Privacy policy
How myLabForty handles client workspace, account, support and device information.
Who is responsible
myLabForty is operated by Лаб40 ЕООД (Lab40 EOOD), trading as LabForty, Bulgarian company registration number (EIK) 205622271, VAT number BG205622271. Our registered address is 56 Kapitan Raycho Street, floor 3, shop 13, 4000 Plovdiv, Bulgaria. Contact us at [email protected].
Lab40 is the controller for client account administration, access security, service communications and its own business records described in this notice. If a client supplies personal data that we process on its instructions as part of a separate service, the client's privacy notice and the applicable service arrangements also apply.
Information and its sources
We receive your name, invited email address, language and company or project permissions from you, your organisation and authorised LabForty staff. The workspace displays only records published for your account: projects, service observations, support agreements and contacts, completed work and recorded effort, maintenance history, client documents and permitted invoices. Invoice access requires a separate finance permission.
We process the support requests, replies and attachments you submit, including their sender and timestamps. The app backend also holds account and sign-in records, session credentials, inbox read status and notification preferences. Business records and publication permissions are managed in the LabForty intranet.
Operating the service involves connection and security information, such as IP addresses, request times, device or browser information and delivery or error records. If you use TestFlight, Apple automatically collects crash and usage information and shares it with LabForty. Feedback you submit through TestFlight is also shared with us.
Purposes and legal grounds
We use account, access and service information to provide the workspace, verify invited users, show permitted records and handle support. Where you are personally a party to our service contract, necessary processing is based on performance of that contract under GDPR Article 6(1)(b). For contacts acting for a client organisation, we rely on legitimate interests under Article 6(1)(f): administering that client relationship, communicating about its services and restricting information to authorised people.
Security checks, delivery records and investigation of errors support our legitimate interests in protecting accounts and maintaining a reliable service. We use TestFlight diagnostics and feedback to find faults and improve the app. Records required to meet applicable accounting, tax or other legal duties are processed under Article 6(1)(c).
We rely on consent under GDPR Article 6(1)(a) to register optional device notifications. Registration also requires device permission. You can withdraw that choice in the app or device settings without losing workspace access. We need an invited email address and the relevant access information to sign you in; without them, we cannot provide a private workspace. Permission checks determine access, but the workspace does not make solely automated decisions with legal or similarly significant effects.
Access, providers and international processing
Authorised LabForty staff handle service and support records. Your organisation's permitted contacts can see information published to the same company or project within their own permissions. Hosting and technical support providers process information needed to operate the service. Microsoft 365 handles our email delivery, including sign-in emails. Cloudflare provides connection delivery and security and processes traffic information. We may disclose relevant records when required by law or necessary to establish, exercise or defend legal claims.
Provider services can involve processing outside the European Economic Area, including in the United States. Their published privacy and data-processing terms describe international processing and safeguards, including standard contractual clauses where applicable. The links below provide those terms. Contact LabForty to ask for the provider and transfer information applicable to your data or a copy of relevant safeguards.
Optional device notifications
The initial TestFlight test does not send push notifications. If you choose to register device notifications, the app uses Expo and the device's notification service, including Apple on iOS, to obtain a device token. We associate the token, an app installation identifier, platform and language with your signed-in account and store notification preferences.
When push delivery is available, the notification contains generic update text and identifiers used to open the authorised inbox item. It does not contain support-message text, attachments or invoice amounts. You can disable device notifications or change their categories in the app. Disabling push does not remove the in-app inbox.
Your device and private files
The mobile app keeps its sign-in credential in protected device storage and saves language, appearance and notification preferences. Optional device unlocking uses the operating system's authentication result; LabForty does not receive your biometric templates.
Unsent text remains in app memory. An interrupted submission can retain its original request in protected storage for an explicit retry. That pending request is removed after successful submission, sign-out or account change. Private download copies are temporary and cleared after sharing or when the session locks or changes.
Only files you select are uploaded. A copy you deliberately save or share outside the app is handled by the destination you choose and is not removed by signing out. The web gateway uses essential session and security cookies. The separate labforty.com website privacy policy explains that website's cookies.
Retention and account removal
Sign-in codes expire after 10 minutes and sessions expire after 30 days. The session-maintenance task removes expired sessions and code records more than one day past expiry. Logging out or revoking a session removes its server credential and associated device registration. These technical limits do not define the retention of business records.
Support attachments uploaded but not submitted with a message expire after 24 hours and are eligible for cleanup. Submitted support messages, documents, work, maintenance and invoice records remain in the intranet. Signing out, withdrawing publication or removing app access does not automatically delete those records.
We retain business, security and testing records while needed for the client relationship, unresolved support or security issues, applicable accounting or legal obligations, or the establishment and defence of claims. The relevant record type, service relationship and any legal requirement determine the duration. Contact us to request account removal or erasure and to ask which retention requirement applies to a particular record.
Your rights and how to contact us
Under the GDPR, you can request access, correction, erasure, restriction or portability where the conditions for that right apply. You can object to processing based on legitimate interests and withdraw consent for processing based on consent. Withdrawal does not affect earlier lawful processing.
Send your request to [email protected], describing the account or information concerned. We may need information to verify your identity and protect other people's data. We handle requests within the applicable GDPR time limits and explain any lawful restriction, retention requirement or permitted extension.
You can complain to the Bulgarian Commission for Personal Data Protection or the supervisory authority in your place of residence, work or the alleged infringement. Contacting us first is optional.
Updates to this notice
The date above identifies this version. We will update this notice when the workspace's processing changes and provide any additional notice or choice required by law. Contact LabForty if you need information about an earlier version.