Dear customers, the days from September 05 to September 07 (inclusive) are non-working days in Bulgaria.
0

PRIVACY POLICY

GoldenMaskDetectors.com
Version 1.0
Effective Date: 1 August 2026

Data Controller:

Linoart Ltd.
VAT No. BG119636351
6-A-3 Bratya Miladinovi Street
8800 Sliven
Republic of Bulgaria
E-mail: salesgoldenmaskdetectors.com
Telephone: +359 87 87 13 500

Table of Contents

1. Introduction
2. Data Controller
3. Scope of this Privacy Policy
4. Definitions
5. Our Data Protection Principles
6. Categories of Personal Data
7. Processing Activities and Legal Bases
8. Recipients of Personal Data
9. International Transfers
10. Data Retention
11. Your Rights under the GDPR
12. Security Measures
13. Cookies and Similar Technologies
14. Children
15. Third-Party Websites
16. Changes to this Policy
17. Contact Us
18. Complaint to the Supervisory Authority

1. Introduction

Linoart Ltd. ("Company", "Seller", "we", "our" or "us") is committed to protecting the privacy of every individual who visits www.goldenmaskdetectors.com ("Website") or purchases products from us.
This Privacy Policy explains how we collect, use, store, disclose and otherwise process Personal Data.
The Policy has been prepared in accordance with:
• Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
• the Bulgarian Personal Data Protection Act;
• the Bulgarian Electronic Commerce Act;
• the Bulgarian Accounting Act;
• applicable tax legislation;
• other applicable European Union and Bulgarian legislation governing the protection of Personal Data.
This Privacy Policy should be read together with our:
• Terms and Conditions of Sale;
• Cookie Policy;
• Shipping Policy;
• Warranty & Returns Policy.

2. Data Controller

The controller responsible for the processing of Personal Data described in this Privacy Policy is:
Linoart Ltd.

Registered Office
6-A-3 Bratya Miladinovi Street
8800 Sliven
Republic of Bulgaria

Operating Address
44-1 Graf Ignatiev Street
8600 Yambol
Republic of Bulgaria
VAT Number
BG119636351
Email
shopgoldenmaskdetectors.com
Telephone
+359 87 87 13 500
Linoart Ltd. acts as the Controller within the meaning of Article 4(7) GDPR.

3. Scope

This Privacy Policy applies whenever we process Personal Data relating to:
• visitors to the Website;
• customers;
• prospective customers;
• persons contacting us by email;
• persons contacting us by telephone;
• persons using the contact form;
• warranty claimants;
• persons requesting technical support;
• persons participating in promotions that we may organise in the future.
This Privacy Policy does not apply to third-party websites linked from our Website.

4. Definitions

For the purposes of this Policy:
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, restriction, deletion or destruction.
Controller means the person determining the purposes and means of processing Personal Data.
Processor means any person processing Personal Data on behalf of the Controller.
Data Subject means the individual whose Personal Data is processed.
Recipient means any natural or legal person to whom Personal Data is disclosed.
GDPR means Regulation (EU) 2016/679.

5. Our Data Protection Principles

Whenever we process Personal Data, we apply the principles established by Article 5 GDPR.
Accordingly, Personal Data is processed:
• lawfully, fairly and transparently;
• only for specified, explicit and legitimate purposes;
• only to the extent necessary for those purposes;
• accurately and kept up to date where necessary;
• no longer than necessary;
• securely and confidentially;
• in a manner that enables us to demonstrate compliance with applicable law.

6. Categories of Personal Data We Process

Depending on your interaction with us, we may process the following categories of Personal Data.
Identity Data
• name
• surname
• company name (where applicable)
• VAT number (Business Customers)

Contact Data
• billing address
• shipping address
• email address
• telephone number
• country

Order Data
• ordered products
• quantities
• prices
• discounts
• order number
• order status
• invoices
• warranty information

Payment Data
We do not store complete payment card information.
Depending on the payment method selected, we may receive:
• payment status;
• transaction reference;
• payment provider identifier;
• payment confirmation.
Payment card details are processed directly by the payment service provider.

Technical Data
• IP address
• browser type
• operating system
• device information
• language settings
• referring website
• access time
• server logs

Communication Data
• emails
• contact form messages
• customer support requests
• warranty correspondence

Marketing Data
Where you have expressly consented, we may process:
• marketing preferences;
• newsletter subscription status;
• consent records.
You may withdraw your consent at any time.

7. Processing Activities and Legal Bases

The following table summarizes the principal processing activities carried out by the Company.
Processing Activity Personal Data Purpose Legal Basis (GDPR) Typical Recipients Retention
Website operation IP address, browser, device data, server logs Provide and secure the Website, diagnose technical issues Art. 6(1)(f) – Legitimate interests Hosting provider Limited operational retention period
Order processing Identity, contact, order details Perform the sales contract Art. 6(1)(b) – Performance of a contract Internal staff, hosting provider As required by contract, accounting and limitation periods
Payment processing Order number, payment status, transaction reference Receive and verify payment Art. 6(1)(b) Payment service provider Accounting retention period
Delivery Name, address, telephone number Deliver Products Art. 6(1)(b) Courier companies As necessary to complete delivery and meet legal obligations
Invoicing and accounting Identity, transaction details Comply with accounting and tax legislation Art. 6(1)(c) – Legal obligation Accountant, tax authorities where required Statutory accounting retention period
Customer support Contact details, correspondence Respond to enquiries and provide after-sales support Art. 6(1)(b) and/or Art. 6(1)(f) Service providers where necessary Until the matter is resolved, then as necessary for legal claims
Warranty administration Contact details, proof of purchase, product information Administer statutory and commercial warranties Art. 6(1)(b) and Art. 6(1)(c) Manufacturer or authorised service partners where necessary Warranty period and applicable limitation periods
Fraud prevention IP address, order details, payment indicators Prevent fraud, abuse and unauthorised transactions Art. 6(1)(f) Payment providers and competent authorities where required Limited period proportionate to the purpose
Marketing communications (only where consent is given) Email address, marketing preferences Send newsletters or promotional information Art. 6(1)(a) – Consent Email service provider Until consent is withdrawn

8. Recipients of Personal Data

We do not sell, rent or otherwise disclose your Personal Data to third parties for their own marketing purposes.
We disclose Personal Data only where necessary to operate our business, fulfil contractual obligations, comply with legal requirements or protect our legitimate interests.
Depending on the circumstances, your Personal Data may be disclosed to the following categories of recipients:

Payment Service Providers

Where you choose to pay electronically, relevant payment information is shared with the selected payment service provider solely for the purpose of processing your payment, preventing fraud and complying with financial regulations.
The payment service provider acts as an independent controller in relation to the payment transaction it processes.

Courier and Logistics Providers

To deliver your order, we provide the courier or postal operator with the information necessary to complete delivery, which may include:
• name;
• delivery address;
• telephone number;
• email address (where required for delivery notifications).

Hosting and IT Service Providers

Our Website and related systems are hosted by professional service providers who process Personal Data solely on our documented instructions and under appropriate contractual safeguards.
These providers may process server logs, technical information and Personal Data strictly as necessary to provide hosting, maintenance, backup, security monitoring and technical support services.

Professional Advisers

Where reasonably necessary, Personal Data may be disclosed to our:
• accountants;
• auditors;
• legal advisers;
• insurers;
• payment consultants;
• other professional advisers, subject to appropriate confidentiality obligations.

Public Authorities

We may disclose Personal Data where required by law or where reasonably necessary to:
• comply with legal obligations;
• respond to lawful requests from competent authorities;
• establish, exercise or defend legal claims;
• protect our rights, customers or business.

9. International Transfers of Personal Data

As a general principle, we seek to process Personal Data within the European Economic Area ("EEA").
Certain service providers engaged by us may process Personal Data outside the EEA.
Where such transfers occur, we ensure that an appropriate safeguard recognised by the GDPR is in place before the transfer takes place.
Depending on the circumstances, such safeguards may include:
• an adequacy decision adopted by the European Commission;
• the European Commission's Standard Contractual Clauses (SCCs);
• another lawful transfer mechanism recognised under Chapter V of the GDPR.
Where required by law, additional supplementary technical, organisational or contractual safeguards will be implemented to ensure an essentially equivalent level of protection.

