StudyRun · Selby Labs · European Union

Data Processing Agreement

Version 1.1  ·  Effective date: 15 April 2025  ·  Applies to: EU, EEA, and UK customers  ·  Includes Standard Contractual Clauses (Module 2)
This Data Processing Agreement and incorporated Standard Contractual Clauses apply to customers whose institution is based in the EU, EEA, or UK, or whose study participants are located in those territories. If your institution is based in Australia, use our Australian DPA. For institutions based in any other country (including the United States, Canada, Brazil, Switzerland, and Asia-Pacific jurisdictions other than Australia), use our International DPA.
How this agreement is formed: This DPA is incorporated by reference into the StudyRun Terms of Service. By clicking "I Agree" during registration or when upgrading your subscription, you accept this DPA and the Standard Contractual Clauses. Your agreement is recorded with your name, timestamp, IP address, and the version of this document in force at the time.

1. Parties

Data Processor / Data Importer (Selby Labs):
Selby Labs Pty Ltd, ABN 50 697 107 083
Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia
Email: support@studyrun.org

EU Representative (Article 27 GDPR):
Chrysanthi Mella
PO Box 1049, Marathonas 19007, Greece
Email: eu-representative@studyrun.org

Data Controller / Data Exporter (Customer):
The researcher or institution identified in your StudyRun account registration and subscription details.

2. Background and Scope

The Customer is a researcher or research institution established in the EU, EEA, or UK that uses the StudyRun platform to conduct digital phenotyping studies. In providing the platform services, Selby Labs processes personal data on behalf of the Customer and transfers that data from the EU to Australia.

Adequacy notice: Australia does not have an adequacy decision from the European Commission under Article 45 GDPR. Accordingly, the transfer of personal data from the EU/EEA to Australia is made solely on the basis of the Standard Contractual Clauses incorporated in Section 11 of this agreement, which constitute the appropriate safeguard under Article 46(2)(c) GDPR.
Demo server (Australia): The StudyRun demo environment is hosted in Australia (AWS ap-southeast-2, Sydney). The demo environment is intended solely for testing and evaluating the platform by researchers. It must not be used to collect data from real research participants. The demo environment is a shared, multi-tenant environment; the per-Customer instance-isolation and operational security commitments described in this agreement (including those in Annex II) apply only to paid subscription servers. By registering for a demo account, EU/EEA researchers acknowledge that their account information and any data entered into the demo environment will be stored in Australia. This transfer is covered by the Standard Contractual Clauses in this agreement. The demo server is provided on a best-efforts basis only and may be suspended, reset, or permanently deleted at any time and without prior notice, at Selby Labs's sole discretion. No data persistence is guaranteed and no liability arises from interruption or deletion of demo data. Real participant study data must only be processed on a paid subscription server in an EU region (eu-west-1 Ireland or eu-central-1 Frankfurt) selected at the time of ordering.

This agreement governs the processing relationship in accordance with Regulation (EU) 2016/679 ("GDPR"), including Article 28 (processor obligations) and Chapter V (international data transfers).

3. Definitions

Personal Data, Data Subject, Processing, Controller, Processor have the meanings given in Article 4 GDPR.

Special Category Data means personal data falling within Article 9(1) GDPR, including health data and biometric data used to uniquely identify a natural person.

Study Data means all personal data and other data collected from Participants through the Customer's studies on the Platform.

Sub-processor means any third party engaged by Selby Labs to process personal data on behalf of the Customer.

Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

SCCs means the Standard Contractual Clauses incorporated in Section 11, adopted pursuant to Commission Implementing Decision (EU) 2021/914.

