Last updated: July 12, 2026

This Privacy Policy describes how the personal data of users and Customers who visit or use www.ecartine.it.
This notice applies, as appropriate, to use of the Site, creation of an account, completion of forms, management of the cart, placement of an order, payment, shipping, assistance and the other available services.
1. Data Controller
The controller of personal data is:
- Business owner: Ioannis Demertzis
- Trading name: Smoking Rolling Paper / Cartine per Rollare
- Address: Karaoli Dimitriou 10, Nea Karvali, 64006, Greece
- Country of establishment: Greece
- VAT number: EL116306705
- Privacy: shop@ecartine.it
- Telephone: +30 6959 006 904
The Controller determines the purposes and principal means of processing carried out through the Website.
2. Applicable Law
Processing is carried out in accordance with:
- Regulation (EU) 2016/679, known as the GDPR;
- Greek law applicable to the protection of personal data;
- European rules on the confidentiality of electronic communications and cookies;
- other provisions applicable to the specific operation.
3. Processing Principles
Personal data is processed in accordance with the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimization;
- accuracy and updating;
- storage limitation;
- integrity and confidentiality;
- accountability of the Controller.
4. Categories of Data Collected
Depending on how the Website is used, the following categories of data may be collected:
- first and last name;
- business or company name;
- VAT number and professional details;
- billing address;
- shipping address;
- email address;
- telephone number;
- username and account data;
- products purchased, quantities and order value;
- cart contents and products viewed;
- shipping, delivery and tracking data;
- payment method and status;
- transaction identifiers;
- communications, complaints and support requests;
- return, refund or warranty requests;
- reviews, wishlists and saved preferences;
- IP address and technical device data;
- browser type, operating system and requested pages;
- date, time and technical logs of operations;
- cookie and consent preferences;
- other data voluntarily provided by the data subject.
5. Sources of Data
Data is collected mainly:
- directly from the user or Customer;
- while browsing and using the Website;
- during checkout and conclusion of the order;
- through contact forms and email communications;
- through carriers, banks and providers used to perform the contract;
- from public sources or professional registers where necessary to verify a B2B request;
- from technical security and fraud-prevention systems.
6. Required and Optional Data
Fields marked as required are necessary to perform the requested function, for example to:
- process an order;
- issue a tax document;
- deliver goods;
- respond to a request;
- manage a refund;
- verify a business supply.
Failure to provide mandatory data may make it impossible to provide the service or complete the order.
I dati non contrassegnati come obbligatori vengono forniti volontariamente.
7. Purposes and Legal Bases
Data may be processed for the following purposes and legal bases:
Performance of a contract and pre-contractual measures
- management of the cart and checkout;
- receipt and verification of orders;
- management of payments;
- preparation, shipping and delivery;
- account management;
- support, returns, refunds and warranties;
- responses to commercial enquiries and quotation requests.
Compliance with legal obligations
- invoicing and accounting;
- tax compliance;
- retention of mandatory documents;
- management of consumer rights;
- cooperation with competent authorities;
- product-safety compliance.
Legitimate interests
- protection of the Website and accounts;
- prevention and detection of fraud or abuse;
- management of complaints and disputes;
- defence of the Controller's rights;
- technical maintenance and improvement of the Website;
- analysis strictly necessary for security and operation;
- preservation of evidence relating to orders and communications.
Consent
- activation of non-essential statistics or marketing cookies;
- loading of external content that is not strictly necessary;
- promotional communications where required by law;
- other activities for which specific consent is requested.
Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
8. Browsing and Technical Logs
During a visit, technical data may be processed automatically, including:
- the IP address;
- date and time of the request;
- page requested;
- browser and operating system;
- referrer;
- server response codes;
- technical and session identifiers;
- security-relevant events.
This data is used to enable communication between the device and server, keep the Website operational, identify errors, prevent unauthorized access and protect the systems.
9. WooCommerce and Order Management
The Site uses WooCommerce to manage the catalogue and orders.
Durante la procedura di acquisto vengono trattati, secondo il caso:
- identification and contact details;
- billing and delivery addresses;
- products ordered;
- amounts, taxes and shipping costs;
- order status;
- payment method and status;
- notes entered by the Customer;
- data required for after-sales support.
