PDL Logo
PDL Legal& Compliance Center
← Back to Directory
ACTIVE POLICY

Transparency Report

PDL Transparency Report — Inaugural Edition (2026)

PsyData Labs L.L.C. ("PDL") is committed to operating with the highest levels of integrity, accountability, and transparency. This inaugural Transparency Report provides stakeholders — including users, clients, researchers, regulators, and the public — with meaningful insight into how PDL responds to legal demands, how we protect user data, and how we govern the ethical use of artificial intelligence. We intend to publish this report annually, with each edition covering the preceding calendar year or reporting period.

Reporting Period: Inception through July 30, 2026 (Early Access / Trial Release Phase)

1. Government & Law Enforcement Requests

PDL operates a strict privacy-first policy with respect to government and law enforcement data requests. We challenge legally deficient, overbroad, or improperly served requests and seek to notify affected users whenever legally permissible.

1.1 Request Handling Principles

  • PDL will only produce user data in response to requests that are legally valid, properly served, and narrowly scoped.
  • We do not provide voluntary access to user data to any government or law enforcement authority outside of valid legal process.
  • We scrutinize all requests for compliance with applicable law, including the Fourth Amendment, the Stored Communications Act (SCA), and NY SHIELD Act obligations.
  • We maintain a legal hold and chain-of-custody process for any data produced in response to legal orders.

1.2 Early Access Reporting Period (Inception – July 30, 2026)

During the Early Access phase, PDL received zero (0) government or law enforcement data requests. As PDL scales, this section will be updated with quantitative reporting on: National Security Letters (NSLs), court orders, subpoenas, warrants, and international mutual legal assistance requests.

2. Data Subject Access Requests (DSARs)

PDL respects the rights of individuals whose personal data we process. Applicable rights include access, correction, deletion, portability, restriction of processing, and opt-out of AI-driven profiling, consistent with CPRA, GDPR, and the NY SHIELD Act.

2.1 DSAR Statistics (Inception – July 30, 2026)

  • Total DSARs Received: 0 (Early Access Phase)
  • DSARs Completed Within Statutory Timeline: N/A
  • DSARs Denied (with explanation): N/A
  • Average Response Time: N/A

2.2 Data Subject Rights We Honor

  • Right of Access: Individuals may request a copy of personal data PDL holds about them.
  • Right to Correction: Individuals may request correction of inaccurate personal data.
  • Right to Deletion: Individuals may request erasure of personal data, subject to legal retention requirements.
  • Right to Portability: Individuals may request their data in a structured, machine-readable format.
  • Right to Opt-Out of Profiling: Individuals may opt out of automated decision-making and AI-driven profiling using Behavioral Data (D-BEH), Psychological Signals (D-PSY), or Inference Outputs (D-INF).

3. Security Incident Disclosures

PDL takes security incidents seriously and maintains a rigorous incident response program aligned with NIST SP 800-61, SOC 2 (CC7), and ISO 27001:2022 Annex A controls. We are committed to notifying affected parties within legally required timelines (72 hours to regulators under GDPR Article 33; prompt notification to affected individuals where required by CPRA and NY SHIELD).

3.1 Security Incidents (Inception – July 30, 2026)

  • Confirmed Data Breaches Affecting User Data: 0
  • Regulatory Notifications Issued: 0
  • Voluntary User Notifications Issued: 0

PDL has not experienced any confirmed data security incidents affecting user personal data during this reporting period.

4. Vulnerability Disclosure Program

PDL operates a responsible Vulnerability Disclosure Program (VDP) as described in our Vulnerability Disclosure Policy. We value the security research community and provide a Safe Harbor framework for good-faith researchers.

4.1 VDP Statistics (Inception – July 30, 2026)

  • Vulnerability Reports Received: 0 (Pre-public launch phase)
  • Valid Reports Triaged: 0
  • Critical Vulnerabilities Remediated: 0
  • Average Time to Acknowledge: Target: within 48 hours
  • Average Time to Remediate (Critical): Target: within 7 calendar days

5. AI Governance Transparency

PDL's AI systems are classified and governed under a formal AI Risk Tiering framework, aligned with NIST AI RMF (AI 100-1) and the EU AI Act. We maintain a Human-in-the-Loop (HITL) requirement for all high-impact AI decisions affecting individuals.

5.1 AI System Classifications (as of July 30, 2026)

  • Tier 1 (Low Risk): Administrative automation, internal analytics dashboards, non-behavioral pattern recognition.
  • Tier 2 (Moderate Risk): Behavioral signal aggregation tools, research-grade inference engines with human review gates.
  • Tier 3 (High Risk): Any AI system producing outputs that inform clinical, behavioral, or psychological assessments. All Tier 3 outputs require mandatory human expert review before use.

5.2 Prohibited AI Uses

PDL strictly prohibits the following uses of its AI systems, regardless of tier:

  • Generating autonomous clinical diagnoses without licensed professional review.
  • Profiling individuals based on protected characteristics for discriminatory purposes.
  • Processing D-BEH/D-PSY/D-INF data for AI training without explicit, documented consent.
  • Deploying AI-generated outputs in life-altering decisions without HITL review.

6. Data Classification & Handling Summary

PDL uses a formal data classification taxonomy to ensure appropriate controls are applied to all data it processes:

  • S0 – Public: No restrictions on disclosure.
  • S1 – Internal: Limited to PDL employees and authorized contractors.
  • S2 – Confidential: Business-sensitive data requiring access controls and encryption at rest.
  • S3 – Restricted: Sensitive personal data, including behavioral signals and inference outputs. Subject to strict access logging, anonymization requirements, and prohibition from non-production environments.
  • S4 – Highly Restricted: Raw psychological signals (D-PSY), identifiable behavioral profiles, and clinical-grade inferences. Requires executive authorization for access and processing.

7. Third-Party Subprocessors

PDL engages vetted subprocessors to deliver its services. All subprocessors are bound by Data Processing Agreements (DPAs) containing Article 28 GDPR-equivalent clauses, CPRA Service Provider obligations, and security requirements consistent with PDL standards.

PDL provides its current subprocessor list upon request. Clients with executed DPAs receive 30 days' prior written notice of any new subprocessor additions, with the right to object.

8. Commitment to Continuous Improvement

PDL is committed to strengthening its transparency practices as the company scales. Future editions of this report will include: year-over-year statistical comparisons, certifications achieved (SOC 2 Type II, ISO 27001/27701 targets), expanded AI model registry disclosures, and third-party audit results where permitted.

For questions about this Transparency Report, contact us at compliance@psydata.org.

Official Document Ledger Record

Transparency Report

ID: PDL-TRAREP-001•REV: 1.0.0
Classification LevelPublic-Facing
Policy OwnerPDL Office of the Executives
StatusACTIVE
Effective Date2026-07-30
Review CycleAnnual
Authorized Signatory
Kyyle Everett Garrow
Kyyle Everett GarrowChief Executive OfficerExecutive Leadership