Data Processor (Selby Labs): Selby Labs Pty Ltd, ABN 50 697 107 083, Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia. Email: support@studyrun.org
Data Controller (Customer): The researcher or institution identified in your StudyRun account registration and subscription details.
The Customer is a researcher or research institution that uses the StudyRun platform to conduct digital phenotyping studies, collecting personal information from research participants. In providing the StudyRun platform services, Selby Labs processes personal information on behalf of the Customer. This agreement governs that processing relationship in accordance with the Australian Privacy Act 1988 (Cth) ("Privacy Act"), the Privacy and Data Protection Act 2014 (Vic), the Health Records Act 2001 (Vic) where applicable, and the Australian Privacy Principles ("APPs").
Personal Information has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive Information has the meaning given in the Privacy Act and includes health information and biometric information.
Study Data means all personal information and other data collected from Participants through the Customer's studies on the Platform.
Platform means the StudyRun digital phenotyping research platform and associated services.
Services means the services provided by Selby Labs to the Customer under the Terms of Service.
Selby Labs processes personal information on behalf of the Customer for the purpose of providing the Platform services, including:
The categories of personal information the Platform is capable of processing are set out below. Each category is enabled per-study by the Customer; no category is processed unless the Customer has enabled it in their study configuration.
The Customer is responsible for:
Selby Labs will:
Selby Labs implements the following security measures to protect Study Data:
Selby Labs uses the following sub-processors to provide the Services. All sub-processors are contractually bound to handle personal information in a manner consistent with this agreement:
*.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Cloudflare is not used as a reverse proxy; participant and researcher traffic does not traverse Cloudflare's networkDevice-platform APIs (not sub-processors): The StudyRun mobile app also reads from APIs provided by the Participant's own device operating system: Apple HealthKit and Core Motion on iOS; and Google Health Connect, Google Play Services Location Services, and Google ML Kit on-device barcode scanning on Android. Data read through these APIs is read from the Participant's device, not from Apple or Google. Use of Google Play Services Location on Android may cause a limited amount of telemetry to be transmitted to Google in the course of normal Android system operation.
Selby Labs will notify the Customer of any changes to the sub-processor list that could affect the processing of Study Data, with at least 14 days written notice before the change takes effect. The Customer may subscribe to sub-processor change notifications by sending an email to support@studyrun.org with the subject line "Sub-processor notifications". Objections on legitimate data-protection grounds, if not resolved, entitle the Customer to terminate this agreement without penalty and with a pro-rata refund of prepaid fees for the unexpired portion of the subscription.
The parties have categorised their relationship as collector/processor, without admission that any contrary categorisation applies. This Section is a contingent fallback only and does not of itself establish joint responsibility.
To the extent the Office of the Australian Information Commissioner or a court determines, on review of a specific subset of processing activities (such as Selby Labs's collection of platform-operational telemetry such as crash reports and device-info events, or the choice of retention periods and pseudonymisation scheme for the Platform), that Selby Labs and the Customer share responsibility as joint APP entities for that subset only, the parties agree that Selby Labs will be the point of contact for Participants in respect of platform-technical queries only, and the Customer will be the point of contact for all study-specific queries. The handling of rights requests where the Customer cannot be reached is addressed separately in Section 7C and is subject to the 30-day attempt period described there. A summary of this fallback arrangement will be made available to Participants on request.
Selby Labs does not itself use Study Data to carry out automated decisions producing legal or similarly significant effects on Participants. The Customer must not configure the Platform to carry out such decisions, and must not export Study Data from the Platform into downstream systems that carry out such decisions, without a lawful basis and appropriate participant notice.
If Selby Labs is made aware that the Customer can no longer be reached (for example because the Customer has ceased to exist as a legal entity, the nominated researcher contact has left the institution and no successor has been appointed, or the Customer's subscription has long since lapsed and all contact attempts have failed) and a Participant whose personal information is still held by Selby Labs for that Customer exercises a right to access, correction, or deletion, Selby Labs may, after at least 30 days of documented unsuccessful attempts to reach the Customer and at Selby Labs's reasonable discretion, respond to the Participant directly to give effect to that right, including by deleting the Participant's personal information.
Study Data is retained for the duration of the Customer's subscription. A countdown and export reminder are shown in the Platform dashboard throughout the subscription, with prominent notice as the subscription end date approaches. At subscription end the Customer has a 7-day export grace period during which read and export access to the Customer's server instance is retained. At the end of that 7-day period the server is terminated, the primary database is deleted, and Study Data is purged from backups on the next rotation of the 7-day backup cycle (no later than 14 days after subscription end).
Selby Labs will provide written confirmation of deletion upon request. The Customer may request deletion of Study Data at any time during the subscription period by contacting support@studyrun.org.
Selby Labs will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a data breach affecting Study Data. The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Participants and records affected, the likely consequences of the breach, the contact details of Selby Labs's data protection contact, and the steps taken or proposed to address the breach and mitigate its effects. Where information is not available in full at the time of initial notification, Selby Labs will provide it in phases without undue further delay.
The Customer is responsible for determining whether the breach is notifiable under the Notifiable Data Breaches scheme and for notifying the Office of the Australian Information Commissioner and affected Participants as required.
Australian customers' Study Data is stored in AWS Sydney (ap-southeast-2) within Australia. Selby Labs staff based in Australia may access the data for platform maintenance and support purposes. No disclosure of Australian customer Study Data to overseas recipients is made except as required by law.
Selby Labs will assist the Customer in fulfilling requests from Participants to access or correct their personal information by providing the necessary tools within the platform dashboard. If a Participant contacts Selby Labs directly, Selby Labs will forward the request to the Customer within 5 business days.
Where a Participant requests deletion of their personal information, the Customer is responsible for making a verified deletion request to Selby Labs. On receipt of a verified request from the Customer, Selby Labs will delete all personal information held for that Participant from primary storage, databases, and logs within 5 business days, and from backup systems on the next rotation of the 7-day backup cycle, with full purge completing no later than 7 business days plus 7 calendar days from the verified request. A non-identifiable deletion-log entry recording the date, pseudonym identifier, and type of deletion is retained for audit purposes; this log does not constitute retention of personal information. Written confirmation is provided once the backup purge completes.
Selby Labs will make available to the Customer, on reasonable request, information necessary to demonstrate compliance with this agreement. The Customer may request an audit of Selby Labs's data processing practices with no less than 30 days notice, subject to reasonable confidentiality protections.
If any part of this agreement is held to be invalid, illegal, or unenforceable, that part will be severed and the remaining provisions will continue in full force and effect.
This agreement commences on the date the Customer accepts the StudyRun Terms of Service and continues until all Study Data has been deleted following subscription termination. Clauses relating to security, confidentiality, and deletion survive termination.
This agreement is governed by the laws of Victoria, Australia, the Privacy Act 1988 (Cth), and the Privacy and Data Protection Act 2014 (Vic). The parties submit to the non-exclusive jurisdiction of the courts of Victoria.
Selby Labs Pty Ltd · ABN 50 697 107 083
Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000
Email: support@studyrun.org