This Data Processing Agreement applies to Customers whose institution is based outside Australia and outside the EU/EEA/UK (for example, in the United States, Canada, Brazil, Switzerland, Japan, Singapore, or any other jurisdiction not covered by our
Australian DPA or our
EU DPA). If your institution is based in Australia, use the Australian DPA. If your institution is based in the EU/EEA/UK, or your study participants are located there, use the EU DPA.
How this agreement is formed: This DPA is incorporated by reference into the StudyRun Terms of Service. By clicking "I Agree" during registration or when upgrading your subscription, you accept this DPA. Your agreement is recorded with your name, timestamp, IP address, and the version of this document in force at the time.
1. Parties
Data Processor (Selby Labs): Selby Labs Pty Ltd, ABN 50 697 107 083, Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia. Email: support@studyrun.org
Data Controller (Customer): The researcher or institution identified in your StudyRun account registration and subscription details.
2. Background
The Customer is a researcher or research institution that uses the StudyRun platform to conduct digital phenotyping studies, collecting personal data from research participants. In providing the StudyRun platform services, Selby Labs processes personal data on behalf of the Customer. This agreement governs that processing relationship, supplementing whatever data-protection legislation applies in the Customer's jurisdiction ("Applicable Data Protection Law").
Demo server: The StudyRun demo environment is hosted in Australia (AWS ap-southeast-2, Sydney). The demo environment is intended solely for testing and evaluating the platform by researchers; it must not be used to collect personal data from real research participants. The demo is a shared, multi-tenant environment; the per-Customer instance-isolation and operational security commitments described in this agreement apply only to paid subscription servers. The demo server is provided on a best-efforts basis only and may be suspended, reset, or permanently deleted at any time and without prior notice, at Selby Labs's sole discretion. No data persistence is guaranteed and no liability arises from interruption or deletion of demo data. Real participant Study Data must only be processed on a paid subscription server.
Use exclusions. The Platform, as offered under this DPA, may NOT be used to process:
- Protected Health Information (PHI) subject to HIPAA (42 U.S.C. §1320d et seq. and 45 C.F.R. parts 160 and 164). If you are a covered entity or business associate under HIPAA and your study involves PHI, you must first execute a separate StudyRun Business Associate Agreement with Selby Labs. Contact support@studyrun.org to request one. Without a countersigned BAA in place, any upload of PHI through the Platform is a breach of this DPA and of the Terms of Service.
- Personal data of children under the age of 13 subject to COPPA (15 U.S.C. §§6501-6506), or personal data of minors below the age of digital consent in the jurisdiction of the child's habitual residence, unless valid parental or guardian consent has been obtained outside the Platform in the form required by the applicable law and by your ethics committee. Selby Labs does not operate an in-app age gate and the Customer is solely responsible for age screening.
3. Definitions
Personal Data means any information relating to an identified or identifiable natural person, as defined by the Applicable Data Protection Law.
Sensitive Personal Information has the meaning given in the Applicable Data Protection Law and includes, in jurisdictions that recognise the concept, health data, biometric identifiers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, and genetic data.
Study Data means all personal data and other data collected from Participants through the Customer's studies on the Platform.
Platform means the StudyRun digital phenotyping research platform and associated services.
Services means the services provided by Selby Labs to the Customer under the Terms of Service.
4. Nature and Purpose of Processing
Selby Labs processes personal data on behalf of the Customer for the purpose of providing the Platform services, including:
- Receiving and storing sensor data, survey responses, and interactive-task results collected from Participants via the StudyRun mobile application
- Making Study Data available to the Customer through the Platform dashboard
- Providing data export tools for the Customer to retrieve Study Data
- Deleting Study Data upon the Customer's instruction or at subscription end
- Maintaining Platform security and availability
The categories of personal data the Platform is capable of processing are set out below. Each category is enabled per-study by the Customer; no category is processed unless the Customer has enabled it in their study configuration.
- Motion & orientation sensors: accelerometer (including high-frequency sampling), linear accelerometer, gyroscope, gravity, rotation, magnetometer, significant-motion events, motion-activity classification, pedometer step counts, and headphone motion.
