Data Processor / Data Importer (Selby Labs):
Selby Labs Pty Ltd, ABN 50 697 107 083
Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia
Email: support@studyrun.org
EU Representative (Article 27 GDPR):
Chrysanthi Mella
PO Box 1049, Marathonas 19007, Greece
Email: eu-representative@studyrun.org
Data Controller / Data Exporter (Customer):
The researcher or institution identified in your StudyRun account registration and subscription details.
The Customer is a researcher or research institution established in the EU, EEA, or UK that uses the StudyRun platform to conduct digital phenotyping studies. In providing the platform services, Selby Labs processes personal data on behalf of the Customer and transfers that data from the EU to Australia.
This agreement governs the processing relationship in accordance with Regulation (EU) 2016/679 ("GDPR"), including Article 28 (processor obligations) and Chapter V (international data transfers).
Personal Data, Data Subject, Processing, Controller, Processor have the meanings given in Article 4 GDPR.
Special Category Data means personal data falling within Article 9(1) GDPR, including health data and biometric data used to uniquely identify a natural person.
Study Data means all personal data and other data collected from Participants through the Customer's studies on the Platform.
Sub-processor means any third party engaged by Selby Labs to process personal data on behalf of the Customer.
Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
SCCs means the Standard Contractual Clauses incorporated in Section 11, adopted pursuant to Commission Implementing Decision (EU) 2021/914.
| Element | Details |
|---|---|
| Subject matter | Digital phenotyping research data collection and storage |
| Duration | For the term of the Customer's subscription and the subsequent export and deletion window |
| Nature of processing | Collection, storage, pseudonymisation, structuring, retrieval, export, and deletion |
| Purpose | To provide the Platform services as instructed by the Customer; no processing for Selby Labs's own purposes |
| Types of personal data | Categories the Platform is capable of processing, each enabled per-study by the Customer:
|
| Special category data (Article 9 GDPR) | Several enableable categories involve special-category data:
|
| Categories of data subjects | Research participants recruited by the Customer who have provided informed consent |
The Customer, as Data Controller, is responsible for:
Selby Labs will:
Selby Labs implements and maintains the following technical and organisational measures:
The Customer may request evidence of compliance. An audit may be conducted with no less than 30 days written notice, at the Customer's cost, subject to confidentiality protections.
The Customer provides general written authorisation for Selby Labs to engage the sub-processors listed below. Selby Labs will inform the Customer of any intended addition or replacement with at least 14 days written notice, providing the Customer an opportunity to object on legitimate data protection grounds. Selby Labs shall impose equivalent obligations on all sub-processors and remains fully liable for sub-processor performance.
| Sub-processor | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | EC2 compute and EBS storage provisioned per paid Customer as an isolated EC2 virtual machine instance with its own EBS volumes on AWS's standard shared-tenancy infrastructure | All Study Data; Customer account metadata | Ireland (eu-west-1) or Germany (eu-central-1), as selected by the Customer at ordering | No transfer; data remains within the EU |
| Wise Europe SA / Wise Payments Ltd | Invoicing and payment processing | Customer billing contact and invoice line items only; no Study Data | Belgium and United Kingdom | No transfer for EU entity; UK adequacy decision for the UK entity |
| OpenWeather Ltd | Ambient-weather lookup by coordinates, when the Customer enables the Weather sensor | Participant GPS coordinates at time of query (no other Study Data) | United Kingdom | UK adequacy decision |
| Cloudflare, Inc. | Authoritative DNS for *.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Cloudflare is not used as a reverse proxy; participant and researcher traffic does not flow through Cloudflare's network | Customer subdomain names and associated DNS records; DNS query metadata observed by resolvers | United States | Standard Contractual Clauses (Module 2, Controller-to-Processor) |
| Internet Security Research Group (Let's Encrypt) | Issuance of TLS certificates for customer subdomains via the ACME protocol | Customer subdomain names only | United States | Standard Contractual Clauses |
| Transactional email provider (current provider identified at support@studyrun.org on request) | Service-related notifications (order confirmation, export reminders, breach notifications) | Customer contact email and message content; no Study Data | Per provider; disclosed on request | Per provider |
Device-platform APIs (not sub-processors): The StudyRun mobile app also reads from and interacts with APIs provided by the operating system of the Participant's own device: Apple HealthKit and Apple Core Motion on iOS; and Google Health Connect, Google Play Services Location Services, and Google ML Kit on-device barcode scanning on Android. Data read through these APIs is read from the Participant's device, not from Apple or Google. Use of Google Play Services Location on Android may cause a limited amount of telemetry to be transmitted to Google in the course of normal Android system operation; Google's handling of that telemetry is governed by Google's own Android-platform privacy documentation. These relationships are disclosed here for transparency and are not sub-processor engagements under Article 28 GDPR.
