Privacy Policy
We take the protection of your personal data seriously and process your data confidentially and in accordance with applicable data protection law (GDPR, German Federal Data Protection Act, German Telecommunications-Telemedia Data Protection Act) and this privacy policy. This policy informs you about the nature, scope, and purpose of the processing of personal data on our website and in connection with our online orders.
Last updated: July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the EU Member States as well as other data protection provisions is:
Gebrüder Grüske GmbH, Im Stöckig 121, 90765 Fürth, Germany
Represented by: Werner Grüske
Email: [email protected]
2. Data Protection Officer
We have not appointed a Data Protection Officer, as the requirements of Art. 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) do not apply. For any data protection questions, please contact the controller listed above.
3. Your rights as a data subject
You have the following rights at any time with respect to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, an informal email to [email protected] is sufficient.
4. Right to object (Art. 21 GDPR)
Where personal data are processed on the basis of Art. 6 (1) (f) GDPR (legitimate interests), you have the right to object at any time, on grounds relating to your particular situation, to the processing. If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms.
Where personal data are processed for the purpose of direct marketing, you have the right to object at any time; this also applies to profiling insofar as it is related to such direct marketing.
5. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent supervisory authority for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland (https://www.lda.bayern.de).
6. Hosting & website provision
We host our website with Hetzner Online GmbH (address: Industriestr. 25, 91710 Gunzenhausen, Deutschland). Servers are located in Nürnberg, Deutschland. When you visit our website, the server automatically processes the following information in so-called server log files:
- IP address of the requesting device (shortened where technically possible)
- Date and time of the request
- Requested URL and HTTP status code
- Amount of data transferred
- Referrer URL (previously visited page)
- Browser type, browser version, and operating system
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the secure, stable, and functional operation of our website and the defense against attacks. Log files are usually deleted automatically after 7 days, unless required for the investigation of a security incident.
A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner Online GmbH. For more information, see https://www.hetzner.com/de/rechtliches/datenschutz.
7. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the address bar in your browser switches from "http://" to "https://" and by the lock icon in the browser bar.
9. Contract performance & orders
To process your order, we collect and process the data you provide during the ordering process. Mandatory information is marked as such; all other information is voluntary.
Categories of data processed
- Inventory data (e.g., name, address)
- Contact data (e.g., email address, telephone number if provided)
- Contract data (e.g., products ordered, delivery and billing address)
- Payment data (see Payment section)
- Usage data (e.g., time of the order)
The legal basis is Art. 6 (1) (b) GDPR (contract performance). To comply with statutory tax and commercial law retention obligations, we store order and invoice data in accordance with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB) for up to ten years (legal basis: Art. 6 (1) (c) GDPR).
Your data will only be passed on if this is necessary for the performance of the contract (e.g., to the payment provider you have chosen and to the shipping service provider). Any further disclosure will not take place or only if you have expressly consented or we are legally obliged to do so.
10. Customer account & guest checkout
You can place orders with us as a guest or by creating a customer account. When creating a customer account, in addition to your order data, your login credentials (email address and a password chosen by you) will be stored. The account allows you to place future orders more easily, view past orders, and manage your data.
The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures and contract performance). You can delete your customer account at any time. Upon deletion, the personal data of your account will be deleted unless statutory retention obligations require otherwise. In such cases, the affected data will be blocked and deleted after the retention period has expired.
Passwords are stored exclusively as cryptographic hashes and are not visible to us in plain text.
11. Payment processing
We offer various payment methods. Depending on the payment method you choose, the data required for processing will be transmitted to the respective payment service provider. The legal basis is Art. 6 (1) (b) GDPR (contract performance) and additionally Art. 6 (1) (f) GDPR (fraud prevention).
Stripe
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. As part of payment processing via Stripe, data (e.g., name, address, bank/card data, IP address, device information) may be transferred to Stripe. Stripe may transfer data to Stripe, Inc. in the United States; such transfers take place on the basis of the EU-US Data Privacy Framework (adequacy decision of the EU Commission, Art. 45 GDPR) and/or EU Standard Contractual Clauses (Art. 46 GDPR).
More information: https://stripe.com/privacy
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. If you select PayPal as the payment method, your data (e.g., name, address, email, order data) will be transferred to PayPal to process the payment. More information: https://www.paypal.com/uk/legalhub/privacy-full
12. Shipping
To deliver your order, we pass the necessary data (name, delivery address, and, if necessary for delivery notification, email address and/or phone number) to our shipping service provider.
Shipping provider: DHL — Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany. Privacy notice: https://www.dhl.de/de/toolbar/footer/datenschutz.html
The legal basis is Art. 6 (1) (b) GDPR (contract performance). Where additional contact data is transmitted for delivery notification, this is based on Art. 6 (1) (f) GDPR (legitimate interest in smooth delivery). You may object to the transmission of such additional data at any time.
13. Contacting us
If you send us inquiries by email ([email protected]) or via a contact form, your information including the contact details you provide will be stored by us for the purpose of processing the inquiry and in case of follow-up questions.
The legal basis is Art. 6 (1) (b) GDPR, insofar as your inquiry is related to the performance of a contract or required for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 (1) (f) GDPR).
The data will be deleted as soon as it is no longer required for the purpose of its collection, at the latest after the expiry of statutory retention periods.
15. Fonts
We use fonts on our website (Instrument Serif and Manrope) that are downloaded by the Next.js framework at build time and subsequently served exclusively from our own servers (see Hosting section). Your browser does not connect to external font CDNs (e.g., Google Fonts) at runtime; no personal data is transmitted to third parties for this purpose.
16. Transparency page (live statistics)
On whirlbiotic.com/transparency we continuously publish aggregated business metrics (gross revenue, number of paid orders, average basket value, daily revenue series, shipping country distribution, and the most recent orders in pseudonymised form).
What is shown: a server-side hashed, non-reversible order identifier; the order timestamp rounded to the hour; the destination country code (only for countries with five or more orders — otherwise displayed as “—”); the number of items; product identifiers; and the gross total amount.
What is explicitly not shown: name, email address, phone number, shipping address (beyond the country code), invoice number, internal order tokens, IP address, browser or device information, or payment method details.
The legal basis is our legitimate interest in transparent business documentation toward customers, partners and the public (Art. 6 (1)(f) GDPR). Publication is exclusively aggregated or pseudonymised; re-identification is systematically prevented through hashing with a server-side secret, time bucketing, and k-anonymity on the country breakdown.
You may object to this processing at any time under Art. 21 GDPR. A request to the contact details above is sufficient; following an objection, your order data will be excluded from the transparency page.
17. Data security
We take technical and organizational security measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction, or against access by unauthorized persons. Our security measures are continuously improved in line with technological developments.
18. Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on our website.
19. Updates to this privacy policy
We reserve the right to update this privacy policy so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy, e.g., when introducing new services. The new privacy policy will then apply to your next visit.