Legal
Privacy Policy
This Privacy Policy explains how PsyLattice collects, uses, stores, shares and protects personal data across the website, research platform, participant experiences, AI-assisted tools, mobile and desktop software, workshops and supported professional services.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through PsyLattice websites, applications, account services, Research workspaces, study links, participant interfaces, Cognitive Lab, ambulatory and longitudinal assessment features, Analysis Lab, Thesis Builder, AI-assisted features, participant companion applications, supported wearable or sensor integrations, desktop or offline software, Workshops and other services made available under the PsyLattice name (collectively, the “Services”).
Different rules may apply depending on whether you are a website visitor, registered user, researcher, study participant, student, Workshop attendee, institutional administrator, professional, client or user of another PsyLattice service.
A study-specific participant information sheet, consent form, institutional privacy notice, data-processing agreement or other specialised notice may provide additional information. Those notices supplement this Policy for the relevant workflow.
2. Who is responsible for your personal data
The person or legal entity identified as the operator of PsyLattice in the Terms and Conditions and on the Contact page is responsible for personal data where PsyLattice decides why and how that data is processed. Depending on the applicable law, this role may be described as a data controller, Data Fiduciary or equivalent responsible party.
In university, research, clinic or institutional workflows, the researcher or organisation may instead determine the purpose, categories of data, participant population, retention and use of the data. In those cases, PsyLattice may act as a processor, service provider or similar party acting on documented instructions.
PsyLattice may remain independently responsible for separate processing necessary for its own account administration, security, fraud prevention, billing, legal compliance and operation of the Services.
3. Our privacy principles
PsyLattice is designed around the following principles:
- collect and process only information reasonably needed for a defined purpose;
- separate access between users, studies, roles and workspaces where appropriate;
- use permission-controlled access for sensitive context and AI features;
- provide meaningful information about what is collected and why;
- support pseudonymous research workflows where direct identity is not necessary;
- apply reasonable technical and organisational security safeguards;
- avoid using sensitive psychological, research or health data for behavioural advertising;
- retain information only for as long as justified by the purpose, contract, research requirements or law.
4. Categories of people whose data we may process
Depending on the Services used, PsyLattice may process data relating to:
- website visitors;
- registered PsyLattice users;
- researchers and research-team members;
- study participants, including participants who do not create a standard PsyLattice account;
- students and Workshop attendees;
- university or institutional administrators;
- professionals and, where enabled, their clients;
- users of Self, Luna or other personal-support features;
- people who contact support, sales or privacy channels;
- individuals whose information is lawfully imported into a workspace by an authorised user.
5. Account and profile information
When you create or use an account, we may process information such as your name, email address, authentication identifiers, account ID, institution, role, designation, country, profile preferences, account status and workspace access information.
We may also process security and account-management information such as email-verification state, login timestamps, password reset events, session metadata, administrative actions, plan status, suspension status or ban status.
You should never send PsyLattice your password, recovery code, API secret or full authentication credential through ordinary support messages.
6. Research workspace and study information
Researchers may create or upload study titles, descriptions, hypotheses, variables, protocols, schedules, questionnaires, consent text, task settings, recruitment information, analysis settings, research notes, datasets, documents and other study materials.
PsyLattice processes this content to provide the requested research workspace and, where PsyLattice acts on behalf of a researcher or institution, according to that party’s lawful instructions and the applicable agreement.
7. Research participant information
A participant may be able to participate through a study link, code, token or participant companion without creating a standard PsyLattice account.
Depending on the study design, participant data may include a participant or session identifier, consent status, timestamps, questionnaire answers, demographic information, study events, task responses, reaction times, accuracy, repeated self-reports, longitudinal responses, EMA or experience-sampling responses, completion status and other information selected by the researcher.
A researcher may also choose to collect direct identifiers such as a name, email address, phone number or externally assigned participant code where that is lawful and necessary.
Participants should read the information and consent materials for the specific study because those materials explain the research purpose, responsible researcher, study-specific data, withdrawal procedure and other information that cannot be fully described in this general Policy.
8. Questionnaire, assessment and psychological information
PsyLattice may process questionnaire answers, assessment responses, scores, subscale values, repeated self-reports, behavioural measures, progress information and related psychological or research information when a user or study uses those features.
Some information may reveal or relate to health, mental health, behaviour or other legally protected characteristics. Such data should be collected only where appropriate for the relevant purpose and with the legal, ethical and institutional safeguards required for that workflow.
