PDL Logo
PDL Legal& Compliance Center
← Back to Directory
ACTIVE POLICY

Data Processing Addendum

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Master Services Agreement or other written or electronic agreement (the "Agreement") between PsyData Labs L.L.C., a Delaware limited liability company ("PDL" or "Data Processor"), and the entity or person utilizing PDL's services ("Customer" or "Data Controller").

This DPA governs the processing of personal data by PDL on behalf of the Customer in the course of providing the services described in the Agreement. By entering into the Agreement, Customer and PDL mutually agree to comply with this DPA.

1. Definitions

  • "Applicable Data Protection Laws" means all applicable privacy and data protection laws and regulations, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act of 2018 ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), and any other applicable national, state, or regional data protection laws.
  • "Customer Data" means any Personal Data processed by PDL on behalf of Customer pursuant to or in connection with the Agreement.
  • "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Subprocessor" shall have the meanings given to them in Applicable Data Protection Laws.
  • "Standard Contractual Clauses" (SCCs) means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

2. Scope and Roles

2.1 Role of the Parties. For the purposes of this DPA and Applicable Data Protection Laws, Customer acts as the Data Controller (or a Data Processor acting on behalf of a third-party Controller), and PDL acts as the Data Processor (or Subprocessor). Customer retains control of the Customer Data and remains responsible for its compliance obligations under Applicable Data Protection Laws.

2.2 Details of Processing. The subject matter, nature, purpose, and duration of the processing, as well as the types of Personal Data and categories of Data Subjects, are determined by the Customer's use of PDL's services and are further specified in Annex I of this DPA.

2.3 PDL's Obligations. PDL shall process Customer Data only in accordance with Customer's documented instructions, unless required to do so by applicable law. PDL shall immediately notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.

3. Security and Confidentiality

3.1 Technical and Organizational Measures. PDL shall implement and maintain appropriate technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to, encryption of data in transit and at rest, role-based access controls, continuous monitoring, and periodic security testing.

3.2 Personnel Confidentiality. PDL shall ensure that all personnel authorized to process Customer Data are subject to a strict duty of confidentiality, whether contractual or statutory, and receive appropriate training on data protection and security.

4. Subprocessors

4.1 Authorization of Subprocessors. Customer provides a general authorization for PDL to engage Subprocessors to process Customer Data. A current list of approved Subprocessors is made available by PDL on its trust center or legal portal.

4.2 Notice of New Subprocessors. PDL shall provide Customer with a 30-day prior written notice (via email or via an in-app notification mechanism) of any intended addition or replacement of a Subprocessor. Customer may object to the new Subprocessor on reasonable data protection grounds within 14 days of receiving notice. If the parties cannot resolve the objection, Customer may terminate the applicable services.

4.3 Subprocessor Obligations. PDL shall enter into a written agreement with each Subprocessor containing data protection obligations not less protective than those in this DPA. PDL remains fully liable for the performance of its Subprocessors.

5. Data Subject Rights

PDL shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising Data Subject rights (e.g., access, rectification, erasure, portability). If PDL receives a request directly from a Data Subject concerning Customer Data, PDL shall promptly forward the request to Customer and shall not respond to the request directly unless authorized by Customer.

6. Personal Data Breaches

6.1 Breach Notification. In the event of a confirmed Personal Data Breach affecting Customer Data, PDL shall notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach).

6.2 Remediation and Cooperation. PDL shall provide Customer with sufficient information to allow Customer to meet any obligations to report a Personal Data Breach to data protection authorities or Data Subjects. PDL shall take prompt remedial action to mitigate the effects of the breach and prevent recurrence.

7. Cross-Border Data Transfers

7.1 Transfer Mechanisms. Any transfer of Customer Data originating from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland to a country not recognized as providing an adequate level of data protection shall be subject to the SCCs.

7.2 Application of SCCs. By entering into this DPA, the parties are deemed to be signing the SCCs (Module Two: Transfer controller to processor, and/or Module Three: Transfer processor to processor, as applicable). The SCCs are hereby incorporated by reference, with Customer acting as the "data exporter" and PDL acting as the "data importer".

7.3 Supplementary Measures. PDL agrees to implement supplementary measures, such as encryption and data minimization, to ensure that the transferred data remains protected under the standard required by Applicable Data Protection Laws.

8. Audits and Compliance

8.1 Audit Rights. Upon Customer's written request (no more than once per year), PDL shall make available to Customer all information necessary to demonstrate compliance with the obligations set forth in this DPA.

8.2 Independent Certifications. To the extent PDL undergoes independent security audits (e.g., SOC 2, ISO 27001), PDL may provide Customer with a summary of the most recent audit report in lieu of an on-site audit, provided that such report sufficiently demonstrates compliance.

9. Return or Deletion of Data

Upon termination or expiration of the Agreement, or upon Customer's earlier request, PDL shall, at the choice of Customer, securely return or delete all Customer Data in its possession, unless applicable laws mandate the retention of the data. Deletion shall be performed in accordance with industry-standard secure wiping protocols.

10. Limitation of Liability

Each party's and all of its affiliates' liability, taken together in the aggregate, arising out of or related to this DPA (including the SCCs) shall be subject to the exclusions and limitations of liability set forth in the Agreement.

Official Document Ledger Record

Data Processing Addendum

ID: PDL-DPA-002•REV: 1.1.0
Classification LevelPublic-Facing
Policy OwnerPDL Office of the Executives
StatusACTIVE
Effective Date2026-07-30
Review CycleAnnual
Authorized Signatory
Kyyle Everett Garrow
Kyyle Everett GarrowChief Executive OfficerExecutive Leadership