4. Nature, Purpose, and Subject Matter of Processing

ElementDetails
Subject matterDigital phenotyping research data collection and storage
DurationFor the term of the Customer's subscription and the subsequent export and deletion window
Nature of processingCollection, storage, pseudonymisation, structuring, retrieval, export, and deletion
PurposeTo provide the Platform services as instructed by the Customer; no processing for Selby Labs's own purposes
Types of personal dataCategories the Platform is capable of processing, each enabled per-study by the Customer:
  • Motion & orientation: accelerometer (including high-frequency sampling), linear accelerometer, gyroscope, gravity, rotation, magnetometer, significant-motion events, motion-activity classification, pedometer step counts, headphone motion.
  • Environment: barometer, ambient light, ambient temperature, proximity, ambient noise level (decibel amplitude only; audio content is not recorded or uploaded by this sensor).
  • Location, connectivity & proximity: GPS coordinates, WiFi scan results, Bluetooth device discovery including iBeacon, network state, cellular telephony metadata.
  • Device & system state: battery, screen on/off, CPU/memory, installed-application list, timezone, headphone connection state, ringer mode.
  • User behaviour: per-application foreground usage; call-log and SMS-log metadata; per-app notification metadata and, where enabled by the Customer, the full title and body of notifications (via the Android NotificationListenerService); active-media-session metadata; touch and gesture events; keystroke events captured either as aggregate typing-rate metrics or, where enabled by the Customer, individual keystrokes (via the Android Accessibility Service); on-screen text visible in any app (via the Android Accessibility Service); full-screen bitmap captures (via the Android MediaProjection API).
  • Personal data stores: calendar events and contacts, where enabled and permitted by the Participant's device.
  • Interactive task data: ESM/EMA responses, PVT reaction-time results, Photo Diary photographs (raw JPEG), Audio Recording task recordings (raw audio), Show-Webpage task responses, Micro-Randomisation allocation outcomes.
  • Internal technical data collected on every study: device model, OS version, app version, crash reports, app-start events.
Special category data (Article 9 GDPR)Several enableable categories involve special-category data:
  • Health & wearable data from Apple HealthKit and Google Health Connect, including, where exposed by those platforms, clinical-health records, menstrual/reproductive/sexual-activity data, blood pressure, blood glucose, heart rate, heart-rate variability, sleep, nutrition, and workouts.
  • Screen text, notification content, keystroke content, and free-text survey responses may incidentally contain special-category data depending on participant device use.
  • Audio recordings where the voice of the Participant is captured (biometric data used to uniquely identify a natural person under Article 4(14) and 9(1) GDPR).
The Customer must identify and document a valid Article 9(2) basis (typically explicit consent under Article 9(2)(a) or Article 9(2)(j) for scientific research) before enabling any category that involves special-category data, and must reflect this basis in the participant privacy notice and consent form.
Categories of data subjectsResearch participants recruited by the Customer who have provided informed consent

5. Customer Obligations (Data Controller)

The Customer, as Data Controller, is responsible for:

6. Selby Labs Obligations (Data Processor under Article 28 GDPR)

Selby Labs will:

7. Security Measures (Article 32 GDPR)

Selby Labs implements and maintains the following technical and organisational measures:

The Customer may request evidence of compliance. An audit may be conducted with no less than 30 days written notice, at the Customer's cost, subject to confidentiality protections.

8. Sub-processors

The Customer provides general written authorisation for Selby Labs to engage the sub-processors listed below. Selby Labs will inform the Customer of any intended addition or replacement with at least 14 days written notice, providing the Customer an opportunity to object on legitimate data protection grounds. Selby Labs shall impose equivalent obligations on all sub-processors and remains fully liable for sub-processor performance.

Sub-processorPurposeData categoriesLocationTransfer mechanism
Amazon Web Services EMEA SARLEC2 compute and EBS storage provisioned per paid Customer as an isolated EC2 virtual machine instance with its own EBS volumes on AWS's standard shared-tenancy infrastructureAll Study Data; Customer account metadataIreland (eu-west-1) or Germany (eu-central-1), as selected by the Customer at orderingNo transfer; data remains within the EU
Wise Europe SA / Wise Payments LtdInvoicing and payment processingCustomer billing contact and invoice line items only; no Study DataBelgium and United KingdomNo transfer for EU entity; UK adequacy decision for the UK entity
OpenWeather LtdAmbient-weather lookup by coordinates, when the Customer enables the Weather sensorParticipant GPS coordinates at time of query (no other Study Data)United KingdomUK adequacy decision
Cloudflare, Inc.Authoritative DNS for *.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Cloudflare is not used as a reverse proxy; participant and researcher traffic does not flow through Cloudflare's networkCustomer subdomain names and associated DNS records; DNS query metadata observed by resolversUnited StatesStandard Contractual Clauses (Module 2, Controller-to-Processor)
Internet Security Research Group (Let's Encrypt)Issuance of TLS certificates for customer subdomains via the ACME protocolCustomer subdomain names onlyUnited StatesStandard Contractual Clauses
Transactional email provider (current provider identified at support@studyrun.org on request)Service-related notifications (order confirmation, export reminders, breach notifications)Customer contact email and message content; no Study DataPer provider; disclosed on requestPer provider