9. Cognitive-task and behavioural data
Cognitive Lab or related features may process task configuration, stimuli presented, trial information, response choices, response times, accuracy, omissions and derived measures.
Where relevant, technical information about the browser, device or session may also be processed to run the task, troubleshoot problems or help the researcher interpret the data.
10. EMA, ambulatory and longitudinal information
Repeated-measurement features may process scheduled prompts, completion timestamps, repeated responses, contextual entries, study events and related information across days or longer periods.
Researchers determine the content and frequency of their study assessments. Notifications should contain only the information reasonably needed to direct the participant to the assigned task and should avoid exposing sensitive responses on a lock screen where possible.
11. Wearables, Health Connect and sensor data
Where supported and enabled, PsyLattice may process authorised wearable, Health Connect or sensor data such as activity, sleep, heart-rate or other supported measurements, depending on the study configuration and permissions granted.
Device permission is separate from research consent. Allowing an operating system to share a data type does not by itself mean that the participant has consented to every research use of that data.
Before sensitive device information is requested, the relevant study or application should explain the data type, purpose, frequency, storage, retention and whether the researcher receives raw values, summaries or derived trigger events.
Revoking an optional device permission stops future collection through that permission, although information already lawfully collected may remain subject to research, legal or retention obligations.
12. Documents, files, media and thesis content
Supported workflows may allow users to upload documents, datasets, images, audio, video, study materials or thesis files. These files may contain personal or confidential information chosen by the user.
PsyLattice processes uploaded material to store, display, analyse, transform, export or otherwise provide the feature the user requested.
Users should avoid uploading personal or confidential information that is unnecessary for their intended purpose.
13. Analysis Lab and export information
Analysis Lab may process variables, datasets, model selections, transformations, statistical outputs, graphs, tables and derived results.
PsyLattice may also process limited export metadata such as the study, export type, format, timestamp, row count, identity mode or whether direct identifiers were included, where that information is used for accountability, security or workspace history.
Once a researcher exports a dataset, the exported copy is under the researcher or institution’s control. They are responsible for the security, storage, sharing and deletion of that copy.
14. AI prompts, conversations and authorised context
When a user uses an AI-assisted feature, PsyLattice may process the prompt, conversation history, selected model, usage metadata and any workspace context that the user has authorised for the request.
Authorised context may include a study description, statistical result, document, thesis text, dataset summary or other workspace information. Where the product provides separate permission controls, granting access to one category of context does not automatically grant access to every other category.
For example, where Thesis Builder includes a separate document access permission, document content should be available to the AI only when the relevant permission is enabled.
15. Cloud AI and local or offline AI
A cloud AI feature may send the prompt and authorised context needed for the request to the selected AI service provider. Different models may have different processing locations, technical safeguards and retention arrangements.
Local or offline AI may process information on the user’s device or within another locally controlled environment, depending on the implementation. If a user later enables cloud sync, cloud AI or another networked feature, the information needed for that feature may leave the local device.
PsyLattice does not use private participant data, sensitive psychological data, private thesis content or private AI conversations to train a general-purpose model for unrelated customers unless a separate, explicit and lawful opt-in programme is introduced and clearly presented.
16. Payment and billing information
If you buy a subscription, Study Pass, Workshop, add-on, institutional entitlement or other paid service, PsyLattice may process the purchaser’s name, email, billing information, tax information, selected product, amount, currency, payment status, order identifier, transaction identifier, subscription status and invoice information.
Payment-card or bank details may be collected directly by a payment processor rather than stored by PsyLattice. PsyLattice may receive limited payment and transaction information needed to activate entitlements, reconcile payments and handle support or disputes.
17. Workshop and training information
Workshop registration may involve your name, email, institution, programme, role, payment or sponsorship status, attendance, questions, submitted exercises, certificate details and communications relating to the event.
If a university or organisation registers or sponsors attendees, it may provide registration information to PsyLattice and may receive appropriate attendance or completion information where this forms part of the arrangement and attendees have been appropriately informed.
If a Workshop is recorded, attendees will receive appropriate notice. Registration alone is not treated as permission for PsyLattice to use an identifiable attendee’s image, voice, testimonial or personal story in public advertising where separate permission is required.
18. Support, complaints and account administration
When you contact PsyLattice, we may process your name, contact details, account identifier, transaction ID, the content of the request, attachments you choose to send and information reasonably necessary to investigate or resolve the issue.
