Privacy

Privacy Policy

We take the protection of your personal data seriously and process your data confidentially and in accordance with applicable data protection law (GDPR, German Federal Data Protection Act, German Telecommunications-Telemedia Data Protection Act) and this privacy policy. This policy informs you about the nature, scope, and purpose of the processing of personal data on our website and in connection with our online orders.

Last updated: July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the EU Member States as well as other data protection provisions is:

Gebrüder Grüske GmbH, Im Stöckig 121, 90765 Fürth, Germany

Represented by: Werner Grüske

Email: [email protected]

2. Data Protection Officer

We have not appointed a Data Protection Officer, as the requirements of Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) do not apply. For any data protection questions, please contact the controller listed above.

3. Your rights as a data subject

You have the following rights at any time with respect to your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

To exercise your rights, an informal email to [email protected] is sufficient.

4. Right to object (Art. 21 GDPR)

Where personal data are processed on the basis of Art. 6 (1) (f) GDPR (legitimate interests), you have the right to object at any time, on grounds relating to your particular situation, to the processing. If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms.

Where personal data are processed for the purpose of direct marketing, you have the right to object at any time; this also applies to profiling insofar as it is related to such direct marketing.

5. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent supervisory authority for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland (https://www.lda.bayern.de).

6. Hosting & website provision

We host our website with Hetzner Online GmbH (address: Industriestr. 25, 91710 Gunzenhausen, Deutschland). Servers are located in Nürnberg, Deutschland. When you visit our website, the server automatically processes the following information in so-called server log files:

  • IP address of the requesting device (shortened where technically possible)
  • Date and time of the request
  • Requested URL and HTTP status code
  • Amount of data transferred
  • Referrer URL (previously visited page)
  • Browser type, browser version, and operating system

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure, stable, and functional operation of our website and the defense against attacks. Log files are usually deleted automatically after 7 days, unless required for the investigation of a security incident.

A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner Online GmbH. For more information, see https://www.hetzner.com/de/rechtliches/datenschutz.

7. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the address bar in your browser switches from "http://" to "https://" and by the lock icon in the browser bar.

8. Cookies & similar technologies

Our website uses strictly necessary cookies required to operate the site (for example, language preference, session security, storage of your privacy choice and a pseudonymous consent identifier used to apply a withdrawal). These cookies are set on the basis of § 25 (2) no. 2 TDDDG and do not require consent. The legal basis for the subsequent processing is Art. 6 (1) (f) GDPR (legitimate interest in proper operation and demonstrably applying your choice).

Optional analytics and marketing technologies are loaded, and server-side marketing events are sent, only after you consent to the respective purpose through our banner. Analytics and Meta advertising can be selected separately. The legal bases are § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. You can change your choice at any time through “Privacy choices” at the bottom of the page; the change applies going forward and stops pending Meta transmissions where they can be linked to your browser.

Meta Pixel and Meta Conversions API

With your separate consent for Meta advertising, we use Meta Pixel and Meta Conversions API provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Browser and server events may include viewed products, cart, checkout, contact and purchase actions, time, page path, product identifiers, order value and currency. For matching, the IP address and browser user agent may be sent unhashed, while email address, name, phone number, city, postal code, country and pseudonymous internal event or order identifiers are sent only as SHA-256 hashes. Meta identifiers such as _fbp and _fbc are forwarded unchanged when available. Shared event IDs deduplicate matching browser and server events.

Processing is used to measure, attribute and optimise our advertising and to create audiences on Meta. Optional Meta cookies _fbp and _fbc may typically be retained in the browser for up to 90 days. Where these identifiers are briefly recorded with an open order for delayed purchase confirmation, we delete them after successful transmission, after withdrawal, or after no more than seven days. Meta may also process data in the United States, in particular under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses. More information: https://www.facebook.com/privacy/policy/ and https://www.facebook.com/legal/technology_terms/.

OpenPanel

With your separate consent for usage analytics, we use OpenPanel to analyse reach and use of our public website. This may include pages viewed, referrer, technical browser information and interactions. This choice is independent of Meta advertising; analytics remains disabled without consent and is used only to improve our offering.

You can configure your browser to inform you when cookies are set, to allow cookies on a case-by-case basis, to refuse the acceptance of cookies for specific cases or generally, and to activate the automatic deletion of cookies when the browser is closed. Disabling cookies may limit the functionality of this website.

9. Contract performance & orders

To process your order, we collect and process the data you provide during the ordering process. Mandatory information is marked as such; all other information is voluntary.

Categories of data processed

  • Inventory data (e.g., name, address)
  • Contact data (e.g., email address, telephone number if provided)
  • Contract data (e.g., products ordered, delivery and billing address)
  • Payment data (see Payment section)
  • Usage data (e.g., time of the order)

The legal basis is Art. 6 (1) (b) GDPR (contract performance). To comply with statutory tax and commercial law retention obligations, we store order and invoice data in accordance with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB) for up to ten years (legal basis: Art. 6 (1) (c) GDPR).

Your data will only be passed on if this is necessary for the performance of the contract (e.g., to the payment provider you have chosen and to the shipping service provider). Any further disclosure will not take place or only if you have expressly consented or we are legally obliged to do so.

