Data Processing Agreement
Last updated: June 29, 2026
1. Parties and Definitions
This Data Processing Agreement ("DPA") forms part of the agreement between:
- Customer ("Controller"): The organization that has entered into a subscription or services agreement with the Processor and determines the purposes and means of processing Personal Data.
- The Decision Lab ("Processor"): The legal entity operating the Artificial Populations platform ("Service") from Quebec, Canada.
For purposes of this DPA:
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Service.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including Quebec Law 25, PIPEDA, and where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR.
2. Scope and Subject Matter
This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Controller's use of the Artificial Populations Artificial research platform, including focus groups, surveys, and interviews.
3. Duration
This DPA remains in effect for the duration of the Controller's subscription or services agreement and until all Personal Data has been deleted or returned in accordance with Section 12, whichever is later.
4. Nature and Purpose of Processing
The Processor processes Personal Data to:
- Provide, operate, and maintain the Service
- Execute Artificial research studies requested by the Controller
- Authenticate users and manage accounts
- Process payments and manage subscriptions
- Send transactional communications
- Provide customer support
- Monitor security and prevent fraud
5. Categories of Data and Data Subjects
Categories of data subjects: Controller's employees, contractors, and authorized users who access the Service; individuals described in research inputs uploaded by the Controller.
Categories of Personal Data:
- Account information (name, email address, organization)
- Authentication and session data
- Research content and inputs uploaded by the Controller
- Usage and technical data (IP address, device information, logs)
- Billing and subscription information (processed via Stripe)
6. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including those set forth in the services agreement and this DPA
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures as described in our Security page
- Not sell Personal Data or use it for purposes unrelated to providing the Service
- Assist the Controller in responding to data subject requests, to the extent permitted by law and technically feasible
- Delete or return all Personal Data upon termination of the services agreement, except where retention is required by law
7. Sub-processors
The Controller authorizes the Processor to engage Sub-processors listed on our Security page, including Vercel, Neon, Stripe, Loops, PostHog, and AI model providers (OpenAI, Anthropic, Google, xAI).
The Processor shall impose data protection obligations on Sub-processors that are substantially similar to those in this DPA. The Processor shall provide the Controller with at least thirty (30) days' prior notice of any intended addition or replacement of Sub-processors, during which the Controller may object on reasonable grounds relating to data protection.
8. International Transfers
Personal Data may be transferred to and processed in Canada, the United States, and other jurisdictions where Sub-processors operate. Where Personal Data is transferred outside the European Economic Area or United Kingdom, the Processor shall ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or other mechanisms recognized under applicable Data Protection Laws.
9. Security Measures
The Processor maintains administrative, technical, and physical safeguards designed to protect Personal Data, including encryption in transit, database row-level security for tenant isolation, session-based authentication, internal audit logging, and access controls. Details are available at artificialpopulations.com/security.
10. Data Subject Rights
The Processor shall assist the Controller in fulfilling obligations to respond to requests from data subjects exercising their rights under Data Protection Laws (access, rectification, erasure, restriction, portability, and objection), taking into account the nature of the Processing and information available to the Processor.
11. Personal Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach affecting Personal Data processed on behalf of the Controller. Such notification shall include, to the extent known, the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
12. Deletion and Return of Data
Upon termination of the services agreement, the Processor shall, at the Controller's choice, delete or return all Personal Data processed on behalf of the Controller, unless applicable law requires retention. Deletion from active systems shall occur within thirty (30) days of termination. Backup copies may persist for a limited retention period before being overwritten.
13. Audit Rights
The Processor shall make available to the Controller information necessary to demonstrate compliance with this DPA, including summaries of security practices and, upon reasonable request, audit log excerpts related to the Controller's account. The Processor may satisfy audit requests through third-party certifications or reports where available.
14. Liability and Governing Law
Each party's liability under this DPA is subject to the limitations set forth in the services agreement. This DPA is governed by the laws of Quebec, Canada, without regard to conflict of law principles, consistent with the Controller's Terms & Conditions.
15. Execution
To execute this DPA, complete the signature blocks below and return to info@artificialpopulations.com.
Controller (Customer)
Company name
Authorized signatory
Title
Date
Signature
Processor (The Decision Lab)
Company name
The Decision Lab
Product
Artificial Populations
Authorized signatory
Date
Signature
See also: Privacy Policy · Terms & Conditions · Security