The Customer may subscribe to sub-processor change notifications by sending an email to support@studyrun.org with the subject line "Sub-processor notifications". Subscribed Customers will receive email notice of any intended addition or replacement of a sub-processor at least 14 days before the change takes effect, together with sufficient information to assess the data-protection implications of the change. The current sub-processor list is also maintained at studyrun.org/sub-processors. Objections to a proposed sub-processor change should be sent to the same address; an unresolved legitimate-grounds objection entitles the Customer to terminate this agreement and the underlying Services subscription on 30 days written notice without penalty, and to a pro-rata refund of prepaid fees for the unexpired portion of the subscription.
Selby Labs will provide reasonable assistance to the Customer in carrying out DPIAs under Article 35 GDPR, including providing relevant documentation on the technical and organisational measures implemented.
Selby Labs will assist the Customer in fulfilling its obligations to respond to data subject rights requests under Articles 15–22 GDPR, including rights of access, rectification, erasure, restriction, portability, and objection, by providing technical tools within the Platform dashboard.
Where a data subject contacts Selby Labs directly with a rights request, Selby Labs will forward the request to the Customer within 5 business days and will not respond to the data subject without the Customer's prior written authorisation.
Where a research participant withdraws consent or requests erasure under Article 17 GDPR, the Customer is responsible for making a verified deletion request to Selby Labs. Upon receiving a verified deletion request from the Customer, Selby Labs will:
Where a participant requests restriction of processing under Article 18 GDPR, Selby Labs will, upon the Customer's instruction, freeze processing for the relevant participant identifier without deleting the data, within 5 business days of the Customer's instruction.
Selby Labs provides export tools within the Platform dashboard enabling the Customer to export all data for a specific participant in machine-readable format (JSON and CSV) to support portability requests under Article 20 GDPR.
If Selby Labs is made aware that the Customer can no longer be reached (for example because the Customer has ceased to exist as a legal entity, the nominated researcher contact has left the institution and no successor has been appointed, or the Customer's subscription has long since lapsed and all contact attempts have failed) and a data subject whose personal data is still held by Selby Labs for that Customer exercises a right under Articles 15–22 GDPR, Selby Labs may, after at least 30 days of documented unsuccessful attempts to reach the Customer and at Selby Labs's reasonable discretion, respond to the data subject directly to give effect to that right, including by deleting the data subject's personal data. Any such action is documented in the deletion log referred to in Section 13.4.
Selby Labs does not itself use Study Data to carry out automated decisions producing legal or similarly significant effects on Participants within the meaning of Article 22 GDPR. The Customer must not configure the Platform to carry out such decisions, and must not export Study Data from the Platform into downstream systems that carry out such decisions, without an Article 22(2) basis and without providing Participants with the safeguards required by Article 22(3).
As noted in Section 2, Australia does not have an EU adequacy decision. The appropriate safeguard for transfers of personal data from the EU/EEA/UK to Australia under this agreement is the Standard Contractual Clauses, adopted pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor), as incorporated below.
Selby Labs shall maintain a record of all international transfers of personal data made under this agreement and the safeguards in place for each transfer. This record is available to the Customer on request.
Selby Labs is established in Australia. Selby Labs personnel located in Australia routinely access EU-hosted infrastructure for platform maintenance, monitoring, incident response, and similar operational purposes. Each such access from Australia constitutes an onward transfer from the EU AWS region to Australia for the purposes of Chapter V GDPR; the parties agree that these transfers are covered by the Standard Contractual Clauses incorporated in Section 11.2. Such access is subject to: (i) least-privilege role-based access controls; (ii) individual named user accounts; (iii) logging of administrative sessions; and (iv) confidentiality obligations on all personnel.
Selby Labs has carried out, and periodically reviews, a Transfer Impact Assessment (TIA) in respect of transfers of personal data from the EU/EEA/UK to Australia under this agreement, consistent with Clause 14 of the Standard Contractual Clauses and the recommendations of the European Data Protection Board. The TIA considers, among other matters, the surveillance and law-enforcement access regime in Australia (including the Telecommunications (Interception and Access) Act 1979 (Cth), the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth), and the Australian Security Intelligence Organisation Act 1979 (Cth)), and the supplementary technical, contractual, and organisational measures applied by Selby Labs to mitigate the risks identified. A copy of the current TIA will be provided to the Customer on request at support@studyrun.org, subject to reasonable confidentiality protections.