Device-platform APIs (not sub-processors): The StudyRun mobile app also reads from and interacts with APIs provided by the operating system of the Participant's own device: Apple HealthKit and Apple Core Motion on iOS; and Google Health Connect, Google Play Services Location Services, and Google ML Kit on-device barcode scanning on Android. Data read through these APIs is read from the Participant's device, not from Apple or Google. Use of Google Play Services Location on Android may cause a limited amount of telemetry to be transmitted to Google in the course of normal Android system operation; Google's handling of that telemetry is governed by Google's own Android-platform privacy documentation. These relationships are disclosed here for transparency and are not sub-processor engagements under Article 28 GDPR.

8.1 Sub-processor change notification

The Customer may subscribe to sub-processor change notifications by sending an email to support@studyrun.org with the subject line "Sub-processor notifications". Subscribed Customers will receive email notice of any intended addition or replacement of a sub-processor at least 14 days before the change takes effect, together with sufficient information to assess the data-protection implications of the change. The current sub-processor list is also maintained at studyrun.org/sub-processors. Objections to a proposed sub-processor change should be sent to the same address; an unresolved legitimate-grounds objection entitles the Customer to terminate this agreement and the underlying Services subscription on 30 days written notice without penalty, and to a pro-rata refund of prepaid fees for the unexpired portion of the subscription.

9. Data Protection Impact Assessment

Selby Labs will provide reasonable assistance to the Customer in carrying out DPIAs under Article 35 GDPR, including providing relevant documentation on the technical and organisational measures implemented.

DPIA note: Given that StudyRun processes health-adjacent behavioural data using systematic mobile monitoring, most studies conducted on the Platform will likely require a DPIA by the Customer before data collection commences. Contact support@studyrun.org to request Selby Labs's technical documentation to support your DPIA.

10. Data Subject Rights

10.1 General assistance

Selby Labs will assist the Customer in fulfilling its obligations to respond to data subject rights requests under Articles 15–22 GDPR, including rights of access, rectification, erasure, restriction, portability, and objection, by providing technical tools within the Platform dashboard.

10.2 Direct requests from data subjects

Where a data subject contacts Selby Labs directly with a rights request, Selby Labs will forward the request to the Customer within 5 business days and will not respond to the data subject without the Customer's prior written authorisation.

10.3 Participant erasure (right to be forgotten)

Where a research participant withdraws consent or requests erasure under Article 17 GDPR, the Customer is responsible for making a verified deletion request to Selby Labs. Upon receiving a verified deletion request from the Customer, Selby Labs will:

10.4 Right to restrict processing

Where a participant requests restriction of processing under Article 18 GDPR, Selby Labs will, upon the Customer's instruction, freeze processing for the relevant participant identifier without deleting the data, within 5 business days of the Customer's instruction.

10.5 Data portability

Selby Labs provides export tools within the Platform dashboard enabling the Customer to export all data for a specific participant in machine-readable format (JSON and CSV) to support portability requests under Article 20 GDPR.

10.6 Orphaned-controller fallback

If Selby Labs is made aware that the Customer can no longer be reached (for example because the Customer has ceased to exist as a legal entity, the nominated researcher contact has left the institution and no successor has been appointed, or the Customer's subscription has long since lapsed and all contact attempts have failed) and a data subject whose personal data is still held by Selby Labs for that Customer exercises a right under Articles 15–22 GDPR, Selby Labs may, after at least 30 days of documented unsuccessful attempts to reach the Customer and at Selby Labs's reasonable discretion, respond to the data subject directly to give effect to that right, including by deleting the data subject's personal data. Any such action is documented in the deletion log referred to in Section 13.4.

10.7 Automated decision-making restriction

Selby Labs does not itself use Study Data to carry out automated decisions producing legal or similarly significant effects on Participants within the meaning of Article 22 GDPR. The Customer must not configure the Platform to carry out such decisions, and must not export Study Data from the Platform into downstream systems that carry out such decisions, without an Article 22(2) basis and without providing Participants with the safeguards required by Article 22(3).

