Privacy Policy
Last updated: 10 August 2026
This Privacy Policy governs the processing of the personal data of users and customers of the website www.twoblackcatsgames.com, in accordance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD, Spain's Data Protection and Digital Rights Act) and Law 34/2002 (LSSI-CE, Spain's Information Society Services and E-Commerce Act).
1. Data controller
| Controller | Ratalaika Games, S.L. — NIF (Spanish tax ID) B-24.650.483 |
|---|---|
| Trading name | Two Black Cats Games |
| Registered address | C/ Capellán, 53, Villarrodrigo de las Regueras, 24197 León (Spain) |
| Contact | For privacy matters, you may contact: support at twoblackcatsgames dot com — Tel. +34 621 277 391 |
For the purposes of Article 4(7) GDPR, Ratalaika Games, S.L. is the controller of the personal data collected through the website.
2. Categories of data we process
Depending on how the user interacts with the site, we may process the following categories of data:
- Identification and contact data: first name and surname, postal address, email address and, where necessary for delivery, order management or customer service, telephone number.
- Order and transaction data: products purchased, amount, shipping and billing addresses, and order history.
- Billing data: name or company name, tax domicile and NIF, VAT ID or other tax identifier where the customer requests a full invoice, acts as a business or professional, where necessary to comply with tax obligations, or where required for customs procedures.
- Licence, download and activation data: licence key, product purchased, number of activations available and used, a technical device identifier generated as a non-reversible fingerprint (hash) from the device's hardware identifiers, which does not by itself allow the machine to be identified, dates and times of activation, deactivation or reset, and any other technical records generated by the licensing system, strictly to the extent necessary to verify the licence, prevent abuse, detect unauthorised sharing, manage reactivations and provide support.
- Support, warranty and incident data: communications held with the user and, where applicable, photographs, videos, technical logs or evidence that the user provides to substantiate an incident, defect or lack of conformity.
- Payment data: managed directly by the payment providers; the controller does not store full card data.
- User account data: profile data, preferences and history linked to the customer account. Access credentials correspond to the Shopify "Shop" account and are managed by Shopify as an independent controller, in accordance with section 6.
- Communications: the data the user includes when contacting customer service.
- Browsing and device data: IP address, identifiers and data derived from cookies, in accordance with the Cookies Policy.
3. Source of the data
We process data obtained:
- (i) directly from the data subject, when they place an order, communicate with us or subscribe to the newsletter;
- (ii) automatically, through the site and cookies; and
- (iii) from our processors, who collect it on our behalf to provide the service.
4. Purposes, legal bases and retention periods
| Purpose | Legal basis | Retention |
|---|---|---|
| Management of the purchase, order and contractual relationship. | Performance of the contract (Art. 6(1)(b) GDPR). | For the duration of the contractual relationship and, thereafter, blocked during the limitation periods for legal, contractual, tax and consumer liabilities. |
| Management of software downloads, keys, licences, activations, deactivations and reactivations. | Performance of the contract (Art. 6(1)(b) GDPR). | For the duration of the licence and, thereafter, blocked during the applicable limitation periods. |
| Verification of the legitimate use of licences, and prevention of abuse, unauthorised sharing, fraud or manipulation of the activation system. | Legitimate interest of the controller (Art. 6(1)(f) GDPR) in protecting its software, licences, systems and intellectual property rights, without prejudice to performance of the contract where the processing is necessary to provide the licensed service. | For the duration of the licence and, thereafter, blocked during the periods necessary for the defence against claims or infringements. |
| Management of payments, transaction confirmation and prevention of payment fraud. | Performance of the contract (Art. 6(1)(b) GDPR) and legitimate interest in preventing fraud and ensuring the security of transactions (Art. 6(1)(f) GDPR). | For the duration of the management of the transaction and, thereafter, during the applicable legal or claim periods. The controller does not store full card data. |
| Invoicing and compliance with tax, accounting and commercial obligations. | Compliance with legal obligations (Art. 6(1)(c) GDPR). | During the legally required periods, including 6 years for commercial and accounting purposes, without prejudice to the applicable tax periods; thereafter, blocking and deletion where appropriate. |
| Management of shipments, deliveries, carriers, logistics incidents and, where applicable, customs procedures. | Performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations where applicable tax, customs or administrative obligations exist (Art. 6(1)(c) GDPR). | For the duration of the management of the order and, thereafter, blocked during the limitation periods for legal, contractual, tax and consumer liabilities. |
| Customer service, technical support, after-sales, management of warranties, lack of conformity, returns, withdrawals and incidents. | Performance of the contract (Art. 6(1)(b) GDPR), compliance with legal obligations regarding consumers and warranties (Art. 6(1)(c) GDPR) and legitimate interest in handling enquiries and defending against claims (Art. 6(1)(f) GDPR). | For the duration of the handling of the enquiry or incident and, thereafter, blocked during the applicable limitation periods. |
| Management of orders, licences, activations and functionalities linked to the customer account. The credentials and login of the "Shop" account are managed by Shopify as an independent controller (section 6). | Performance of the contract or application of pre-contractual measures (Art. 6(1)(b) GDPR), where the account is necessary to manage purchases, licences or activations. Ancillary account functionalities are based on the user's consent (Art. 6(1)(a) GDPR). | While the account remains active and, thereafter, blocked during the applicable limitation periods, unless earlier deletion is appropriate. |
