Legal

Privacy Policy

For the member portal of the 8-Week Anti-Candida Program.

Last updated: 28 August 2026

1. Data controller

VantArc e.U. (Rootonika)
Friedrich Scharinger
Lüfteneggerstraße 7, 4020 Linz, Österreich
Email: info@rootonika-wellness.com

We process personal data solely in accordance with the GDPR (EU 2016/679) and the Austrian Data Protection Act (DSG).

2. What data we process

  • Account data: email address, display name, program start date, language.
  • Payment data: purchase/payment status and Stripe customer ID. Card details are processed exclusively by Stripe and are never visible to us.
  • Program progress: completed weeks and checklist ticks.
  • Health-related data (Art. 9 GDPR): voluntary journal entries on energy, bloating, brain fog, sugar cravings and free-text notes.
  • Consent records: which consents you gave, when, and under which policy version.
  • Technical data: sign-in logs, IP address and timestamps used to secure the login.

3. Purposes and legal bases

  • Delivering the program and the login – Art. 6(1)(b) GDPR (contract).
  • Payment processing and bookkeeping – Art. 6(1)(b) and (c) GDPR (contract, statutory retention).
  • Health journal – Art. 9(2)(a) GDPR (explicit consent). Without this consent you can use the program without the journal.
  • Security, abuse prevention and error analysis – Art. 6(1)(f) GDPR (legitimate interest).
  • Non-essential cookies and analytics – Art. 6(1)(a) GDPR (consent), withdrawable at any time.

4. Processors and recipients

  • Supabase (database, authentication, hosting of program data) – EU region, data processing agreement in place.
  • Stripe Payments Europe, Ltd. (payment processing) – controller in its own right for payment data.
  • Email delivery service for sign-in and system messages.
  • Hosting/CDN provider of the portal.

Transfers to third countries only take place under EU Standard Contractual Clauses or an adequacy decision. We never sell data.

5. Retention

  • Account, progress and journal data: until you delete your account or withdraw consent.
  • Invoices and payment records: 7 years as required by § 132 of the Austrian Federal Fiscal Code.
  • Consent records: for as long as we must be able to demonstrate consent after withdrawal.
  • Security logs: typically 30 days.

6. Cookies and storage

We use strictly necessary cookies and local storage for your login session, language selection and your cookie choice. These are required to operate the portal and need no consent. Non-essential categories are only activated after your active opt-in.

7. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and you may withdraw consent at any time.

In the portal, your Profile page offers a data export (JSON) and a way to request deletion of your account. We handle requests within 30 days.

Supervisory authority: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.

8. No medical advice

The content is informational and educational and does not constitute medical diagnosis or treatment. Your journal entries are not medically assessed.