Clinic Data Sharing Agreement
Clinic Data-Sharing Agreement
Between ScalarRatio LLC (HairLinQ) and the Clinic Last updated: 4 September 2026
This Clinic Data-Sharing Agreement ("Agreement") governs the sharing of prospective-patient personal data between ScalarRatio LLC, operating the HairLinQ platform, 75 E 3rd St, Sheridan, WY 82801, United States ("HairLinQ"), and the Clinic that receives that data. It forms part of the Clinic Terms. HairLinQ is a brand of ScalarRatio LLC.
1. Roles
HairLinQ and the Clinic each act as an independent controller. HairLinQ is the controller for collecting prospective-patient data and matching it to clinics. The Clinic becomes an independent controller of the data it receives, for the purpose of responding to the prospective patient and, if engaged, providing treatment. Neither party is the other's processor, and this is not joint control.
2. What is shared, and why
HairLinQ shares a prospective patient's request with the Clinic only when the prospective patient has opted in to receive the Clinic's quote. The data shared may include identity and contact details, the request details, health information about the person's hair and scalp, and photographs of the head or scalp. The purpose is to enable the Clinic to assess the request, provide a quote, and, if the prospective patient engages the Clinic, provide treatment.
3. Lawful basis and transparency
HairLinQ obtains the prospective patient's explicit consent to process their health data and to share it with the Clinic and transfer it to Turkey. The Clinic is responsible for its own lawful basis for its further processing, for its own transparency to the individual, and for compliance with Turkish data-protection law (KVKK).
4. International transfer (Standard Contractual Clauses)
The Clinic is located in Turkey, which does not have an EU adequacy decision. The transfer of prospective-patient data from HairLinQ to the Clinic is therefore made under the EU Standard Contractual Clauses, Module One (controller to controller), set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which are incorporated into this Agreement and completed in Appendix 1. HairLinQ is the data exporter and the Clinic is the data importer.
5. Security
Each party will implement appropriate technical and organisational measures to protect the data, at least equivalent to those in Annex II to Appendix 1. HairLinQ hosts prospective-patient data in the European Union (Germany).
6. Personal data breach
Each party will notify the other without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the shared data, and will cooperate in good faith so each party can meet its own notification obligations.
7. Retention and deletion
HairLinQ retains and deletes prospective-patient data as described in its Patient Privacy Statement. The Clinic keeps the data only as long as necessary for the purposes in section 2 and its own legal obligations, and then deletes or anonymises it.
8. Data-subject requests and complaints
Each party handles requests from individuals (such as access, erasure, or objection) for the data it controls, and forwards to the other any request that clearly concerns the other party's processing, so it can be handled without undue delay.
9. Liability
Each party is responsible for its own compliance with data-protection law and for loss it causes by its own breach. As between the parties, neither is liable for the other's independent processing. The third-party-beneficiary and liability provisions of the Standard Contractual Clauses apply as stated in those clauses.
10. Term
This Agreement applies for as long as the Clinic uses HairLinQ and for as long as it holds prospective-patient data received through HairLinQ. Termination of the Clinic Terms does not end the Clinic's obligations for data it still holds.
11. Governing law and jurisdiction
This Agreement and the Standard Contractual Clauses in Appendix 1 are governed by the law of the Netherlands, and disputes relating to them fall to the courts of the Netherlands, as required by the clauses. (This is separate from the arbitration provision in the Clinic Terms, which governs commercial disputes.)
Appendix 1: EU Standard Contractual Clauses
(Module One, controller to controller)
The parties adopt the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module One, with the following selections:
Clause 7 (docking clause): included.
Clause 11 (optional independent dispute-resolution body): not selected.
Clause 17 (governing law): the law of the Netherlands.
Clause 18 (choice of forum and jurisdiction): the courts of the Netherlands.
Annex I
A. List of parties
Data exporter:
Name: ScalarRatio LLC (operating the HairLinQ platform)
Address: 75 E 3rd St, Sheridan, WY 82801, United States
Contact: hairlinq.com/contact
Activities relevant to the transfer: operating a comparison and introduction platform that matches prospective patients to clinics
Role: controller
Data importer:
Identity: the Clinic that registers for and uses HairLinQ and accepts this Agreement. The Clinic's legal name, address, contact details, and Authorization Certificate number, as provided by the Clinic during registration and held in its clinic account, complete this entry and form part of this Agreement for that Clinic.
Activities relevant to the transfer: providing hair-transplant consultation and treatment to prospective patients who opt in
Role: controller
B. Description of transfer
Categories of data subjects: prospective patients who opt in to receive the importer's quote.
Categories of personal data: identity and contact details (such as name, email, phone, country), request details, and health information about the person's hair and scalp.
Special categories of data: health data, including photographs of the head or scalp. Applied safeguards: explicit consent, purpose limitation, access controls, and encryption.
Frequency of the transfer: on a continuous basis, each time a prospective patient opts in.
Nature and purpose: to enable the importer to assess the request, provide a quote, and, if engaged, provide treatment.
Retention: for as long as necessary for that purpose and the importer's legal obligations.
C. Competent supervisory authority
The Netherlands Data Protection Authority (Autoriteit Persoonsgegevens), as the data exporter is established in the Netherlands.
Annex II: Technical and organisational measures
Encryption of data in transit and at rest.
Role-based access control and least-privilege access, with authenticated accounts.
EU hosting of prospective-patient data (Germany) by the exporter.
Logging of access to personal data.
Staff bound by confidentiality and given data-protection instructions.
Data minimisation and purpose limitation.
Secure deletion at the end of the retention period.
A personal data breach procedure, including notification as set out in section 6.
The importer applies measures at least equivalent to the above to the data it receives.