Docs/Legal

Rights review

The questions we answer about your contracts and the law before we list any of your data.

We check that you have the right to license data before we touch any of it. The review happens after the NDA is signed and before the readiness report. None of what follows is legal advice, and for regulated data we ask your own counsel to sign off.

Ownership and contracts

You must own the data, or hold a license to it that allows a sale. We read your customer agreements, data processing agreements and confidentiality clauses. A clause such as "used only to provide the service" blocks a sale even after scrubbing.

Controller or processor

If you hold the data on behalf of your customers, as their processor, you usually cannot license it without their written permission. See Data you hold for customers.

Lawful basis under GDPR

Licensing data to an AI lab is a new purpose for it. Under UK and EU GDPR, that purpose needs a documented legal basis, privacy notices that cover it, and consent where consent is the basis.

California

Under California law, transferring data for money counts as a sale. De-identified data is exempt only if re-identification is banned in contract and prevented in practice. Our licenses ban it, and the scrubber and its report address the practical side.

Data leaving the UK or EEA

Sending data from the UK or EEA to a lab in the United States needs standard contractual clauses and a transfer risk assessment.

Sector rules

Health, finance, government and export-controlled data need their own review or are excluded. Semiconductor data needs an export control check.

What is excluded by default

Raw source code, security logs, credentials, and free text containing personal details stay out unless they pass a dedicated review.

Before every sale

We run the re-identification test before every sale and keep the report.