Skip to content
Ragdoll RagSweet

Privacy Policy

Last updated: March 21, 2026

Privacy and Data Protection Policy

In accordance with the legislation in force, RagSweet Kitten Cattery (hereinafter, also the Website) undertakes to adopt the technical and organisational measures necessary in line with a level of security appropriate to the risk of the data collected.

Laws incorporated into this privacy policy

This privacy policy is adapted to the Spanish and European regulations in force regarding the protection of personal data on the internet. Specifically, it complies with the following:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
  • Spanish Organic Law 3/2018 of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPD-GDD).
  • Royal Decree 1720/2007 of 21 December, approving the Regulation implementing Organic Law 15/1999, on the Protection of Personal Data (RDLOPD).
  • Law 34/2002 of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the data controller

  • Controller: Lourdes Martín García
  • Tax ID (NIF): 53157813Y
  • Address: Calle Aloe Vera, 45, Málaga (Spain)
  • Contact telephone: 607803830
  • Contact email: Ragsweetkittencattery@hotmail.com
  • Website: ragdoll-ragsweet.com

Registration of personal data

In compliance with the GDPR and the LOPD-GDD, we inform you that the personal data collected through the forms on its pages — mainly the contact form — will be incorporated into and processed in our file in order to facilitate, expedite and fulfil the commitments established between the Website and the User, to maintain the relationship established in the forms the User completes, or to respond to a request or query.

Principles applicable to data processing

The processing of the User's personal data shall be subject to the principles set out in Article 5 of the GDPR:

  • Lawfulness, fairness and transparency: the User's consent will always be required after fully transparent information about the purposes for which the data are collected.
  • Purpose limitation: data will be collected for specified, explicit and legitimate purposes.
  • Data minimisation: only data strictly necessary for the purposes for which they are processed will be collected.
  • Accuracy: data must be accurate and always kept up to date.
  • Storage limitation: data will be kept only for the time necessary for the purposes of their processing.
  • Integrity and confidentiality: data will be processed in a way that guarantees their security and confidentiality.
  • Accountability: the Controller is responsible for ensuring that the above principles are met.

Categories and legal basis for processing

The categories of data processed are solely identifying data. Under no circumstances are special categories of personal data within the meaning of Article 9 of the GDPR processed.

The legal basis for processing is consent. The Controller undertakes to obtain the User's express and verifiable consent for the processing of their data for one or more specific purposes. The User shall have the right to withdraw consent at any time; it shall be as easy to withdraw it as to give it.

Purposes of processing

Personal data are collected and managed in order to facilitate, expedite and fulfil the commitments established between the Website and the User, to maintain the relationship established in the forms the User completes, or to respond to a request or query.

Retention periods

Personal data will only be retained for the minimum time necessary for the purposes of their processing and, in any case, until the User requests their deletion.

Recipients of the data

The User's personal data will not be transferred or sold to third parties, except for the data processors strictly necessary to operate the Website, which are described below.

Data processors

In order to provide its service, the Website relies on external providers that act as data processors under a contract that complies with Article 28 of the GDPR — specifically, a web hosting provider and an email provider used to manage and respond to the messages sent through the contact form. These providers process the data only on our instructions and do not use them for their own purposes.

Personal data of minors

In accordance with Article 8 of the GDPR and Article 7 of Organic Law 3/2018, only persons over 14 years of age may give their consent for the processing of their personal data. For minors under 14, the consent of parents or guardians is required.

Secrecy and security of the data

The Controller undertakes to adopt the technical and organisational measures necessary, in line with a level of security appropriate to the risk of the data collected, so as to guarantee their security and prevent their accidental or unlawful destruction, loss or alteration. The Website has an SSL (Secure Socket Layer) certificate which ensures that personal data are transmitted securely and confidentially.

Rights of the User

The User may exercise the following rights recognised in the GDPR and Organic Law 3/2018 against the Controller:

  • Right of access: to obtain confirmation of whether or not their personal data are being processed and, if so, to access them.
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten"): to obtain the deletion of data when they are no longer necessary for the purposes for which they were collected.
  • Right to restriction of processing: to restrict the processing of data in the cases provided for by law.
  • Right to data portability: to receive their data in a structured, commonly used and machine-readable format and to transmit them to another controller.
  • Right to object: to object to the processing of their personal data.
  • Right not to be subject to automated individual decisions, including profiling.

The User may exercise their rights by written communication addressed to the Controller with the reference "GDPR", to the postal address Calle Aloe Vera, 45, Málaga (Spain) or to the email address Ragsweetkittencattery@hotmail.com, stating their identifying details, the specific request and an address for notifications.

Links to third-party websites

The Website may include hyperlinks or links that allow access to third-party websites, which are not operated by the Controller. The owners of those websites have their own data protection policies and are themselves responsible for their own files and privacy practices.

Complaints to the supervisory authority

Should the User consider that there is a problem or infringement of the regulations in force in the way their data are being processed, they have the right to effective judicial protection and to lodge a complaint with a supervisory authority. In Spain, the supervisory authority is the Spanish Data Protection Agency (www.aepd.es).

Acceptance and changes to this Privacy Policy

Use of the Website implies acceptance of this Privacy Policy. The Controller reserves the right to modify it, at its own discretion or motivated by a legislative, jurisprudential or doctrinal change of the Spanish Data Protection Agency. Users are advised to consult this page periodically to keep up to date with the latest changes or updates.