11. International Data Transfers and Standard Contractual Clauses

11.1 Transfer mechanism and record-keeping

As noted in Section 2, Australia does not have an EU adequacy decision. The appropriate safeguard for transfers of personal data from the EU/EEA/UK to Australia under this agreement is the Standard Contractual Clauses, adopted pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller to Processor), as incorporated below.

Selby Labs shall maintain a record of all international transfers of personal data made under this agreement and the safeguards in place for each transfer. This record is available to the Customer on request.

11.1A Support-access disclosure

Selby Labs is established in Australia. Selby Labs personnel located in Australia routinely access EU-hosted infrastructure for platform maintenance, monitoring, incident response, and similar operational purposes. Each such access from Australia constitutes an onward transfer from the EU AWS region to Australia for the purposes of Chapter V GDPR; the parties agree that these transfers are covered by the Standard Contractual Clauses incorporated in Section 11.2. Such access is subject to: (i) least-privilege role-based access controls; (ii) individual named user accounts; (iii) logging of administrative sessions; and (iv) confidentiality obligations on all personnel.

11.1B Transfer Impact Assessment

Selby Labs has carried out, and periodically reviews, a Transfer Impact Assessment (TIA) in respect of transfers of personal data from the EU/EEA/UK to Australia under this agreement, consistent with Clause 14 of the Standard Contractual Clauses and the recommendations of the European Data Protection Board. The TIA considers, among other matters, the surveillance and law-enforcement access regime in Australia (including the Telecommunications (Interception and Access) Act 1979 (Cth), the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth), and the Australian Security Intelligence Organisation Act 1979 (Cth)), and the supplementary technical, contractual, and organisational measures applied by Selby Labs to mitigate the risks identified. A copy of the current TIA will be provided to the Customer on request at support@studyrun.org, subject to reasonable confidentiality protections.

11.1C Transparency regarding access requests by public authorities

In accordance with Clause 15 of the Standard Contractual Clauses, Selby Labs shall: (a) if legally permitted, promptly notify the Customer and, where the Customer cannot be reached, the affected data subjects, of any binding legally-enforceable request from a public authority for access to personal data transferred under this agreement; (b) where Selby Labs is legally prohibited from notifying the Customer, use reasonable efforts to obtain a waiver of the prohibition and document its efforts; (c) provide the minimum amount of personal data permissible when responding to any such request, based on a reasonable interpretation of the request; and (d) challenge any request it considers unlawful or disproportionate under applicable law. Selby Labs publishes aggregate transparency statistics about such requests, to the extent legally permissible, at studyrun.org/transparency.

11.1D Joint-controller fallback

The parties have categorised their relationship as controller-processor, without admission that any contrary categorisation applies. This Section is a contingent fallback only and does not of itself establish joint controllership.

To the extent a competent supervisory authority or court determines, on review of a specific subset of processing activities such as Selby Labs's collection of platform-operational telemetry (crash reports, device-info events) or the choice of retention periods and pseudonymisation scheme for the Platform as a whole, that the parties are joint controllers within the meaning of Article 26 GDPR for that subset only, the parties agree that: (i) Selby Labs is the point of contact for data subjects in respect of platform-technical queries only (for example, questions about the technical operation of the app or data-integrity checks). The "rights exercise where Participants cannot reach the Customer" path is the separate orphaned-controller fallback in Section 10.6 and is subject to the 30-day attempt period described there, not this Section; (ii) the Customer is the point of contact for all study-specific queries (including requests relating to the purposes of processing, consent validity, and the content of surveys and tasks); and (iii) this Section operates as an Article 26 arrangement for the specific subset of processing so found, and for no other processing. A summary of this arrangement will be made available to data subjects on request and at studyrun.org/joint-controllership.

11.2 Incorporation of the Standard Contractual Clauses

The parties incorporate into this agreement, by reference and as if set out in full herein and without modification, Module 2 (Controller-to-Processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as published in the Official Journal of the European Union, L 199, 7.6.2021, pp. 31-61 (the "Standard Contractual Clauses" or "Clauses").