In accordance with Clause 15 of the Standard Contractual Clauses, Selby Labs shall: (a) if legally permitted, promptly notify the Customer and, where the Customer cannot be reached, the affected data subjects, of any binding legally-enforceable request from a public authority for access to personal data transferred under this agreement; (b) where Selby Labs is legally prohibited from notifying the Customer, use reasonable efforts to obtain a waiver of the prohibition and document its efforts; (c) provide the minimum amount of personal data permissible when responding to any such request, based on a reasonable interpretation of the request; and (d) challenge any request it considers unlawful or disproportionate under applicable law. Selby Labs publishes aggregate transparency statistics about such requests, to the extent legally permissible, at studyrun.org/transparency.
The parties have categorised their relationship as controller-processor, without admission that any contrary categorisation applies. This Section is a contingent fallback only and does not of itself establish joint controllership.
To the extent a competent supervisory authority or court determines, on review of a specific subset of processing activities such as Selby Labs's collection of platform-operational telemetry (crash reports, device-info events) or the choice of retention periods and pseudonymisation scheme for the Platform as a whole, that the parties are joint controllers within the meaning of Article 26 GDPR for that subset only, the parties agree that: (i) Selby Labs is the point of contact for data subjects in respect of platform-technical queries only (for example, questions about the technical operation of the app or data-integrity checks). The "rights exercise where Participants cannot reach the Customer" path is the separate orphaned-controller fallback in Section 10.6 and is subject to the 30-day attempt period described there, not this Section; (ii) the Customer is the point of contact for all study-specific queries (including requests relating to the purposes of processing, consent validity, and the content of surveys and tasks); and (iii) this Section operates as an Article 26 arrangement for the specific subset of processing so found, and for no other processing. A summary of this arrangement will be made available to data subjects on request and at studyrun.org/joint-controllership.
The parties incorporate into this agreement, by reference and as if set out in full herein and without modification, Module 2 (Controller-to-Processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as published in the Official Journal of the European Union, L 199, 7.6.2021, pp. 31-61 (the "Standard Contractual Clauses" or "Clauses").
The official text of the Standard Contractual Clauses is available at eur-lex.europa.eu/eli/dec_impl/2021/914/oj. A plain-text copy of the Clauses will be provided free of charge by Selby Labs on request to support@studyrun.org, and the Data Importer shall make a copy available to any data subject free of charge on request as required by Clause 8.3 of the Clauses.
Where this agreement and the Clauses are inconsistent, the Clauses shall prevail, in accordance with Clause 5 of the Clauses.
For the purposes of the Clauses: the Data Exporter is the Customer identified in the StudyRun account registration; the Data Importer is Selby Labs Pty Ltd. The Annexes to the Clauses are completed in Annex I, Annex II, and Annex III of this agreement.
The parties record the following selections and options in accordance with the optional provisions of the Clauses:
| Clause | Parties' selection |
|---|---|
| Clause 7: Docking clause | Not included. Additional parties may only accede to the Clauses by separate written agreement with the existing parties. |
| Clause 9(a): Use of sub-processors | Option 2: General written authorisation. The Data Importer has the Data Exporter's general authorisation to engage the sub-processors listed in Annex III. The Data Importer shall inform the Data Exporter in writing of any intended changes to that list at least 14 days in advance, giving the Data Exporter sufficient time to object before engagement. |
| Clause 11(a): Independent dispute resolution body | The optional element regarding an independent dispute resolution body is not included. Data subjects retain all rights to lodge complaints with their competent supervisory authority and to seek judicial redress as provided by Clauses 10 and 11 of the Clauses. |
| Clause 13: Supervision | The competent supervisory authority is the supervisory authority of the EU/EEA Member State in which the Data Exporter (Customer) is established. Where the Data Exporter is not established in an EU/EEA Member State but the processing falls within the territorial scope of Article 3(2) GDPR, the competent supervisory authority is the supervisory authority of the Member State in which the Data Importer's EU Representative (appointed under Article 27 GDPR) is established, as recorded in Annex I.C. |
| Clause 17: Governing law | Option 1. The Clauses are governed by the law of Ireland, being an EU Member State whose law allows for third-party beneficiary rights. |
| Clause 18(b): Choice of forum and jurisdiction | Any dispute arising from the Clauses shall be resolved by the courts of Ireland. Data subjects retain the right under Clause 18(c) of the Clauses to bring proceedings against the Data Exporter and/or the Data Importer before the courts of their habitual residence. |
Populated per the template in Annex I of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Sub-headings A, B, and C follow the OJ schema.