- Environment: barometer, ambient light, ambient temperature, proximity, and ambient noise level (decibel amplitude only; audio content is not recorded or uploaded by this sensor).
- Location, connectivity & proximity: GPS coordinates, WiFi scan results, Bluetooth device discovery including iBeacon proximity, network connectivity state, and cellular telephony metadata.
- Device & system state: battery, screen on/off events, CPU and memory utilisation, installed application list, timezone, headphone connection state, and ringer mode.
- User behaviour: per-application foreground usage; call-log and SMS-log metadata; per-app notification metadata and, where enabled by the Customer, the full title and body of notifications (via the Android NotificationListenerService); active-media-session metadata; touch and gesture events; keystroke events captured as aggregate typing-rate metrics or, where enabled by the Customer, individual keystrokes (via the Android Accessibility Service); on-screen text visible in any app (via the Android Accessibility Service); and full-screen bitmap captures (via the Android MediaProjection API).
- Health & wearable data: Apple HealthKit on iOS and Google Health Connect on Android, including, where exposed by those platforms, clinical-health records, menstrual/reproductive/sexual-activity data, blood pressure, blood glucose, heart rate, heart-rate variability, sleep, nutrition, and workout data. This is sensitive personal information under most Applicable Data Protection Laws (including California CPRA, Illinois BIPA where biometrics are implicated, Washington MHMD for consumer health data, and Brazil's LGPD); the Customer is responsible for the lawful-processing basis and any required explicit consent. Collection of this category without a pre-executed BAA is, specifically, prohibited where HIPAA applies (see "Use exclusions" above).
- Personal data stores: calendar events and contacts, where enabled and permitted by the Participant's device.
- Interactive task data: ESM/EMA responses, PVT reaction-time results, photographs uploaded as Photo Diary entries (raw JPEG), audio recordings made as Audio Recording tasks (raw audio), responses to Show-Webpage tasks, and Micro-Randomisation allocation outcomes.
- Internal technical data collected by Selby Labs for platform reliability: device model, OS version, app version, crash reports, and app-start events. This category is collected on every study regardless of Customer configuration.
5. Customer Obligations (Data Controller)
The Customer is responsible for:
- Identifying and documenting a lawful basis for processing each category of personal data under the Applicable Data Protection Law
- Obtaining valid, informed consent from all Participants before data collection commences, in the form required by the Applicable Data Protection Law and the Customer's ethics committee, including, where applicable: CCPA/CPRA notice at collection (California, Virginia, Colorado, Connecticut, Utah, Texas, and similar US state laws); Illinois BIPA written informed consent before any biometric identifier is collected; Washington MHMD authorisation before collecting consumer health data; LGPD informed consent (Brazil); PIPEDA/Quebec Law 25 consent (Canada); PDPA notification and consent (Singapore); APPI notice (Japan); PIPA consent (South Korea); and analogous requirements of any other jurisdiction in which Participants reside
- Providing Participants with a privacy notice that accurately describes the data collection and the role of StudyRun
- Ensuring all Participants are made aware of and agree to the Additional Terms for Participants before using the StudyRun mobile app
- Obtaining all required ethics approvals (IRB / HREC / REC / equivalent) before commencing any study, and keeping those approvals current for the duration of the study
- Complying with the Applicable Data Protection Law, sector-specific laws (including HIPAA where PHI is involved, FERPA where educational records are involved, GLBA where financial records are involved), and any applicable research-ethics framework (including 45 CFR 46 Common Rule for US-funded research)
- Honouring the use exclusions in Section 2 of this DPA
- Maintaining records that link Participant identifiers to individual Participants. Selby Labs stores data against pseudonymous identifiers only and does not hold any such mapping.
