Last updated: 23 July 2026
This Privacy Policy explains how personal data relating to users and Customers who visit or use rolling_papers are collected, used, retained and protected.
Depending on the circumstances, this notice applies to simple browsing of the Site, account registration, completion of forms, cart management, submission of an order, payment, shipping, support and other available services.
Kifisias 1–3, 115 23 Athens, Greece
Website: www.dpa.gr
Telephone: +30 210 6475600 The data subject may also contact the authority in the country of habitual residence, place of work or place of the alleged infringement in the cases provided by the GDPR.
1. Data controller
The controller of personal data is:- Business owner: Despoina Grigoriadou
- Trading name: rolling_papers
- Address: Karaoli Dimitriou 10, Nea Karvali, 64006, Greece
- Country of establishment: Greece
- VAT number: EL116306705
- Privacy email: shop@e-cartine.it
- Telephone: +30 695 900 6904
2. Applicable law
Personal data are processed in accordance with:- Regulation (EU) 2016/679, known as the GDPR;
- applicable Greek data-protection law;
- European legislation on privacy in electronic communications and cookies;
- other provisions applicable to the specific processing activity.
3. Processing principles
Personal data are processed according to the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy and updating; storage limitation; integrity and confidentiality; and accountability of the Controller.4. Categories of data collected
Depending on how the Site is used, the following categories of data may be processed:- first and last name;
- company or business name;
- VAT number and professional information;
- billing address;
- delivery address;
- email address;
- telephone number;
- username and account-related data;
- products purchased, quantities and order value;
- cart contents and products viewed;
- shipping, delivery and tracking information;
- payment method and status;
- transaction identifiers;
- communications, complaints and support requests;
- return, refund or warranty requests;
- reviews, wishlist and saved preferences;
- IP address and technical device data;
- browser, operating system and pages requested;
- date, time and technical records of operations;
- cookie and consent preferences;
- other data voluntarily provided by the data subject.
5. Sources of data
Data are collected mainly:- directly from the user or Customer;
- during browsing and use of the Site;
- during checkout and conclusion of an order;
- through contact forms and email communications;
- through carriers, banks and providers involved in performance of the contract;
- from public sources or professional registers where necessary to verify a B2B request;
- through technical systems used for security and fraud prevention.
6. Mandatory and optional data
Fields marked as mandatory are necessary to perform the requested function, for example to process an order, issue a fiscal document, deliver products, answer a request, manage a refund or verify a professional supply relationship. Failure to provide mandatory data may prevent provision of the service or completion of the order. Data not expressly marked as mandatory are provided voluntarily.7. Purposes and legal bases of processing
Performance of a contract and pre-contractual measures
Processing may be carried out for cart and checkout management, receipt and verification of orders, payment management, preparation, shipping and delivery, account management, support, returns, refunds and warranty, and responses to commercial requests and quotations.Compliance with legal obligations
Processing may be carried out for invoicing and accounting, tax obligations, retention of mandatory documentation, management of consumer rights, cooperation with competent authorities and product-safety obligations.Legitimate interests
Processing may be carried out to protect the Site and accounts, prevent and detect fraud or abuse, manage complaints and disputes, defend the Controller’s rights, maintain and technically improve the Site, conduct analyses strictly necessary for security and operation, and retain evidence relating to orders and communications.Consent
Consent may be used for activation of non-essential statistical or marketing cookies, loading of non-essential external content, promotional communications where consent is required and other activities for which specific consent is requested. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.8. Browsing and technical logs
During visits to the Site, technical data may be processed automatically, including IP address, date and time of request, requested page, browser and operating system, referring website or page, server response codes, technical and session identifiers and security-relevant events. This information is used to enable communication between the device and server, keep the Site operational, identify errors, prevent abusive access and protect systems.9. WooCommerce and order management
The Site uses WooCommerce to manage the catalogue, cart and orders. During the purchase procedure, the following may be processed: identification and contact details, billing and delivery addresses, products ordered, amounts, taxes and shipping charges, order status, payment method and status, notes entered by the Customer and information necessary for after-sales support. Where the relevant function is active, an order may also be placed as a guest. The Customer may also create an account during checkout if the option is offered.10. Customer account
Where an account is registered, the following may be retained: first and last name, email address, username, password protected through cryptographic hashing, saved addresses, order history, preferences and wishlist and other information entered in the profile. The Customer must protect account credentials and promptly inform the Controller of unauthorised access.11. Cart and recovery of incomplete carts
The Site uses technical functions to maintain cart contents during browsing. A function for recovery of incomplete carts may also be active, in which case the following may be processed temporarily: email address entered at checkout, cart contents, indicative order value, technical and session identifiers and date and status of the cart. Any recovery communications are sent only where there is a valid legal basis and in compliance with rules applicable to electronic communications. The Customer may object to non-essential communications by writing to shop@e-cartine.it.12. Wishlist and preferences