10. Customer account & guest checkout

You can place orders with us as a guest or by creating a customer account. When creating a customer account, in addition to your order data, your login credentials (email address and a password chosen by you) will be stored. The account allows you to place future orders more easily, view past orders, and manage your data.

The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures and contract performance). You can delete your customer account at any time. Upon deletion, the personal data of your account will be deleted unless statutory retention obligations require otherwise. In such cases, the affected data will be blocked and deleted after the retention period has expired.

Passwords are stored exclusively as cryptographic hashes and are not visible to us in plain text.

11. Payment processing

We offer various payment methods. Depending on the payment method you choose, the data required for processing will be transmitted to the respective payment service provider. The legal basis is Art. 6 (1) (b) GDPR (contract performance) and additionally Art. 6 (1) (f) GDPR (fraud prevention).

Stripe

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. As part of payment processing via Stripe, data (e.g., name, address, bank/card data, IP address, device information) may be transferred to Stripe. Stripe may transfer data to Stripe, Inc. in the United States; such transfers take place on the basis of the EU-US Data Privacy Framework (adequacy decision of the EU Commission, Art. 45 GDPR) and/or EU Standard Contractual Clauses (Art. 46 GDPR).

More information: https://stripe.com/privacy

PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. If you select PayPal as the payment method, your data (e.g., name, address, email, order data) will be transferred to PayPal to process the payment. More information: https://www.paypal.com/uk/legalhub/privacy-full

12. Shipping

To deliver your order, we pass the necessary data (name, delivery address, and, if necessary for delivery notification, email address and/or phone number) to our shipping service provider.

Shipping provider: DHL — Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany. Privacy notice: https://www.dhl.de/de/toolbar/footer/datenschutz.html

The legal basis is Art. 6 (1) (b) GDPR (contract performance). Where additional contact data is transmitted for delivery notification, this is based on Art. 6 (1) (f) GDPR (legitimate interest in smooth delivery). You may object to the transmission of such additional data at any time.

13. Contacting us

If you send us inquiries by email ([email protected]) or via a contact form, your information including the contact details you provide will be stored by us for the purpose of processing the inquiry and in case of follow-up questions.

The legal basis is Art. 6 (1) (b) GDPR, insofar as your inquiry is related to the performance of a contract or required for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) (f) GDPR).

The data will be deleted as soon as it is no longer required for the purpose of its collection, at the latest after the expiry of statutory retention periods.

14. Newsletter & email delivery

If you subscribe to our newsletter, we use the data required or separately provided by you to regularly send you our newsletter. Subscription is carried out via the so-called double opt-in procedure: after your subscription, you will receive an email with a confirmation link. Only after clicking on this link will your email address be added to the mailing list.

The legal basis is your consent under Art. 6 (1) (a) GDPR in conjunction with § 7 (2) UWG. You can revoke the newsletter and your consent at any time with effect for the future, e.g., via the unsubscribe link contained in every newsletter. The time of subscription and confirmation as well as your IP address are stored to prove the consent given (Art. 7 (1) GDPR).

Email delivery provider: Resend

For the technical delivery of our emails and newsletters, we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Resend processes your email address, the content of the email, and technical metadata (e.g., IP addresses of mail servers, delivery times, bounce and spam status).

Since Resend may process data in the United States, transmission takes place on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) and/or EU Standard Contractual Clauses (Art. 46 GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Resend. More information: https://resend.com/legal/privacy-policy

15. Fonts

We use fonts on our website (Instrument Serif and Manrope) that are downloaded by the Next.js framework at build time and subsequently served exclusively from our own servers (see Hosting section). Your browser does not connect to external font CDNs (e.g., Google Fonts) at runtime; no personal data is transmitted to third parties for this purpose.

16. Transparency page (live statistics)

On whirlbiotic.com/transparency we continuously publish aggregated business metrics (gross revenue, number of paid orders, average basket value, daily revenue series, shipping country distribution, and the most recent orders in pseudonymised form).

What is shown: a server-side hashed, non-reversible order identifier; the order timestamp rounded to the hour; the destination country code (only for countries with five or more orders — otherwise displayed as “—”); the number of items; product identifiers; and the gross total amount.

What is explicitly not shown: name, email address, phone number, shipping address (beyond the country code), invoice number, internal order tokens, IP address, browser or device information, or payment method details.

The legal basis is our legitimate interest in transparent business documentation toward customers, partners and the public (Art. 6 (1)(f) GDPR). Publication is exclusively aggregated or pseudonymised; re-identification is systematically prevented through hashing with a server-side secret, time bucketing, and k-anonymity on the country breakdown.

You may object to this processing at any time under Art. 21 GDPR. A request to the contact details above is sufficient; following an objection, your order data will be excluded from the transparency page.

17. Data security

We take technical and organizational security measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction, or against access by unauthorized persons. Our security measures are continuously improved in line with technological developments.

18. Automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on our website.

19. Updates to this privacy policy

We reserve the right to update this privacy policy so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy, e.g., when introducing new services. The new privacy policy will then apply to your next visit.