10. Data Retention

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including the purposes of satisfying legal, accounting, tax, warranty and regulatory obligations or establishing, exercising or defending legal claims.
Retention periods vary depending on the category of Personal Data and the purpose of processing.
Examples include:
Category Typical Retention Period
Orders and invoices As required under applicable accounting and tax legislation
Customer correspondence Until the enquiry is resolved and thereafter where reasonably necessary for legal claims
Warranty documentation For the duration of the applicable warranty period and any applicable legal limitation period
Technical server logs For a limited operational period necessary for security, diagnostics and system administration
Marketing consent records Until consent is withdrawn or the records are no longer required to demonstrate compliance
Cookie consent records For the period necessary to demonstrate compliance with applicable cookie legislation

Where Personal Data is no longer required, it will be securely deleted, anonymised or otherwise disposed of using appropriate technical and organisational measures.

11. Your Rights Under the GDPR

Subject to the conditions and limitations established by applicable law, you may exercise the following rights.
Data Subject Right Description
Right of Access You have the right to obtain confirmation as to whether we process your Personal Data and, where applicable, to receive a copy of that Personal Data together with information concerning the processing.
Right to Rectification You have the right to request correction of inaccurate Personal Data and completion of incomplete Personal Data.
Right to Erasure You may request deletion of your Personal Data where one of the grounds specified in Article 17 GDPR applies.

This right is not absolute and may be restricted where continued processing is necessary to comply with legal obligations or establish, exercise or defend legal claims.
Right to Restriction of Processing You may request that processing be restricted in the circumstances described in Article 18 GDPR.
Right to Data Portability Where processing is based on consent or the performance of a contract and carried out by automated means, you may request a copy of your Personal Data in a structured, commonly used and machine-readable format and, where technically feasible, request its transmission to another controller.
Right to Object Where processing is based on our legitimate interests, you may object to such processing on grounds relating to your particular situation.

Where Personal Data is processed for direct marketing purposes, you have the unconditional right to object at any time.
Right to Withdraw Consent Where processing is based upon your consent, you may withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Rights Relating to Automated Decision-Making We do not make decisions producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR.

Should this change in the future, we will update this Privacy Policy and ensure that all applicable legal safeguards are implemented.

Exercising Your Rights

You may exercise your GDPR rights by contacting us using the contact details provided in this Privacy Policy. To protect your Personal Data, we may request reasonable evidence of your identity before responding to your request. We aim to respond without undue delay and, in any event, within one month of receiving your request, unless the GDPR permits an extension due to the complexity or number of requests.
No fee is normally charged for exercising your rights.
However, where requests are manifestly unfounded or excessive, particularly because of their repetitive nature, we may charge a reasonable administrative fee or refuse to act on the request where permitted by Article 12 GDPR.

12. Security of Personal Data

We implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Such measures may include, where appropriate:
• encrypted communications using Transport Layer Security (TLS);
• access controls based on business need;
• strong authentication for administrative access;
• regular software updates and security patches;
• firewall and server security measures;
• malware protection;
• secure backups;
• logging and monitoring of security-related events;
• confidentiality obligations applicable to personnel and service providers.
While we take appropriate steps to safeguard Personal Data, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure.
Accordingly, we cannot guarantee absolute security, although we continually review and improve our security practices in accordance with technological developments and applicable legal requirements.

13. Personal Data Breaches

We maintain documented procedures for identifying, investigating, containing and responding to actual or suspected personal data breaches.
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
Where we become aware of a personal data breach, we will promptly assess:
• the nature of the incident;
• the categories and approximate number of affected individuals;
• the categories and approximate volume of Personal Data concerned;
• the potential consequences for affected individuals; and
• the measures required to mitigate any adverse effects.
Where required by applicable law, and in particular Articles 33 and 34 of the GDPR, we will:
• notify the competent supervisory authority without undue delay and, where applicable, within the statutory time limits; • notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms, unless an exemption under the GDPR applies; and
• document the facts relating to the breach, its effects and the corrective measures taken.
Where appropriate, we will take immediate technical and organisational measures to contain the incident, minimise any potential impact and reduce the likelihood of similar incidents occurring in the future.
Nothing in this Privacy Policy limits our obligations under applicable data protection legislation concerning the reporting, investigation or management of personal data breaches.