- Fulfilling data-subject / consumer rights requests (access, deletion, correction, portability, opt-out of sale or sharing, and any other rights granted by the Applicable Data Protection Law) and relaying them to Selby Labs for technical execution as contemplated in Section 11
6. Selby Labs Obligations (Data Processor / Service Provider)
Selby Labs will:
- Process Study Data only in accordance with the Customer's instructions and for the purpose of providing the Services
- Not use, retain, sell, share, or disclose Study Data for any purpose other than the specific purpose of providing the Services specified in this DPA. For the avoidance of doubt, and for the purposes of the California Consumer Privacy Act / California Privacy Rights Act and analogous US state laws, Selby Labs acts as a service provider / processor / contractor, does not sell or share Study Data, does not combine Study Data with personal information received from or on behalf of any other person or collected from its own interactions with the consumer, and does not use Study Data for cross-context behavioural advertising
- Not disclose Study Data to any third party except sub-processors engaged in accordance with Section 7, or as required by law (subject to Section 11.4)
- Implement and maintain the technical and organisational security measures set out in Section 8
- Notify the Customer of a security breach affecting Study Data in accordance with Section 10
- Provide the Customer with tools to export, correct, and delete Study Data
- Capture a timestamped in-app consent record for each Participant, bound to the Participant's pseudonymous identifier, the study identifier, and the device identifier, before any sensor data collection begins for that Participant. This record is uploaded with Study Data and is available to the Customer through the Platform export tools. The record supplements, and does not replace, the Customer's own informed-consent process required by the Applicable Data Protection Law (including written informed consent under Illinois BIPA, signed authorisation under Washington MHMD, and COPPA-compliant parental consent where applicable); Selby Labs does not capture signatures, identity verification, or the exact rendered consent text
- Delete all Study Data at subscription end as described in Section 9, and provide written confirmation of deletion on request
- Remain fully liable to the Customer for the performance of any sub-processor's obligations
7. Sub-processors
Selby Labs uses the following sub-processors to provide the Services. All sub-processors are contractually bound to handle personal data in a manner consistent with this agreement:
- Amazon Web Services (AWS): EC2 compute and EBS storage provisioned per paid Customer as an isolated EC2 virtual machine instance with its own EBS volumes on AWS's standard shared-tenancy infrastructure, and for the shared demo environment. For international Customers the default region is AWS Sydney (ap-southeast-2); EU regions are available on request
- Wise: Invoicing and payment processing (Customer billing contact and invoice line items only; no Study Data transferred).
- OpenWeather Ltd (United Kingdom): Ambient-weather lookup by latitude/longitude (rounded to ~1.1 km precision), when the Customer enables the Weather sensor in their study
- Cloudflare, Inc. (United States): Authoritative DNS for
*.studyrun.org customer subdomains and ACME DNS-01 challenge for TLS certificate issuance. Cloudflare is not used as a reverse proxy; participant and researcher traffic does not traverse Cloudflare's network
- Internet Security Research Group / Let's Encrypt (United States): Issuance of TLS certificates for customer subdomains via the ACME protocol. Only the subdomain name is shared
- Transactional email provider: Current provider identified on request at support@studyrun.org. Used for service-related notifications; Customer contact email and message content only; no Study Data
Device-platform APIs (not sub-processors): The StudyRun mobile app also reads from APIs provided by the Participant's own device operating system: Apple HealthKit and Core Motion on iOS; and Google Health Connect, Google Play Services Location Services, and Google ML Kit on Android. Data read through these APIs is read from the Participant's device, not from Apple or Google.
Selby Labs will notify the Customer of any changes to the sub-processor list that could affect the processing of Study Data, with at least 14 days written notice before the change takes effect. The Customer may subscribe to sub-processor change notifications by sending an email to support@studyrun.org with the subject line "Sub-processor notifications". Unresolved legitimate-grounds objections entitle the Customer to terminate this agreement without penalty and with a pro-rata refund of prepaid fees for the unexpired portion of the subscription.
