Privacy Policy
The protection of your personal data is of great importance to us. This privacy policy explains what personal data we process in connection with our website, our services, enquiries, bookings, orders, consultations, digital content and other business relationships; the purposes for which this is done; the legal basis on which the processing is carried out; and the rights you are entitled to. Personal data is any information relating to an identified or identifiable natural person. This includes, in particular, your name, contact details, contract details, payment details, communication content, technical usage data and, where applicable, any other information that you voluntarily provide to us. We process personal data exclusively in accordance with the applicable data protection provisions, in particular the General Data Protection Regulation (GDPR/DSGVO), the Austrian Data Protection Act (DPA/DSG) and the relevant provisions of telecommunications law concerning cookies and similar technologies.
Table of Contents
- Data Controller
- Principles of Data Processing
- Accessing and Using Our Website
- Contacting Us
- Orders, Bookings, Consultations and Contract Processing
- Payment Processing
- Newsletter und Direct Marketing
- Cookies und Similar Technologies
- Analytics and Tracking Tools
- External media and embedded content
- Social Media Presence
- doTERRA and External Partner Offers
- Recipients of Personal Data
- Data Transfer to Third Countries
- Storage Period and Deletion
- Your Rights
- Objection to Direct Marketing
- Right to Lodge a Complaint with the Supervisory Authority
- Data Security
- Validity and Amendments to this Privacy Policy
1. Data Controller
The data controller for the processing of personal data within the meaning of the GDPR is: Santrum Veritas e.U. Steingasse 6a 4020 Linz Austria E-Mail: info@santrumveritas.com Phone: +43 677 6183 7404 Where this Privacy Policy refers to “we”, “us” or “Santrum Veritas”, this means Santrum Veritas e.U. A data protection officer has not been appointed because, according to our current assessment, there is no legal obligation to do so. If you have any questions regarding data protection, you can contact us at any time using the contact details provided above.
2. Principles of Data Processing
In every processing operation involving personal data, we pay particular attention to the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Purpose limitation: We process data only for specified, explicit and legitimate purposes. Data minimisation: We collect only the data that is necessary for the respective purpose. Storage limitation: We store personal data only for as long as this is necessary or legally required. Confidentiality: We take appropriate technical and organisational measures to protect your data.
3. Accessing and Using Our Website
When you visit our website https://santrumveritas.com, the browser used on your device automatically transmits information to our website’s server. This information may be processed temporarily in so-called server log files.
3.1 Data Processed
- IP address of the requesting device
- date and time of access
- time zone difference from Greenwich Mean Time (GMT), where recorded on the server
- page accessed or file requested
- HTTP status code and access status
- amount of data transferred
- referrer URL, where transmitted
- browser type, browser version, language settings
- operating system and user interface of the end device
3.2 Purposes of Processing
- provision of the website and ensuring a stable connection
- ensuring system security and technical stability
- error analysis, detection of misuse and defence against attacks
- administrative evaluation to improve the website
3.3 Legal Basis and Storage Period
The processing is carried out on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the secure, stable and functional provision of our website, as well as in preventing misuse and attacks. Server log data is generally stored only for as long as is necessary for the purposes stated. Data may be stored for a longer period only if this is required to investigate security incidents, to establish, exercise or defend legal claims, or to comply with legal obligations.
4. Contacting Us
If you contact us by email, telephone, via the contact form, on social media or by any other means, we will process the information you provide in order to respond to your enquiry and handle our communication with you.
4.1 Data Processed
- name and contact details, where provided by you
- content of your message and other communication details
- time at which contact was made
- where applicable, data required to process your enquiry
4.2 Legal Basis
Where your enquiry is aimed at entering into or performing a contract, the processing is carried out on the basis of Article 6(1)(b) of the GDPR. In all other cases, the processing is carried out on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in the proper handling of incoming enquiries. Where you provide us with your consent, the processing is carried out on the basis of Article 6(1)(a) of the GDPR. Enquiries are deleted as soon as they have been fully processed and there are no statutory retention periods, obligations to provide evidence or legitimate interests in further storage.
5. Orders, Bookings, Consultations and Contract Processing
When you book services with us, purchase products, request digital content, order vouchers or enter into any other contracts with us, we process the personal data required for these purposes.
5.1 Data Processed
- name, billing address and, where applicable, delivery address
- email address and telephone number
- order, booking, appointment and service data
- payment and transaction information
- company data, VAT identification number or company registration number, where relevant
- correspondence in connection with contract processing
- where applicable, information that you voluntarily provide to us in the context of a consultation
5.2 Purposes of Processing
- pre-contractual communication and conclusion of contracts
- provision of booked services and performance of consultations
- processing of orders, payments, vouchers, cancellations and refunds
- customer communication, appointment organisation and service
- fulfilment of statutory retention, accounting and tax obligations
- asserting, exercising or defending legal claims
5.3 Legal Basis
Data processing is carried out for the purpose of taking pre-contractual measures and for the performance of a contract in accordance with Article 6(1)(b) of the GDPR. Where statutory retention or documentation obligations apply, processing is carried out in accordance with Article 6(1)(c) of the GDPR. Where we process data for the purposes of legal proceedings, internal organisation, economic evaluation or the improvement of our services, this is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR.