Support staff should request only information reasonably needed for the issue. Do not send passwords, full payment-card details or unrelated participant or clinical datasets through ordinary support channels.
19. Device, technical and usage information
PsyLattice may process technical information such as IP address, browser type, device type, operating system, app version, language, timestamps, session identifiers, error logs, performance information, referring pages and security events.
This information may be used to operate the Services, troubleshoot errors, maintain security, investigate abuse, measure reliability and understand how product features are functioning.
20. Cookies, browser storage and similar technologies
PsyLattice may use cookies, local storage, session storage, authentication tokens and similar technologies for sign-in, security, preferences, shopping-cart state, session continuity and other core functionality.
If PsyLattice uses non-essential analytics, advertising or similar technologies for which applicable law requires consent, those technologies should be activated only after the required choice and should be manageable through an appropriate consent control.
21. Where personal data comes from
PsyLattice may receive personal data:
- directly from you;
- from a researcher, university, clinic, employer or other organisation using PsyLattice;
- from another authorised user who invites you to a study or workspace;
- from a device or service you choose to connect;
- from authentication or payment providers;
- from technical logs generated through use of the Services;
- from data or files lawfully uploaded by an authorised user.
An organisation that provides PsyLattice with personal data is responsible for having an appropriate basis to do so and for providing any notice required by applicable law.
22. Why we process personal data
Depending on the workflow, PsyLattice may process personal data to:
- create, authenticate and administer accounts;
- provide research, participant, analysis, writing and AI functionality;
- run questionnaires, cognitive tasks and longitudinal protocols;
- deliver authorised reminders and notifications;
- support wearable or sensor integrations chosen by the user or study;
- process purchases, subscriptions, Workshop registrations and invoices;
- provide support and respond to complaints;
- prevent fraud, abuse and unauthorised access;
- protect users, participant data, accounts and platform security;
- maintain reliability and diagnose technical problems;
- comply with legal, tax and accounting requirements;
- establish, exercise or defend legal claims;
- improve the Services using appropriately limited, de-identified or aggregated information where suitable.
23. Legal bases under the GDPR and similar laws
Where the GDPR or a similar legal framework applies, the legal basis depends on the activity. PsyLattice may rely on one or more of the following:
- Contract where processing is necessary to provide an account, subscription, Workshop or feature requested by the user.
- Legitimate interests where appropriate for security, fraud prevention, service operation, support or improvement after considering the rights and interests of the individual.
- Consent for optional activities where consent is the appropriate basis, such as certain integrations, marketing choices or optional data access.
- Legal obligation where processing is needed for tax, accounting, regulatory or other legal requirements.
- Another lawful basis applicable to a particular research, health or institutional workflow.
Where special-category data is processed under the GDPR, an additional condition under Article 9 or applicable Member State law is required. The responsible controller must determine the appropriate condition and safeguards for the particular processing.
24. Processing under India’s data-protection framework
Where India’s Digital Personal Data Protection Act, 2023 and applicable rules apply, PsyLattice processes digital personal data for lawful purposes on a basis recognised by applicable law, including valid consent or another permitted use where available.
Where consent is the basis, the relevant notice should describe the personal data and specified purpose in clear language and provide a practical method to withdraw consent and exercise the rights that apply.
The Indian framework has phased commencement dates for different provisions. PsyLattice applies obligations according to the law in force for the relevant processing activity.
25. Sensitive, health and special-category information
Psychological, health, biometric, genetic or other sensitive information may receive additional legal protection. A researcher or user should not collect sensitive data merely because the platform technically permits a field to be created.
The party responsible for the processing must have the legal basis, special-category condition, consent, research safeguard or other authority required by applicable law.
Sensitive participant, psychological and health information is not used by PsyLattice for unrelated behavioural advertising.
26. Research controller and processor roles
In many researcher-led studies, the researcher, university, sponsor or institution determines the scientific purpose, participant population, variables, retention period and research use of the data. That party may therefore be the controller, Data Fiduciary or equivalent responsible party for the research processing.
PsyLattice may process that data as a processor or service provider. A data-processing agreement may describe documented instructions, confidentiality, security, subprocessors, international transfers, deletion or return of data and assistance with privacy rights.
PsyLattice may separately act as an independent controller or Data Fiduciary for its own account management, billing, security, fraud prevention and legal compliance.
27. Consent is specific to the activity
Accepting the PsyLattice Terms does not automatically mean that a user has consented to research participation, wearable access, professional sharing, marketing, Workshop publicity, every AI data flow or every form of personal-data processing.
