Privacy Policy
Last updated: 15-06-2026
This Privacy Policy explains how Lab Accident LTD, a company registered in Bulgaria, collects, uses, stores and protects personal data when you visit or purchase from our e-commerce website labaccident.art.
We process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), and applicable Bulgarian data protection law.
1. Data Controller
The data controller is:
Lab Accident LTD
Registered office: Ulitsa Peter Delyan 7b, Sofia, Bulgaria
Company registration number / UIC: [company number]
Email: privacy@labaccident.art
Website: labaccident.art
For privacy-related requests, you may contact us at: [privacy email].
We have not appointed a Data Protection Officer because, based on our current activities, we do not believe this is legally required. If this changes, this Privacy Policy will be updated accordingly.
2. Personal Data We Collect
We may collect the following categories of personal data:
Account and identification data
Name, surname, username, email address, billing address, shipping address, telephone number, account login details and customer ID.
Order and transaction data
Products purchased, order history, payment status, invoices, refunds, gift card or store credit information, delivery information, customer service requests and communications.
Payment data
We do not store full card details. Payments are processed by external payment service providers. We may receive limited payment information, such as transaction ID, payment status, last digits of a card where applicable, fraud screening results or payment confirmation.
Technical and usage data
IP address, browser type, device information, operating system, pages viewed, access times, referral source, session data, security logs and cookie identifiers.
Marketing and preference data
Newsletter subscription status, communication preferences, consent records, promotional interactions and product preferences.
User-generated content
Reviews, messages, support requests or other content voluntarily submitted through the website.
3. Why We Process Your Data and Legal Bases
We process personal data for the following purposes:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Account and contact data | Contract performance or pre-contractual steps |
| Processing and fulfilling orders | Account, order, delivery and payment data | Contract performance |
| Payment processing and fraud prevention | Payment status, transaction data, technical data | Contract performance and legitimate interest |
| Shipping and delivery | Name, address, telephone, order data | Contract performance |
| Customer support | Contact data, order data, communications | Contract performance and legitimate interest |
| Legal, tax and accounting obligations | Invoice, order, payment and company records | Legal obligation |
| Website security and abuse prevention | IP address, logs, device data | Legitimate interest |
| Improving the website and services | Usage data, analytics data | Legitimate interest or consent, depending on the technology used |
| Sending newsletters or marketing communications | Email, preferences, consent records | Consent or legitimate interest where legally permitted |
| Managing cookies and tracking technologies | Cookie IDs, technical data | Consent, except for strictly necessary cookies |
Under the GDPR, processing must rely on a valid legal basis, including contract performance, legal obligation, consent or legitimate interests. (EUR-Lex)
4. E-commerce Orders, Delivery and Invoicing
When you place an order, we process the personal data necessary to:
- confirm your purchase;
- receive and verify payment;
- prepare and ship the products;
- issue invoices and accounting records;
- handle returns, refunds, warranty requests or complaints;
- prevent fraud, abuse or unauthorized transactions.
Certain order, invoice and accounting data must be retained to comply with legal, tax and accounting obligations.
5. Gift Cards, Store Credit and Recipient Data
If our website offers gift cards, gift credit or gifting features, we may process data relating to both the purchaser and the recipient.
Depending on the feature used, this may include:
- purchaser name, email, billing and payment data;
- recipient email address or account identifier;
- gift amount, gift message, gift code or gift credit balance;
- redemption history;
- internal transaction links between purchase, gift credit and redeemed products.
We use this data to issue, deliver, redeem, audit and prevent misuse of gift cards or gift credits. Recipient personal data is not shared with the purchaser except where strictly necessary to complete the gift process, for example confirmation that a gift was delivered or redeemed, if such functionality is enabled.
6. Cookies and Similar Technologies
Our website uses cookies and similar technologies.
Some cookies are strictly necessary for the operation of the website, such as cart, checkout, login, security and session cookies. These do not require prior consent.
Other cookies, such as analytics, marketing, profiling or third-party tracking cookies, are used only where you have given consent through the cookie banner or preference center.
You can change or withdraw your cookie consent at any time through [cookie settings link].
