Silver Data Lab
Silver Data Lab

Privacy Policy

Last updated: 18 August 2026

1. Who we are

SILVER DATA LAB is the data controller responsible for the personal data described in this policy.

ControllerSilver Data Lab
Address4 Marko Balabanov str., Vazrazhdane Distr., 1303 Sofia, Bulgaria
Contact for privacy mattersprivacy@silverdatalab.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). Privacy enquiries are handled at the address above.

2. What this policy covers

This policy explains how we collect and use personal data when you visit silverdatalab.com and any subdomain operated by us, and when you correspond with us.

A note on our published research. The studies published on this website are derived from aggregated official statistics released by Eurostat and other public statistical authorities. They describe populations, not individuals, and contain no personal data. Nothing in our published output identifies, or can be used to identify, any person.

3. Personal data we process

3.1 Technical data collected automatically

When you visit the website, our hosting infrastructure records standard server log data, including your IP address, the date and time of the request, the pages requested, the HTTP status returned, your browser type and version, your operating system, and the referring page.

Purpose: delivering the website, maintaining its security and availability, detecting and preventing abuse, and diagnosing technical faults.

Legal basis: our legitimate interests in operating a secure and functioning website (Article 6(1)(f) GDPR).

Retention: two months, after which logs are deleted or aggregated into non-identifying statistics.

3.2 Analytics

Subject to your consent, we use Google Analytics 4 to understand how visitors use the website — which pages are read, how visitors arrive, and how they navigate between studies. This is done using cookies and similar identifiers.

Google Analytics processes information such as a randomly generated identifier stored on your device, pages viewed, approximate geographic location derived from your IP address, device and browser characteristics, and referral source. Google Analytics 4 does not store IP addresses in the data available to us.

Purpose: measuring audience and improving the structure and content of our research output.

Legal basis: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.

Retention: two months at Google’s end; aggregated reports are retained by us for as long as they remain useful for editorial planning.

If you do not consent, analytics cookies are not set and no data is transmitted to Google Analytics.

3.3 Correspondence

If you contact us by email, or through the form on our Contacts page, we process your email address, your name if you provide it, and the content of your message. The same applies to an invitation request sent from our Membership page, where we process the name and email address you give and any note you add. If you are a member and send a question to our research desk through the form at the foot of a study, we process your question, the name and email address on your account, and a reference to the study the question concerns; the same applies to a study proposal sent from the members' form on our Data Lab page, where we process the proposal and the name and email address on your account.

If you are a member and choose to follow a study, we store that choice with your account and email you when the data behind that study changes. The same control on the study page removes the choice, and no further email is sent. We send no other unrequested email.

Purpose: responding to your enquiry and keeping a record of the exchange.

Legal basis: our legitimate interests in responding to enquiries addressed to us, or the steps necessary prior to entering into a contract where your message concerns a possible engagement (Article 6(1)(f) and Article 6(1)(b) GDPR).

Retention: twelve months from the last exchange, unless a longer period is required for accounting or legal purposes.

3.4 Spam protection on our forms

The form on our Contacts page, the invitation request form on our Membership page, the member sign-in and password-reset forms on our sign-in page, the question form for members at the foot of each study, and the members' study proposal form on our Data Lab page, are protected by Google reCAPTCHA v3, provided by Google Ireland Limited. reCAPTCHA analyses how the form is used in order to distinguish a person from an automated script, and to do so it collects technical and behavioural information including your IP address, browser and device characteristics, and your interaction with the page. That information is transmitted to and evaluated by Google.

The reCAPTCHA script is loaded only on the pages that carry one of these forms, and only once you begin filling it in. Simply opening one of them, or reading any page of this website, sends nothing to reCAPTCHA.

Purpose: preventing automated abuse of the contact, invitation request, member question and study proposal forms, and protecting member accounts against automated sign-in attempts and against the password-reset form being used to send unrequested email.