5.4 Storage Period
Contract and invoicing data are stored for the duration of the business relationship and beyond, in accordance with the statutory retention periods. In Austria, in particular, retention obligations under tax and company law may generally apply for a period of seven years; in individual cases, longer retention may be necessary, for example to assert, exercise or defend legal claims.
6. Payment Processing
For paid services or products, payment service providers, banks, credit card companies or other payment processors may be involved depending on the payment method selected. The data processed in this context is the data required for payment processing, in particular name, invoice amount, payment reference, payment status and, where applicable, account or card details. We process this data to fulfil the contract in accordance with Article 6(1)(b) of the GDPR and to comply with legal obligations in accordance with Article 6(1)(c) of the GDPR. Payment service providers may process data partly under their own responsibility under data protection law. Their respective privacy notices also apply.
7. Newsletter und Direct Marketing
If you subscribe to our newsletter or consent to receiving electronic information, we use your email address and, where applicable, your name to send you information about our offers, content, events, products and services.
7.1 Subscription and Consent
The sending of newsletters is generally based on your consent pursuant to Article 6(1)(a) of the GDPR. Consent is voluntary and may be withdrawn at any time with effect for the future, for example via the unsubscribe link in the newsletter or by email to info@santrumveritas.com.
7.2 Performance Measurement
If we measure opening rates or click rates for a newsletter, this is done only where valid consent has been obtained or another permissible legal basis exists. In this context, technical information such as opening time, clicked links, IP address, browser information and device information may be processed. These evaluations serve to improve our content and communication.
7.3 Advertising to Existing Customers
Where legally permissible, we may also inform existing customers about our own similar products or services without separate consent. You may object to such use at any time without incurring any costs other than the transmission costs charged at standard rates.
8. Cookies und Similar Technologies
Our website may use cookies and similar technologies. Cookies are small text files that are stored on your device. They may be technically necessary to provide the website, or may be used optionally, for example for statistics, analysis, marketing, external media or convenience features.
8.1 Technically Necessary Cookies
Technically necessary cookies are required for the website to function properly. These may include cookies for page navigation, security, shopping cart, language or consent management. The processing is carried out on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR or for the provision of functions expressly requested by you.
8.2 Non-Essential Cookies
We use non-essential cookies, in particular analytics, marketing and third-party cookies, only if you have given valid prior consent. The legal basis is Article 6(1)(a) of the GDPR. You can withdraw or amend your consent at any time, with effect for the future, by accessing the cookie settings again.
8.3 Cookie Settings
You can restrict, delete or block cookies via the settings of your browser. Please note that if cookies are completely disabled, certain functions of the website may be limited. Where a cookie banner or consent management tool is used on our website, you can make your selection there and change it later.
9. Analytics and Tracking Tools
We may use analytics and tracking tools to evaluate the use of our website, measure reach, improve content and make our offering more user-friendly. To the extent that such tools are not technically necessary, they are used only on the basis of your prior consent.
9.1 Google Analytics
Where Google Analytics is used, it is a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics may use cookies or similar technologies that enable an analysis of the use of our website. In this context, information about the use of the website, technical device and browser information, shortened IP addresses, referrer URLs, visit times and interactions may in particular be processed. We use Google Analytics only with IP anonymisation activated, insofar as this is technically available. The processing takes place only on the basis of your consent pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time. In addition, you can prevent the storage of cookies in your browser or use available browser add-ons to disable Google Analytics. When using Google services, it cannot be ruled out that data may be transferred to Google LLC in the United States. Where data is transferred to the United States or other third countries, such transfer is based – depending on the specific circumstances – on the European Commission’s decision on the adequacy of the level of protection, appropriate security measures such as EU Standard Contractual Clauses, or your explicit consent
10. External media and embedded content
Third-party content may be embedded on our website, such as videos, maps, fonts, social media content or other external media. When such content is accessed, personal data, in particular IP address, device information, browser data and usage information, may be transmitted to the respective providers. Where external media is not technically necessary, activation generally takes place only after your consent pursuant to Article 6(1)(a) of the GDPR. Before your consent is given, such content is blocked where possible or displayed only as a placeholder
10.1 YouTube / Google Services
Where YouTube videos or other Google services are embedded, data processing is carried out by Google Ireland Limited and, where applicable, by Google LLC in the United States. When embedded content is played, usage data and technical data may be processed. If you are simultaneously logged into a Google account, Google may associate the use with your account.
10.2 Social Media Content
Where content or links to platforms such as Facebook, Instagram or Pinterest are embedded, data may be transferred to the respective providers if you actively use them or after you have given your consent. We do not have complete influence over the data processing carried out by these providers. Their privacy notices also apply.
