Privacy Policy
Last updated: 1 August 2026
Data controller:
Agriturismo Magna Grecia – Franca Magrini
Ancient Olympia, Elis 27065, Greece
Registration Number: 128289925000
VAT Number: 114385040
Email: info [at] magnagrecia [dot] gr — use our secure contact form
Telephone: +30 26240 22739
1. Scope of this Privacy Policy
This Privacy Policy explains how Magna Grecia collects, uses, stores, shares and protects personal information when users visit magnagrecia.gr, place an order, contact us, visit our physical premises, participate in an experience or submit a cancellation, return, refund or withdrawal request.
The rights described in this policy apply according to the data-protection law governing the relevant processing. Individuals in different countries may have additional mandatory rights. Nothing in this policy limits a non-waivable right provided by applicable law.
2. Information we may collect
Depending on how you interact with us, we may collect:
- identity and contact information, such as name, postal address, billing address, email address and telephone number;
- order and transaction information, including products or services purchased, quantities, prices, order number, delivery details, payment method, transaction references and refund status;
- information supplied for tours, tastings, workshops, bookings or other experiences;
- communications, enquiries, complaints, reviews and customer-service records;
- withdrawal, cancellation, return and refund information;
- technical information, such as IP address, browser type, device information, operating system, referring pages, security logs and cookie identifiers;
- marketing preferences and consent records, where applicable.
3. Payment information
Online card payments are processed by the relevant payment service provider. Magna Grecia does not receive or store the complete card number, PIN or card-verification code used for an online payment.
For card payments made at our physical premises, the POS provider and acquiring bank process the card transaction. Magna Grecia may retain the receipt, transaction reference, payment amount, card type and a masked or truncated card reference where required for accounting, reconciliation, fraud prevention or refunds.
Customers must not send complete payment-card numbers, PINs, card-verification codes or photographs of cards by email or through another unprotected communication channel.
4. How and why we use personal information
We may process personal information for the following purposes and legal bases:
- To process orders and provide products or services: to confirm orders, arrange payment, package and ship goods, provide tracking information, manage bookings and communicate about the contract. This processing is necessary for the performance of a contract or to take requested steps before entering into a contract.
- To manage payments and refunds: to reconcile payments, prevent duplicate or fraudulent refunds and return funds through the relevant payment provider. This is necessary for performance of the contract, compliance with legal obligations and our legitimate interests in secure financial administration.
- To comply with legal obligations: including tax, accounting, consumer-protection, customs, food-safety, fraud-prevention and regulatory obligations.
- To provide customer service: to answer enquiries, investigate delivery issues, manage complaints and protect or enforce legal rights. This may be necessary for the contract or based on our legitimate interests.
- To maintain and secure the Site: to prevent abuse, fraud, unauthorised access and technical failures and to maintain logs required for security and evidentiary purposes. This is based on our legitimate interests and, where applicable, legal obligations.
- To send marketing communications: only where we have the required consent or another lawful basis. Marketing consent may be withdrawn at any time.
- To improve our products, services and Site: using aggregated information, feedback or analytics where permitted by law.
5. Processing of electronic withdrawal requests
When a user submits an electronic withdrawal statement, we process the information necessary to identify and manage the request. This may include the name, order or contract number, billing and confirmation email addresses, selected goods or services and quantities, the content of the statement, the date and time of submission, request status, administrative notes and records of actions taken.
For security, fraud-prevention and evidentiary purposes, the withdrawal system may retain technical security records and an audit history. Where an IP-related identifier is retained by the withdrawal system, it is stored as an irreversible keyed hash rather than as the raw IP address.
This processing is necessary to comply with legal obligations, manage the contractual relationship, confirm receipt of the statement and establish, exercise or defend legal claims.
6. Cloudflare Turnstile and security verification
The electronic withdrawal form is protected by Cloudflare Turnstile. During verification, technical information such as the IP address, browser or device information and a security-verification token may be transmitted to Cloudflare for abuse and automated-traffic detection.
Cloudflare processes this information according to its applicable privacy information and contractual safeguards. The verification is used to protect the form and the Site from spam, fraud and automated abuse.
7. Cookies and similar technologies
The Site may use essential cookies required for security, shopping-cart operation, checkout, user sessions and other requested functionality. The Site may also use preference, analytics or marketing technologies where permitted by law.
Where consent is legally required for non-essential cookies, those cookies will not be activated until the user has made the relevant choice through the available consent mechanism. Users may also manage cookies through their browser settings, although disabling essential cookies may prevent parts of the Site from functioning correctly.
8. Who may receive personal information
We may disclose personal information only where necessary to:
- hosting, website-maintenance, security, email and technical service providers;
- payment service providers, acquiring banks and POS providers;
- postal operators, couriers, freight providers, customs brokers and customs authorities;
- accountants, legal advisers, insurers and professional consultants;
- public authorities, courts or regulators where disclosure is required by law or necessary to protect legal rights.
Service providers receive only the information reasonably necessary for their task and are required to process it under applicable data-protection and confidentiality obligations.
9. International transfers
Some service providers, payment networks, carriers or technology providers may process information outside Greece or outside the European Economic Area. Where data-protection law requires safeguards for such transfers, we use an available lawful transfer mechanism, such as an adequacy decision, approved contractual clauses or another permitted safeguard.
10. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to comply with tax, accounting, customs, consumer-protection, fraud-prevention and other legal obligations.
Order, invoice and payment records may be retained for the period required by applicable accounting and tax law. Withdrawal, return, refund, complaint and audit records may be retained for as long as necessary to comply with legal obligations, maintain evidence and establish, exercise or defend legal claims. After the applicable period, information is deleted or anonymised where reasonably possible.
11. Security
We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. Data transmitted between the Site and its users is protected through an SSL/TLS-secured connection.
No method of transmission or storage is completely risk-free. Users should protect their account credentials and should not send sensitive payment or identification information through unprotected channels.
12. Your data-protection rights
Depending on the law applicable to the processing, you may have the right to:
- request access to personal information held about you;
- request correction of inaccurate or incomplete information;
- request deletion where the legal conditions are met;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format;
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out lawfully;
- submit a complaint to the competent data-protection authority.
To exercise a right, contact us using the details below. We may request information necessary to verify identity and protect personal information from unauthorised disclosure. Some rights are subject to legal exceptions, including obligations to retain transaction or tax records.
Individuals in Greece or another European Economic Area country may also contact their competent supervisory authority. The Greek supervisory authority is the Hellenic Data Protection Authority.
13. Marketing communications
Where a user has subscribed to marketing communications, we may send information about products, services, events or company news. Every electronic marketing message will provide an unsubscribe method where required. Withdrawing from marketing does not stop essential messages about an order, booking, withdrawal request, refund or other active transaction.
14. Changes to this Privacy Policy
We may update this Privacy Policy when our practices, service providers or legal obligations change. The current version and its update date will be published on this page. Material changes will be communicated in an appropriate manner where required by law.
15. Contacting us
For questions about this Privacy Policy or the processing of personal information, contact:
Agriturismo Magna Grecia – Franca Magrini
Ancient Olympia, Elis 27065, Greece
Telephone: +30 26240 22739
Email: info [at] magnagrecia [dot] gr — use our secure contact form