È possibile effettuare un ordine come ospite quando tale funzione è disponibile.
The Customer may also create an account during checkout when the option is displayed.
10. Customer Account
When an account is created, the following may be stored:
- first and last name;
- email address;
- username;
- password in a protected form using cryptographic hashing systems;
- saved addresses;
- order history;
- preferences and wishlists;
- other information provided in the profile.
The Customer must keep their credentials confidential and promptly inform the Controller of any unauthorized access.
11. Cart and Recovery of Incomplete Carts
The Site uses technical features to retain the contents of the cart while the user browses.
It may also use an incomplete-cart recovery feature, through which the following may be processed temporarily:
- the email address entered at checkout;
- cart contents;
- the approximate order value;
- technical and session identifiers;
- the date and status of the cart.
Eventuali comunicazioni di recupero vengono inviate soltanto quando esiste una valida base giuridica e nel rispetto delle regole applicabili alle comunicazioni elettroniche.
The Customer may object to non-essential communications by writing to shop@ecartine.it.
12. Wishlist and Preferences
The Site may allow the Customer to create and save a wishlist.
La funzione può utilizzare:
- the Customer's account;
- cookies or local identifiers;
- identifiers of selected products;
- the date the list was created or changed.
Wishlists do not constitute an order or reservation of products.
13. Payments
Il metodo di pagamento attualmente attivo è il bonifico bancario diretto.
Per la gestione del bonifico possono essere trattati:
- the payer's name;
- the amount;
- the payment description and order reference;
- the date of the transaction;
- the IBAN or other data visible in the banking transaction;
- the payment status.
I dati vengono comunicati agli istituti bancari coinvolti nella transazione secondo le rispettive regole e obblighi legali.
The technical presence of a payment extension does not mean that the corresponding method is active. The available methods are those actually shown at checkout.
14. Shipping and Tracking
To prepare, ship and deliver orders, the necessary data may be disclosed to the selected couriers.
I servizi attualmente utilizzati o disponibili comprendono:
- FedEx Economy;
- DHL EXPRESS.
The following may be communicated:
- the recipient's first and last name;
- delivery address;
- telephone number;
- email address, where necessary;
- order number or shipment reference;
- weight, number of parcels and information required for delivery.
Carriers may process this data as independent controllers or processors, depending on the service and applicable law.
15. Tax Documents, Invoices and Packing Lists
Order data may be used to generate:
- receipts;
- invoices;
- credit notes;
- transport documents;
- packing lists;
- administrative exports necessary to manage the business.
Access to these documents is limited to authorized persons and providers who must process them for accounting, tax or contractual obligations.
16. Contact Form
Il Sito utilizza Contact Form 7 per consentire l’invio di richieste.
Quando viene utilizzato un modulo possono essere trattati:
- the Customer's name;
- email address;
- telephone number, where requested;
- subject;
- message content;
- any attachments;
- technical data required for transmission and spam prevention.
I messaggi vengono trasmessi agli indirizzi e-mail configurati per il Sito.
The form must not be used to submit special categories of personal data, health data, identity documents or unsolicited financial information.
17. Email and Support
Communications sent to shop@ecartine.it are used to:
- respond to requests;
- manage orders and shipping;
- manage returns, refunds and complaints;
- provide support;
- manage B2B enquiries;
- retain evidence of relevant communications.
Messages may be processed by email providers and operators authorized to manage support.
18. Reviews and User Content
Where the Website permits reviews or user content, the following may be processed:
- name or pseudonym;
- email address;
- review content;
- the rating given;
- reference to the product or order;
- IP address and anti-fraud technical data.
Le recensioni pubblicate possono essere visibili agli altri utenti.
The email address is not published as part of the review.
19. Cookies and Similar Technologies
The Website uses cookies and similar technologies to:
- provide essential technical functions;
- maintain the cart and session;
- manage login and accounts;
- protect the Website;
- store consent preferences;
- activate, with prior authorization where necessary, statistical functions or external content.
Full information is available in the Cookie Policy.