Where consent is required, it should be obtained for the relevant purpose. Withdrawing consent does not make earlier lawful processing unlawful, and some data may still need to be retained where another valid legal basis or obligation applies.
28. Children and minors
PsyLattice does not assume that a person is legally able to consent to research or sensitive-data processing merely because the person can access a study link.
Researchers and institutions conducting research involving children or minors are responsible for determining the applicable age threshold, obtaining parental or guardian permission and assent where required, and applying appropriate ethical safeguards.
Where applicable law requires verifiable parental consent or imposes special restrictions on processing children’s data, those requirements must be implemented before collecting the relevant information.
29. Sharing with researchers and authorised organisations
Research participant data may be made available to the researcher, authorised research team, university, sponsor or other organisation identified for the study according to the study design, permissions and applicable agreement.
PsyLattice does not give every researcher access to every participant or every study. Access is intended to be restricted to the relevant workspace, study, role, invitation or token.
Once data is exported or otherwise placed under an organisation’s control, that organisation is responsible for its downstream access and handling.
30. Institutional administrators and sponsored access
If your account or Workshop access is provided, paid for or managed by a university, employer, laboratory, clinic or other organisation, authorised administrators may receive account, licence, seat, attendance, usage or access information needed to manage that arrangement.
Institutional sponsorship does not automatically give an administrator unrestricted access to private research content, thesis drafts, private AI conversations, personal reflections or participant-level data unless the product role, institutional agreement and applicable law authorise that access.
31. Service providers and subprocessors
PsyLattice may use service providers for functions such as cloud hosting, databases, authentication, file storage, content delivery, payment processing, email, push notifications, security, monitoring, analytics, customer support and AI model access.
Providers receive information only as reasonably necessary for the function they perform and are subject to contractual, confidentiality, security or data-protection obligations as appropriate.
Where PsyLattice acts as a processor for an institution, subprocessor arrangements may also be governed by the applicable data-processing agreement.
32. AI service providers
If a user invokes a cloud AI model, the prompt and authorised context needed for that request may be sent to the selected AI provider. Different AI providers may use different processing locations, technical safeguards and limited retention practices.
PsyLattice seeks to configure AI providers, where technically and contractually available, so submitted business and research content is not used for unrelated provider model training.
Users should not provide participant-identifying or otherwise sensitive information to an AI feature unless that use is permitted by the relevant study, institution and applicable law.
33. Payment providers
Independent payment providers may process card details, bank information, fraud signals, payment credentials and transaction information under their own privacy terms and legal obligations.
PsyLattice may receive transaction IDs, order status, subscription status and other limited payment information needed to activate purchases, reconcile accounts and resolve billing issues.
34. Advertising, sponsorships and free access
PsyLattice may support parts of a free service through advertising or sponsorships. Sensitive research, questionnaire, psychological, health, wearable, thesis or private AI-conversation data is not used by PsyLattice to target behavioural advertisements.
Advertising may be contextual to the page, product category or other non-sensitive context. Any use of non-essential advertising technologies remains subject to applicable consent and privacy requirements.
35. We do not sell sensitive user or research data
PsyLattice does not operate as a data broker and does not sell research participant datasets, private psychological information, health data, thesis content or private AI conversations to third parties for their own unrelated use.
If a future activity would legally constitute a “sale” or “sharing” of personal information under an applicable law, PsyLattice would provide any required disclosure and choice before engaging in that activity.
36. Legal disclosures, fraud and safety
PsyLattice may disclose information where reasonably necessary to comply with applicable law, a valid court order, lawful government request, regulatory obligation or legal process, or to establish, exercise or defend legal claims.
We may also disclose limited information where reasonably necessary to investigate fraud, abuse, serious security incidents, threats to safety or material violations of the Terms, subject to applicable law.
37. International data transfers
PsyLattice and its service providers may process information in more than one country. The location may depend on the user, hosting configuration, institution, selected AI provider, payment provider or other feature.
Where personal data is transferred internationally, PsyLattice will use a transfer mechanism or safeguard required by applicable law.
Institutions with mandatory data-residency requirements should confirm those requirements with PsyLattice before collecting regulated or restricted data.
38. EEA transfer safeguards
Where the GDPR applies to a transfer outside the European Economic Area, safeguards may include an adequacy decision, approved Standard Contractual Clauses or another transfer mechanism permitted by Chapter V of the GDPR.
Supplementary technical, contractual or organisational measures may also be used where appropriate.
