Legal

Privacy Policy

For the member portal of the 28-Day Vital Organs Cleanse.

Last updated: 31 August 2026

1. Data controller

VantArc e.U. (Rootonika)
Friedrich Scharinger
Lüfteneggerstraße 7, 4020 Linz, Österreich
Email: info@rootonika-wellness.com

We process personal data solely in accordance with the GDPR (EU 2016/679) and the Austrian Data Protection Act (DSG).

2. What data we process

  • Account data: email address, display name, program start date, language preference.
  • Payment data: purchase and payment status plus the Stripe customer ID. Card details are processed exclusively by Stripe and are never visible to us.
  • Program progress: completed days and ticks in the daily protocols.
  • Login security: active sessions, timestamps and IP address, used to prevent account sharing.
  • Consent records: which consents you gave, when, and under which policy version.
  • Email delivery logs for sign-in and system messages.

The program does not ask you for health data. Please avoid entering health details in free-text fields if you would rather not share them.

3. Purposes and legal bases

  • Delivering the program and the login, Art. 6(1)(b) GDPR (contract).
  • Payment processing and bookkeeping, Art. 6(1)(b) and (c) GDPR (contract, statutory retention).
  • Security, abuse prevention and error analysis, Art. 6(1)(f) GDPR (legitimate interest).
  • Recording your acknowledgements (health disclaimer, withdrawal waiver), Art. 6(1)(c) GDPR (accountability).
  • Non-essential cookies and analytics, Art. 6(1)(a) GDPR (consent), withdrawable at any time.

4. Processors and recipients

  • Database, authentication and hosting provider for the program data, EU region, data processing agreement in place.
  • Stripe Payments Europe, Ltd. (payment processing), controller in its own right for payment data.
  • Email delivery service for sign-in and system messages.
  • Hosting and CDN provider of the portal.

Transfers to third countries only take place under EU Standard Contractual Clauses or an adequacy decision. We never sell data.

5. Retention

  • Account and progress data: until you delete your account.
  • Invoices and payment records: 7 years as required by § 132 of the Austrian Federal Fiscal Code.
  • Consent records: for as long as we must be able to demonstrate consent after withdrawal.
  • Session and security logs: typically 30 days.

6. Cookies and storage

We use strictly necessary cookies and local storage for your login session, language selection and your cookie choice. These are required to operate the portal and need no consent. Non-essential categories (analytics, marketing) are only activated after your active opt-in and can be withdrawn at any time.

7. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and you may withdraw consent at any time.

In the portal, your Profile page offers a data export (JSON) and a way to request deletion of your account. We handle requests within 30 days.

Supervisory authority: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.

8. No medical advice

The content is informational and educational and does not constitute medical diagnosis or treatment. Please seek professional medical advice for any health concerns.