Data Processing Agreement (Practitioner)
Last updated: 14 July 2026
Parties
- Controller: the Practitioner (the professional using Holohabits to advise their clients).
- Processor: Biohacker Center Platform OÜ (registry code 16795881, registered in Estonia; address Tööstuse 43-100, 10411 Tallinn, Estonia), operating the Holohabits platform (“Holohabits”, “we”). Privacy contact: our contact page.
Where Holohabits processes client personal data on the Practitioner’s behalf and instructions, Holohabits acts as processor and the Practitioner as controller. For our own purposes — product improvement, anonymised statistics, and security — we are an independent controller; those uses are described in the Privacy Policy.
1. Subject matter, duration, nature and purpose
- Subject matter:processing of the Practitioner’s clients’ personal data, including special-category health data (biomarker results and lifestyle intake), to provide the Holohabits platform (storage, enrichment, AI-assisted analysis, scheduling, results delivery).
- Duration:for the term of the Practitioner’s use of the platform and until data is deleted per section 7.
- Nature/purpose: hosting, analysis, and delivery of biomarker and consultation data as directed by the Practitioner.
2. Categories of data subject and personal data
- Data subjects:the Practitioner’s clients (customers).
- Personal data: name, email, phone, date of birth, sex, body metrics, city/country; special category: biomarker values, allergies, lifestyle/diet.
3. Processor obligations (Art. 28(3))
Holohabits shall: (a) process personal data only on the Practitioner’s documented instructions; (b) ensure persons authorised to process are under confidentiality; (c) implement the security measures in section 6; (d) respect the sub-processor conditions in section 4; (e) assist the Practitioner in responding to data-subject requests (access, export, and erasure are available in the app); (f) assist with security, breach-notification, and DPIA obligations; (g) delete or return personal data at the end of the service per section 7; and (h) make available information to demonstrate compliance and allow audits.
4. Sub-processors
The Practitioner gives general authorisation for the sub-processors listed in the platform’s sub-processor register (see the Privacy Policy). Current health-data sub-processors: Microsoft Azure OpenAI (EU/Sweden) for AI analysis, Brevo (EU/France) for transactional email, and Qdrant Cloud (EU) for vector search (query embeddings only). Optional/marketing services: Google Calendar, Zoom, Meta, Sentry, Cohere, and Tavily — client identifiers are stripped before any such call. Self-hosted infrastructure (PostgreSQL, MinIO, Redis) runs on our own premises and is not a sub-processor. We will give notice of intended additions or replacements and allow the Practitioner to object.
5. International transfers
Health-data processing is EU-hosted. Where a sub-processor handling other (non-health) data is outside the EEA, transfers rely on an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses.
6. Security measures (Art. 32)
Access control and role-based authorisation; encryption in transit; JWT auth with two-factor authentication; PII redaction before any LLM call; health data kept out of third-party calendar events; access-audit logging of staff access to client data; retention limits; and least-privilege data minimisation.
7. Return and deletion
On termination, or on a data-subject erasure request, personal data is deleted across the database, object storage, and caches (in-app right-to-erasure). Backups age out under the retention schedule.
8. Data-subject rights
The platform provides staff-operated export (portability) and erasure functions per client, and records consent in an auditable register.
Accepted in-app by the Practitioner and recorded with version, timestamp, and IP address in the consent register. This acceptance forms the operative agreement between the parties for the processing described above.