No products in the cart.

Privacy Policy

Last updated: 15-06-2026

This Privacy Policy explains how Lab Accident LTD, a company registered in Bulgaria, collects, uses, stores and protects personal data when you visit or purchase from our e-commerce website labaccident.art.

We process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), and applicable Bulgarian data protection law.

1. Data Controller

The data controller is:

Lab Accident LTD
Registered office: Ulitsa Peter Delyan 7b, Sofia, Bulgaria
Company registration number / UIC: [company number]
Email: privacy@labaccident.art
Website: labaccident.art

For privacy-related requests, you may contact us at: [privacy email].

We have not appointed a Data Protection Officer because, based on our current activities, we do not believe this is legally required. If this changes, this Privacy Policy will be updated accordingly.

2. Personal Data We Collect

We may collect the following categories of personal data:

Account and identification data

Name, surname, username, email address, billing address, shipping address, telephone number, account login details and customer ID.

Order and transaction data

Products purchased, order history, payment status, invoices, refunds, gift card or store credit information, delivery information, customer service requests and communications.

Payment data

We do not store full card details. Payments are processed by external payment service providers. We may receive limited payment information, such as transaction ID, payment status, last digits of a card where applicable, fraud screening results or payment confirmation.

Technical and usage data

IP address, browser type, device information, operating system, pages viewed, access times, referral source, session data, security logs and cookie identifiers.

Marketing and preference data

Newsletter subscription status, communication preferences, consent records, promotional interactions and product preferences.

User-generated content

Reviews, messages, support requests or other content voluntarily submitted through the website.

3. Why We Process Your Data and Legal Bases

We process personal data for the following purposes:

PurposeData usedLegal basis
Creating and managing your accountAccount and contact dataContract performance or pre-contractual steps
Processing and fulfilling ordersAccount, order, delivery and payment dataContract performance
Payment processing and fraud preventionPayment status, transaction data, technical dataContract performance and legitimate interest
Shipping and deliveryName, address, telephone, order dataContract performance
Customer supportContact data, order data, communicationsContract performance and legitimate interest
Legal, tax and accounting obligationsInvoice, order, payment and company recordsLegal obligation
Website security and abuse preventionIP address, logs, device dataLegitimate interest
Improving the website and servicesUsage data, analytics dataLegitimate interest or consent, depending on the technology used
Sending newsletters or marketing communicationsEmail, preferences, consent recordsConsent or legitimate interest where legally permitted
Managing cookies and tracking technologiesCookie IDs, technical dataConsent, except for strictly necessary cookies

Under the GDPR, processing must rely on a valid legal basis, including contract performance, legal obligation, consent or legitimate interests. (EUR-Lex)

4. E-commerce Orders, Delivery and Invoicing

When you place an order, we process the personal data necessary to:

  • confirm your purchase;
  • receive and verify payment;
  • prepare and ship the products;
  • issue invoices and accounting records;
  • handle returns, refunds, warranty requests or complaints;
  • prevent fraud, abuse or unauthorized transactions.

Certain order, invoice and accounting data must be retained to comply with legal, tax and accounting obligations.

5. Gift Cards, Store Credit and Recipient Data

If our website offers gift cards, gift credit or gifting features, we may process data relating to both the purchaser and the recipient.

Depending on the feature used, this may include:

  • purchaser name, email, billing and payment data;
  • recipient email address or account identifier;
  • gift amount, gift message, gift code or gift credit balance;
  • redemption history;
  • internal transaction links between purchase, gift credit and redeemed products.

We use this data to issue, deliver, redeem, audit and prevent misuse of gift cards or gift credits. Recipient personal data is not shared with the purchaser except where strictly necessary to complete the gift process, for example confirmation that a gift was delivered or redeemed, if such functionality is enabled.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Some cookies are strictly necessary for the operation of the website, such as cart, checkout, login, security and session cookies. These do not require prior consent.

Other cookies, such as analytics, marketing, profiling or third-party tracking cookies, are used only where you have given consent through the cookie banner or preference center.

You can change or withdraw your cookie consent at any time through [cookie settings link].

