Definitions

"Controller" means the Customer organization that determines the purposes and means of processing personal data and engages PDL as a Processor.
"Processor" means PsyData Labs L.L.C. in its capacity as a data processor acting on documented instructions from the Controller.
"Sub-processor" means any third party engaged by PDL to process personal data on behalf of the Controller.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
"Data Subject Rights Request" means a formal request from a data subject to exercise rights under applicable data protection law.
"Standard Contractual Clauses (SCCs)" means the standard contractual clauses adopted by the European Commission for international transfers of personal data.
"Technical and Organizational Measures (TOMs)" means the security and procedural safeguards implemented by PDL to protect personal data.

Roles and Scope

Customer is the Data Controller. PsyData Labs L.L.C. is the Data Processor (or Sub-processor where a third party acts as primary processor). PDL shall process personal data only on documented instructions from Controller, unless required to do so by applicable law. PDL shall promptly inform Controller if it believes any instruction violates applicable data protection law.

Processing Obligations

PDL shall process personal data only as necessary to fulfill the Service and in accordance with Controller's documented instructions;
PDL shall ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations;
PDL shall implement Technical and Organizational Measures (TOMs) appropriate to the risk, including encryption, pseudonymization, access controls, and incident response procedures;
TOMs shall be reviewed and updated regularly to reflect the state of the art.

Sub-processors

PDL shall maintain and provide Controller with a list of approved Sub-processors. PDL shall inform Controller of intended changes to Sub-processors with reasonable prior notice. Controller may object to new Sub-processors on reasonable grounds; in such case, the parties shall work in good faith to resolve the objection. PDL shall impose data protection obligations on Sub-processors equivalent to those in this DPA.

Data Subject Rights Assistance

PDL shall assist Controller in responding to Data Subject Rights Requests, including access, rectification, erasure, restriction, portability, and objection requests. PDL shall promptly forward to Controller any Data Subject Rights Requests received directly and shall cooperate to enable Controller to fulfill its obligations within applicable statutory timeframes.

Data Breach Notification

PDL shall notify Controller within seventy-two (72) hours of discovering a Personal Data Breach. Notification shall include, to the extent available: the nature of the breach; categories and approximate number of Data Subjects affected; categories and approximate number of records affected; likely consequences; and measures taken or proposed to address the breach. PDL shall cooperate with Controller in investigating, mitigating, and notifying regulatory authorities and Data Subjects as required by law.

Deletion and Return of Data

Upon termination of the service relationship, PDL shall, at Controller's election, delete or return all personal data processed under this DPA within a commercially reasonable timeframe. PDL shall provide written certification of deletion upon Controller's request. PDL may retain data where required by applicable law, in which case it shall notify Controller of the legal basis for retention.

Audit Rights

Controller may audit or commission audits of PDL's data processing activities upon reasonable notice, no more than once per year absent a suspected breach. PDL may require auditors to sign appropriate confidentiality agreements prior to audit. PDL shall provide all reasonably requested documentation and cooperation.

International Transfers

Where personal data is transferred outside the European Economic Area, the United Kingdom, or another jurisdiction with adequacy protection, such transfers shall be subject to Standard Contractual Clauses (SCCs) in the form approved by the European Commission, or such other approved mechanism as may be required by applicable law. PDL shall maintain a record of cross-border transfer mechanisms.

GDPR Article 28 Compliance

This DPA is intended to satisfy the requirements of GDPR Article 28 for contracts between Controllers and Processors. All provisions herein shall be interpreted to achieve compliance with GDPR Article 28 obligations to the extent applicable.

HIPAA BAA Provisions

Where PDL processes Protected Health Information on behalf of a HIPAA Covered Entity, the parties shall execute a separate Business Associate Agreement (BAA) compliant with 45 CFR Part 164, Subpart E. This DPA does not substitute for or supersede a required BAA. PHI processing obligations under HIPAA shall be governed exclusively by the applicable BAA.

Termination

This DPA terminates upon termination of the underlying service agreement between PDL and Controller. Data deletion obligations in Section 16 survive termination.

Warranty Disclaimer

PDL MAKES NO WARRANTY THAT ITS TECHNICAL AND ORGANIZATIONAL MEASURES WILL PREVENT ALL PERSONAL DATA BREACHES. PDL WARRANTS THAT IT WILL IMPLEMENT MEASURES CONSISTENT WITH THE OBLIGATIONS SET FORTH IN THIS DPA AND APPLICABLE LAW.

Limitation of Liability

PDL'S LIABILITY UNDER THIS DPA SHALL BE SUBJECT TO THE LIMITATION OF LIABILITY SET FORTH IN THE UNDERLYING SERVICE AGREEMENT. PDL IS NOT LIABLE FOR PERSONAL DATA BREACHES RESULTING FROM CONTROLLER'S INSTRUCTIONS, CONTROLLER'S SECURITY FAILURES, OR THIRD-PARTY ACTIONS BEYOND PDL'S REASONABLE CONTROL.

Indemnification

Each party shall indemnify the other from claims arising from that party's breach of this DPA, failure to comply with applicable data protection law, or negligent or willful acts in connection with personal data processing.

Governing Law

This DPA shall be governed by the laws of Madison County, New York State, United States, subject to mandatory requirements of applicable data protection law.

Contact Information

PsyData Labs L.L.C. | legal@psydata.org | https://www.psydata.net

Project-Specific Schedule — Schedule A

Field Value
Controller Name [CUSTOMER ORGANIZATION NAME]
Processor Name PsyData Labs L.L.C.
Nature of Processing [DESCRIBE PROCESSING ACTIVITIES]
Categories of Data [LIST DATA CATEGORIES]
Data Subjects [LIST DATA SUBJECT CATEGORIES]
Transfer Mechanism [SCCs / ADEQUACY DECISION / OTHER]
Retention Period [RETENTION PERIOD]
Expiration Date [EXPIRATION DATE]

Document Metadata