Data Processing Agreement
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or Terms of Service (the "Agreement") between PsyData Labs L.L.C., a New York limited liability company ("PDL" or "Processor"), and the customer entity executing the Agreement ("Customer" or "Controller"). This DPA governs the Processing of Personal Data by PDL on behalf of Customer in providing the Services.
1. Definitions
- "Applicable Data Protection Laws" means all laws and regulations applicable to PDL's Processing of Personal Data under the Agreement, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CPRA"), and the New York SHIELD Act.
- "Behavioral Data (D-BEH)" means observable interaction data (sessions, tasks, navigation, device context) used to model usage patterns, excluding raw clinical diagnoses unless separately classified.
- "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
- "Inference Output (D-INF)" means any score, label, segment, or profile produced by automated or hybrid human-AI processing.
- "Personal Data" means any information relating to an identified or identifiable natural person processed by PDL on behalf of Customer pursuant to the Agreement.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
- "Processor" means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.
- "Psychological Signal (D-PSY)" means measured or self-reported constructs (mood proxies, cognitive load, scale responses) processed for analytics or model features.
- "Subprocessor" means any third party engaged by PDL to Process Personal Data.
2. Scope and Roles
2.1 Roles of the Parties. The parties acknowledge and agree that with regard to the Processing of Personal Data, Customer is the Controller and PDL is the Processor. PDL will Process Personal Data solely in accordance with Customer's documented instructions as set forth in the Agreement and this DPA.
2.2 Customer Responsibilities. Customer warrants that it has all necessary rights, lawful bases, and consents to provide the Personal Data to PDL for the Processing contemplated by the Agreement.
3. Customer Instructions and Processing Restrictions
3.1 Documented Instructions. PDL shall Process Personal Data only on the documented instructions of Customer, unless required to do so by applicable law to which PDL is subject.
3.2 Behavioral and Psychological Data. PDL processes Behavioral Data (D-BEH) and Psychological Signals (D-PSY) strictly for the provision of the Services. PDL shall not use raw Psychological Signals (D-PSY) for advertising targeting under any circumstances.
3.3 AI and Inference Processing. Models affecting sensitive data must undergo Human-in-the-Loop (HITL) review for high-risk psychological profiles (H-RP). PDL shall not engage in fully automated denial of service, employment, or insurance decisions based on Inference Outputs (D-INF).
4. California Privacy Rights Act (CPRA) Service Provider Terms
4.1 Service Provider Status. PDL is acting as a "Service Provider" as defined under the CPRA.
4.2 Processing Prohibitions. PDL certifies that it shall not:
- Sell or Share the Personal Data;
- Retain, use, or disclose the Personal Data for any purpose other than for the specific purpose of performing the Services specified in the Agreement;
- Retain, use, or disclose the Personal Data outside of the direct business relationship between PDL and Customer; or
- Combine Personal Data received from Customer with Personal Data received from other sources, except as explicitly permitted under the CPRA.
4.3 Compliance. PDL certifies that it understands the restrictions in this Section 4 and will comply with them.
5. Security and Confidentiality
5.1 Security Measures. PDL shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and logging, compliant with the NY SHIELD Act, SOC 2, and ISO 27001 standards.
5.2 Confidentiality. PDL shall ensure that persons authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Personal Data Breach Notification
6.1 Notification. In the event of a Personal Data Breach, PDL shall notify Customer without undue delay, and in no event later than seventy-two (72) hours after becoming aware of the Personal Data Breach.
6.2 Remediation and Assistance. PDL will promptly investigate the Personal Data Breach, take all necessary and advisable corrective actions, and provide Customer with reasonable assistance and information to enable Customer to meet its breach notification obligations under Applicable Data Protection Laws.
7. Subprocessing
7.1 General Authorization. Customer grants PDL general authorization to engage Subprocessors, subject to the conditions of this Section.
7.2 Subprocessor Obligations. PDL shall enter into a written agreement with each Subprocessor imposing data protection terms that require the Subprocessor to protect Personal Data to the standard required by this DPA.
7.3 Notice of Changes. PDL shall inform Customer of any intended changes concerning the addition or replacement of Subprocessors, giving Customer the opportunity to object to such changes.
8. Data Subject Rights
8.1 Assistance. Taking into account the nature of the Processing, PDL shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising the data subject's rights (e.g., Data Subject Access Requests, or DSARs) under Applicable Data Protection Laws.
8.2 Notification of Requests. PDL shall promptly notify Customer if it receives a request directly from a data subject and shall not respond to the request directly, except to direct the data subject to Customer or as otherwise legally required.
9. Return or Deletion of Data
Upon termination or expiration of the Agreement, PDL shall, at the choice of Customer, delete or return all Personal Data to Customer, and delete existing copies unless applicable law requires storage of the Personal Data. Deletion routines shall be completed within thirty (30) days of the request.
10. Audits and Inspections
PDL shall make available to Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer.
11. Cross-Border Data Transfers
If PDL transfers Personal Data originating from the European Economic Area, Switzerland, or the United Kingdom to countries that have not received an adequacy decision, such transfers shall be subject to the applicable Standard Contractual Clauses (SCCs), which are hereby incorporated by reference.