The official text of the Standard Contractual Clauses is available at eur-lex.europa.eu/eli/dec_impl/2021/914/oj. A plain-text copy of the Clauses will be provided free of charge by Selby Labs on request to support@studyrun.org, and the Data Importer shall make a copy available to any data subject free of charge on request as required by Clause 8.3 of the Clauses.

Where this agreement and the Clauses are inconsistent, the Clauses shall prevail, in accordance with Clause 5 of the Clauses.

For the purposes of the Clauses: the Data Exporter is the Customer identified in the StudyRun account registration; the Data Importer is Selby Labs Pty Ltd. The Annexes to the Clauses are completed in Annex I, Annex II, and Annex III of this agreement.

11.3 Module-specific selections and elected options

The parties record the following selections and options in accordance with the optional provisions of the Clauses:

ClauseParties' selection
Clause 7: Docking clause Not included. Additional parties may only accede to the Clauses by separate written agreement with the existing parties.
Clause 9(a): Use of sub-processors Option 2: General written authorisation. The Data Importer has the Data Exporter's general authorisation to engage the sub-processors listed in Annex III. The Data Importer shall inform the Data Exporter in writing of any intended changes to that list at least 14 days in advance, giving the Data Exporter sufficient time to object before engagement.
Clause 11(a): Independent dispute resolution body The optional element regarding an independent dispute resolution body is not included. Data subjects retain all rights to lodge complaints with their competent supervisory authority and to seek judicial redress as provided by Clauses 10 and 11 of the Clauses.
Clause 13: Supervision The competent supervisory authority is the supervisory authority of the EU/EEA Member State in which the Data Exporter (Customer) is established. Where the Data Exporter is not established in an EU/EEA Member State but the processing falls within the territorial scope of Article 3(2) GDPR, the competent supervisory authority is the supervisory authority of the Member State in which the Data Importer's EU Representative (appointed under Article 27 GDPR) is established, as recorded in Annex I.C.
Clause 17: Governing law Option 1. The Clauses are governed by the law of Ireland, being an EU Member State whose law allows for third-party beneficiary rights.
Clause 18(b): Choice of forum and jurisdiction Any dispute arising from the Clauses shall be resolved by the courts of Ireland. Data subjects retain the right under Clause 18(c) of the Clauses to bring proceedings against the Data Exporter and/or the Data Importer before the courts of their habitual residence.
Note on scope. Incorporation-by-reference is expressly permitted by the Clauses themselves (which, per Clause 2, may not be modified but may be included within a wider contract) and is commonly used in commercial DPAs. The Annexes below are the only parts of the Clauses the parties may fill in. Before go-live, Selby Labs recommends that each Customer satisfy itself, through its own legal review, that the text of the Clauses as published in Commission Implementing Decision (EU) 2021/914 meets its institutional requirements.

Annex I: Description of Transfer

Populated per the template in Annex I of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Sub-headings A, B, and C follow the OJ schema.

A. List of Parties

Data Exporter (Controller): The EU/EEA/UK researcher or research institution identified in the StudyRun account registration for the Customer accepting this DPA. The Data Exporter's specific legal name, registered address, country of establishment, designated contact person, role, and electronic-signature record (typed name, timestamp, IP address, document version) are captured in the clickwrap acceptance snapshot recorded at the time of acceptance. These details are Customer-specific and are preserved in the users and upgrade_orders records for the Customer's account, and are surfaced to the Customer via the /api/v1/auth/me endpoint. This per-Customer population of Party details is consistent with the SCCs, which contemplate that the Parties are those identified at the time of contract formation rather than statically listed in the template.

Data Importer (Processor): Selby Labs Pty Ltd, ABN 50 697 107 083, Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia. Designated contact: the Selby Labs support team at support@studyrun.org. Role: Data Processor under Article 28 GDPR and Data Importer under the SCCs.

Data Importer's EU Representative (appointed under Article 27 GDPR): Chrysanthi Mella, PO Box 1049, Marathonas 19007, Greece, Email: eu-representative@studyrun.org.

B. Description of the transfer

Categories of data subjects: Research participants recruited by the Data Exporter who have provided informed consent to participate in a study. No employee, contractor, or commercial-contact personal data is processed under this agreement.

