Data controller
The data controller is Aleksandra Bogocz, who runs the mrumi.com project. Contact: hello@mrumi.com.
Scope of processed data
The Controller processes account data (email address and hashed password), data provided by the User while using the Service, technical data (IP address, anonymous application error logs), and data about how the Service is used.
Purposes and legal bases
Data is processed to provide the Service (Art. 6(1)(b) GDPR), to ensure security and prevent abuse (Art. 6(1)(f) GDPR), to analyse how the Service is used and to improve it (Art. 6(1)(f) GDPR), and — solely if the User signs up — to deliver the newsletter (Art. 6(1)(a) GDPR, consent).
Recipients of data
Data may be entrusted to processors acting on the Controller's behalf to the extent necessary to provide the Service. Some processors may be located outside the European Economic Area; in such cases transfers rely on standard contractual clauses approved by the European Commission. The Controller does not sell data and does not share it for advertising purposes.
Retention period
Account data is retained until the User deletes the account; after deletion — for the period necessary to establish, exercise, or defend legal claims (Art. 118 et seq. of the Polish Civil Code). Newsletter subscriber data — until consent is withdrawn. Application error logs, technical data, and analytics data — for the period necessary to fulfil the purpose for which they were collected.
User rights
The User has the right of access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent. To exercise any right, contact hello@mrumi.com. The Controller responds within one month (GDPR Art. 12(3)).
Right to lodge a complaint
Every data subject has the right to lodge a complaint with the supervisory authority — the President of the Polish Personal Data Protection Office (uodo.gov.pl).
Cookies and analytics
The Service uses cookies and similar browser-storage technologies — both strictly necessary for its operation (authentication session, theme preference) and used to analyse how the Service is used and to improve it, including session monitoring. For this purpose the Controller uses third-party analytics tools whose providers process data within the European Union. Analytics data is not used for advertising and is not sold.
Security
Connections to the Service are encrypted (HTTPS). Passwords are stored in hashed form. Access to personal data is limited to authorized persons.
Changes to the policy
The Controller announces material changes to this policy with appropriate advance notice — by email (if the User has an account) or via an on-site notice.
Cattery directory
The Service maintains a public directory of cat catteries. That data does not come from the data subjects themselves but from publicly available cattery registers kept by feline organisations (including FPL, WCF, TICA) and from cattery websites (Art. 14 GDPR). The published fields are: cattery name together with its prefix, town and region, approximate location, breeds, website address, and club affiliation with a reference to the source. Email addresses and phone numbers obtained from public sources are not published.
The legal basis is the legitimate interest of the Controller in maintaining a directory of catteries operating under the supervision of feline organisations (Art. 6(1)(f) GDPR). The data is retained until an objection is raised or until the purpose for which it was collected ceases.
A person running a cattery has the right of access, rectification, erasure, and objection to the processing (Art. 21 GDPR). It is enough to state the cattery name and write to hello@mrumi.com or use the contact form — the entry then stops being published and the cattery name is added to an exclusion list that prevents it from being re-added at the next directory update. We respond within one month.