Grewus Logo

Data Protection

1. Our commitment to data protection

At GREWUS GmbH, we are committed to protecting your personal data and respecting your privacy. This Data Protection Policy explains how we collect, use, and safeguard your personal information when you interact with our website and services.

Legal framework

We process your data in accordance with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws. Our policies and procedures are designed to ensure compliance with these regulations.

2. Information we collect

Personal data

Personal data refers to any information that can identify you as an individual. We may collect the following types of personal data:

  • Contact information (name, email address, phone number, postal address)
  • Account information (username, password)
  • Payment information (credit card details, billing address)
  • Profile information (preferences, interests)
  • Communication data (messages, feedback)

Technical data

When you visit our website, we automatically collect certain technical information, including:

  • IP address
  • Browser type and version
  • Operating system
  • Date and time of access
  • Websites from which you access our site
  • Pages you visit on our website

3. How we use your data

We use your personal data only for specific purposes and with a valid legal basis. The main purposes for which we process your data include:

Providing our services

We use your data to provide the services you have requested, including processing orders, managing your account, and responding to your inquiries. The legal basis for this processing is the performance of our contract with you.

Improving our website and services

We analyze usage data to understand how our website is used and to improve its functionality and user experience. The legal basis for this processing is our legitimate interest in maintaining and enhancing our services.

Marketing communications

With your consent, we may send you marketing communications about our products and services. You can withdraw your consent at any time by using the unsubscribe link in our emails or by contacting us directly.

Compliance with legal obligations

We may process your data to comply with legal obligations, such as tax requirements or in response to legal proceedings.

4. Data sharing and transfers

Service providers

We may share your data with third-party service providers who perform services on our behalf, such as payment processing, hosting, and customer support. These providers are contractually obligated to process data only according to our instructions and to maintain appropriate security measures.

Legal requirements

We may disclose your data if required by law, regulation, or legal process, or to protect our rights, property, or safety, or that of our users or others.

International transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place to protect your data, such as Standard Contractual Clauses approved by the European Commission.

5. Data security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of sensitive data
  • Regular security assessments
  • Access controls and authentication
  • Staff training on data protection
  • Incident response procedures

While we take all reasonable steps to protect your data, no security measure is completely foolproof. We cannot guarantee the absolute security of your data transmitted to our website.

6. Data retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.

7. Your rights

Under data protection laws, you have the following rights regarding your personal data:

Right to access

You have the right to request a copy of the personal data we hold about you.

Right to rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to erasure

In certain circumstances, you have the right to request that we delete your personal data.

Right to restriction of processing

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to data portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to object

You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.

To exercise any of these rights, please contact us using the details provided below. We will respond to your request within one month of receiving it.

8. Contact information

If you have any questions or concerns about our data protection practices or this policy, please contact us at:

GREWUS GmbH

Langenhorner Chaussee 40

22335 Hamburg

Phone: +49 (0) 40 539 32 64 0

Email: [email protected]

9. Updates to this policy

We may update this Data Protection Policy from time to time to reflect changes in our practices or legal requirements. The updated policy will be posted on our website with a revised effective date. We encourage you to review this policy periodically.

This Data Protection Policy was last updated on April 22, 2025.