The Site may allow Customers to create and retain a wishlist. This function may use the Customer’s account, cookies or local identifiers, identifiers of selected products and the date on which the list was created or changed. A wishlist does not constitute an order or reservation of products.13. Payments
The payment method indicated as currently active is direct bank transfer. For management of a bank transfer, the following may be processed: payer name, amount, payment reference and order reference, date of transaction, IBAN or other information visible in the banking transaction and payment status. Data are communicated to the banking institutions involved according to their respective rules and legal obligations. The mere technical presence of a payment extension does not mean that the related payment method is active. Only methods actually displayed at checkout apply.14. Shipping and tracking
To prepare, dispatch and deliver orders, the necessary data may be communicated to selected carriers. Services indicated as used or available include FedEx Economy and DHL EXPRESS. The following may be transmitted: recipient’s first and last name, delivery address, telephone number, email address where necessary, order number or shipment reference, parcel weight and number of parcels and other information required for delivery. Carriers may act as independent controllers or processors depending on the service and applicable law.15. Fiscal documents, invoices and packing lists
Order data may be used to produce receipts, invoices, credit notes, transport documents, packing lists and administrative exports required to manage the business. Access to such documents is restricted to authorised persons and providers that need to process them for accounting, tax or contractual purposes.16. Contact form
The Site uses Contact Form 7 to allow requests to be submitted. When a form is completed, the following may be processed: name, email address, telephone number where requested, subject of the communication, message content, any attachments and technical data necessary for transmission and spam prevention. Messages are forwarded to email addresses configured for the Site. The form must not be used to transmit special categories of personal data, health data, identity documents or financial information that has not been requested.17. Email and support
Communications sent to shop@e-cartine.it may be used to answer requests, manage orders and shipping, handle returns, refunds and complaints, provide support, manage B2B requests and retain evidence of relevant communications. Messages may be processed by email providers and authorised support personnel.18. Reviews and user content
Where the Site allows reviews or other user content, the following may be processed: name or pseudonym, email address, review content, rating, reference to the product or order, IP address and anti-fraud technical data. Published reviews may be visible to other users. The email address is not displayed as part of the review.19. Cookies and similar technologies
The Site uses cookies and similar technologies to provide essential technical functions, maintain cart and session, manage login and accounts, protect the Site, store consent preferences and, where authorised, activate statistical functions or external content. Full information is available in the Cookie Policy.20. Complianz and consent management
The Site uses Complianz – GDPR/CCPA Cookie Consent to manage the cookie banner, consent categories, acceptance or refusal of unnecessary cookies, changes to preferences, prior blocking of certain content or scripts and, where configured, technical documentation of preferences. Strictly necessary cookies may be used without consent where indispensable to provide a requested service. Statistical, marketing or non-essential external-service cookies are activated only according to the user’s preferences and the applicable configuration. Preferences may be changed or withdrawn through the permanent consent-management control available on the Site.21. YouTube content
The Site may embed videos supplied by YouTube, a service belonging to the Google group. When a video or related scripts are loaded, YouTube or Google may receive IP address, browser and device data, the page visited, interactions with the video and cookies or identifiers according to the service’s and user’s settings. Where required by law, the content is blocked until consent is given through Complianz. The mere presence of a link to YouTube does not necessarily cause external content to load automatically.22. Statistics and non-essential tools
Statistical or measurement tools that are not strictly necessary are used only after they have actually been configured, correctly disclosed in the Cookie Policy, consent has been obtained where required and available protective measures have been applied. The presence of old technical settings or inactive plugins in the database does not by itself demonstrate use of an analytics service.23. Recipients of data
Data may be disclosed, within what is strictly necessary, to:- authorised staff and collaborators;
- hosting, server and infrastructure providers;
- IT maintenance and security providers;
- email providers;
- banks and payment institutions;
- carriers and logistics operators;
- software providers for orders, invoicing and tracking;
- accountants, advisers and professionals bound by confidentiality;
- tax, administrative, judicial or supervisory authorities;
- other parties where disclosure is necessary to perform the contract or comply with a legal obligation.
24. Processors and independent controllers
Some providers process data on behalf of the Controller as processors. Other parties, such as banks, carriers or authorities, may process data as independent controllers in accordance with their own legal obligations and purposes. The qualification depends on the service actually provided and the role actually performed.25. Transfers outside the European Economic Area
Some technical providers or external services may process data in countries outside the European Economic Area. Where an international transfer occurs, the Controller verifies, to the extent applicable, that an appropriate legal mechanism exists, for example:- a European Commission adequacy decision;
- standard contractual clauses;
- supplementary measures;
- a specific derogation provided by the GDPR;
- explicit consent where appropriate.
