HairDraw — Data Processing Agreement (DPA)
Last updated:
Version legal-2026-10-01.2 — effective October 1, 2026
Between the Clinic ("Controller") and HairDraw, operated by Yaakov Lopes (sole proprietor), Be'er Sheva, Israel ("Processor"), forming part of the Terms of Service.
1. Roles and scope
1.1 For Patient Data, the Clinic is the controller and HairDraw is the processor. HairDraw processes Patient Data only on the Clinic's documented instructions, which are these Terms, this DPA and the Clinic's use of app settings.
1.2 Separate controller processing. If, and only if, §9 is activated, HairDraw processes a de-identified derivative of certain images for its own product improvement. For that processing HairDraw is an independent controller, not a processor, and is solely responsible for having its own legal basis, transparency and rights handling. This is not an instruction from the Clinic and is not covered by the processor obligations below.
1.3 Details of processing are in Annex I.
2. Processor obligations
HairDraw will:
(a) process Patient Data only on documented instructions, including for transfers, unless law requires otherwise (and then inform the Clinic unless prohibited);
(b) inform the Clinic if it believes an instruction infringes data-protection law;
(c) ensure personnel with access are bound by confidentiality and trained;
(d) implement the measures in Annex II;
(e) assist the Clinic, taking into account the nature of processing, with data-subject requests, security, breach notification, DPIAs and prior consultation;
(f) make available information needed to demonstrate compliance and allow audits (§7);
(g) not sell Patient Data, not use it for its own purposes (except §9 as a separate controller) and not combine it with other clients' data.
3. Subprocessors
3.1 The Clinic gives general authorization to the subprocessors in Annex III.
3.2 HairDraw will notify the Clinic at least 30 days before adding or replacing a subprocessor (by e-mail to the Clinic and on hairdraw.app/subprocessors). The Clinic may object on reasonable data-protection grounds; if unresolved, the Clinic may terminate the affected service and receive a pro-rata refund of prepaid fees.
3.3 HairDraw will impose on each subprocessor obligations no less protective than this DPA and remains liable for them.
3.4 The cloud AI provider may change. Any replacement must contractually (i) not train on Clinic content, (ii) limit retention, and (iii) offer transfer safeguards.
4. Security
Measures in Annex II, reviewed at least annually and whenever the architecture changes (e.g. launch of the server archive).
5. Personal data breach
5.1 HairDraw will notify the Clinic without undue delay and in any case within 48 hours after becoming aware of a breach affecting Patient Data, with: nature, categories and approximate numbers, likely consequences, measures taken/proposed, and a contact. Information may be provided in phases.
5.2 HairDraw will not notify authorities or patients on the Clinic's behalf unless instructed or required by law. (Note deadlines on the Clinic side: GDPR 72 h; LGPD 3 business days (Res. CD/ANPD 15/2024); Israel "immediately" for severe events; Korea PIPA 72 h.) US only: where HIPAA applies, breach reporting follows the BAA.
5.3 Contacts: the Clinic reports suspected security incidents to security@hairdraw.app and data-protection matters to privacy@hairdraw.app; HairDraw sends breach notices to the Clinic's registered contact.
6. Deletion and return
6.1 The Clinic can delete patients at any time in the app. Deleted patients go to a Trash, where the Clinic can restore them for 15 days; after that they are permanently erased with their photos and results. If the Clinic has enabled online services (when available), deletion propagates to the server archive within 30 days, including backups within 35 days.
6.2 Retention tied to the subscription. HairDraw keeps Patient Data on its servers only while the Clinic's subscription (or free trial) is active. If a renewal payment fails, the Clinic keeps full access for a 30-day grace period. After the grace period, or at the end of the paid period of a cancelled subscription, or at the end of a free trial without a subscription, the Clinic's account becomes read-only for 90 days (view and export only), and HairDraw notifies the Clinic's owners by e-mail and in the app 30, 7 and 1 days before deletion. At the end of the 90 days HairDraw permanently deletes all Patient Data and the Clinic's audit, consent and user records from its servers, certifying on request. By accepting the Terms, the Clinic instructs HairDraw to delete the data in this way (Art. 28(3)(g) GDPR). Paying again before the deletion date restores full access and cancels the deletion.
