Privacy policy

Privacy Policy and Personal Data Protection

Applicable to services related to compensation for disrupted air passenger rights, the purchase and management of insurance claims, as well as the use of the website claimster.bg.

 

Administrator

LEGAL ASSIST Ltd., UIC 202986699
Registered office and address of management: 161 Pozitano St., Floor 1, Apt. 1, Sofia 1309, Bulgaria

Correspondence address / office: 6 Tri Ushi St., Floor 1, Office 3, Sofia 1000, Bulgaria

Data protection contacts

Email (GDPR): gdpr@claimster.bg

General contact details: info@claimster.bg

| +359 88 596 7297



 

This Privacy Policy aims to clearly explain what personal data we process, why we process it, where we obtain it from, how long we retain it, to whom it may be disclosed, and what rights you have in this regard.

1. Scope of the Policy

This Policy applies to the processing of personal data in connection with the use of the websites claimster.bg and claimster.bg, when submitting inquiries via contact forms, when requesting services, when submitting and managing claims against air carriers, when purchasing and managing insurance claims, as well as in the course of subsequent communication, payments, accounting, and legal services.

The Policy also applies when we receive personal data relating to other individuals — for example, other passengers under the same booking, parents or legal guardians of minors, as well as individuals whose data is provided to us in connection with an insurance claim.

2. Categories of Personal Data We Process

2.1. Data Provided Directly by You

  • identification and contact details — first name, last name, email address, telephone number, correspondence address;
  • data submitted through contact forms — type of inquiry, message content, attached documents and files;
  • data provided in connection with the conclusion of contracts, powers of attorney, declarations, assignment agreements, or other legal documents;
  • payment and financial data — bank account details, account holder, payment information, invoicing and accounting data.

2.2. Data Related to Flight Claims

  • flight and booking details — flight number, date, route, carrier, booking reference, boarding pass, ticket, and accompanying passengers’ data;
  • data necessary to substantiate the claim — communications from the airline, correspondence, confirmations, vouchers, expense receipts, and other supporting documentation;
  • data required for representation — signed power of attorney and, where necessary, identification document details for the purpose of verifying identity and the connection to the booking.

2.3. Data Related to the Purchase and Management of Insurance Claims

  • data concerning the event and the claim — policy or claim number, date and location of the event, description of damages, correspondence with the insurer, expert reports, assessments, quotations, and refusals;
  • data relating to a vehicle or other affected property, where necessary for the identification and management of the claim;
  • data required for the conclusion and performance of an assignment agreement or other contractual mechanism for the acquisition and/or management of the claim.

2.4. Data Obtained from Other Sources

  • from other passengers, parents, guardians, custodians, or authorised representatives, where the claim is submitted on their behalf;
  • from air carriers, insurers, lawyers, courts, administrative authorities, experts, court-appointed experts, payment institutions, and other parties involved in the process;
  • from public registers or official sources, where necessary for identification purposes, the establishment, exercise, or defence of legal claims, or compliance with legal obligations.

2.5. Technical Data and Website Usage Data

  • IP address, logs, browser type and version, device, operating system, date and time of access, referring URL, and technical diagnostic data;
  • identifiers from cookies and similar technologies, where such are used.

Where analytical, functional, or marketing cookies are used on the website and are not strictly necessary, they shall only be activated on the basis of a valid legal ground and after providing an appropriate mechanism for managing user preferences.

3. Purposes and Legal Grounds for Processing

  • o respond to your inquiry and to take steps prior to entering into a contract — Article 6(1)(b) GDPR.
  • To conclude, perform, and administer a contract for claim assistance, representation, or assignment — Article 6(1)(b) GDPR.
  • To comply with legal obligations related to accounting, taxation, proof of payments, consumer protection, and cooperation with competent authorities — Article 6(1)(c) GDPR.
  • To establish, exercise, or defend legal claims, to prevent fraud and abuse, to maintain the security of the website, and to administer our business activities — Article 6(1)(f) GDPR.
  • Where applicable and explicitly requested — for marketing communications, analytics, or other non-essential technologies — based on consent under Article 6(1)(a) GDPR.

Where we rely on legitimate interests, such interests include, in particular: the efficient administration of our activities, maintenance of information security, prevention of fraud and abuse, collection and protection of receivables, as well as the establishment, exercise, or defence of legal claims.



 

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal shall not affect the lawfulness of processing carried out prior to such withdrawal.

4. Special Categories of Data, Children’s Data, and Data of Third Parties

As a rule, we do not require special categories of personal data within the meaning of Article 9 GDPR. In certain cases, primarily related to insurance claims, we may receive documents containing data concerning health or other data requiring a higher level of protection. In such cases, we process such data only to the extent necessary for the establishment, exercise, or defence of legal claims, for the performance of a contract, or where another applicable legal basis exists.