The European Commission’s own cookie guidance distinguishes between necessary cookies and cookies used for preferences or statistics, and asks users to accept or refuse non-essential cookies. (European Commission)

A separate Cookie Policy should be published at: [cookie policy URL].

7. Newsletter and Marketing Communications

If you subscribe to our newsletter or agree to receive marketing communications, we will use your email address and preferences to send you updates, promotions or product information.

You may unsubscribe at any time by clicking the unsubscribe link in our emails or by contacting us at [privacy email].

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

8. Who We Share Data With

We may share personal data only where necessary with:

  • hosting and infrastructure providers;
  • payment processors;
  • shipping and logistics providers;
  • accounting, tax and legal advisors;
  • email and communication service providers;
  • fraud prevention and security providers;
  • analytics or marketing providers, where consent has been given;
  • public authorities, courts, regulators or law enforcement bodies where legally required.

All service providers are required to process personal data only according to our instructions, where they act as processors, and to apply appropriate security measures.

We do not sell personal data.

9. International Data Transfers

Where personal data is transferred outside the European Economic Area, we ensure that appropriate safeguards are in place, such as:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses;
  • additional technical and organizational safeguards where required.

This may apply, for example, to cloud, email, analytics, payment or support providers located outside the EEA.

10. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Indicative retention periods:

Data categoryRetention period
Account dataUntil account deletion, unless longer retention is required
Order and invoice dataFor the period required by Bulgarian tax/accounting law
Payment confirmation dataAs long as necessary for accounting, fraud prevention and dispute handling
Customer support communications[e.g. 24–36 months] after resolution
Marketing consent recordsUntil consent is withdrawn, plus a reasonable proof period
Security logs[e.g. 6–12 months], unless needed for investigation
Cookie consent records[e.g. 6–12 months] or as configured in the consent system
Gift card / credit recordsUntil expiry/redemption plus accounting and fraud-control retention periods

When data is no longer needed, it will be deleted, anonymized or securely archived.

11. Security Measures

We apply appropriate technical and organizational measures to protect personal data, including where appropriate:

  • HTTPS encryption;
  • access controls;
  • secure authentication;
  • role-based administrative permissions;
  • logging and monitoring;
  • backup procedures;
  • payment processing through specialized payment providers;
  • regular updates of website software and plugins;
  • measures against unauthorized access, fraud and abuse.

No online service can be guaranteed to be completely secure, but we take reasonable steps to protect your personal data.

12. Your GDPR Rights

Under the GDPR, you may have the right to:

  • access your personal data;
  • request correction of inaccurate data;
  • request deletion of your data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • withdraw consent at any time;
  • request data portability;
  • lodge a complaint with a supervisory authority.

The Bulgarian Commission for Personal Data Protection also explains that GDPR gives individuals stronger control over their personal data and rights over how their data is processed. (CPDP)

To exercise your rights, contact us at [privacy email].

We may need to verify your identity before responding. We will respond within the time limits required by applicable law.

13. Right to Lodge a Complaint

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.

For Bulgaria, the supervisory authority is:

Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Email: kzld@cpdp.bg
Website: www.cpdp.bg

The CPDP identifies itself as the Bulgarian data protection authority and provides contact details for data protection matters. (CPDP)

14. Children’s Data

Our website is not intended for children under the age of 18. We do not knowingly collect personal data from children without appropriate parental or legal guardian consent where required.

If you believe that a child has provided us with personal data, please contact us at [privacy email].

15. Automated Decision-Making and Profiling

We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects on users.

We may use automated tools for fraud prevention, payment risk assessment, security monitoring, product recommendations or marketing segmentation. Where required by law, these activities are based on appropriate legal grounds and safeguards.

16. Links to Third-Party Websites

Our website may contain links to third-party websites, plugins or services. We are not responsible for the privacy practices of those third parties. We recommend reading their privacy policies before providing personal data.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations or data processing practices.

The updated version will be published on this page with a revised “Last updated” date.

18. Contact

For any privacy-related question or request, please contact:

Lab Accident EOOD
Email: privacy@labaccident.art
Address: Ulitsa Peter Delyan 7b, Sofia, Bulgaria