Data Exporter (Controller): The EU/EEA/UK researcher or research institution identified in the StudyRun account registration for the Customer accepting this DPA. The Data Exporter's specific legal name, registered address, country of establishment, designated contact person, role, and electronic-signature record (typed name, timestamp, IP address, document version) are captured in the clickwrap acceptance snapshot recorded at the time of acceptance. These details are Customer-specific and are preserved in the users and upgrade_orders records for the Customer's account, and are surfaced to the Customer via the /api/v1/auth/me endpoint. This per-Customer population of Party details is consistent with the SCCs, which contemplate that the Parties are those identified at the time of contract formation rather than statically listed in the template.
Data Importer (Processor): Selby Labs Pty Ltd, ABN 50 697 107 083, Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia. Designated contact: the Selby Labs support team at support@studyrun.org. Role: Data Processor under Article 28 GDPR and Data Importer under the SCCs.
Data Importer's EU Representative (appointed under Article 27 GDPR): Chrysanthi Mella, PO Box 1049, Marathonas 19007, Greece, Email: eu-representative@studyrun.org.
Categories of data subjects: Research participants recruited by the Data Exporter who have provided informed consent to participate in a study. No employee, contractor, or commercial-contact personal data is processed under this agreement.
Categories of personal data transferred: As set out in Section 4 of this DPA. In summary: motion and orientation sensor data; environmental sensor data; location, connectivity, and proximity data (GPS, WiFi, Bluetooth, iBeacon, cellular telephony, network state); device and system-state data; user-behaviour data including per-app foreground usage, call-log and SMS-log metadata, notification metadata and (where enabled) notification title and body, touch and keystroke events (aggregate or raw), on-screen text, full-screen bitmap captures, and active-media-session metadata; calendar and contacts data where enabled; interactive task data including ESM/EMA responses, PVT results, raw photographs, raw audio recordings, Show-Webpage responses, and Micro-Randomisation allocation outcomes; and internal technical data (device model, OS version, app version, crash reports, app-start events).
Sensitive data (Article 9 GDPR special-category data): Health and wearable data from Apple HealthKit and Google Health Connect, including clinical-health records, menstrual/reproductive/sexual-activity data, blood pressure, blood glucose, heart rate, heart-rate variability, sleep, nutrition, and workouts; audio recordings capturing the Participant's voice (biometric data under Article 4(14) GDPR); and free-text inputs (survey responses, keystroke content, on-screen text, notification content) that may incidentally contain special-category data. The Data Exporter is responsible for identifying a valid Article 9(2) basis and reflecting it in the participant privacy notice before enabling any such category. Additional restrictions and safeguards for sensitive data: study-level opt-in per sensor (no category is collected unless the Data Exporter has enabled it in the study configuration), pseudonymisation before upload, and per-Participant in-app consent capture.
Frequency of transfer: Continuous during active study periods. Study Data is transmitted from participant devices to the EU AWS server on an ongoing basis while the StudyRun mobile app is installed and the study is active. Selby Labs staff in Australia access the EU-hosted infrastructure only for platform maintenance, monitoring, and incident response (see Section 11.1A).
Nature of processing: Collection, storage, pseudonymisation, structuring, retrieval, export, and deletion of Study Data on behalf of the Data Exporter. No processing is carried out for Selby Labs's own purposes.
Purpose of processing: To provide the StudyRun platform services as instructed by the Data Exporter, comprising receipt of sensor data, availability of researcher dashboards, provision of export tools, and deletion of data on instruction or at subscription end.
Period of retention / Duration of processing: For the term of the Customer's subscription, followed by a 7-day export grace period. After the grace period the server is terminated and personal data is deleted from primary storage; backups are purged on the next 7-day rotation (no later than 14 days after subscription end). Per-Participant erasure requests are executed within 5 business days on primary storage and on the next backup rotation thereafter.
Transfers to (sub-) processors: See Annex III for the list of sub-processors, the nature and duration of processing for each, and the transfer mechanism that applies.
