Data Processing Agreement (Practitioner)
Last updated: 11 September 2026
Parties
- Controller: the Practitioner (the professional using Holohabits to advise their clients).
- Processor: Biohacker Center Platform OÜ (registry code 16795881, registered in Estonia; address Tööstuse 43-100, 10411 Tallinn, Estonia), operating the Holohabits platform (“Holohabits”, “we”). Privacy contact: our contact page.
Where Holohabits processes client personal data on the Practitioner’s behalf and instructions, Holohabits acts as processor and the Practitioner as controller. For product improvement, anonymised statistics, and security, we are an independent controller; those uses are described in the Privacy Policy.
1. Subject matter, duration, nature and purpose
- Subject matter: processing customer information and biomarker data on behalf of the Practitioner to provide storage, enrichment, AI-assisted analysis, scheduling and results delivery on the Holohabits platform. Biomarker results and lifestyle intake are treated as special-category data under Art. 9.
- Duration: for the term of the Practitioner’s use of the platform and until data is deleted per section 7.
- Nature/purpose: hosting, analysis, and delivery of biomarker and consultation data as directed by the Practitioner.
2. Categories of data subject and personal data
- Data subjects: the Practitioner’s clients (customers).
- Customer information: name, email, phone, date of birth, sex, body metrics, city/country. Biomarker data and lifestyle information (special category): biomarker values, allergies, lifestyle/diet.
3. Processor obligations (Art. 28(3))
Holohabits shall: (a) process personal data only on the Practitioner’s documented instructions; (b) ensure persons authorised to process are under confidentiality; (c) implement the security measures in section 6; (d) respect the sub-processor conditions in section 4; (e) assist the Practitioner in responding to data-subject requests (access, export, and erasure are available in the app); (f) assist with security, breach-notification, and DPIA obligations; (g) delete or return personal data at the end of the service per section 7; and (h) make available information to demonstrate compliance and allow audits.
4. Sub-processors
The Practitioner gives general authorisation for the sub-processors listed in the platform’s sub-processor register (see the Privacy Policy). Current sub-processors for biomarker analysis, results delivery and search: Microsoft Azure OpenAI (EU/Sweden) for AI analysis, Brevo (EU/France) for transactional email, and Qdrant Cloud (EU) for vector search (query embeddings only). Optional and marketing services: Google Calendar, Zoom, Meta, Sentry (technical crash and error monitoring), Cohere, and Tavily. Client identifiers are removed before AI model calls. Self-hosted infrastructure (PostgreSQL, MinIO, Redis) runs on our own premises and is not a sub-processor. We will give notice of intended additions or replacements and allow the Practitioner to object.
5. International transfers
Biomarker data is processed in the EU. Where a sub-processor handling other information is outside the EEA, transfers rely on an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses.
Transfers to Sentry in the United States require only technical data for crash and error monitoring, with no identifiable personal information required. We disable default collection of personal information and remove request and user details before sending monitoring events to Sentry.
6. Security measures (Art. 32)
We limit access by role and encrypt data in transit. We use token-based authentication with two-factor authentication, remove personal identifiers before AI model calls, and exclude biomarker data and consultation notes from third-party calendar events. We log staff access to customer records, apply retention limits and limit access to the information needed for each task.
7. Return and deletion
On termination, or on a data-subject erasure request, personal data is deleted across the database, object storage, and caches (in-app right-to-erasure). Backups age out under the retention schedule.
8. Data-subject rights
The platform provides staff-operated export (portability) and erasure functions per client, and records consent in an auditable register.
Accepted in-app by the Practitioner and recorded with version, timestamp, and IP address in the consent register. This acceptance forms the operative agreement between the parties for the processing described above.