26. Retention periods
Data are retained for as long as necessary for the purposes for which they were collected. In particular:- orders, invoices and tax data: for the period required by applicable tax, accounting and commercial law;
- account data: until the account is deleted or for as long as necessary to provide the service, subject to legal obligations;
- incomplete carts: for a limited period determined by technical configuration and recovery or security needs;
- support requests: for the time necessary to respond and handle possible disputes;
- returns, refunds and warranties: for the period necessary to manage and defend the relevant rights;
- security logs: for a period proportionate to prevention and investigation of incidents;
- consent preferences: for the period necessary to respect and demonstrate the user’s choices;
- dispute documentation: until conclusion of the dispute and expiry of applicable limitation periods.
27. Data security
The Controller adopts technical and organisational measures proportionate to risk, including, where applicable, HTTPS/TLS connections, access control, limitation of privileges, protected passwords and credentials, software updates, backups, firewalls and security systems, log monitoring, anti-fraud measures and incident-management procedures. No information system can guarantee absolute security.28. Personal data breaches
Where a personal data breach occurs, the Controller assesses the nature of the incident, categories and volume of data involved, possible consequences for data subjects, corrective measures to be taken, whether notification to the competent authority is required and whether communication to data subjects is required. Notifications and communications are made where required and within the periods provided by applicable law.29. Rights of the data subject
Where the relevant conditions are met, the data subject may exercise the right to:- receive information about processing;
- access personal data;
- obtain rectification of inaccurate data;
- obtain completion of incomplete data;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive data in a structured, machine-readable format;
- transmit data to another controller where technically feasible;
- withdraw consent;
- not be subject to decisions based solely on automated processing in the cases provided by law;
- lodge a complaint with a supervisory authority;
- seek judicial remedies before competent courts.
30. How to exercise rights
Requests may be sent to shop@e-cartine.it. The request should state the requester’s name and contact details, the right to be exercised, the data or processing concerned, information useful to identify the account or order and any documentation necessary to verify identity. The Controller responds without undue delay and, as a rule, within one month of receipt. The period may be extended in the cases provided by the GDPR, taking account of the complexity and number of requests. Identity is verified only to the extent necessary to prevent unauthorised disclosure or erasure.31. Right to object
The data subject may object at any time, on grounds relating to the particular situation, to processing based on legitimate interests. In the case of direct marketing, the right to object may be exercised at any time and processing for that purpose is stopped.32. Withdrawal of consent
Where processing is based on consent, the data subject may withdraw it through the Complianz panel, through a link in communications where available, or by writing to shop@e-cartine.it. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.33. Complaint to a supervisory authority
The data subject may lodge a complaint with the competent supervisory authority. Because the Controller is established in Greece, complaints may be addressed to: Hellenic Data Protection AuthorityKifisias 1–3, 115 23 Athens, Greece
Website: www.dpa.gr
Telephone: +30 210 6475600 The data subject may also contact the authority in the country of habitual residence, place of work or place of the alleged infringement in the cases provided by the GDPR.
34. Minors
The Site and purchases are intended exclusively for adults. The Controller does not intend knowingly to collect personal data of minors for the conclusion of orders. Where unauthorised collection is identified, reasonable measures are taken to erase the data or restrict its processing.35. Automated decision-making and profiling
The Site may use automated checks to identify anomalies, protect checkout, prevent fraud, manage the cart and session and apply technical shipping or payment rules. As a rule, such checks do not produce decisions based solely on automated processing that have legal or similarly significant effects on the data subject. Where a significant decision requires review, the Customer may request human intervention and provide explanations.36. Links to external websites
The Site may contain links to websites of manufacturers, carriers, banks, social networks, video platforms or authorities. This Privacy Policy does not govern processing carried out independently by those websites. Users are invited to review the relevant privacy notices before providing personal data.37. Changes to this Privacy Policy
This Privacy Policy may be updated following changes to legislation, services and functions, plugins and providers, payment or shipping methods, purposes and methods of processing or the Controller’s contact details. The date of the latest update is shown at the beginning of the page. Where a change requires new consent, that consent is requested before the related processing is activated.38. Privacy contact details
For questions, requests or exercise of rights:- Email: shop@e-cartine.it
- Telephone: +30 695 900 6904
- Address: Karaoli Dimitriou 10, Nea Karvali, 64006, Greece
Main legal references
- Regulation (EU) 2016/679 – GDPR;
- Directive 2002/58/EC on privacy and electronic communications;
- applicable Greek personal-data-protection legislation;
- European and national law applicable to cookies and similar technologies;
- other provisions applicable to the specific processing activity.