PsyProxy
MethodologyMCP/APIModel store
Sign in
Organizations

Data Processing Addendum

Processor terms for organizational customers that direct PsyProxy to process personal data in research or business datasets.

Version 2026-07-10Effective July 10, 2026PsyProxy Limited, Colorado, USA
Legal and privacy
  • Policy center
  • Terms
  • Privacy
  • Data handling
  • Acceptable use
  • Consumer health

1. Roles and scope

For customer personal data in Input, the customer is the controller or processor and PsyProxy is its processor or subprocessor. PsyProxy processes the data only on documented instructions in the agreement, order, and product configuration, including to provide, secure, support, and optimize service quality.

2. Customer instructions and obligations

The customer will comply with applicable data-protection law, provide a lawful basis and notices, honor data-subject rights, and avoid prohibited regulated data unless a signed order expressly authorizes it. PsyProxy will inform the customer if an instruction appears unlawful unless prohibited from doing so.

3. Confidentiality and security

Personnel authorized to process customer personal data are bound by confidentiality. PsyProxy maintains appropriate technical and organizational measures described in the Security Overview, taking account of the state of the art, cost, nature and purpose of processing, and risk.

4. Subprocessors

The customer gives general authorization for the listed subprocessors. PsyProxy remains responsible for their data-protection obligations to the extent required by law and will provide notice of material additions for customers entitled to notice under an order.

5. Assistance and incidents

Taking account of the nature of processing and information available, PsyProxy will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. PsyProxy will notify the customer without undue delay after confirming a personal-data breach affecting customer data.

6. Return, deletion, and audits

At the end of services, PsyProxy will delete or return customer personal data as directed unless law requires retention. The default project period is six months after last activity. PsyProxy will provide information reasonably necessary to demonstrate compliance and support proportionate audits, subject to confidentiality, security, and cost protections.

7. International transfers

For restricted transfers from the EEA, the parties incorporate the then-current EU Standard Contractual Clauses using the module that matches their roles, with PsyProxy as data importer. For UK restricted transfers, the UK International Data Transfer Addendum applies. The order and Subprocessor List supply the processing and transfer details. Customers may request a completed transfer annex from privacy@psyproxy.ai.

8. Processing details

  • Subject matter: language analysis and related account, storage, support, and security services.
  • Duration: the account or order term plus the deletion period.
  • Data subjects: people represented in customer Input, users, researchers, staff, and other persons selected by the customer.
  • Data: text, dependent variables, identifiers the customer includes, project settings, account data, and generated proxy variables.
  • Purpose: customer-directed analysis and the operational purposes described above.
© 2026 PsyProxy Limited. All rights reserved. PsyProxy™ is a trademark of PsyProxy Limited.B.0.3.5