14. Data Protection by Design and by Default

Linoart Ltd. is committed to implementing the principles of Data Protection by Design and Data Protection by Default in accordance with Article 25 of Regulation (EU) 2016/679 (General Data Protection Regulation).
When designing, developing, implementing or updating our Website, internal systems, business processes or services involving the processing of Personal Data, we take appropriate technical and organisational measures to ensure that data protection principles are effectively integrated into those activities.
In particular, we seek to:
• process only the Personal Data that is necessary for the specific purpose for which it is collected;
• limit the amount, scope and retention of Personal Data to what is reasonably required;
• ensure that Personal Data is accessible only to authorised personnel whose duties require such access;
• implement appropriate security measures throughout the lifecycle of Personal Data;
• consider privacy risks when introducing new technologies, services or processing activities;
• review and update our internal procedures where necessary to reflect changes in legislation, technology or business operations; and
• promote awareness of data protection responsibilities among individuals who process Personal Data on our behalf.
Where appropriate and required by applicable law, we may carry out a Data Protection Impact Assessment (DPIA) before commencing processing activities that are likely to result in a high risk to the rights and freedoms of natural persons.
We regularly review our technical and organisational measures to ensure that they remain appropriate in light of technological developments, the nature of the processing, and the risks presented to the rights and freedoms of Data Subjects.
The implementation of Data Protection by Design and by Default forms part of our broader commitment to accountability, transparency and continuous improvement in the protection of Personal Data.

15. Accountability and GDPR Compliance

Linoart Ltd. is committed to maintaining an effective data protection governance framework and to demonstrating compliance with Regulation (EU) 2016/679 (General Data Protection Regulation) and all other applicable data protection legislation.
Data protection is an integral part of our business processes, system design and decision-making. We regularly review our privacy practices to ensure that the processing of Personal Data remains lawful, fair, transparent and proportionate.

15.1 Governance

We maintain appropriate technical and organisational measures designed to ensure ongoing compliance with applicable data protection legislation.
These measures include:
• maintaining internal policies and procedures governing the processing of Personal Data;
• periodically reviewing the categories of Personal Data processed and the purposes for which it is processed;
• limiting access to Personal Data to authorised personnel with a legitimate business need;
• implementing security measures appropriate to the nature of the Personal Data and the risks associated with the processing;
• reviewing our data retention practices on a regular basis; and
• periodically reviewing this Privacy Policy and related documentation to ensure that they remain accurate and up to date.

15.2 Records of Processing Activities

Where Article 30 GDPR requires us to do so, we will maintain records of processing activities containing the information prescribed by applicable legislation.
Such records may include:
• categories of processing activities;
• categories of Personal Data;
• categories of Data Subjects;
• recipients of Personal Data;
• international transfers;
• applicable retention periods; and
• technical and organisational security measures.

15.3 Data Processors

Where we engage third-party processors, we will ensure that processing is governed by a written agreement that satisfies the requirements of Article 28 GDPR.
Before appointing a processor, we seek to satisfy ourselves that the processor provides sufficient guarantees to implement appropriate technical and organisational measures to protect Personal Data.
We periodically review our relationships with processors where appropriate to ensure continued compliance.

15.4 Privacy Risk Assessments

When introducing new technologies, services or processing activities involving Personal Data, we consider the potential impact on the rights and freedoms of Data Subjects.
Where required by Article 35 GDPR, we will carry out a Data Protection Impact Assessment before commencing processing that is likely to result in a high risk to individuals.
Where appropriate, we review existing processing activities to identify opportunities for improving privacy protection and reducing unnecessary processing.

15.5 Cooperation with Supervisory Authorities

Where required by applicable law, we will cooperate with competent supervisory authorities in relation to our data protection obligations.
This may include:
• responding to lawful requests for information;
• providing documentation where legally required;
• implementing corrective measures where appropriate;
• complying with legally binding decisions issued by competent authorities.

15.6 Continuous Improvement

Data protection is an ongoing process rather than a one-time compliance exercise.
Accordingly, we periodically review our technical, organisational and contractual safeguards in light of:
• changes in applicable legislation;
• developments in technology;
• cybersecurity risks;
• changes to our business operations;
• guidance issued by competent supervisory authorities; and
• recognised industry best practices.
Where improvements are identified, we aim to implement them within a reasonable period, taking into account the nature of the risk, available technology, implementation costs and the scope of the processing.

15.7 No Waiver of Statutory Rights

Nothing in this Privacy Policy limits or excludes any rights granted to Data Subjects under applicable data protection legislation.
Similarly, nothing in this section creates contractual obligations exceeding those imposed by applicable law.
Descriptions of our governance framework are intended to explain our general approach to privacy compliance and may evolve over time as our business, technologies and legal obligations develop.