39. Data residency
A standard PsyLattice account does not guarantee that every category of data remains in a particular country unless such a commitment is expressly stated in the product, order form or written agreement.
If a university, clinic or research sponsor requires a specific hosting region or localisation arrangement, that requirement should be agreed before collecting restricted data.
40. Retention generally
PsyLattice does not retain every category of personal data for the same period. Retention depends on the purpose, account status, plan, study instructions, contractual obligations, applicable law, security needs, dispute periods and whether the information has been anonymised or de-identified.
Where there is no longer a valid purpose or legal reason to keep personal data, it should be deleted, anonymised or otherwise placed beyond ordinary use according to the relevant retention process.
41. Research data retention
Study data may remain available while a study is active and for a period afterwards to support analysis, export, research integrity, contractual obligations or the responsible institution’s retention requirements.
Expiry of a Study Pass or subscription does not necessarily mean participant responses must immediately be destroyed. A study may move into a non-collecting or read-only state while retention and export follow the Data Policy, institutional instructions and applicable law.
Researchers should maintain their own secure copies of records their institution requires them to preserve.
42. AI data retention
Retention of AI prompts, responses and authorised context may differ by feature and selected model. Some conversation history may be stored in PsyLattice to provide continuity, while other requests may be transient or subject to provider retention controls.
Where a feature stores AI history, the product should make that state reasonably clear and provide appropriate deletion or workspace controls.
43. Workshop records and recordings
Workshop registration, attendance, payment and certificate records may be retained for administration, support, fraud prevention, accounting, tax, certification and legal purposes.
Recordings, attendee chat or submitted exercises should be kept only for the period justified by the stated Workshop purpose and access model.
44. Backups, security logs and audit records
Security, access and audit information may be retained separately where reasonably necessary to investigate incidents, preserve platform integrity, comply with law or demonstrate security controls.
Backups may retain information for a limited period after the primary copy is deleted. Backup data is generally isolated from ordinary product use and is overwritten or expired according to the applicable backup cycle.
45. Account deletion and study deletion
Account deletion may remove or de-identify information that no longer needs to be retained. Some records may remain where required for billing, tax, fraud prevention, security, legal claims, regulatory obligations or research integrity.
A researcher deleting an account does not automatically mean that every participant record can lawfully or ethically be deleted. Research data may remain subject to institutional, ethics or legal retention requirements.
Where PsyLattice acts as processor for an institution, deletion of institutional study data may require instructions from the responsible organisation.
46. Offline and desktop data
Desktop or offline versions may store project information or local AI data on the user’s device. Information that remains local and is never synchronised to PsyLattice servers is controlled primarily by the user’s device and local security practices.
PsyLattice cannot delete or restore local-only files on a device it cannot access. Users are responsible for local backups, device access controls, encryption and secure disposal of devices containing sensitive data.
47. Security measures
PsyLattice uses or intends to use safeguards appropriate to the nature and risk of the data, including authentication, access controls, owner- or role-based permissions, encrypted network transport, database security controls, restricted service credentials, logging, monitoring, rate limits, backups and incident-response procedures where appropriate.
Public study participation should use study- or session-scoped access rather than broad database permissions. Private backend service credentials should not be exposed in public client applications.
No online service can guarantee absolute security. Users and institutions must also protect their devices, credentials, exported files and sharing practices.
48. Personal data breaches
If PsyLattice becomes aware of a personal data breach, it will investigate, contain and remediate the incident as appropriate.
Where applicable law requires notification, PsyLattice will notify affected individuals, responsible institutional controllers and/or relevant authorities within the legally required timeframe.
When PsyLattice acts as processor for an institution, breach notification and cooperation may also be governed by the applicable data-processing agreement.
49. Your privacy rights
Your rights depend on your location, the type of data and whether PsyLattice or another organisation is the responsible controller or Data Fiduciary.
Depending on applicable law, you may have rights to receive information about processing, access personal data, correct inaccurate information, request deletion, withdraw consent, object to or restrict certain processing, receive certain data in portable form, nominate another person where legally provided, and complain to a regulator.
Privacy rights are not always absolute. For example, information may need to be retained for legal obligations, research integrity, security or defence of legal claims.
50. Rights under India’s DPDP framework
Where India’s Digital Personal Data Protection framework applies and the relevant provisions are in force, a Data Principal may have rights including access to information about processing, correction, completion, updating or erasure of personal data, grievance redressal, withdrawal of consent where consent is the basis, nomination and other rights provided by applicable law.
