading as Nirius Brands ul. Kolednitsa №2, floor 1 Ruse, Bulgaria, 7002 Email: info@niriusbrands.com Telephone: +40 785 308 147 Alternative: +39 377 390 3785