Werhner Lab
RUO · Research Use OnlyCartAccount

Version 2026-08-v1

Privacy Policy (GDPR)

Controller: Werhner Lab
Website: werhnerlab.com
Territory: European Union
Language: English (this is the binding version)

This Policy explains how Werhner Lab collects, uses, stores, and protects personal data when you use the website, create an account, or place an order.

1. Who is responsible

Werhner Lab is the data controller for personal data processed through this website and for order fulfilment. Contact: [email protected]

2. What data we process

2.1 Account and authentication

  • Email address
  • Password hash (handled by Supabase Auth; we do not store plaintext passwords)
  • Magic-link / session tokens
  • Preferred language, last login timestamp

2.2 Order and customer data

  • Order IDs, status, amounts, items
  • Country of delivery (ISO code)
  • Acceptance of Terms, Privacy Policy, and RUO disclaimer (version + timestamp)
  • Support messages you send us

2.3 Sensitive delivery data (encrypted)

We treat the following as high-sensitivity personal data and store them encrypted at rest (application-level AES-256-GCM, in addition to database encryption): full name, address lines 1 and 2, city, postal code, state/province, and phone (if provided). Decryption happens only on the server when needed to ship an order, show your address book to you, or handle a lawful request. These fields are not stored in plaintext.

2.4 Payment data

Payment provider (CoinGate, Bitnovo, or similar), provider payment ID, status, amount in EUR, crypto amount/currency, payment URL and expiry, and webhook metadata needed to confirm the order. We do not collect or store card numbers, CVV, or cardholder data. If a gateway lets you pay by card and convert to crypto, that card data is processed only by the gateway, under its own privacy notice.

2.5 Technical data

IP address, browser user agent, basic device/session data, and cookie/similar identifiers (see section 11).

2.6 What we do not want

Health data, payment cards, or identity documents, unless a legal process requires them. Do not send medical information or dosing questions — this shop is for laboratory research only.

3. Why we use the data

PurposeDataLegal basis
Create and manage your accountEmail, auth dataArt. 6(1)(b) contract
Process orders and ship ProductsName, address, order, countryArt. 6(1)(b) contract
Confirm crypto paymentsPayment IDs, amounts, webhooksArt. 6(1)(b) contract
Record RUO / Terms acceptanceDisclaimer version, timestampArt. 6(1)(b) and (c)
Invoices, tax, accountingOrder and billing identifiersArt. 6(1)(c) legal obligation
Security, abuse, fraud, auditIP, logs, account flagsArt. 6(1)(f) legitimate interests
Customer supportEmail and message contentArt. 6(1)(b) or (f)
Emails strictly about your orderEmailArt. 6(1)(b) contract
Optional marketing emailsEmailArt. 6(1)(a) consent (opt-in only)
Improve site security and performanceTechnical logsArt. 6(1)(f) legitimate interests

You may refuse marketing. You cannot refuse data that is necessary to complete a paid order.

4. How long we keep data

  • Account: while active, then deleted or anonymised on request unless law requires keeping it.
  • Orders and invoices: generally 6 years (Spanish tax/commercial record-keeping), longer if a dispute is open.
  • Encrypted addresses: kept while needed for delivery, returns, and legal records linked to the order.
  • Payment logs / webhooks: kept as needed to prove payment and prevent fraud, then minimised.
  • Security audit logs: typically up to 12 months, unless an investigation requires longer.
  • Marketing consent: until you withdraw consent.

When the retention period ends, data is deleted or irreversibly anonymised.

5. Who receives data

  • Hosting and database — infrastructure in the EU (Supabase PostgreSQL in an EU region, Vercel/Railway as configured).
  • Authentication — Supabase Auth.
  • Crypto payment providers — CoinGate, Bitnovo Pay, or the provider shown at checkout.
  • Carriers / fulfilment — name, delivery address, phone, parcel contents as needed to ship.
  • Professional advisers — accountants, lawyers, only as required.
  • Authorities — if legally obliged.

We do not sell personal data.

6. International transfers

We aim to keep personal data in the EEA. If a provider processes data outside the EEA, we use a valid GDPR transfer tool (adequacy decision or Standard Contractual Clauses) and only the minimum data required.

7. Security measures

  • HTTPS on the website
  • GDPR-oriented hosting in the EU where available
  • Row Level Security (RLS) so users can only access their own records
  • Encryption of name and shipping fields (AES-256-GCM) on the server
  • No card data stored
  • Access to admin tools restricted; 2FA required for administration
  • Rate limiting, WAF (Cloudflare), and encrypted backups
  • Principle of least privilege for staff and service keys

No system is perfect. If a personal-data breach is likely to result in a high risk to you, we will notify the competent authority and affected users as required by Articles 33–34 GDPR.

8. Your rights

  • Access — a copy of your data
  • Rectification — fix inaccurate data
  • Erasure — "right to be forgotten", where no legal retention applies
  • Restriction — limit processing in certain cases
  • Portability — receive order/account data in a structured format
  • Objection — to processing based on legitimate interests
  • Withdraw consent — for marketing, at any time
  • Lodge a complaint — with the Spanish AEPD (aepd.es) or your local EU authority

To exercise rights: [email protected] from the email on the account. We may need to verify your identity. We respond within one month (extendable by two months for complex requests, with notice).

Erasure limits: we cannot delete invoices or order records that tax or commercial law requires us to keep. Those records stay locked for the legal period.

9. Children

The shop is for adults only. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete the account and related data unless the law requires keeping part of it.

10. Automated decisions

We do not use solely automated decisions that produce legal effects about you (no credit scoring). Automated checks may flag risky orders (country not allowed, payment expired, abuse patterns). A human can review if you contact us.

11. Cookies and similar technologies

We use strictly necessary cookies/storage (session, cart, security, checkout) which do not require consent, and optional analytics or marketing cookies only with consent, if enabled. You can manage optional cookies in the banner and in your browser. Blocking necessary cookies may stop login or checkout from working.

12. Source of data

Most data comes from you (registration, checkout, support). Some data comes from payment providers (payment status) and from your device (IP, logs).

13. Changes

We may update this Policy. The version that applies is the one published on this page on the date you use the site or place an order. Material changes will be highlighted where reasonable (banner or email).

14. Contact and complaints

Privacy / data requests: [email protected]
Orders: [email protected]

Supervisory authority (Spain): Agencia Española de Protección de Datos (AEPD) — aepd.es. You may also complain to the authority in your EU country of residence.