An archival ledger and brass instruments

POSTERIOR POLICY

Data Privacy Policy

Data Privacy Policy — AI Training Data Services

Version 1.0 — effective 2026-09-15. This policy governs our data services: collection, annotation, review, and delivery of AI training data. Our general website policy is the Company Privacy Policy. Privacy contact for everything below: partnerships@[your-domain]. We respond within 30 days.

1. Scope and roles

This policy covers every person whose data enters our programs: contributors (people recorded or annotated), client contacts, and anyone exercising rights below. Where we design collection to a buyer specification, we act as controller of contributor data and as processor of buyer-supplied material, used strictly within program scope under written agreement.

2. Lawful collection end to end (PD.09)

Our lawful basis is informed, signed consent obtained before any capture, with AI-training use explicitly disclosed. The chain:

  1. Brief. The buyer spec becomes a written capture protocol: what is recorded, who may participate (adults 18+ only), in what settings, and what counts as accepted.
  2. Consent. Each contributor signs consent covering purpose (AI model training and evaluation, including delivery to international clients), capture types, handling terms, retention, and the rights in section 4. No recording starts without it; consent status is verified before each session.
  3. Collection under content rules. Scripted fictional material only. Hands-only framing where faces must stay out. No documents, plates, screens, passwords, or personal details in frame or on mic. Takes that break the rules are rejected at capture, not cleaned downstream.
  4. Separation. Names, contacts, and signed forms live in a private, access-controlled registry that never leaves our operation and never ships to clients. Deliveries carry contributor and consent codes only.
  5. Annotation and independent review. A different person from the collector/annotator accepts or rejects every file with reasons.
  6. Withdrawal window. Contributors may withdraw before export; affected files are pulled and the manifest reflects only active consents.
  7. Export. Raw files are never overwritten. Deliveries ship as raw plus annotations plus previews plus a per-file manifest with checksums, consent codes, and reviewer verdicts.

3. Data minimisation by design (PD.04)

We exclude personal data at capture rather than scrubbing it later, through framing rules, scripted content and a capture stack that avoids device identifiers, serials, IP addresses, precise locations and GPS values. Contributor personal data is never delivered to clients. Only coded, consented media, annotations and manifests are delivered to buyers. This design keeps most cross-border personal-data exposure out of scope.

4. Your rights and how to exercise them (PD.05)

  • Access: request what we hold on you — files, consent record, manifest entries — via lookup by contributor code.
  • Rectification: wrong attributes or consent records are corrected in the registry and reflected in manifests before export.
  • Withdrawal of consent: honoured any time before export; files pulled, manifest regenerated, withdrawal logged.
  • Erasure: pre-export, full deletion of raw, derived files, and registry entries. Post-export erasure from delivered copies is pursued with buyers case by case with confirmation; this limit is disclosed in consent materials.
  • Objection and limitation: limit capture types, settings, or uses; limits are written into the protocol and briefings.
  • Portability: files plus manifest in open formats (media, JSON/CSV) with checksums, exportable to the subject in portable form.

Write to the inbox above. We verify identity against the registry, log every request with its outcome, and charge no fee. Objection to processing and restriction of processing are honoured the same way.

5. Multi-jurisdictional compliance (PD.04)

  • India (home base): consent-first practice aligned with the Digital Personal Data Protection Act, 2023 — signed consent, purpose limitation, minimisation, withdrawal.
  • EU/UK (GDPR): consent records per contributor, purpose-limited collection, minimisation by design, subject-request handling as in section 4, and a GDPR-style data processing agreement scoped per client and program. Records of processing are maintained in the registry and manifests.
  • California (CCPA/CPRA): opt-out and deletion request handling plus service-provider terms, set per client and case to case depending on the data involved and the buyer’s role. We do not sell personal information.
  • Documentation, safeguards and commercial terms — including DPAs, standard contractual clauses, retention schedules, evidence depth and audit support — are set per client and on a case-to-case basis, proportionate to the data involved and the jurisdictions in play, and are recorded in the programme agreement.

6. International transfers (PD.06)

Yes — coded, consented deliverables are transferred to AI clients in other jurisdictions. Contributor personal data is not transferred.

What is transferred: only coded, consented deliverables cross borders. These include media with no personal data by design, annotation files, previews and manifests that carry only codes and SHA-256 checksums. Contributor identities, contact details and signed consent forms are never transferred and never leave the private registry.

How compliance is ensured:

  • Consent and transparency: consent materials explicitly disclose that deliverables will be provided to international AI clients for training and evaluation.
  • Purpose limitation and contracts: all buyer deliveries are governed by a written agreement that limits use to the agreed programme purpose.
  • Jurisdiction-specific safeguards set per client and on a case-to-case basis: for EU/UK transfers, data processing terms with standard contractual clauses are agreed for each client and each transfer case; for California and other jurisdictions, handling is set per client depending on the data involved and the buyer’s role. Home-base practice is aligned with India’s DPDP Act 2023.
  • Minimisation by design and separation: personal data is excluded at capture, and the registry remains segregated from deliverables by architecture.
  • Escalation: any programme that would require personal-data transfer beyond this model will proceed only after a joint safeguards review that is documented in writing.

7. Retention

Consent records: life of the supported datasets plus legal limitation periods, then deleted. Program files: per buyer agreement, then deleted with confirmation. Registry access logs: one year. Deletion is confirmed in writing.

8. Security and breach handling

Registry access restricted to named staff; contributor identities segregated from deliverables by architecture; per-file SHA-256 checksums (NIST FIPS 180-4) make tampering evident. Suspected breaches trigger containment, assessment, notification to affected contributors and relevant buyers without undue delay, and a logged post-incident review.

9. Adults only

All contributors are 18+. Age is confirmed at consent. Any material found to involve a minor is quarantined and deleted, and the program lead is notified the same day.

10. Complaints

First to us at the inbox above. India: grievance redressal follows DPDP timelines once rules are operative. EU/UK: you retain the right to lodge a complaint with your supervisory authority. California: Attorney General complaints process applies.

11. Changes

Material changes are versioned here with a date and, where they affect contributors, communicated before further collection. Past collection remains governed by the version signed.

Changelog

  • v1.0 (2026-09-15) — initial publication; split from the Company Privacy Policy to govern data services.
A researcher studying an observatory at dusk

NEXT / YOUR SYSTEM

Find a clearer
way forward.

Whether you're an investor, a partner, or a builder — we'd love to hear from you.

Get in touch