PsyLattice will provide the mechanisms required by the law as the relevant provisions apply to its processing.
51. Rights under the GDPR
Where the GDPR applies, you may have the right to be informed, access your personal data, correct inaccurate data, request erasure, restrict processing, receive certain data in portable form, object to certain processing and withdraw consent where consent is the legal basis.
You may also lodge a complaint with the competent data-protection authority. Withdrawal of consent does not affect processing that was lawful before withdrawal.
52. How to exercise your rights
You may use available account controls or contact PsyLattice through the Contact page to make a privacy request.
We may need to verify your identity before fulfilling a request so personal data is not disclosed, changed or deleted at the request of an unauthorised person.
If your request concerns data collected for a researcher- or university-led study, PsyLattice may direct or forward the request to the responsible researcher or institution where that party is the controller. PsyLattice will provide assistance where required by law or contract.
53. Research withdrawal and privacy deletion are different
Withdrawing from a research study, withdrawing consent for future research activity, deleting a PsyLattice account and requesting erasure of personal data are different actions.
Study materials should explain what happens when a participant withdraws and whether data already collected can or must remain in the research dataset. The responsible researcher or institution determines that position subject to the approved protocol and applicable law.
54. Marketing communications
PsyLattice may send service communications needed for account security, billing, study administration or important product changes. These are different from optional marketing communications.
Promotional email or similar marketing will be sent only where there is an appropriate legal basis. Users can use the available unsubscribe mechanism for optional marketing.
55. Push notifications
If you enable push notifications, PsyLattice may process a device registration token, account or participant identifier and task or notification identifiers needed to deliver the message.
Sensitive questionnaire answers, health values or diagnoses should not be included in ordinary notification text unless a particular workflow requires it and appropriate safeguards have been implemented.
Users can change notification permissions through their device or operating-system controls where supported.
56. Automated decision-making and profiling
PsyLattice is not designed to make solely automated high-stakes decisions about a person’s medical care, employment, insurance, education or legal rights merely from an AI output or questionnaire score.
Researchers may configure study branching, eligibility rules, randomisation or scoring. The responsible researcher must ensure that those rules are lawful, ethically appropriate and accurately disclosed where required.
If PsyLattice introduces automated decision-making that produces legal or similarly significant effects, this Policy and the relevant workflow will be updated with the disclosures and rights required by applicable law.
57. Product analytics and service improvement
PsyLattice may use limited technical, usage and performance information to understand reliability, fix errors and improve the Services.
Where practical, product improvement should use aggregated, de-identified or otherwise minimised information rather than sensitive participant-level research content.
Private participant responses, health information, thesis text and private AI conversations are not treated as general marketing analytics merely because they are stored in the platform.
58. De-identified and aggregated information
PsyLattice may create aggregated or de-identified information for reliability, security, product measurement and improvement where the information is no longer reasonably linked to an identifiable person under applicable law.
We do not describe information as anonymous where identifiers or combinations of data still make individuals reasonably identifiable.
59. Third-party links and external resources
PsyLattice may link to journals, questionnaire publishers, university resources, payment pages, external documentation or other third-party services.
A link from PsyLattice does not mean PsyLattice controls the third party’s privacy practices. Users should review the privacy terms of external services they choose to use.
60. Business transfers and changes of ownership
If PsyLattice is incorporated, reorganised, financed, merged, acquired or transfers all or part of its business, personal data may be transferred as part of that transaction where lawful and subject to appropriate confidentiality and data-protection safeguards.
If the identity of the responsible controller materially changes, affected users will receive any notice required by applicable law.
61. Changes to this Privacy Policy
PsyLattice may update this Policy when the Services, data practices, service providers, legal requirements or organisational structure change.
The latest version will display an updated date. Where a material change requires advance notice, consent or another action, PsyLattice will provide it before the new processing takes effect where required by applicable law.
62. Privacy contact and complaints
Privacy questions, requests and complaints can be submitted through the PsyLattice Contact page.
The production legal notice should identify the responsible operator, postal address, privacy or grievance contact and any Data Protection Officer, EU representative or other statutory representative required by applicable law.
Where applicable, you may also have the right to complain to the competent privacy or data-protection authority in your jurisdiction.
63. Related legal documents
This Privacy Policy should be read together with the Terms and Conditions and Data Policy.
Research participants should also read the participant information and consent materials for their specific study. Workshop attendees and institutional users should review any additional privacy notice or written agreement provided for the relevant service.