8. Security Measures
Selby Labs implements the following security measures to protect Study Data:
- Server-side encryption at rest: AWS EBS volume encryption (AES-256-XTS) with AWS-managed keys, applied to all paid subscription servers and the shared demo server
- TLS 1.2 or higher encryption of all data in transit
- Pseudonymisation: Study Data is stored against pseudonymous Participant identifiers assigned by the Customer. Selby Labs does not hold or have access to any mapping between those identifiers and the natural persons they refer to
- Role-based access controls limiting access to authorised personnel only; principle of least privilege enforced
- Comprehensive audit logging of access to personal data
- Regular security reviews and vulnerability assessments
- Network and application-layer protections: the Caddy reverse proxy terminates TLS; AWS Shield Standard mitigates common volumetric and protocol-layer denial-of-service attacks; application-layer rate limiting on sensitive endpoints
- Per-Customer instance isolation: each paid Customer receives its own AWS EC2 virtual machine instance and its own EBS storage volumes; Study Data is logically isolated within the StudyRun application and database and is not co-mingled with other Customers' data. The underlying AWS physical infrastructure operates under AWS's standard shared-tenancy model with hypervisor-level isolation between AWS tenants; AWS Dedicated Host or Dedicated Instance tenancy is available as a paid add-on on request
- Remote access by Selby Labs staff in Australia governed by documented procedures and full audit logging
- Vulnerability scanning and penetration testing conducted at least annually
- Business continuity and disaster recovery plan tested annually
- All personnel with access to personal data bound by confidentiality obligations
9. Data Retention and Deletion
Study Data is retained for the duration of the Customer's subscription. A countdown and export reminder are shown in the Platform dashboard throughout the subscription, with prominent notice as the subscription end date approaches. At subscription end the Customer has a 7-day export grace period during which read and export access to the Customer's server instance is retained. At the end of that 7-day period the server is terminated, the primary database is deleted, and Study Data is purged from backups on the next rotation of the 7-day backup cycle (no later than 14 days after subscription end).
Important: Once data is deleted from the StudyRun Platform, deletion is permanent and cannot be reversed. Please ensure you export all required Study Data before your subscription expires or before requesting deletion.
Selby Labs will provide written confirmation of deletion upon request. The Customer may request deletion of Study Data at any time during the subscription period by contacting support@studyrun.org.
10. Data Breach Notification
Selby Labs will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a data breach affecting Study Data. The notification will include, to the extent known at the time: the nature of the breach, the categories and approximate number of Participants affected, the likely consequences, the contact details of Selby Labs's data protection contact, and the steps taken or proposed to address the breach and mitigate its effects. Where information is not available in full at the time of initial notification, Selby Labs will provide it in phases without undue further delay.
The Customer is responsible for determining whether the breach is notifiable under the Applicable Data Protection Law and for notifying the relevant supervisory authority and affected Participants as required. This includes, where applicable, notification under the US state breach-notification laws (all 50 states plus DC, Puerto Rico, and the US Virgin Islands), the HIPAA Breach Notification Rule (45 C.F.R. §§164.400-414) where a BAA has been executed, LGPD Article 48 (Brazil), PIPEDA (Canada), PDPA (Singapore), APPI (Japan), PIPA (South Korea), POPIA (South Africa), and analogous rules elsewhere.
11. Data Subject and Consumer Rights
11.1 General assistance
Selby Labs will assist the Customer, on reasonable request, in responding to verifiable requests from Participants to exercise rights under the Applicable Data Protection Law, including rights of access, correction/rectification, deletion/erasure, portability, restriction, and (where applicable) opt-out of sale or sharing, by providing technical tools within the Platform dashboard.
11.2 Direct requests from Participants
If a Participant contacts Selby Labs directly with a rights request, Selby Labs will forward the request to the Customer within 5 business days and will not respond to the Participant substantively without the Customer's prior written authorisation, except as permitted by Section 11.3.
11.3 Participant-level erasure
Where a Participant withdraws consent or requests deletion of their personal data, the Customer is responsible for making a verified deletion request to Selby Labs. On receipt of a verified request from the Customer, Selby Labs will delete all personal data held for that Participant from primary storage, databases, and logs within 5 business days, and from backup systems on the next rotation of the 7-day backup cycle, with full purge completing no later than 7 business days plus 7 calendar days from the verified request. Written confirmation is provided once the backup purge completes. A non-identifiable deletion-log entry recording the date, pseudonym identifier, and type of deletion is retained for audit purposes; this log does not constitute retention of personal data.