Categories of personal data transferred: As set out in Section 4 of this DPA. In summary: motion and orientation sensor data; environmental sensor data; location, connectivity, and proximity data (GPS, WiFi, Bluetooth, iBeacon, cellular telephony, network state); device and system-state data; user-behaviour data including per-app foreground usage, call-log and SMS-log metadata, notification metadata and (where enabled) notification title and body, touch and keystroke events (aggregate or raw), on-screen text, full-screen bitmap captures, and active-media-session metadata; calendar and contacts data where enabled; interactive task data including ESM/EMA responses, PVT results, raw photographs, raw audio recordings, Show-Webpage responses, and Micro-Randomisation allocation outcomes; and internal technical data (device model, OS version, app version, crash reports, app-start events).

Sensitive data (Article 9 GDPR special-category data): Health and wearable data from Apple HealthKit and Google Health Connect, including clinical-health records, menstrual/reproductive/sexual-activity data, blood pressure, blood glucose, heart rate, heart-rate variability, sleep, nutrition, and workouts; audio recordings capturing the Participant's voice (biometric data under Article 4(14) GDPR); and free-text inputs (survey responses, keystroke content, on-screen text, notification content) that may incidentally contain special-category data. The Data Exporter is responsible for identifying a valid Article 9(2) basis and reflecting it in the participant privacy notice before enabling any such category. Additional restrictions and safeguards for sensitive data: study-level opt-in per sensor (no category is collected unless the Data Exporter has enabled it in the study configuration), pseudonymisation before upload, and per-Participant in-app consent capture.

Frequency of transfer: Continuous during active study periods. Study Data is transmitted from participant devices to the EU AWS server on an ongoing basis while the StudyRun mobile app is installed and the study is active. Selby Labs staff in Australia access the EU-hosted infrastructure only for platform maintenance, monitoring, and incident response (see Section 11.1A).

Nature of processing: Collection, storage, pseudonymisation, structuring, retrieval, export, and deletion of Study Data on behalf of the Data Exporter. No processing is carried out for Selby Labs's own purposes.

Purpose of processing: To provide the StudyRun platform services as instructed by the Data Exporter, comprising receipt of sensor data, availability of researcher dashboards, provision of export tools, and deletion of data on instruction or at subscription end.

Period of retention / Duration of processing: For the term of the Customer's subscription, followed by a 7-day export grace period. After the grace period the server is terminated and personal data is deleted from primary storage; backups are purged on the next 7-day rotation (no later than 14 days after subscription end). Per-Participant erasure requests are executed within 5 business days on primary storage and on the next backup rotation thereafter.

Transfers to (sub-) processors: See Annex III for the list of sub-processors, the nature and duration of processing for each, and the transfer mechanism that applies.

C. Competent supervisory authority

In accordance with Clause 13 of the SCCs, the competent supervisory authority is determined as follows:

Annex II: Technical and Organisational Measures

Populated per the template in Annex II of the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), regrouped under the Implementing Decision's own category headings so each is directly mappable to the OJ schema.

Measures of pseudonymisation and encryption of personal data

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures

Measures for user identification and authorisation

Measures for the protection of data during transmission

Measures for the protection of data during storage

Measures for ensuring events logging

Measures for ensuring limited data retention and erasure

Measures for ensuring accountability

Specific measures for transfers to sub-processors

Annex III: List of Sub-processors

Sub-processorPurposeData categoriesLocationTransfer mechanism
Amazon Web Services EMEA SARLEC2 compute and EBS storage provisioned per paid Customer as an isolated EC2 virtual machine instance with its own EBS volumes on AWS's standard shared-tenancy infrastructureAll Study Data; Customer account metadataIreland (eu-west-1) or Germany (eu-central-1), as selected by the Customer at orderingNo transfer; data remains within the EU
Wise Europe SA / Wise Payments LtdInvoicing and payment processingCustomer billing contact and invoice line items only; no Study DataBelgium and United KingdomNo transfer for EU entity; UK adequacy decision for the UK entity
OpenWeather LtdAmbient-weather lookup by coordinates, when the Weather sensor is enabledParticipant GPS coordinates at time of query (no other Study Data)United KingdomUK adequacy decision
Cloudflare, Inc.Authoritative DNS for *.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Not used as a reverse proxyCustomer subdomain names and DNS records; DNS query metadata observed by resolversUnited StatesStandard Contractual Clauses (Module 2)
Internet Security Research Group (Let's Encrypt)Issuance of TLS certificates via the ACME protocolCustomer subdomain names onlyUnited StatesStandard Contractual Clauses
Transactional email providerService-related notifications (order confirmation, export reminders, breach notifications)Customer contact email and message content; no Study DataDisclosed on request at support@studyrun.orgPer provider