6.3 After the deletion HairDraw keeps no Patient Data. It keeps only the minimum billing record required by tax and accounting law, anonymized, and, to prevent repeated free trials, a salted hash of the e-mail address and user ID of the person who started a trial, for 24 months (Privacy Policy §7).
6.4 The Clinic may instruct earlier deletion in Settings › Data retention (patients without activity for 6, 12 or 24 months, which go through the Trash first). It cannot instruct HairDraw to keep data beyond the subscription.
6.5 Record keeping is the Clinic's responsibility. Where record-keeping laws (for example medical-record rules) require the Clinic to keep records for longer, the Clinic must export them, during the subscription or the read-only period, and keep them itself. HairDraw is not a record-keeping service.
6.6 Data on the Clinic's devices (iPad or iPhone) is under the Clinic's control; uninstalling the app deletes the local encrypted store.
7. Audits
HairDraw provides, on request, its security documentation, relevant certifications or third-party reports and answers to reasonable questionnaires. On-site or remote audits by the Clinic or its auditor: once per year, 30 days' notice, at the Clinic's cost, under confidentiality, not disrupting operations; more often after a breach or regulator request.
8. International transfers
8.1 Where Patient Data subject to GDPR is transferred to a country without adequacy, the EU SCCs Module 2 (Clinic→HairDraw) apply and are incorporated by reference, with: Clause 7 docking included; Clause 9 option 2 (general authorization, 30 days); Clause 11 optional redress not included; Clause 17 law of Ireland; Clause 18 courts of Ireland. Annexes I–III of this DPA serve as the SCC annexes. HairDraw uses Module 3 with its subprocessors.
8.2 UK: the ICO International Data Transfer Addendum. Switzerland: FDPIC adjustments.
8.3 Brazil: the ANPD standard contractual clauses (Res. CD/ANPD 19/2024), incorporated by reference as set out in Annex IV.
8.4 Korea, Israel and other countries: the transfer mechanisms set out in Annex IV.
8.5 HairDraw keeps a transfer impact assessment available on request.
9. Product improvement with de-identified images (optional)
9.1 Status: OFF by default. It applies only to patients for whom the Clinic records the optional product-improvement consent, and it is not available in the US region.
9.2 What: images from which the name and identifiers are removed and the eyes are blurred, plus non-identifying labels (simulation type such as hair, beard or eyebrows, age band, sex, rating of the simulation).
9.3 Conditions: only for patients for whom the Clinic has recorded the specific product-improvement consent; no re-identification attempts; access limited to named staff; not shared outside HairDraw and its processors; not used to train third-party models; deletion on withdrawal where technically feasible.
9.4 Important: a blurred-eye face is generally still personal (pseudonymised) data under GDPR/LGPD. This processing therefore requires its own legal basis and transparency; it is not "anonymous" unless a documented anonymisation assessment concludes otherwise. US only: this processing is not offered to clinics in the US region.
9.5 The Clinic may switch this off at any time for future data.
9.6 This processing is separate from the cloud AI provider, which does not use Clinic content to train its models (§3.4, Annex III).
10. Liability, term, precedence
Liability per the Terms (§10). This DPA lasts as long as HairDraw processes Patient Data. The operator (Yaakov Lopes, sole proprietor) may assign or transfer this DPA to a successor company operating HairDraw together with the Terms, with prior written notice to the Clinic and without a new signature; the successor assumes all Processor obligations unchanged. In conflict: SCCs > this DPA > Terms.
Annex I — Description of processing
- Controller: the Clinic that accepted these Terms. Processor: HairDraw.
- Data subjects: patients and prospective patients of the Clinic; Clinic users.
- Categories: identification (name, sex, age, optional contact); patient images (facial/head photos); the doctor's notes and drawings (including drawing masks); simulations and reports; consent/audit records.
- Sensitive data: patient images (facial/head photos) may be sensitive or biometric data under some laws, although HairDraw does not process them to identify anyone; they receive the protections in Annex II. The Service is an illustrative visual simulation tool, not a health, medical or clinical tool.
- Nature: capture, encrypted storage, transmission of the whole photo and the drawing mask (no name or identifiers) to the AI provider for generation, return and display, report generation, archive/backup on the server (when available and enabled by the Clinic), deletion.