11.4 Government access requests
If Selby Labs receives a legally-enforceable request from a public authority for access to Study Data, it will: (a) where legally permitted, promptly notify the Customer and, where the Customer cannot be reached, the affected Participants; (b) where legally prohibited from notifying the Customer, use reasonable efforts to obtain a waiver of the prohibition and document its efforts; (c) provide the minimum amount of personal data permissible based on a reasonable interpretation of the request; and (d) challenge any request that it considers unlawful or disproportionate under applicable law. Selby Labs has received no such request as at the effective date of this agreement.
12. International Data Transfers
Selby Labs is based in Australia, and Study Data may be stored on AWS servers in Sydney, Australia (or, at the Customer's request, in an AWS region within the EU). Any transfer of personal data from the Customer's jurisdiction to Australia or another country is subject to the Applicable Data Protection Law's transfer requirements. Where the Applicable Data Protection Law requires a specific transfer safeguard (for example, Switzerland's revised Federal Act on Data Protection, Québec's Law 25, or Brazil's LGPD), the parties agree to execute the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 (Module 2, Controller to Processor), or the equivalent model clauses adopted by the Customer's jurisdiction where available, as an appendix to this DPA on request. Contact support@studyrun.org to initiate that process.
13. Orphaned-controller fallback
If Selby Labs is made aware that the Customer can no longer be reached (for example because the Customer has ceased to exist as a legal entity, the nominated researcher contact has left the institution and no successor has been appointed, or the Customer's subscription has long since lapsed and all contact attempts have failed) and a Participant whose personal data is still held by Selby Labs for that Customer exercises a right, Selby Labs may, after at least 30 days of documented unsuccessful attempts to reach the Customer and at Selby Labs's reasonable discretion, respond to the Participant directly to give effect to that right, including by deleting the Participant's personal data.
14. Roles: joint-controller fallback
The parties have categorised their relationship as Data Processor / Service Provider, without admission that any contrary categorisation applies. This Section is a contingent fallback only and does not of itself establish joint controllership.
To the extent a competent regulator or court determines, on review of a specific subset of processing activities (such as Selby Labs's collection of platform-operational telemetry like crash reports and device-info events, or the choice of retention periods and pseudonymisation scheme for the Platform), that the parties share controller-like responsibility for that subset only, the parties agree that Selby Labs will be the point of contact for Participants in respect of platform-technical queries only, and the Customer will be the point of contact for all study-specific queries. The handling of rights requests where the Customer cannot be reached is addressed separately in Section 13 (Orphaned-controller fallback) and is subject to the 30-day attempt period described there.
15. Automated decision-making restriction
Selby Labs does not use Study Data to carry out automated decisions producing legal or similarly significant effects on Participants. The Customer must not configure the Platform to carry out such decisions, and must not export Study Data from the Platform into downstream systems that carry out such decisions, without a lawful basis under the Applicable Data Protection Law and without providing Participants with the safeguards it requires.
16. Audit
Selby Labs will make available to the Customer, on reasonable request, information necessary to demonstrate compliance with this agreement. The Customer may request an audit of Selby Labs's data-processing practices with no less than 30 days written notice, at the Customer's cost, subject to reasonable confidentiality protections. Selby Labs may provide relevant third-party certifications or security assessment reports in lieu of on-site audits.
17. Severability
If any part of this agreement is held to be invalid, illegal, or unenforceable, that part will be severed and the remaining provisions will continue in full force and effect.
18. Term
This agreement commences on the date the Customer accepts the StudyRun Terms of Service and continues until all Study Data has been deleted following subscription termination. Clauses relating to security, confidentiality, deletion, and liability survive termination.
19. Governing Law
This agreement is governed by the laws of Victoria, Australia, without prejudice to non-excludable rights the Customer or any Participant may have under the Applicable Data Protection Law of the Customer's or Participant's jurisdiction. The parties submit to the non-exclusive jurisdiction of the courts of Victoria, Australia. Nothing in this clause deprives a Participant of the right to bring proceedings against Selby Labs in the courts of the Participant's habitual residence where the Applicable Data Protection Law confers such a right.