1. Roles and scope
For customer personal data in Input, the customer is the controller or processor and PsyProxy is its processor or subprocessor. PsyProxy processes the data only on documented instructions in the agreement, order, and product configuration, including to provide, secure, support, and optimize service quality.
2. Customer instructions and obligations
The customer will comply with applicable data-protection law, provide a lawful basis and notices, honor data-subject rights, and avoid prohibited regulated data unless a signed order expressly authorizes it. PsyProxy will inform the customer if an instruction appears unlawful unless prohibited from doing so.
3. Confidentiality and security
Personnel authorized to process customer personal data are bound by confidentiality. PsyProxy maintains appropriate technical and organizational measures described in the Security Overview, taking account of the state of the art, cost, nature and purpose of processing, and risk.
4. Subprocessors
The customer gives general authorization for the listed subprocessors. PsyProxy remains responsible for their data-protection obligations to the extent required by law and will provide notice of material additions for customers entitled to notice under an order.
5. Assistance and incidents
Taking account of the nature of processing and information available, PsyProxy will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. PsyProxy will notify the customer without undue delay after confirming a personal-data breach affecting customer data.
6. Return, deletion, and audits
At the end of services, PsyProxy will delete or return customer personal data as directed unless law requires retention. The default project period is six months after last activity. PsyProxy will provide information reasonably necessary to demonstrate compliance and support proportionate audits, subject to confidentiality, security, and cost protections.
7. International transfers
For restricted transfers from the EEA, the parties incorporate the then-current EU Standard Contractual Clauses using the module that matches their roles, with PsyProxy as data importer. For UK restricted transfers, the UK International Data Transfer Addendum applies. The order and Subprocessor List supply the processing and transfer details. Customers may request a completed transfer annex from privacy@psyproxy.ai.
8. Processing details
- Subject matter: language analysis and related account, storage, support, and security services.
- Duration: the account or order term plus the deletion period.
- Data subjects: people represented in customer Input, users, researchers, staff, and other persons selected by the customer.
- Data: text, dependent variables, identifiers the customer includes, project settings, account data, and generated proxy variables.
- Purpose: customer-directed analysis and the operational purposes described above.
