Privacy Policy

Your privacy is important to me. Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable Austrian data protection law.

This Privacy Policy explains how personal data is collected and processed when you visit this website, subscribe to my newsletter, contact me, purchase digital products, access online courses, or interact with my sales pages and checkout pages, including pages hosted through ThriveCart.

1. Data Controller

Johanna Putz
Fischachstr. 32
5161 Elixhausen
Austria
Email: info@eatwellwithjohanna.com

2. Website & Blog Usage

When you visit this website, technical data may be collected automatically, including:

  • IP address

  • browser type and version

  • device information

  • operating system

  • date and time of access

  • pages visited

  • referring website, where applicable

This data is processed to ensure website functionality, security, stability, and basic technical operation.

The legal basis is my legitimate interest in operating a secure and functional website pursuant to Art. 6 para. 1 lit. f GDPR.

3. Contact

If you contact me by email or through a contact form, the data you provide, such as your name, email address, and message, will be processed for the purpose of responding to your inquiry.

The legal basis is Art. 6 para. 1 lit. b GDPR if your inquiry relates to a contract or pre-contractual communication, and Art. 6 para. 1 lit. f GDPR for general inquiries.

4. Newsletter & Email Communication

If you request a free digital product (such as a free e-book, starter plan, or guide), your name and email address are processed to deliver the requested product. By requesting the free product, you enter into a contractual agreement where you receive the free material in exchange for subscribing to my newsletter. Through this newsletter, you will regularly receive recipes, blog updates, educational content, tips on healthy plant-based nutrition, and information about my online courses or offers. This promotional connection is a core component of the agreement to receive the free material.

The data you provide in the form is processed immediately to send you the download link and add you to the newsletter mailing list.

You may unsubscribe from the newsletter at any time by clicking the unsubscribe link included in every single email or by contacting me at info@eatwellwithjohanna.com. Unsubscribing will not affect your right to keep the e-book you already downloaded.

The legal basis for this processing is contract performance pursuant to Art. 6 para. 1 lit. b GDPR, as the processing and the subscription to the newsletter are part of the mutual agreement to receive the free e-book.

Email Service Provider:

For the delivery of the e-book, the management of my contact list, and the distribution of newsletters, I use the email marketing platform Hostinger Reach, operated by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. A data processing agreement pursuant to Art. 28 GDPR has been concluded with this provider. Hostinger stores and processes data within the European Union.

Transactional Emails: If you purchase a paid product later on, I will also use this system to send you transactional emails related to your purchase (order confirmations, login details, product updates). The legal basis for these specific emails is contract performance pursuant to Art. 6 para. 1 lit. b GDPR.

5. Online Courses, Digital Products & ThriveCart

I use ThriveCart to provide sales pages, checkout pages, payment-related order processing, customer management, and access to digital products and online courses through ThriveCart Learn.

When you purchase a course or digital product, the following data may be processed:

  • name

  • email address

  • billing address, where applicable

  • payment status

  • order details

  • purchased products

  • discount codes or order bumps, where applicable

  • access data for digital products or courses

  • login credentials, where applicable

  • course access and usage information

  • technical data such as IP address, browser, device, and time of access

This data is processed to handle your purchase, provide access to digital products, manage your customer account, deliver course content, provide customer support, comply with legal obligations, and protect against misuse or fraud.

The legal basis is contract performance pursuant to Art. 6 para. 1 lit. b GDPR, legal obligations pursuant to Art. 6 para. 1 lit. c GDPR, and my legitimate interest in secure and reliable course delivery pursuant to Art. 6 para. 1 lit. f GDPR.

ThriveCart may process data on servers outside the European Economic Area. Where required, appropriate safeguards such as Standard Contractual Clauses are used.

6. Payment Providers

Payments are processed through third-party payment providers such as Stripe and PayPal.

Depending on the payment method selected, the following data may be processed by the payment provider:

  • name

  • email address

  • billing information

  • payment amount

  • transaction details

  • payment method information

  • fraud prevention and security data

Stripe and PayPal may act as independent data controllers for payment processing. I only receive the information necessary to confirm payment, issue invoices, manage access to the purchased product, and comply with accounting obligations.

The legal basis is contract performance pursuant to Art. 6 para. 1 lit. b GDPR and legal obligations pursuant to Art. 6 para. 1 lit. c GDPR.

7. Vimeo Video Hosting

Course videos may be hosted and streamed through Vimeo.

When you access or play course videos, Vimeo may process technical data such as:

  • IP address

  • browser and device information

  • video access and playback information

  • referring website

  • technical identifiers

  • cookies or similar technologies, where applicable

This processing is necessary to deliver and play the course videos.

Where possible, privacy-friendly Vimeo settings, such as reduced tracking or Do-Not-Track parameters, may be used. However, Vimeo may still process technical data required for video delivery and may receive cookies already stored in your browser from previous visits to Vimeo.

The legal basis is contract performance pursuant to Art. 6 para. 1 lit. b GDPR where videos are part of a purchased course, and my legitimate interest in reliable video delivery pursuant to Art. 6 para. 1 lit. f GDPR.

8. Meta Pixel, Meta Ads & Conversion Tracking

I use Meta Pixel and related Meta business tools provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.

Meta Pixel may be used on this website, on sales pages, and on ThriveCart checkout pages to measure the effectiveness of Facebook and Instagram ads, understand user behavior, optimize advertising campaigns, create custom audiences, and track conversions such as page views, checkout events, and purchases.

