Data Processing Agreement (Practitioner)

Last updated: 14 July 2026

Parties

  • Controller: the Practitioner (the professional using Holohabits to advise their clients).
  • Processor: Biohacker Center Platform OÜ (registry code 16795881, registered in Estonia; address Tööstuse 43-100, 10411 Tallinn, Estonia), operating the Holohabits platform (“Holohabits”, “we”). Privacy contact: our contact page.

Where Holohabits processes client personal data on the Practitioner’s behalf and instructions, Holohabits acts as processor and the Practitioner as controller. For our own purposes — product improvement, anonymised statistics, and security — we are an independent controller; those uses are described in the Privacy Policy.

1. Subject matter, duration, nature and purpose

  • Subject matter:processing of the Practitioner’s clients’ personal data, including special-category health data (biomarker results and lifestyle intake), to provide the Holohabits platform (storage, enrichment, AI-assisted analysis, scheduling, results delivery).
  • Duration:for the term of the Practitioner’s use of the platform and until data is deleted per section 7.
  • Nature/purpose: hosting, analysis, and delivery of biomarker and consultation data as directed by the Practitioner.

2. Categories of data subject and personal data

  • Data subjects:the Practitioner’s clients (customers).
  • Personal data: name, email, phone, date of birth, sex, body metrics, city/country; special category: biomarker values, allergies, lifestyle/diet.

3. Processor obligations (Art. 28(3))

Holohabits shall: (a) process personal data only on the Practitioner’s documented instructions; (b) ensure persons authorised to process are under confidentiality; (c) implement the security measures in section 6; (d) respect the sub-processor conditions in section 4; (e) assist the Practitioner in responding to data-subject requests (access, export, and erasure are available in the app); (f) assist with security, breach-notification, and DPIA obligations; (g) delete or return personal data at the end of the service per section 7; and (h) make available information to demonstrate compliance and allow audits.

4. Sub-processors

The Practitioner gives general authorisation for the sub-processors listed in the platform’s sub-processor register (see the Privacy Policy). Current health-data sub-processors: Microsoft Azure OpenAI (EU/Sweden) for AI analysis, Brevo (EU/France) for transactional email, and Qdrant Cloud (EU) for vector search (query embeddings only). Optional/marketing services: Google Calendar, Zoom, Meta, Sentry, Cohere, and Tavily — client identifiers are stripped before any such call. Self-hosted infrastructure (PostgreSQL, MinIO, Redis) runs on our own premises and is not a sub-processor. We will give notice of intended additions or replacements and allow the Practitioner to object.

5. International transfers

Health-data processing is EU-hosted. Where a sub-processor handling other (non-health) data is outside the EEA, transfers rely on an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses.

6. Security measures (Art. 32)

Access control and role-based authorisation; encryption in transit; JWT auth with two-factor authentication; PII redaction before any LLM call; health data kept out of third-party calendar events; access-audit logging of staff access to client data; retention limits; and least-privilege data minimisation.

7. Return and deletion

On termination, or on a data-subject erasure request, personal data is deleted across the database, object storage, and caches (in-app right-to-erasure). Backups age out under the retention schedule.

8. Data-subject rights

The platform provides staff-operated export (portability) and erasure functions per client, and records consent in an auditable register.

Accepted in-app by the Practitioner and recorded with version, timestamp, and IP address in the consent register. This acceptance forms the operative agreement between the parties for the processing described above.