Transparency Report — PsyData Labs L.L.C.

Effective: 2026-06-03

PsyData Labs L.L.C. maintains enterprise security, privacy, and AI governance programs mapped to SOC 2, ISO 27001/27701, NIST CSF, NIST AI RMF, GDPR, CPRA, NY SHIELD Act (NY GBL §899-aa), and EU AI Act obligations where applicable. This page is a standalone summary of our transparency posture.

Program overview

We implement defense-in-depth controls across people, process, and technology. Policies are reviewed annually and mapped to auditable requirements with evidence retained per our records management standard.

Security controls

Encryption in transit (TLS 1.2+) and at rest for S2+ data; MFA for administrative access; least privilege IAM; centralized logging and incident response with 72-hour GDPR supervisory notification where applicable; annual penetration testing; vulnerability remediation SLAs; vendor risk assessments before onboarding processors.

Privacy and data subject rights

Data classification taxonomy (S0–S4; D-BEH/D-PSY/D-INF domains). DSAR handling within statutory timelines (45 days CPRA with permitted extension; one month GDPR). Processor agreements include Art. 28-style clauses, subprocessor notice, and deletion upon termination.

AI governance

Risk tiering for models; human-in-the-loop for high-impact decisions; bias testing and drift monitoring; prohibited uses include unlawful discrimination and unapproved clinical diagnosis; synthetic data controls to prevent memorization leakage.

Behavioral and psychological data

Collection limited to disclosed purposes with consent or other lawful basis. Psychological signals barred from non-production environments without scrubbing. Inference outputs logged with explainability metadata for S3+ paths.

Compliance attestations

Executive and control owners complete annual attestations. External audit readiness maintained for SOC 2/ISO alignments. Exceptions require written approval with compensating controls and expiry.

Incident and breach communication

We notify affected individuals and regulators per GDPR Arts. 33–34, CPRA, and NY SHIELD when legally required. Customers with DPAs receive contractual notice per agreed timelines.

Subprocessors and transfers

Subprocessor list available on request. International transfers use SCCs and TIAs where required.

Accessibility and language

We provide English notices; translations may be offered for key public documents where commercially reasonable.

Updates

We publish material program changes at least annually on this site and in customer security packs.

Contact channels

. Privacy: privacy@psydatalabs.com
. Security: security@psydatalabs.com
. Legal: legal@psydatalabs.com
. Ethics: compliance@psydatalabs.com


//Public page — transparency; enterprise agreements may specify additional commitments.//