20. Complianz and Consent Management
The Website uses the Complianz – GDPR/CCPA Cookie Consent plugin to manage:
- the cookie banner;
- consent categories;
- acceptance or refusal of non-essential cookies;
- changes to preferences;
- prior blocking of certain content or scripts;
- technical documentation of preferences, where configured.
I cookie strettamente necessari possono essere utilizzati senza consenso quando indispensabili per fornire il servizio richiesto.
I cookie statistici, di marketing o relativi a servizi esterni non essenziali vengono attivati soltanto secondo le preferenze espresse e la configurazione applicabile.
The user may change or withdraw their preferences through the permanent consent-management control available on the Site.
21. YouTube Content
Il Sito può incorporare video forniti da YouTube, servizio appartenente al gruppo Google.
Quando il video o i relativi script vengono caricati, YouTube o Google possono ricevere:
- the IP address;
- browser and device data;
- the page visited;
- interactions with the video;
- cookies or identifiers, depending on the service and user settings.
Quando richiesto dalla normativa, il contenuto viene bloccato fino alla prestazione del consenso mediante Complianz.
The mere presence of a link to YouTube does not necessarily result in the automatic loading of external content.
22. Statistics and Non-essential Tools
Any statistics or measurement tools that are not strictly necessary are used only after:
- they have actually been configured;
- they have been correctly identified in the Cookie Policy;
- consent has been collected where required;
- available protective measures have been applied.
The presence of old technical options or inactive plugins in the database does not automatically mean that an analytics service is being used.
23. Recipients of Data
Within the limits of what is necessary, data may be communicated to:
- authorized personnel and collaborators;
- hosting, server and infrastructure providers;
- IT maintenance and security providers;
- email providers;
- banks and payment institutions;
- carriers and logistics operators;
- software providers for orders, invoices and tracking;
- accountants, advisers and other professionals bound by confidentiality;
- tax, administrative, judicial or supervisory authorities;
- other persons where communication is necessary to perform the contract or comply with a legal obligation.
Recipients receive only the data necessary for their respective function.
24. Processors and Independent Controllers
Alcuni fornitori trattano i dati per conto del Titolare in qualità di responsabili del trattamento.
Other parties, such as banks, couriers or authorities, may process data as independent controllers on the basis of their own legal obligations and purposes.
La qualificazione dipende dal servizio concretamente fornito e dal ruolo effettivamente svolto.
25. Transfers Outside the European Economic Area
Alcuni fornitori tecnici o servizi esterni possono trattare dati in Paesi esterni allo Spazio Economico Europeo.
Quando avviene un trasferimento internazionale, il Titolare verifica, nei limiti applicabili, l’esistenza di una base legale adeguata, ad esempio:
- an adequacy decision of the European Commission;
- standard contractual clauses;
- supplementary measures;
- a specific derogation provided by the GDPR;
- explicit consent, where appropriate.
Non-essential external content is, where necessary, made subject to the user's choice.
26. Retention Periods
I dati vengono conservati per il tempo necessario alle finalità per cui sono stati raccolti.
In particolare:
- orders, invoices and tax data: for the period required by applicable tax, accounting and commercial law;
- account data: until the account is deleted or for as long as necessary to provide the service, without prejudice to legal obligations;
- incomplete carts: for a limited period determined by technical configuration and recovery or security needs;
- support requests: for the time necessary to respond and manage any disputes;
- returns, refunds and warranties: for the time necessary to manage and defend the relevant rights;
- security logs: for a period proportionate to incident prevention and analysis;
- consent preferences: for the time necessary to respect and demonstrate the user's choices;
- dispute documentation: until the dispute is concluded and the relevant limitation periods have expired.
When data is no longer necessary, it is deleted, anonymized or made no longer directly identifiable, unless retention obligations apply.
27. Data Security
The Controller adopts technical and organizational measures proportionate to the risks, including, where applicable:
- HTTPS/TLS connections;
- access controls;
- restriction of privileges;
- protected passwords and credentials;
- software updates;
- backups;
- firewalls and security systems;
- log monitoring;
- anti-fraud measures;
- incident-management procedures.
No information system can guarantee absolute security.
