Privacy Policy (Practitioners)
Last updated: 14 July 2026
Who we are & the two roles
The Holohabits Nutrition OS platform is operated by Biohacker Center Platform OÜ(registry code 16795881), registered in Estonia at Tööstuse 43-100, 10411 Tallinn, Estonia (“Holohabits”, “we”, “us”). This notice covers your data as a practitioner. For your clients’ data that you manage on the platform, you are the controller and we act as your processor under the Data Processing Agreement; your clients have their own privacy notice. For our own purposes — product improvement, anonymised statistics, and security — we are an independent controller.
Practitioner data we process
- Account data — name, email, phone, hashed password, role, and optional two-factor authentication data.
- Usage & security data — sign-in and access-audit logs of staff/practitioner access to client data.
- Billing data where a paid plan applies.
Why we process it and our lawful basis
- To provide the platform to you and operate your account — performance of a contract (Art. 6(1)(b)).
- To keep the platform secure and improve it — legitimate interest (Art. 6(1)(f)).
- To meet accounting and tax obligations — legal obligation (Art. 6(1)(c)).
Your clients' data
We process your clients’ personal and special-category health data only on your documented instructions to provide the platform (storage, enrichment, AI-assisted analysis, scheduling, results delivery). The full terms are in the Data Processing Agreement. You are responsible for having a lawful basis — your client’s consent — for each client whose data you access.
Sub-processors & transfers
Health-data processing is EU-hosted: Microsoft Azure OpenAI (Sweden) for AI analysis, Brevo (France) for transactional email, and Qdrant (EU) for search (query embeddings only). Client identifiers are stripped before any AI model call, and health data is kept out of third-party calendar events. Our databases and file storage are self-hosted on our own premises. Any other transfer (not related to health-data) outside the EEA relies on an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses. The full list is in the DPA.
Retention
We keep your account data while your account is active and delete it on request or under our retention schedule. Records of consent and the fact of an erasure are kept as proof of compliance.
Your rights
As a data subject in respect of your own account data, you have the right to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. To exercise them, use our contact page. You may also lodge a complaint with the Estonian or your local data protection authority.