CART 0

Privacy Policy

Effective date: 01.09.2026
Last updated: 01.09.2026
Content

Privacy Policy

Effective date: 1 September 2026 | Last updated: 1 September 2026

MID Auto respects your privacy and is committed to processing personal data lawfully, fairly and transparently. This Privacy Policy explains how we collect, use, store, share and protect personal data when you use our website, create an account, place an order, submit a form, make a warranty or return claim, or otherwise interact with us. It is designed to comply with Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act and the applicable rules on cookies and similar technologies.

1. Who We Are - Data Controllers

The MID Auto website (www.midauto.com) uses shared infrastructure operated by the following three related companies, whose controller roles depend on the specific processing operation:

- MID Auto Ltd. - UIC 103140975, VAT BG103140975, registered address: Varna, Evksinograd, Street 14 No. 3, Bulgaria - sales and services for customers in Bulgaria (outside the Sofia region) and all workshop services performed in Varna

- M I D Auto - Sofia Ltd. - UIC 201535043, VAT BG201535043, registered address: 10 Arch. Stefan Kolchev Str., Varna, Bulgaria, shop location: Sofia, Manastirski Livadi - sales for customers in the Sofia region

- MID AUTO INTERNATIONAL Ltd. - UIC 208695399, VAT BG208695399, registered address: 14G Filip Kutev Blvd., Sofia, Bulgaria - all international sales and inquiries

For common Site operation and security, the unified customer account, initial receipt and routing of enquiries/orders, shared CRM history and jointly determined marketing, the companies act as joint controllers under Article 26 GDPR. For performance, invoicing, delivery, returns and claims relating to a specific order, the company displayed as Seller before ordering and on the invoice acts as an independent controller.

The joint controllers have internally allocated responsibilities, including transparency, security, breaches and data-subject requests. The essence for you is that rights may be exercised through the common contact point or directly against any company; the internal allocation does not restrict your rights.

Contact for all privacy matters: [email protected] (Bulgaria) / [email protected] (international) | +359 899 136 644 | ZPZ, str. Usta Kolyu Ficheto 3;

2. What Personal Data We Collect

Depending on the interaction, we may process: identity and contact details; company, authority and VAT data; delivery and billing addresses; orders, payments, refunds and an IBAN where needed; account and access records; communications; VIN, registration and technical vehicle/transmission data; serial numbers, photographs, videos, diagnostic reports, fault codes, installation and warranty documents; logistics and customs data; IP address, device, browser, server and security logs; fraud-prevention data; cookie identifiers; marketing preferences and evidence of consent/objection. We do not store full payment-card details.

3. How We Collect Personal Data

We collect data from you; a person, business or workshop on whose behalf you act; a recipient/vehicle owner where you are authorised; payment, courier, customs and logistics providers; our systems, server logs and cookies; and technical documents provided to us. When supplying another person’s data, you must have a lawful basis, inform them and avoid sending unnecessary special-category data.

4. Purposes and Legal Bases

4.1 Orders and contracts - accounts, routing to the relevant Seller based on delivery address, compatibility support, ordering, payment, invoicing, delivery, after-sales support, returns and warranties. Basis: pre-contractual steps and contract performance (Art. 6(1)(b)); for employees/representatives of B2B customers, legitimate interest in performing the business relationship.

4.2 Legal obligations - accounting and tax records, consumer protection, product safety and traceability, customs, sanctions and regulatory duties. Basis: Art. 6(1)(c) GDPR.

4.3 Enquiries and business communication - responses, quotations, partnerships and technical support. Basis: pre-contractual steps or legitimate interest in reliable communication, documentation and business development.

4.4 Claims, returns and abuse prevention - identifying the order and unit, RMA handling, technical inspection, photographs/tests, cause analysis, fraud prevention and establishing, exercising or defending legal claims. Basis: contract, legal obligation and legitimate interest in a secure and auditable process. Address-based routing only determines which Seller handles an order; it does not evaluate personal characteristics or independently produce significant adverse effects.

4.5 Site operation and security - authentication, shopping cart, fraud prevention, abuse limitation, logs, backups, diagnostics and measurement. Basis: contract and legitimate interest in a secure service; consent for optional cookies under the Cookie Policy.

4.6 Marketing - electronic offers to individuals are sent with prior consent or under the expressly permitted existing-customer exception for our own similar products, always with an easy free opt-out. For B2B contacts, we comply with applicable rules and the Bulgarian public opt-out register for legal entities. Basis: consent or legitimate interest only where legally permitted. Direct-marketing objections are implemented immediately.

5. Who We Share Data With

We share data only where necessary: between the three companies under the roles above; Econt, DHL and other carriers/customs agents; Stripe, banks and payment providers; Hetzner and IT, cybersecurity, backup, CRM, e-mail and maintenance providers; manufacturers, suppliers, testing laboratories or workshops only for identification and technical claims; accountants, auditors, insurers and legal advisers; competent authorities. We do not sell personal data. Processors are bound under Article 28 GDPR, while independent recipients have their own legal duties.

6. International Transfers

Data is processed mainly in the EU/EEA. A transfer outside the EEA occurs only after verifying the applicable mechanism: an adequacy decision, valid participation in the EU-US Data Privacy Framework, or Standard Contractual Clauses with the required assessment and supplementary measures. You may request information about the relevant safeguard, subject to protected or confidential information.

7. Retention

We use differentiated periods: accounting and tax records - up to 10 years or longer where specifically required; contracts, orders and delivery evidence - normally 5 years after completion unless a longer tax/legal risk applies; technical traceability, remanufacturing files, serious defects and product safety - up to 10 years; claims/RMA files - 5 years after final closure or until a dispute ends; inactive accounts - normally 3 years; security logs - normally up to 12 months unless an incident occurs; evidence of consent, withdrawal and objection - up to 5 years after use ends. Data under a legal hold is retained until the basis ends, then deleted or anonymised.

8. Your Rights

You have rights of access, rectification, erasure where applicable, restriction, portability, objection to legitimate-interest processing and direct marketing, and consent withdrawal without retroactive effect. Rights are not absolute and may be limited by contractual, accounting, product-safety or legal-claim obligations. We may request reasonable identity evidence and apply Article 12(5) GDPR to manifestly unfounded or excessive repetitive requests. Contact [email protected] or [email protected]; we respond within one month, subject to a permitted extension with notice.

You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / КЗЛД): www.cpdp.bg, 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, or with your local supervisory authority in the EU.

9. Security

We use appropriate technical and organisational measures including HTTPS, role-based access, MFA where appropriate, audit logs, backups, contractual confidentiality and periodic review. We notify the CPDP within 72 hours unless a breach is unlikely to risk rights and freedoms, and notify affected persons without undue delay where a high risk is likely.

10. Cookies

Cookies are described in the Cookie Policy. Optional analytics, functional and marketing technologies are not activated before valid consent. Settings can be changed or withdrawn at any time as easily as consent was given.

11. Children

The Site is intended for adults and authorised business representatives. We do not direct services to children or knowingly collect their data. If we identify data supplied by a child without a valid basis, we will delete it unless retention is legally required.

12. Changes to This Policy

We may update this Policy prospectively. The current version and date are published on this page; material changes are communicated appropriately. A change does not retroactively create a new legal basis for processing.