In accordance with Clause 13 of the SCCs, the competent supervisory authority is determined as follows:
Populated per the template in Annex II of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), regrouped under the Implementing Decision's own category headings so each is directly mappable to the OJ schema.
pg_dump, retained on a 7-day rolling cycle on the same encrypted volume as the primary database.| Sub-processor | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | EC2 compute and EBS storage provisioned per paid Customer as an isolated EC2 virtual machine instance with its own EBS volumes on AWS's standard shared-tenancy infrastructure | All Study Data; Customer account metadata | Ireland (eu-west-1) or Germany (eu-central-1), as selected by the Customer at ordering | No transfer; data remains within the EU |
| Wise Europe SA / Wise Payments Ltd | Invoicing and payment processing | Customer billing contact and invoice line items only; no Study Data | Belgium and United Kingdom | No transfer for EU entity; UK adequacy decision for the UK entity |
| OpenWeather Ltd | Ambient-weather lookup by coordinates, when the Weather sensor is enabled | Participant GPS coordinates at time of query (no other Study Data) | United Kingdom | UK adequacy decision |
| Cloudflare, Inc. | Authoritative DNS for *.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Not used as a reverse proxy | Customer subdomain names and DNS records; DNS query metadata observed by resolvers | United States | Standard Contractual Clauses (Module 2) |
| Internet Security Research Group (Let's Encrypt) | Issuance of TLS certificates via the ACME protocol | Customer subdomain names only | United States | Standard Contractual Clauses |
| Transactional email provider | Service-related notifications (order confirmation, export reminders, breach notifications) | Customer contact email and message content; no Study Data | Disclosed on request at support@studyrun.org | Per provider |
Device-platform APIs (not sub-processors): Apple HealthKit and Core Motion on iOS; Google Health Connect, Play Services Location Services, and ML Kit on Android. Data read through these APIs is read from the Participant's own device. See Section 8 for the full note.
Selby Labs will notify the Customer without undue delay and in any event within 48 hours after becoming aware of a data breach affecting Study Data, to enable the Customer to meet its 72-hour notification obligation under Article 33 GDPR. The notification will include:
Where information is not available in full at the time of initial notification, Selby Labs will provide it in phases without undue further delay. Selby Labs cooperates fully with the Customer in investigating, remediating, and reporting any breach. Selby Labs maintains an internal breach register in accordance with Article 33(5) GDPR. The Customer, as Data Controller, remains responsible for notifying the supervisory authority under Article 33 and data subjects under Article 34 GDPR where required.
Upon termination of services, or upon the Customer's written request at any time during the subscription period, Selby Labs shall, at the Customer's choice, delete or return all personal data and delete all existing copies, unless applicable law requires storage. Deletion shall cascade across all storage systems, databases, backup systems, and logs; because backups rotate on a 7-day cycle, purging of personal data from backups completes no later than 7 days after the primary database deletion. Selby Labs shall provide written confirmation of deletion on the Customer's request.
A countdown and export reminder are shown in the Platform dashboard throughout the subscription, with prominent notice as the subscription end date approaches. At subscription end the Customer has a 7-day export grace period during which they retain read and export access to their server instance. At the end of that 7-day period the server is terminated, the primary database is deleted, and Study Data is purged from backups on the next rotation of the 7-day backup cycle (no later than 14 days after subscription end). Written confirmation of deletion is provided on request.
The Customer may request deletion of all data held for a specific participant at any time. Upon receiving a verified deletion request, Selby Labs will delete all identifiable data for that participant, cascading across all systems, within 5 business days, and provide written confirmation. See Section 10.3 for full details.
For all deletions, Selby Labs retains a non-identifiable deletion log recording the date, the pseudonym identifier, and the type of deletion action. This log does not constitute retention of personal data and is maintained for audit purposes only.
Selby Labs shall make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and this agreement. The Customer or a mandated auditor may conduct an audit with no less than 30 days written notice, at the Customer's cost, subject to confidentiality protections. Selby Labs may provide relevant third-party certifications or security assessment reports in lieu of on-site audits.
Each party shall be liable to the other for material damage caused by non-compliance with this agreement. The Customer shall indemnify Selby Labs against third-party claims arising from the Customer's failure to have a lawful basis for processing or to obtain valid Participant consent. Selby Labs's liability is subject to the limitation in the Terms of Service, except as required by mandatory law including the GDPR and the SCCs.
In the event of conflict regarding personal data subject to GDPR: the SCCs (Section 11) take precedence over this DPA, which takes precedence over the Terms of Service. Nothing in the Terms of Service limits the rights of data subjects or the obligations of the parties under the SCCs.
This Data Processing Agreement (excluding the SCCs which are governed by Irish law) is governed by the laws of Victoria, Australia, without prejudice to mandatory rights of data subjects under GDPR. Disputes shall be referred to the courts of Victoria, Australia, except where mandatory GDPR or SCC provisions require otherwise.
Selby Labs Pty Ltd · ABN 50 697 107 083
Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia
Email: support@studyrun.org
EU Representative (Article 27 GDPR):
Chrysanthi Mella
PO Box 1049, Marathonas 19007, Greece