Legal basis: our legitimate interest in protecting these forms, our mailbox and our members' accounts from automated submissions (Article 6(1)(f) GDPR).

Retention: retention of the data collected by reCAPTCHA is determined by Google. Its handling is described in the Google Privacy Policy.

If you would rather not use reCAPTCHA, you can reach us without it by writing directly to info@silverdatalab.com, which involves no processing by Google.

4. Cookies and similar technologies

A cookie is a small text file that a website asks your browser to store on your device. Similar technologies achieve comparable results by other means: local storage and session storage hold data in the browser rather than transmitting it with each request. Where this section says “cookies”, it covers both unless stated otherwise.

We use two categories, and no others.

Strictly necessary cookies are required for the website to work or to record a choice you have made. Without them, functions you have asked for cannot be delivered. They do not require your consent, as provided by Article 5(3) of Directive 2002/58/EC as implemented in Bulgarian law.

Analytics cookies help us understand which studies are read and how visitors move between pages. They are not necessary for the site to function, and are set only after you have given consent.

We do not use advertising or marketing cookies. We do not build profiles of visitors, we do not carry out cross-site tracking, and we do not allow third parties to use our website to follow you elsewhere.

4.1 Strictly necessary

NameProviderTypeDurationPurpose
sdl_cookie_consentSilver Data Lab (first party)Cookie180 daysRecords your cookie choices so that you are not asked again on every page.
tsr-scroll-restoration-v1_3Silver Data Lab (first party)Session storageUntil the tab is closedRestores your scroll position when you move back and forward between pages.
sdl_sessionSilver Data Lab (first party)Cookie1 hourSet only if you sign in as a member. It keeps you signed in from one page to the next, and is renewed silently while you are using the site.
sdl_refreshSilver Data Lab (first party)Cookie30 daysSet only if you sign in as a member. It lets your session be renewed without asking you for your password again, and is deleted when you sign out.
sdl_memberSilver Data Lab (first party)Cookie30 daysSet only if you sign in. It records nothing but the fact that a session exists, so that the page knows to greet you by name instead of asking the server on every visit. It holds no name, address or identifier.

sdl_session, sdl_refresh and sdl_member exist only for signed-in members and only after you have entered your password: simply reading the site never sets them. The first two are HttpOnly, meaning no script running on the page can read them, and all three are SameSite=Lax, meaning they are not sent when another site links to ours. sdl_member is readable by the page on purpose, because it is what tells the page a session exists; its value is the single character 1 and it identifies nobody. All three are strictly necessary to provide a service you have asked for — staying signed in — and are therefore not subject to consent; they are never used to analyse your behaviour or shared with anyone. Signing out deletes all three immediately.

sdl_cookie_consent is set by this website and is never sent to a third party. It is restricted with the SameSite=Lax attribute, which prevents it from being transmitted when another site links to or embeds ours. Its value is a small JSON record containing the version of this policy in force when you chose, the date of your choice, and which categories you accepted or declined. It holds no identifier for you, and nothing in it can be used to recognise you on another website.

It expires after 180 days, in line with the recommendation of the European Data Protection Board that consent be renewed at least twice a year. You will be asked again after that period, or sooner if the cookies used on this site change.

4.2 Analytics — set only with your consent

NameProviderTypeDurationPurpose
_gaGoogle Ireland LimitedCookie (third party)2 yearsDistinguishes one browser from another by storing a randomly generated identifier, so that repeat visits are not counted as new visitors.
_ga_DXM2CXGMZPGoogle Ireland LimitedCookie (third party)2 yearsMaintains the analytics session state for this website’s Google Analytics 4 property.

These cookies are set by Google Analytics 4. The data they generate is processed by Google Ireland Limited and may be transferred outside the European Economic Area under the safeguards described in section 6. Google Analytics 4 does not make IP addresses available to us.

If you decline analytics cookies, neither cookie is set and no information is sent to Google Analytics.

4.3 Managing your choices

On this website. Select Cookie preferences in the footer of any page to review or change your choices at any time. Changing your choice rewrites the consent cookie and takes effect immediately: if you withdraw consent for analytics, the cookies listed in section 4.2 are deleted and no further data is sent to Google Analytics. Withdrawing consent is as straightforward as giving it.

In your browser. Every major browser lets you block or delete cookies, either wholly or by site. The setting is normally found under Privacy or Privacy and security in the browser’s preferences. Deleting cookies removes your recorded preference as well, so you will be asked again on your next visit. Blocking strictly necessary cookies may prevent parts of the site from working as intended; blocking analytics cookies has no effect on your ability to read anything published here.

Automated signals. Where your browser sends a Global Privacy Control signal, we treat it as an objection to non-essential cookies. There is no agreed standard for Do Not Track headers, and we do not respond to them.

5. Recipients of personal data

We do not sell personal data and we do not share it for the commercial purposes of others. We disclose personal data only to:

  • Service providers acting on our instructions, under written data processing agreements meeting the requirements of Article 28 GDPR. These currently comprise our hosting provider, Vercel Inc., Google Ireland Limited for analytics and for reCAPTCHA on our forms, the email provider that delivers messages sent through those forms, and Supabase, which holds member accounts and the record of cookie consent.
  • Professional advisers, such as accountants and lawyers, where necessary and under a duty of confidentiality.
  • Public authorities, where we are required to disclose data by law or to establish, exercise or defend legal claims.

6. Transfers outside the European Economic Area

Our hosting provider, Vercel Inc., our analytics provider, the reCAPTCHA service used on our forms and our email delivery provider may process data on servers located outside the EEA, including in the United States.

Where this occurs, the transfer is made under the Standard Contractual Clauses adopted by the European Commission, and — for providers certified under the EU-US Data Privacy Framework — under the adequacy decision of 10 July 2023. Our providers apply supplementary technical measures, including encryption in transit and at rest.

You may request a copy of the safeguards applicable to a specific transfer by writing to privacy@silverdatalab.com.

7. Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects concerning you, and we do not engage in profiling within the meaning of Article 22 GDPR.

8. Security

We apply technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS) across the whole website, access control on administrative systems, and restriction of access to personal data to those who need it for their work.

No system is perfectly secure, and we do not claim otherwise. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Commission for Personal Data Protection within 72 hours, and will inform you directly where the risk is high.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Rectification of inaccurate data and completion of incomplete data.
  • Erasure of your data where one of the grounds in Article 17 GDPR applies.
  • Restriction of processing in the circumstances set out in Article 18 GDPR.
  • Data portability for data you have provided to us, where processing is based on consent or contract and carried out by automated means.
  • Object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
  • Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, write to privacy@silverdatalab.com. We will respond within one month of receiving your request. Where a request is complex or where we receive several requests from you, we may extend that period by up to two further months, and will tell you if we do. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.

We may ask you for information sufficient to confirm your identity before acting on a request. We ask only for what is necessary for that purpose.

10. Complaints

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

Commission for Personal Data Protection (Комисия за защита на личните данни)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Email: kzld@cpdp.bg · Telephone: +359 2 915 3518 · Website: www.cpdp.bg

You may also lodge a complaint with the supervisory authority of the EU Member State where you live or work, or where the alleged infringement took place. You have the right to an effective judicial remedy in addition to, or instead of, a complaint to a supervisory authority.

11. Children

This website is intended for a professional and academic audience. We do not knowingly collect personal data from children under the age of 14, the age of consent for information society services under Bulgarian law. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this policy

We may update this policy to reflect changes in our processing or in the applicable law. The date at the top of the page shows when it was last revised. Where a change materially affects how we use your personal data, we will bring it to your attention on the website before the change takes effect.

13. Contact

Questions about this policy or about how we handle personal data:

Silver Data Lab
4 Marko Balabanov str., Vazrazhdane Distr.
1303 Sofia, Bulgaria
privacy@silverdatalab.com