Personal identification numbers, ID card numbers, passport details, and copies of identity documents are not automatically classified as special categories under Article 9 GDPR; however, they are subject to an enhanced level of protection and restricted access.

Where you provide us with personal data relating to other individuals — including other passengers, minors, or children — you must ensure that you are entitled to do so and, where applicable, that you have informed them of such disclosure. Where we have not obtained the personal data directly from the data subject, we provide the information required under Article 14 GDPR within the applicable time limits and subject to the relevant exemptions.

5. Is the Provision of Data Mandatory

The provision of certain personal data is necessary for us to assess the eligibility of a claim, to conclude and perform a contract, to verify identity, to prepare a power of attorney, to execute payments, or to comply with legal obligations. If you do not provide the required data, we may not be able to accept the case, continue processing it, or execute a payment.

The provision of personal data for marketing communications and the use of non-essential cookies is not a condition for accessing the core services, unless a specific functionality explicitly requires it.

6. Recipients of Personal Data
We may disclose personal data to:

  • air carriers, airport operators, handling agents, or their representatives, where necessary for submitting and substantiating a claim;
  • insurance companies, claims handling centres, experts, repair service providers, assessors, and other parties involved in the management or purchase of an insurance claim;
  • external lawyers, legal representatives, mediators, courts, enforcement agents, arbitration bodies, and administrative authorities;
  • banks, payment institutions, and accounting/audit consultants;
  • providers of hosting, email services, cloud storage, CRM systems, IT support, electronic signature solutions, archiving, and other processors acting on our behalf;
  • competent public authorities, where we are required to disclose data by law.

For each processor acting on our behalf, we maintain contractual and organisational measures in accordance with Article 28 GDPR.

7. Transfers of Personal Data Outside the European Economic Area

Some recipients of personal data — such as air carriers, insurers, technology providers, or their affiliated subcontractors — may be located outside the European Union / European Economic Area. In such cases, we transfer personal data only where a valid legal basis under Chapter V of the GDPR is in place, such as an adequacy decision, standard contractual clauses, or another appropriate safeguard.



 

Upon request, you may obtain further information regarding the applicable safeguards, insofar as this is permissible and does not adversely affect the rights and freedoms of other individuals.

8. Data Retention Periods

Category of Data

Standard Retention Period

Notes

Data from contact forms and general inquiries

Up to 12 months

Unless the communication develops into a contractual relationship or dispute
Data related to claims against air carriers

Up to 5 years after final resolution

Longer in case of litigation, enforcement proceedings, or applicable limitation periods
Data related to insurance claims and assignments

Up to 5 years after final resolution

Longer in case of ongoing dispute, debt collection, or statutory limitation periods
Powers of attorney, contracts, evidence, and procedural documents

Until the expiry of the applicable limitation periods

Retained as long as necessary for the establishment, exercise, or defence of legal claims
Accounting and payment documents

10 years

In accordance with applicable accounting and tax legislation
Technical logs and security data

Up to 12 months

Unless longer retention is required for incident investigation or legal protection

After the expiry of the applicable retention period, personal data shall be deleted, anonymised, or retained in a restricted manner where necessary for the establishment, exercise, or defence of legal claims.

9. Automated Decision-Making

We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.



 

We may use automated support tools for the preliminary assessment of case eligibility, the potential amount of compensation, or organisational prioritisation; however, the final assessment and actions taken in relation to a case are not based solely on automated decision-making.

10. Security of Processing

We implement appropriate technical and organisational measures to protect personal data, taking into account the nature of the data processed and the associated risks. Such measures include, for example, access control, logical access segregation, data backups, encryption/pseudonymisation, secure communication channels, contractual confidentiality obligations, and internal access policies.

11. Your Rights

  • the right to access the personal data we process about you;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure, where the legal requirements are met;
  • the right to restriction of processing in the cases provided by law;
  • the right to data portability, where processing is based on consent or a contract and is carried out by automated means;
  • the right to object to processing based on legitimate interests, including for direct marketing purposes;
  • the right to withdraw consent at any time, where processing is based on consent;
  • the right not to be subject to a decision based solely on automated processing, where the conditions of Article 22 GDPR are met.

You may exercise your rights by contacting us at gdpr@claimster.bg

. We may request additional information to verify your identity. As a rule, we respond within one month of receiving your request.

12. Complaint to a Supervisory Authority

If you believe that the processing of your personal data infringes applicable legislation, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, website: www.cpdp.bg.

13. Changes to This Policy

We may update this Policy in the event of changes in legislation, technological developments, the way our services are provided, or the service providers we engage. The current version will be published on our website and will indicate the date of the latest update.

14. Last Update

Last update: 06 April 2026

This version has been prepared as a revised Privacy Policy, aligned with the publicly available services of Claimster as of the date of the update.