The European Commission’s own cookie guidance distinguishes between necessary cookies and cookies used for preferences or statistics, and asks users to accept or refuse non-essential cookies. (European Commission)
A separate Cookie Policy should be published at: [cookie policy URL].
7. Newsletter and Marketing Communications
If you subscribe to our newsletter or agree to receive marketing communications, we will use your email address and preferences to send you updates, promotions or product information.
You may unsubscribe at any time by clicking the unsubscribe link in our emails or by contacting us at [privacy email].
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
8. Who We Share Data With
We may share personal data only where necessary with:
- hosting and infrastructure providers;
- payment processors;
- shipping and logistics providers;
- accounting, tax and legal advisors;
- email and communication service providers;
- fraud prevention and security providers;
- analytics or marketing providers, where consent has been given;
- public authorities, courts, regulators or law enforcement bodies where legally required.
All service providers are required to process personal data only according to our instructions, where they act as processors, and to apply appropriate security measures.
We do not sell personal data.
9. International Data Transfers
Where personal data is transferred outside the European Economic Area, we ensure that appropriate safeguards are in place, such as:
- an adequacy decision by the European Commission;
- Standard Contractual Clauses;
- additional technical and organizational safeguards where required.
This may apply, for example, to cloud, email, analytics, payment or support providers located outside the EEA.
10. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.
Indicative retention periods:
| Data category | Retention period |
|---|---|
| Account data | Until account deletion, unless longer retention is required |
| Order and invoice data | For the period required by Bulgarian tax/accounting law |
| Payment confirmation data | As long as necessary for accounting, fraud prevention and dispute handling |
| Customer support communications | [e.g. 24–36 months] after resolution |
| Marketing consent records | Until consent is withdrawn, plus a reasonable proof period |
| Security logs | [e.g. 6–12 months], unless needed for investigation |
| Cookie consent records | [e.g. 6–12 months] or as configured in the consent system |
| Gift card / credit records | Until expiry/redemption plus accounting and fraud-control retention periods |
When data is no longer needed, it will be deleted, anonymized or securely archived.
11. Security Measures
We apply appropriate technical and organizational measures to protect personal data, including where appropriate:
- HTTPS encryption;
- access controls;
- secure authentication;
- role-based administrative permissions;
- logging and monitoring;
- backup procedures;
- payment processing through specialized payment providers;
- regular updates of website software and plugins;
- measures against unauthorized access, fraud and abuse.
No online service can be guaranteed to be completely secure, but we take reasonable steps to protect your personal data.
12. Your GDPR Rights
Under the GDPR, you may have the right to:
- access your personal data;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- request data portability;
- lodge a complaint with a supervisory authority.
The Bulgarian Commission for Personal Data Protection also explains that GDPR gives individuals stronger control over their personal data and rights over how their data is processed. (CPDP)
To exercise your rights, contact us at [privacy email].
We may need to verify your identity before responding. We will respond within the time limits required by applicable law.
13. Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.
For Bulgaria, the supervisory authority is:
Commission for Personal Data Protection
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Email: kzld@cpdp.bg
Website: www.cpdp.bg
The CPDP identifies itself as the Bulgarian data protection authority and provides contact details for data protection matters. (CPDP)
14. Children’s Data
Our website is not intended for children under the age of 18. We do not knowingly collect personal data from children without appropriate parental or legal guardian consent where required.
If you believe that a child has provided us with personal data, please contact us at [privacy email].
15. Automated Decision-Making and Profiling
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects on users.
We may use automated tools for fraud prevention, payment risk assessment, security monitoring, product recommendations or marketing segmentation. Where required by law, these activities are based on appropriate legal grounds and safeguards.
16. Links to Third-Party Websites
Our website may contain links to third-party websites, plugins or services. We are not responsible for the privacy practices of those third parties. We recommend reading their privacy policies before providing personal data.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations or data processing practices.
The updated version will be published on this page with a revised “Last updated” date.
18. Contact
For any privacy-related question or request, please contact:
Lab Accident EOOD
Email: privacy@labaccident.art
Address: Ulitsa Peter Delyan 7b, Sofia, Bulgaria