Processed data may include:

  • IP address

  • browser and device information

  • visited pages

  • interactions with website, sales page, or checkout content

  • checkout events, such as page views, initiate checkout, and purchase events

  • order value and product information, where applicable

  • cookie IDs or other online identifiers

  • hashed contact data, such as email address, where applicable

I may also use Meta Conversions API, where available. This allows certain conversion events, such as purchases or checkout events, to be transmitted to Meta from the server side, for example through ThriveCart. This may improve ad measurement and attribution.

The legal basis for Meta Pixel, Meta Conversions API, and similar marketing tracking is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

Marketing and tracking technologies are only activated after you have given consent via the cookie banner or consent mechanism, where required. You may withdraw or change your consent at any time via the cookie settings.

Meta may process data outside the European Economic Area, including in the United States. Where required, Meta relies on appropriate safeguards such as Standard Contractual Clauses.

Regarding the collection and transmission of event data through Meta Business Tools, including the Meta Pixel, Eat Healthy with Johanna and Meta Platforms Ireland Ltd. may act as Joint Controllers within the meaning of Art. 26 GDPR.

This joint controllership applies to the collection of personal data through Meta Business Tools on this website, sales pages, or checkout pages and the transmission of such data to Meta Platforms Ireland Ltd.

The joint processing is governed by Meta’s Controller Addendum, which forms part of the Meta Business Tools Terms and defines the respective responsibilities of Meta and the website operator for compliance with GDPR obligations.

Meta Platforms Ireland Ltd. is primarily responsible for enabling data subject rights regarding personal data processed by Meta after transmission. You may also contact me at info@eatwellwithjohanna.com regarding any privacy-related questions.

9. Meta Custom Audiences from Customer Lists

I may use the “Custom Audiences from Customer Lists” feature provided by Meta Platforms Ireland Ltd.

For this purpose, email addresses or other contact data of newsletter subscribers or customers may be uploaded to Meta in hashed form. Meta compares this hashed data with its own user data to create custom audiences or statistically similar audiences, known as Lookalike Audiences.

This is used to show relevant ads to people who have already shown interest in my content or products, or to reach similar audiences.

The legal basis for this processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR, where required. You may withdraw your consent or object to this use of your data at any time by contacting info@eatwellwithjohanna.com.

10. Cookies & Consent

This website, sales pages, checkout pages, and course platforms may use cookies and similar technologies.

Some cookies are technically necessary for website functionality, checkout functionality, security, login, payment processing, and access to digital products. These cookies are required to provide the requested service.

Optional cookies and tracking technologies, such as analytics, marketing cookies, Meta Pixel, or similar tools, are only used with your consent, where required by law.

You can withdraw or change your cookie consent at any time via the cookie settings or by adjusting your browser settings.

Please note that disabling certain cookies may affect the functionality of the website, checkout, or course access.

11. Analytics and Marketing Tools

Where consent has been given, I may use analytics and marketing tools to understand how visitors use my website, sales pages, checkout pages, and offers.

These tools help me improve my content, measure ad performance, optimize campaigns, and provide more relevant offers.

The legal basis is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

12. Data Retention

Personal data is stored only as long as necessary for the purposes described in this Privacy Policy or as required by law.

Typical retention periods include:

  • accounting and invoice data: 7 years according to Austrian legal requirements

  • newsletter data: until you unsubscribe or withdraw consent

  • customer and course access data: for as long as your account or course access exists, unless deletion is requested and no legal retention obligation applies

  • support emails and inquiries: as long as needed to process the inquiry and for reasonable documentation purposes

  • technical logs: short-term storage for security and technical operation

  • consent records: as long as needed to document consent and comply with legal obligations

13. Legal Bases for Processing

Personal data is processed on the following legal bases:

  • Art. 6 para. 1 lit. a GDPR — consent, for example for newsletters, marketing cookies, Meta Pixel, or optional tracking

  • Art. 6 para. 1 lit. b GDPR — contract performance, for example for course purchases, checkout processing, access to digital products, and customer support

  • Art. 6 para. 1 lit. c GDPR — legal obligations, for example accounting and tax records

  • Art. 6 para. 1 lit. f GDPR — legitimate interests, for example website security, fraud prevention, technical functionality, and business communication

14. International Data Transfers

Some service providers used for website hosting, checkout processing, payment processing, email communication, marketing, analytics, or video hosting may process personal data outside the European Economic Area.

Where personal data is transferred to third countries, appropriate safeguards are used where required, such as Standard Contractual Clauses or other legally recognized transfer mechanisms.

15. Your Rights

Under the GDPR, you have the right to:

  • request access to your personal data

  • request correction of inaccurate data

  • request deletion of your data

  • request restriction of processing

  • object to certain processing activities

  • withdraw consent at any time

  • request data portability

  • lodge a complaint with a supervisory authority

To exercise your rights, contact: info@eatwellwithjohanna.com

You also have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
Austria
www.dsb.gv.at

16. Changes to This Privacy Policy

I may update this Privacy Policy from time to time, especially if legal requirements, technical tools, or service providers change.

The current version is always available on this page.

Last updated: 14.06.2026

Stay in touch

Questions or thoughts?
I'd love to hear from you.

© 2026 Eat Healthy with Johanna

info@eatwellwithjohanna.com