Privacy Policy (Practitioners)
Last updated: 11 September 2026
Who we are & the two roles
The Holohabits Nutrition OS platform is operated by Biohacker Center Platform OÜ (registry code 16795881), registered in Estonia at Tööstuse 43-100, 10411 Tallinn, Estonia (“Holohabits”, “we”, “us”). This notice covers your data as a practitioner. For your clients’ data that you manage on the platform, you are the controller and we act as your processor under the Data Processing Agreement; your clients have their own privacy notice. For product improvement, anonymised statistics, and security, we are an independent controller.
Practitioner data we process
- Account data: name, email, phone, hashed password, role, and optional two-factor authentication data.
- Usage and security data: sign-in and access-audit logs of staff/practitioner access to client data.
- Billing data where a paid plan applies.
Why we process it and our lawful basis
- To provide the platform to you and operate your account: performance of a contract (Art. 6(1)(b)).
- To keep the platform secure and improve it: legitimate interest (Art. 6(1)(f)).
- To meet accounting and tax obligations: legal obligation (Art. 6(1)(c)).
Your clients' data
We process customer information and biomarker data only on your documented instructions to provide storage, enrichment, AI-assisted analysis, scheduling and results delivery. Biomarker results and lifestyle information are special-category data under Art. 9. The full terms are in the Data Processing Agreement. You are responsible for having a lawful basis (your client’s consent) for each client whose data you access.
Sub-processors & transfers
Our EU-based processors for biomarker analysis, results delivery and search are Microsoft Azure OpenAI (Sweden) for AI analysis, Brevo (France) for transactional email, and Qdrant (EU) for search (query embeddings only). Client identifiers are removed before any AI model call. Biomarker data and consultation notes are excluded from third-party calendar events. Our databases and file storage are self-hosted on our own premises. Transfers of other information outside the EEA rely on an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses. The full list is in the DPA.
Transfers to Sentry in the United States require only technical data for crash and error monitoring, with no identifiable personal information required. We disable default collection of personal information and remove request and user details before sending monitoring events to Sentry.
Retention
We keep your account information while your account is active. You can request access to and erasure of your personal information at any time. Access-audit logs are kept for 730 days. Records of consent and the fact of an erasure are kept as proof of compliance, and accounting records for as long as tax law requires.
Your rights
As a data subject in respect of your own account data, you have the right to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. To exercise them, use our contact page. You may also lodge a complaint with the Estonian or your local data protection authority.