Skip to content

Legal

Privacy

Last updated 21 September 2026 · English is the governing language of this document.

The short version

We are a two-person olive grove, not a data business. We collect what is needed to send you olive oil and to satisfy tax law. We do not sell or share your data for advertising. We run no third-party trackers, and our analytics cannot identify you.

The long version follows, because you are entitled to it.

Who is responsible

The controller of your personal data is registered company name (legal form, e.g. sole trader / IKE / OE), registered address, registered under GEMI / company registration number.

For anything about your data, write to our contact form. We are below the size that requires a data protection officer and have not appointed one. The people who read that address are the people who run the business.

What we collect, and why

WhatWhyLegal basis
Name, delivery address, email, phone To take the order, ship it and tell you where it is Performance of a contract, Art. 6(1)(b)
Order contents, totals, VAT, invoice To sell it to you, and because tax law requires us to keep records Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
Payment reference and status To know the order is paid. We never receive your card number Contract, Art. 6(1)(b)
VAT number, if you give one To apply the reverse charge on business orders Legal obligation, Art. 6(1)(c)
Messages you send us To answer you Legitimate interests, Art. 6(1)(f) — replying to people who write to us
Newsletter address, plus a hashed record of your consent To send the harvest note, and to prove you asked for it Consent, Art. 6(1)(a)
Hashed IP for spam and abuse checks To stop bots flooding the contact form and checkout Legitimate interests, Art. 6(1)(f) — keeping the shop working

We do not collect special category data, we do not profile you, and no decision affecting you is made automatically.

Website analytics

We count how many people visit, which products they look at, roughly which country they are in and where they arrived from. We do this ourselves, on our own infrastructure, and it is built so that it cannot identify you:

  • No cookie is set for analytics, and no identifier is stored in your browser.
  • Events are aggregated into daily counters. After that there is no row that describes a single visit.
  • Where a visit does need stitching together for an order, the key is a one-way hash of your IP address and browser string combined with a secret that changes every day. It cannot be reversed to your IP and cannot be joined across days.
  • Nothing is shared with an advertising network, because we do not use one.

That is why this site has no cookie banner. See the cookie policy for the full reasoning.

How long we keep it

WhatHow longWhy that long
Orders and invoices10 yearsTax and accounting retention rules in Greece and Germany. We cannot delete these on request.
Baskets you never checked out30 daysSo you can come back and finish.
Contact messages2 yearsSo we can look back at an earlier conversation.
Newsletter subscriptionUntil you unsubscribeThen we keep only the fact you unsubscribed, so we do not mail you again.
Raw analytics events90 daysDeleted automatically by a nightly job, not by good intentions.
Daily analytics countersIndefinitelyThey contain no personal data at all.

Who else touches it

Only the companies that actually run parts of the shop — hosting, the database, email delivery, payments and the courier. Each is listed, with what they see and where they are, on the sub-processors page.

We do not sell your data, we do not rent it, and we do not share it for advertising. If we are ever legally compelled to disclose something, we will tell you unless we are prohibited from doing so.

Where it is stored

Your order data lives in a database hosted in Frankfurt, Germany, inside the EU. Email is sent by a French provider. Payments are handled by providers in Greece and the Netherlands.

Our website is served by Cloudflare, which operates globally and has a United States parent company. Where that involves a transfer outside the EEA it is covered by the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

Your rights

You can ask us to:

  • Show you what we hold about you.
  • Correct anything wrong.
  • Delete it — except records we are legally required to keep, such as invoices.
  • Restrict or object to how we use it.
  • Send it to you, or to someone else, in a portable format.
  • Withdraw consent for the newsletter, at any time, which does not affect anything sent before.

Email our contact form. We answer within one month. There is no charge, and we will not make you justify the request.

If you are not satisfied, you can complain to a supervisory authority — in Greece the Hellenic Data Protection Authority, or the authority in the country where you live or work.

Security

The website and shop hold no database credentials at all: every request goes through our own servers, and the database itself denies access by default to everything except those servers. Payment card details never reach us. Admin access requires two factors and sits behind a separate access gate, and every change to an order or a product is recorded with who made it.

If you find a security problem, please tell us — see reporting a vulnerability.

Changes

If we change how we use your data in a way that matters, we will update this page and change the date at the top. If the change requires your consent, we will ask for it rather than assume it.