28. Personal Data Breaches
In the event of a personal data breach, the Controller assesses:
- the nature of the incident;
- the categories and volume of data involved;
- the possible consequences for data subjects;
- the corrective measures required;
- whether the competent authority must be notified;
- whether data subjects must be informed.
Notifications are made where and within the periods required by applicable law.
29. Rights of the Data Subject
Where the relevant conditions are met, the data subject may exercise the following rights:
- receive information about processing;
- access their personal data;
- obtain rectification of inaccurate data;
- obtain completion of incomplete data;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive data in a structured, machine-readable format;
- transmit data to another controller where technically feasible;
- withdraw consent;
- not be subject to decisions based solely on automated processing in the cases provided by law;
- lodge a complaint with a supervisory authority;
- bring proceedings before the competent courts.
30. How to Exercise Your Rights
Requests may be sent to:
The request should state:
- the requester's name and contact details;
- the right to be exercised;
- the data or processing concerned;
- information useful for identifying the account or order;
- any documentation needed to verify identity.
Il Titolare risponde senza ingiustificato ritardo e, di norma, entro un mese dalla ricezione.
The period may be extended in the cases provided by the GDPR, taking account of the complexity and number of requests.
Identity verification is carried out only to the extent necessary to prevent unauthorized disclosure or deletion.
31. Right to Object
L’interessato può opporsi in qualsiasi momento, per motivi connessi alla propria situazione particolare, al trattamento basato sul legittimo interesse.
In the case of direct marketing, the right to object may be exercised at any time and processing for that purpose will be stopped.
32. Withdrawal of Consent
Where processing is based on consent, the data subject may withdraw it:
- through the Complianz panel;
- through the link included in communications, where available;
- by writing to shop@ecartine.it.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
33. Complaint to a Supervisory Authority
L’interessato ha diritto di presentare reclamo all’autorità di controllo competente.
Poiché il Titolare è stabilito in Grecia, è possibile rivolgersi alla:
Hellenic Data Protection Authority
Autorità Ellenica per la Protezione dei Dati Personali
- Website: www.dpa.gr
- Address: Kifisias 1–3, 115 23 Athens, Greece
- Telephone: +30 210 6475600
The data subject may also contact the authority of their habitual residence, place of work or place of the alleged infringement in the cases provided by the GDPR.
34. Minors
Il Sito e gli acquisti sono destinati a persone maggiorenni.
The Controller does not intend knowingly to collect personal data from minors for the purpose of concluding orders.
When unauthorized collection of a minor’s data is identified, reasonable measures are taken to erase the data or restrict its processing.
35. Automated Decision-making and Profiling
The Website may use automated checks to:
- identify anomalies;
- secure checkout;
- prevent fraud;
- manage the cart and session;
- apply technical shipping or payment rules.
Such checks do not normally involve decisions based solely on automated processing that produce legal or similarly significant effects for the data subject.
When a relevant decision requires review, the Customer may request human intervention and provide clarification.
36. Links and External Websites
Il Sito può contenere collegamenti verso siti appartenenti a produttori, corrieri, banche, social network, piattaforme video o autorità.
La presente Privacy Policy non disciplina i trattamenti effettuati autonomamente dai siti esterni.
L’utente è invitato a consultare le relative informative prima di fornire dati personali.
37. Changes to the Privacy Policy
This Privacy Policy may be updated following changes to:
- applicable law;
- services and functions;
- plugins and providers;
- payment or shipping methods;
- the purposes and methods of processing;
- the Controller's contact details.
The date of the latest update is indicated at the beginning of the page.
When a change requires new consent, that consent is requested before the relevant processing is activated.
38. Privacy Contact Details
For questions, requests or the exercise of rights:
- Email: shop@ecartine.it
- Telephone: +30 6959 006 904
- Address: Karaoli Dimitriou 10, Nea Karvali, 64006, Greece
Main legal references
- Regulation (EU) 2016/679 – GDPR;
- Directive 2002/58/EC on privacy and electronic communications;
- Greek law applicable to the protection of personal data;
- European and national rules applicable to cookies and similar technologies;
- other provisions applicable to the specific processing activity.