- Purpose: provide the illustrative visual simulation Service to the Clinic.
- Frequency: continuous. Duration: the subscription (or free trial), plus a 30-day grace period after a failed payment and a 90-day read-only period for export (§6.2).
- Retention: only while the subscription is active, then deletion as in §6 and Privacy Policy §7.
Annex II — Technical and organisational measures
Items 1–10 describe what HairDraw does today. Items marked planned are not yet in place.
- Encryption at rest on the Clinic's devices (iPad or iPhone): patient records and photos are stored with iOS Data Protection, Complete Protection class (hardware-backed encryption; readable only while the device is unlocked), and are excluded from iCloud and computer backups. Files the Clinic exports use the same protection.
- Encryption in transit: TLS (iOS App Transport Security) for every request to the AI provider.
- Data minimisation: the whole photo and a separate mask/reference image of the doctor's drawing are sent for generation; no name or other identifiers in AI requests.
- Access control: app lock with Face ID or the device passcode (optional on opening, required again after a few minutes in the background) and confirmation with Face ID or passcode for sensitive actions such as exports, deletions and advanced settings; the Clinic keeps a passcode on every device (Terms §6.2).
- Audit trail: consent attestation (text version, doctor, date/time), generation events, credit refunds, exports and deletions, in a hash-chained log (SHA-256), so that editing or deleting an event breaks the chain.
- Output integrity: "Illustrative simulation" notice embedded in every generated image and every PDF page; exports cannot remove it.
- Validation of generated images: every image returned by the AI provider must pass an integrity check (a valid, readable image) and, where applicable, a pose check (the AI must not turn the head or add a face) before it is saved; rejected images are discarded, their credits refunded, and the event is recorded in the audit trail.
- Secrets: the AI provider key is kept in the iOS Keychain (this device only, only while unlocked) and is never written to logs.
- Personnel and process: confidentiality agreements, least privilege, training, dependency updates, internal security review before releases, and an incident response plan.
- Online services (web app, and the iPad/iPhone apps when signed in): per-user login and role-based access; server storage of Patient Data with per-clinic tenant isolation (row-level security, private file storage with short-lived signed links), EU region; AI requests routed through a HairDraw server so that no provider key is kept on devices; TLS to the server. Planned: documented backup retention and full sync of the iPad/iPhone apps with the server.
- Planned: periodic independent penetration tests.
- These measures are reviewed at least annually and whenever the architecture changes.
Annex III — Subprocessors
Subprocessors are listed by category:
| Category | Service | Data | Location | Safeguard |
|---|---|---|---|---|
| Cloud AI provider | image generation | whole photo + drawing mask/reference image, prompt (no name or identifiers) | US / global | provider data-processing terms; SCCs; no training on submitted content; abuse-monitoring retention of up to ~55 days |
| Hosting, database and file storage | authentication, database and file storage | Clinic user accounts and Patient Data stored on the server (encrypted) | EU | DPA + SCCs |
| Website and e-mail | website, support e-mail | Clinic contact and support data; no Patient Data | EU | DPA |
| Payment provider | billing (when available) | Clinic billing data only | UK | own controller terms |
| App distribution | app store distribution | no Patient Data | US | own terms |
The current list of subprocessors, with company names, is published at hairdraw.app/subprocessors.
Annex IV — Other transfer mechanisms
Where Patient Data leaves a country whose law requires a specific transfer mechanism, the following are incorporated into this DPA by reference and prevail over it in case of conflict. The Clinic is the exporter and HairDraw the importer; HairDraw applies equivalent mechanisms to onward transfers to its subprocessors.
- Brazil (LGPD): the ANPD standard contractual clauses (Resolution CD/ANPD 19/2024), in their full, unmodified text.
- Korea (PIPA): a basis provided by PIPA for overseas transfers, in particular the patient's separate consent collected by the Clinic, with the information PIPA requires (items transferred, destination country, timing and method, recipient, purpose and retention period).
- Israel: the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, including HairDraw's written undertaking to protect the data and not to transfer it onward except under the same conditions.
- EU/EEA, UK and Switzerland: as set out in §8.1 and §8.2.
- Other countries: the mechanism required by local law, agreed in writing between the Clinic and HairDraw before the transfer.