Device-platform APIs (not sub-processors): Apple HealthKit and Core Motion on iOS; Google Health Connect, Play Services Location Services, and ML Kit on Android. Data read through these APIs is read from the Participant's own device. See Section 8 for the full note.

12. Data Breach Notification

Selby Labs will notify the Customer without undue delay and in any event within 48 hours after becoming aware of a data breach affecting Study Data, to enable the Customer to meet its 72-hour notification obligation under Article 33 GDPR. The notification will include:

Where information is not available in full at the time of initial notification, Selby Labs will provide it in phases without undue further delay. Selby Labs cooperates fully with the Customer in investigating, remediating, and reporting any breach. Selby Labs maintains an internal breach register in accordance with Article 33(5) GDPR. The Customer, as Data Controller, remains responsible for notifying the supervisory authority under Article 33 and data subjects under Article 34 GDPR where required.

13. Deletion and Return of Data

13.1 On termination or Customer request

Upon termination of services, or upon the Customer's written request at any time during the subscription period, Selby Labs shall, at the Customer's choice, delete or return all personal data and delete all existing copies, unless applicable law requires storage. Deletion shall cascade across all storage systems, databases, backup systems, and logs; because backups rotate on a 7-day cycle, purging of personal data from backups completes no later than 7 days after the primary database deletion. Selby Labs shall provide written confirmation of deletion on the Customer's request.

13.2 At subscription end

A countdown and export reminder are shown in the Platform dashboard throughout the subscription, with prominent notice as the subscription end date approaches. At subscription end the Customer has a 7-day export grace period during which they retain read and export access to their server instance. At the end of that 7-day period the server is terminated, the primary database is deleted, and Study Data is purged from backups on the next rotation of the 7-day backup cycle (no later than 14 days after subscription end). Written confirmation of deletion is provided on request.

13.3 Participant-level deletion

The Customer may request deletion of all data held for a specific participant at any time. Upon receiving a verified deletion request, Selby Labs will delete all identifiable data for that participant, cascading across all systems, within 5 business days, and provide written confirmation. See Section 10.3 for full details.

13.4 Deletion confirmation log

For all deletions, Selby Labs retains a non-identifiable deletion log recording the date, the pseudonym identifier, and the type of deletion action. This log does not constitute retention of personal data and is maintained for audit purposes only.

14. Audit Rights

Selby Labs shall make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and this agreement. The Customer or a mandated auditor may conduct an audit with no less than 30 days written notice, at the Customer's cost, subject to confidentiality protections. Selby Labs may provide relevant third-party certifications or security assessment reports in lieu of on-site audits.

15. Liability and Indemnification

Each party shall be liable to the other for material damage caused by non-compliance with this agreement. The Customer shall indemnify Selby Labs against third-party claims arising from the Customer's failure to have a lawful basis for processing or to obtain valid Participant consent. Selby Labs's liability is subject to the limitation in the Terms of Service, except as required by mandatory law including the GDPR and the SCCs.

16. Order of Precedence

In the event of conflict regarding personal data subject to GDPR: the SCCs (Section 11) take precedence over this DPA, which takes precedence over the Terms of Service. Nothing in the Terms of Service limits the rights of data subjects or the obligations of the parties under the SCCs.

17. Governing Law (DPA)

This Data Processing Agreement (excluding the SCCs which are governed by Irish law) is governed by the laws of Victoria, Australia, without prejudice to mandatory rights of data subjects under GDPR. Disputes shall be referred to the courts of Victoria, Australia, except where mandatory GDPR or SCC provisions require otherwise.

Contact

Selby Labs Pty Ltd  ·  ABN 50 697 107 083

Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia

Email: support@studyrun.org

EU Representative (Article 27 GDPR):

Chrysanthi Mella

PO Box 1049, Marathonas 19007, Greece

eu-representative@studyrun.org