11. Social Media Presence
We may maintain our own social media accounts to communicate with prospective customers, existing customers and visitors, and to provide information about our services. When you visit our social media pages or interact with us via social media, personal data may be processed by us and by the respective platform operator. Our processing is based on our legitimate interest, in accordance with Article 6(1)(f) of the GDPR, in public relations, communication and marketing. Where you contact us via social media, the provisions regarding contact set out in this privacy policy shall also apply. The platform operators may process personal data for their own purposes, in particular for analysis, advertising, reach measurement and profiling. We have only limited influence over this processing. Please therefore also refer to the privacy policies of the respective platforms.
12. doTERRA and External Partner Offers
Where our website or communications refer to products, websites or offers from doTERRA Global Limited, its subsidiaries, affiliated companies or other external partners, these constitute offers and data processing activities outside our direct area of responsibility, provided that the order or use does not take place directly via Santrum Veritas e.U. If you click on external links or purchase products or services directly from an external provider, the data protection provisions of the respective provider shall apply. Santrum Veritas e.U. is generally not responsible for data processing carried out there, unless we expressly act as joint data controllers with the external provider or process data ourselves in the context of mediation or communication.
13. Recipients of Personal Data
Personal data is disclosed only where this is legally permissible and necessary for the respective purpose. Recipients may in particular include:
- IT, hosting, maintenance and support service providers
- payment service providers, banks and accounting service providers
- tax advisers, legal advisers and public authorities, where necessary
- shipping, communications and newsletter service providers
- appointment, booking or platform service providers, where used
- providers of analytics, marketing, social media or external media services, where you have given your consent
- other service providers who assist us in delivering our services Where service providers process personal data on our behalf, we enter into corresponding data processing agreements with them pursuant to Article 28 of the GDPR.
14. Data Transfer to Third Countries
Personal data may be transferred to recipients outside the European Union or the European Economic Area, in particular when using certain IT, analytics, communications, newsletter, payment, social media or cloud services. Such a transfer will only take place if the requirements of Articles 44 ff. of the GDPR are met. This may occur, in particular, on the basis of the European Commission’s decision on the adequacy of the level of protection, appropriate security measures such as EU Standard Contractual Clauses, binding corporate rules or explicit consent. In the case of transfers to the USA, an adequacy decision under the EU-US Data Privacy Framework may be relevant, provided that the respective recipient is certified accordingly. Otherwise, appropriate safeguards or other permissible transfer mechanisms will be used.
15. Storage Period and Deletion
We only store personal data for as long as is necessary for the respective processing purposes or where statutory retention periods apply. As soon as the purpose no longer applies and there are no legal or legitimate grounds for further storage, the data will be deleted or anonymised. We generally store data processed on the basis of your consent until such consent is withdrawn, provided there is no other legal basis for further processing. Data processed for the performance of a contract or due to legal obligations is stored in accordance with the applicable statutory retention periods.
16. Your Rights
Subject to the statutory requirements, you have the following rights:
- Access under Article 15 of the GDPR: You may request information as to whether we process personal data relating to you and, if so, what data we process.
- Rectification under Article 16 of the GDPR: You may request the rectification of inaccurate data or the completion of incomplete data.
- Erasure under Article 17 of the GDPR: You may request the erasure of personal data, provided there are no legal or legitimate grounds preventing this.
- Restriction under Article 18 of the GDPR: You may, under certain conditions, request the restriction of processing.
- Data portability under Article 20 of the GDPR: You may request to receive the data you have provided in a structured, commonly used and machine-readable format.
- Objection under Article 21 of the GDPR: You may object to the processing if it is based on legitimate interests and there are grounds relating to your particular situation.
- Withdrawal under Article 7(3) of the GDPR: You may withdraw your consent at any time with effect for the future.
To exercise your rights, simply send an email to info@santrumveritas.com. We may request appropriate confirmation of your identity for clear identification, where necessary.
17. Objection to Direct Marketing
Where we process personal data for the purposes of direct marketing, you have the right to object to such processing at any time. Once you have objected, we will no longer use your personal data for direct marketing purposes.
18. Right to Lodge a Complaint with the Supervisory Authority
If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority. In particular, the Austrian Data Protection Authority may be competent: Austrian Data Protection Authority Barichgasse 40-42 1030 Vienna Austria Telephone: +43 1 52 152-0 Email: dsb@dsb.gv.at Website: https://www.dsb.gv.at
19. Data Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, disclosure or destruction. These include, in particular, access restrictions, secure transmission channels, organisational confidentiality rules and ongoing adjustments to the state of the art. Our website uses encrypted transmission via TLS/SSL where this is technically available. You can usually recognise an encrypted connection by the lock symbol in the address bar of your browser and by the use of “https://”.
20. Validity and Amendments to this Privacy Policy
This privacy policy is currently in force and is dated August 2026. We reserve the right to amend this privacy policy should there be any changes to our website, our services, the services we use, legal requirements or regulatory guidelines. The latest version is available on our website.