GDPR & Your Data Rights
Effective: 1 January 2026 · Version 1.0 · Vitantra · vitantra.ai
Vitantra is built with privacy at its core. This page explains your rights under the General Data Protection Regulation (GDPR) and how to exercise them easily and quickly — on any tier, including free.
Your Rights Under GDPR
As a resident of the European Economic Area (EEA) or the United Kingdom, you have the following rights under GDPR:
- Right of Access (Article 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Article 16): Correct inaccurate or incomplete data.
- Right to Erasure / “Right to be Forgotten” (Article 17): Request deletion of your personal data. Available to all users on all tiers, including free, at any time.
- Right to Restriction of Processing (Article 18): Request that we limit how we use your data in certain circumstances.
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format (JSON or CSV).
- Right to Object (Article 21): Object to processing based on legitimate interests.
- Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to solely automated decisions that have a significant effect on you. Vitantra’s AI plans are wellness recommendations and are not solely automated decisions with legal or similarly significant effects.
Health Data (Special Category)
Your health and wellness data — including goals, body measurements, food logs, and wearable data — is classified as “special category data” under GDPR Article 9. We process this data only with your explicit consent, which you grant when you create an account and configure your wellness profile.
You may withdraw consent at any time by deleting your account or adjusting your data settings. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Data Processing Agreements
All third-party services that process personal data on our behalf operate under Data Processing Agreements (DPAs) that comply with GDPR Chapter IV. These include Stripe (payments), Supabase and AWS (infrastructure), and wearable platform integrations.
Data Transfers Outside the EEA
Some of our infrastructure partners may be located outside the EEA. Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Article 33 and 34.
How to Exercise Your Rights
To exercise any of your data rights:
- Within the app: Go to Account Settings → Data & Privacy for self-service options including data export and account deletion.
- By email: Contact privacy@vitantra.ai with your request. We will respond within 30 days.
We do not charge a fee for exercising your rights (unless requests are manifestly unfounded or excessive). We may ask you to verify your identity before processing your request.
Supervisory Authority
You have the right to lodge a complaint with your national data protection supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk. In the EEA, please contact your local data protection authority.
Our Data Protection Officer
For GDPR enquiries, you can reach our Data Protection team at dpo@vitantra.ai. We aim to respond to all DPO enquiries within 10 business days.
Contact & Questions
For any questions about this document, please contact us at legal@vitantra.ai or visit our Contact page. We respond to all enquiries within 5 business days.