| Evidencing of contractual acceptances, consent to the immediate commencement of the supply of digital content, acknowledgement of the loss of the right of withdrawal, acceptance of the EULA and retention of proof of such acceptances. | Performance of the contract (Art. 6(1)(b) GDPR), compliance with legal information and consumer-contracting obligations (Art. 6(1)(c) GDPR) and legitimate interest in evidencing the contractual relationship and defending against claims (Art. 6(1)(f) GDPR). | For the duration of the contractual relationship and, thereafter, blocked during the applicable limitation periods. |
| Newsletter and commercial communications. | Consent of the data subject (Art. 6(1)(a) GDPR and Art. 21(1) LSSI-CE), given through voluntary subscription to the newsletter. Each communication includes a simple, free-of-charge opt-out mechanism. | Until consent is withdrawn or an objection is made. Minimal information may be retained to evidence the consent given and to maintain suppression lists that prevent further mailings. |
| Analytics and advertising cookies. | Consent of the user (Art. 6(1)(a) GDPR). | In accordance with the Cookies Policy. |
| Security of the Website, technical maintenance, detection of malicious activity, prevention of unauthorised access and protection of systems. | Legitimate interest of the controller in ensuring the security of the website, services, users and systems (Art. 6(1)(f) GDPR). | For the time necessary to analyse and resolve the incident and, thereafter, during the applicable liability periods. |
| Management of claims, and the exercise of or defence against legal, administrative or contractual actions. | Legitimate interest in defending the rights and interests of the controller (Art. 6(1)(f) GDPR) and compliance with legal obligations where applicable (Art. 6(1)(c) GDPR). | During the limitation periods of the applicable actions or liabilities. |
The processing activities based on legitimate interest have been weighed against the rights and freedoms of the data subjects, with that interest prevailing.
5. Recipients and processors
To provide the service we rely on the following providers, with whom we maintain the contracts required by Art. 28 GDPR.
| Provider | Function | Location |
|---|---|---|
| Shopify | Hosting and eCommerce platform | Ireland/EEA |
| Shopify Payments | Payment processing | EU; group outside the EEA |
| MailerLite | Newsletter and email marketing | Lithuania (EU) |
| Quaderno | Invoicing and taxes | Ireland (EU) |
| Web analytics (Analytics) | USA | |
| Measurement and advertising | USA | |
| Meta / Facebook | Measurement and advertising | USA / Ireland |
Likewise, to the extent necessary to provide the service, data may be accessed by the carriers and logistics operators responsible for delivering physical products, postal operators, payment entities, technology providers, invoicing and tax providers, email marketing tools, analytics and advertising providers where the user has consented to the corresponding cookies, professional advisers and, where applicable, public authorities, tax authorities, customs authorities, and competent administrative or judicial bodies.
6. Relationship with Shopify
The site is hosted on Shopify, which processes data relating to access to and use of the service in order to provide and improve it. For certain advanced functions, Shopify may act as an independent controller, being responsible for handling users' rights in respect of those uses, in accordance with its own privacy policy. In particular, customer accounts ("Shop") are a service provided by Shopify across the stores that operate on its platform: Shopify manages the credentials and login as an independent controller, and the controller processes only the order, licence and activation data linked to that account.
7. International transfers
Some providers may process personal data outside the European Economic Area. In such cases, international transfers will be carried out in accordance with the safeguards provided for in Chapter V of the GDPR, including, where applicable, adequacy decisions, the provider's adherence to the EU-U.S. Data Privacy Framework, or the execution of Standard Contractual Clauses approved by the European Commission, together with any supplementary measures that may be necessary.
8. Retention and blocking
We retain the data for as long as necessary to fulfil the stated purposes and, thereafter, duly blocked during the limitation periods of any potential liabilities, in accordance with the LOPDGDD, after which it is deleted.
9. Rights of data subjects
The user may exercise the rights of access, rectification, erasure, objection, restriction of processing and portability (Arts. 15 to 22 GDPR), as well as withdraw the consent given, by contacting support at twoblackcatsgames dot com and identifying themselves appropriately. The controller will address the request within one month (Art. 12 GDPR), which may be extended in accordance with the regulations. The exercise of these rights is free of charge.
The user has the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, C/ Jorge Juan, 6, 28001 Madrid; www.aepd.es) if they consider that the processing does not comply with the regulations (Art. 77 GDPR).
10. Security
The controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR).
11. Minors
The Website is not directed at minors. Educational licences are contracted by teachers, educational institutions or other responsible adults. The Owner does not request or process personal data of minor students in the contracting process, unless expressly informed otherwise and the corresponding legal safeguards are put in place.
12. Automated decisions and personalised advertising
Advertising or measurement profiles may be created through cookies or similar technologies, only where the user has given their consent and in accordance with the Cookies Policy. No decisions are taken based solely on automated processing that produce legal effects on the user or similarly significantly affect them.
13. Changes to the policy
The controller may amend this Privacy Policy to adapt it to legislative developments or changes in processing activities, providing notice through the website and updating the revision date.
お客様のデータに関する権利
GDPR および同等の法令に基づき、お使いのブラウザに紐づくサーバー上の記録をいつでも確認・削除いただけます。これらの操作は Cookie バナーからも利用できます。
- アクセス権 (GDPR 第15条) — ブラウザの匿名識別子に紐づくすべてのデータを JSON ファイルでダウンロード。
- 削除権 (GDPR 第17条) — サーバー上のすべての記録を削除し、Cookie をリセット。

