Skip to content

Privacy Policy

Effective Date: June 3, 2026

Welcome to PsyData Labs L.L.C. (“PDL“, “we“, “us“, or “our“). We are committed to safeguarding your personal data, behavioral telemetry, and psychological measurements. This Privacy Policy describes how we collect, use, protect, and process information across our websites, applications, research platforms, and APIs in accordance with the General Data Protection Regulation (GDPR), the California Privacy Rights Act (CPRA), the New York SHIELD Act, and other applicable global privacy laws.

1. Data Classifications and Definitions

Because of the highly sensitive nature of our research and analytics, we classify data into distinct categories, applying rigorous technical and administrative controls to each:

  • Behavioral Data (D-BEH): Observable interaction data—such as session length, task performance, navigational patterns, and device context—used to model user interaction and system performance.
  • Psychological Signals (D-PSY): Measured or self-reported psychological constructs, including mood proxies, cognitive load indicators, and psychometric scale responses.
  • Inference Outputs (D-INF): Automated or hybrid human-AI generated scores, labels, segments, or profiles derived from user data.
  • High-Risk Psychological Profiles (H-RP): Composite inferences that could materially affect an individual’s access to services, pricing, employment, or health-adjacent outcomes.

2. Information We Collect

We collect information through your direct interactions with our services and through automated telemetry:

  • Direct Identifiers and Contact Data: Name, email address, account credentials, and communication records.
  • Automated Behavioral Telemetry (D-BEH): IP addresses, browser types, device identifiers, and granular interaction event logs.
  • Psychological and Measurement Data (D-PSY): Information explicitly provided via surveys, research tasks, and clinical scales. Important: We only collect D-PSY data with your explicit, affirmative opt-in consent.

3. How We Process and Use Your Information

We only process your information when we have a documented lawful basis (such as your consent, contract fulfillment, or legitimate interests). We use your data to:

  • Deliver, secure, and improve our platform functionality and user experience.
  • Generate analytical insights and research cohorts utilizing Behavioral Data.
  • Develop Inference Outputs (D-INF) to provide personalized insights and features.
  • Comply with legal obligations, enforce our terms, and prevent fraud or security incidents.

Strict Prohibition on Advertising: We categorically prohibit the use of Psychological Signals (D-PSY) and sensitive Inference Outputs (D-INF) for targeted advertising or third-party marketing.

4. Artificial Intelligence and Automated Inferences

Our processing includes AI-driven modeling. We enforce strict ethical boundaries for all automated processing:

  • Human-in-the-Loop (HITL): We require mandatory human review before any High-Risk Psychological Profile (H-RP) can be used to make material decisions about you.
  • No Fully Automated Harm: We strictly prohibit fully automated denial of service, employment, or insurance decisions based on Inference Outputs.
  • Bias and Drift Monitoring: We continuously monitor our models for drift and disparate impact to ensure fairness.
  • Right to Appeal: If you are subject to an adverse decision influenced by our automated inferences, you maintain the right to appeal the decision and request human intervention.

5. Your Privacy Rights

Depending on your jurisdiction (including the EU/EEA and California), you possess comprehensive rights regarding your personal information:

  • Right to Access and Portability: You may request a copy of the personal data we hold about you, including the specific inferences drawn.
  • Right to Deletion (Right to be Forgotten): You can request that we delete your personal data, subject to limited statutory exceptions (e.g., active legal holds).
  • Right to Correction: You may request corrections to inaccurate or incomplete information.
  • Right to Opt-Out: You have the right to opt-out of the “sale” or “sharing” of your data. Note: PDL does not sell D-BEH, D-PSY, or D-INF data.
  • Right to Withdraw Consent: Where processing is based on consent (especially for D-PSY), you may withdraw it at any time. We will propagate this withdrawal to downstream systems within 72 hours.
  • Right to Non-Discrimination: We will not deny you goods or services, nor charge you different prices, for exercising your privacy rights.

To exercise your rights, please submit a Data Subject Request (DSR) using the contact details below. We acknowledge requests within 48 hours and resolve them within statutory deadlines (e.g., 45 days under the CPRA, 30 days under the GDPR).

6. Data Security and NY SHIELD Act Compliance

We deploy production-class security architectures designed to safeguard your information against unauthorized access, breach, and exfiltration. Our safeguards include:

  • HIPAA-like administrative, physical, and technical safeguards for health-adjacent and psychological data.
  • Comprehensive data encryption in transit and at rest.
  • Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), and Data Loss Prevention (DLP) systems.
  • Continuous monitoring and regular third-party audits.

In the event of a data breach affecting your rights or private information, we will notify you and relevant supervisory authorities strictly within legally mandated timelines (e.g., within 72 hours for GDPR, and without unreasonable delay under the NY SHIELD Act).

7. Data Retention

We retain personal information only for as long as it is necessary to fulfill the purposes detailed in this policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Consent records and DSAR logs are securely archived for a minimum of 24 months to demonstrate compliance.

8. International Data Transfers

PDL operates globally. If you reside outside the United States, your information may be transferred to and processed in the U.S. or other jurisdictions. We utilize legally recognized transfer mechanisms, including Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and Transfer Impact Assessments (TIAs), to ensure your data is adequately protected regardless of where it is processed.

9. Children’s Privacy

We strictly adhere to COPPA guidelines. Our services are not intended for or directed at children under the age of 13. We prohibit the processing of behavioral or psychological data from children under 13 without verifiable, documented parental consent.

10. Contact Information

If you have any questions, concerns, or wish to exercise your privacy rights, please contact our Data Protection Lead: