Privacy & Cookies Policy

Last updated: 25 August 2026

This policy explains how personal data is handled when you visit or interact with cherryfic.eu, the official website of the CHERRYFIC promotional programme.

1. Data Controller

The controller responsible for personal data processed through cherryfic.eu is Agricultural Cooperative of Common Agricultural Exploitation “O Agios Loukas” of Rachi Pieria (Αγροτικός Συνεταιρισμός Κοινής Γεωργικής Εκμετάλλευσης Ράχης Πιερίας «Ο Άγιος Λουκάς»).

Address: Rachi Pieria, 60150, Greece
Email: info@kerasiarachis.gr
Telephone: +30 23510 98711
VAT number: EL 096088105

CHERRYFIC is an EU co-funded promotional programme (Project 101251107) coordinated by the above Cooperative.

2. What Personal Data We May Process

Depending on how you use the website, we may process information that you voluntarily provide when contacting us, such as your name, email address, telephone number, organisation and the content of your message.

We may also process limited technical information needed to operate and protect the website, including IP address, browser and device information, date and time of access, server/security logs and cookie-consent preferences. Where you consent to Google Analytics, analytics information may also be processed, including pseudonymous online identifiers, pages viewed, session and interaction data, referring source, browser/device information and approximate location information derived from technical data.

We do not intentionally request sensitive categories of personal data through this website. Please do not send sensitive information unless it is genuinely necessary.

3. Why We Process Personal Data and Legal Bases

Enquiries and communication: to respond to requests and communicate about the CHERRYFIC programme or related activities. The legal basis is taking steps at your request before entering into a contract where applicable, and/or our legitimate interest in responding to enquiries.

Website operation and security: to maintain the availability, integrity and security of the website, prevent abuse, diagnose technical issues and protect against malicious or automated traffic. The legal basis is our legitimate interest in operating a secure website.

Legal compliance: where processing is necessary to comply with an applicable legal obligation.

Google Analytics: with your consent, we use Google Analytics (GA4) to understand how visitors use the website, for example which pages are viewed and how visitors interact with the site. The legal basis is consent. Analytics storage must remain disabled until consent is granted, and consent may be withdrawn at any time through the website’s cookie settings.

4. Recipients and Service Providers

Personal data may be processed by trusted service providers that support the operation of the website, such as hosting, email, website maintenance, technical support and security providers. We also use Google Analytics, provided in the EEA by Google Ireland Limited, to process analytics information when you have consented to analytics cookies. Service providers receive only the information necessary for the relevant service and are required to protect personal data in accordance with applicable law and their contractual obligations.

Personal data may also be disclosed where required by law or to competent public authorities. We do not sell personal data.

5. International Transfers

Where a service provider processes personal data outside the European Economic Area, appropriate safeguards required by the GDPR are used where applicable, such as an adequacy decision or the European Commission’s Standard Contractual Clauses. Google Analytics may involve processing by Google group companies or subprocessors outside the EEA; applicable transfer safeguards are used in accordance with Google’s data-protection terms.

6. How Long We Keep Personal Data

Personal data is kept only for as long as necessary for the purpose for which it was collected. Enquiries are retained for the time reasonably required to answer and manage the relevant communication. If an enquiry leads to a contractual or commercial relationship, relevant records may be kept for the periods required by tax, accounting or other applicable law.

Technical and security logs are retained for a limited period appropriate to security, troubleshooting and abuse-prevention purposes.

7. Cookies and Similar Technologies

Cookies and similar technologies may be used to provide essential website functions, protect the website and remember privacy choices. Strictly necessary technologies do not require consent when they are required to provide a service requested by the visitor.

Google Analytics cookies are non-essential and are used only after the visitor has provided the required consent. Visitors can reject analytics cookies and can change or withdraw their choice at any time through the website’s cookie settings. Where consent is denied, analytics cookies should not be stored or read.

The services currently identified for ordinary website access are listed below. Google Analytics 4 uses the _ga cookie and a property-specific _ga_ cookie by default. Exact technical identifiers may vary if the Analytics property or the website configuration changes.

Cookie / ServiceProviderPurposeDurationCategory
Security verification / anti-bot protectionWebsite hosting / security infrastructureProtects the website against automated or malicious traffic and helps verify legitimate requests.Session / short-livedStrictly Necessary
_gaGoogle Analytics (Google Ireland Limited)Distinguishes visitors for website analytics and measurement.Up to 2 years (default)Analytics
_ga_<container-id>Google Analytics (Google Ireland Limited)Maintains session state for the Google Analytics 4 property.Up to 2 years (default)Analytics

8. Third-Party Links and Embedded Content

The website may contain links to third-party websites or social-media services. Those services are independent and process personal data according to their own privacy notices. Where embedded third-party content requires non-essential tracking technologies, it should be activated only after the required consent.

9. Your Data Protection Rights

Subject to the conditions of the GDPR, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, data portability and, where applicable, object to processing. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights, contact us at info@kerasiarachis.gr. We may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), www.dpa.gr.

10. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. No internet transmission or storage system can, however, be guaranteed to be completely secure.

11. Changes to This Policy

This Privacy & Cookies Policy may be updated when the website, the technologies used or applicable legal requirements change. The latest version will be published on cherryfic.eu. Last updated: 25 August 2026.

12. Contact

For privacy questions or requests, contact Agricultural Cooperative of Common Agricultural Exploitation “O Agios Loukas” of Rachi Pieria at info@kerasiarachis.gr or +30 23510 98711.