YPAI
Services Data Industries Company
AI Data & Evaluation
Data collection and sourcing Consent-led multimodal collection. Dataset licensing Rights-cleared datasets, ready to license. Annotation and curation Labelling, review and adjudication. Model and agent evaluation Human evaluation and regression testing. Explore AI Data & Evaluation Create, source and evaluate the data your AI depends on.
AI Implementation
Discovery and architecture Scope the use case and the system design. RAG and knowledge systems Retrieval over your own knowledge. Agents and workflow automation Agents and automation in production. Private and enterprise deployment Private, controlled deployment. Explore AI Implementation Turn a defined AI use case into a system you can operate.
Delivery
Connected Delivery Data, evaluation and implementation under one structure. Pilots Validate the delivery method before scale.
Explore all services
AI Data & Evaluation
Speech & Audio Data Multilingual speech, acoustic environments and voice data. Image, 3D & Sensor Data Images, documents, multi-view data, LiDAR and sensor fusion. Video, Physical AI & Robotics Data On-camera, conversational, egocentric and robotics data. Dataset Licensing & Sourcing Rights-cleared datasets, bespoke sourcing and acquisition. Annotation & Data Production Ontology design, labelling, review and model-ready delivery. Model & Agent Evaluation Human evaluation, multilingual testing and failure analysis.
Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Training data, preference data and evaluation loops. Automotive & Mobility In-cabin speech, perception, video and sensor data. Financial Services Document AI, knowledge systems and traceability. Healthcare & Life Sciences Specialist data, domain review and privacy-sensitive work. Industrial & Energy Field data, operational workflows and integration. Public Sector Controlled data operations and reviewable AI systems.
Explore industry solutions
Company
About YPAI Company, mission, operating model and delivery history. Partnerships Commercial, technology and delivery collaboration. AI Blog Research, technical perspectives and company updates. Contact Projects, partnerships, procurement and general enquiries.
Become a Contributor Contact us
YPAI
AI Data & Evaluation
Data collection and sourcing Dataset licensing Annotation and curation Model and agent evaluation Explore AI Data & Evaluation
AI Implementation
Discovery and architecture RAG and knowledge systems Agents and workflow automation Private and enterprise deployment Explore AI Implementation
Delivery
Connected Delivery Pilots Explore all services
AI Data & Evaluation
Speech & Audio Data Image, 3D & Sensor Data Video, Physical AI & Robotics Data Dataset Licensing & Sourcing Annotation & Data Production Model & Agent Evaluation Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Automotive & Mobility Financial Services Healthcare & Life Sciences Industrial & Energy Public Sector Explore industry solutions
About YPAI Partnerships AI Blog Contact
Contact us Become a Contributor

Legal

How YPAI processes customer and project data.

Last updated: July 2026

This page provides procurement, privacy and security teams with a company-wide overview of YPAI's data-processing model. The applicable roles, instructions, data categories, controls, subprocessors, transfer mechanisms and retention terms are defined for each engagement in the contract and, where required, the Data Processing Agreement.

On this page

  • 1. What this page covers
  • 2. Roles per engagement
  • 3. Data categories and purposes
  • 4. Processing lifecycle
  • 5. Access and security
  • 6. Subprocessors and transfers
  • 7. Retention and deletion
  • 8. Data subjects and incidents
  • 9. Documents for review

1. What this page covers

This is a public due-diligence overview.

It is not the privacy policy, which explains YPAI's own processing to the people whose data it concerns.

It is not the Data Processing Agreement.

The signed documents for a project take precedence over this page.

2. Roles are defined per engagement

Engagement pattern Typical starting point Documentation
The customer supplies data for annotation or evaluation The customer is the controller, YPAI is the processor SOW, DPA and security annex
YPAI collects participant data for the customer The role follows who determines the purposes and essential means DPA, data-sharing or controller terms, consent and releases
YPAI licenses or brokers existing data Roles and rights are settled per dataset and source Dataset licence, rights record and processing terms
YPAI builds a system with customer data Normally the processor for customer data handled under instruction SOW, DPA, security and residency annexes

The role cannot be settled by a label in the contract alone. It follows who actually determines why and how the processing happens.

3. Data categories and purposes

Depending on the engagement, processing can involve:

  • Customer and project data
  • Documents, images, video, audio, text and sensor data
  • Contributor and participant data
  • Annotations, evaluations and QA results
  • Consent, rights and provenance records
  • System logs and technical metadata
  • Business contact data

The purpose of processing is tied to the specific delivery the data belongs to, as defined in the contract. Data supplied or collected for one engagement is not repurposed for other work without a rights basis that covers it.

4. Processing lifecycle

Every engagement follows one linear process:

Scope and instructions → provision or collection → preparation, annotation, evaluation or implementation → quality review → controlled delivery → return, deletion or agreed retention.

Step Access Purpose Governed by Evidence produced
Scope and instructions Project lead and the customer Define scope, instructions, roles and controls SOW and, where required, the DPA Signed scope and instruction set
Provision or collection Named project staff; contributors where collection applies Receive customer data or collect participant data under instruction SOW, DPA, consent and release framework Intake or collection log, consent records
Preparation, annotation, evaluation or implementation Named project staff and approved contributors Perform the contracted work on the data SOW and project guidelines Work records and QA inputs
Quality review QA reviewers Verify the work against the acceptance specification Quality and acceptance specification QA results and review records
Controlled delivery Delivery owner and customer recipients Deliver the agreed output through the agreed channel SOW and delivery terms Delivery manifest
Return, deletion or agreed retention Delivery owner Close out the engagement as contracted DPA and retention schedule Deletion or retention record

5. Access, security and confidentiality

Project environments apply these control categories:

  • Authorized users and least privilege
  • Environment and project separation
  • Access control and authentication
  • Encryption where the actual architecture supports the claim
  • Logging and audit where this exists for the environment
  • Confidentiality obligations for staff and contributors
  • Controlled delivery and deletion

Detailed technical and organizational measures are provided for review during due diligence.

6. Subprocessors, residency and transfers

Subprocessors are approved before use and documented for the engagement they serve. The actual list, the purposes they serve and the jurisdictions involved are defined or disclosed for the specific delivery, and changes are notified as agreed in the contract.

EEA-based processing is available where required. Residency, access locations and transfer mechanisms are defined per engagement. Where a relevant transfer requires it, standard contractual clauses or another valid mechanism is used.

Location, jurisdiction, access and transfer controls are covered in depth on EEA data residency.

A DPA is available where the processing relationship requires one. In data engagements where YPAI processes personal data, the DPA ships with the Statement of Work.

7. Retention, return and deletion

The retention period follows the purpose, the contract and legal requirements. There is no single fixed retention schedule across all projects.

  • The customer and YPAI agree return, deletion or limited further retention at closeout
  • Backup, audit and statutory exceptions are handled explicitly in the agreed terms
  • Deletion can be documented with a deletion record where the contract includes it
  • Extracts, downstream deliveries and derived artifacts are handled according to the actual dataset and its rights basis

8. Data-subject support and incidents

YPAI supports the parties it processes for with:

  • Access, rectification, erasure, restriction and objection requests
  • Withdrawal of consent where consent is the basis used
  • Identification of affected recordings or records
  • Security-incident handling, notification and cooperation
  • Audits and information requests

Where copies of data exist downstream outside YPAI's control, YPAI supports the request to the extent of its own systems and its contractual position, and does not promise outcomes it cannot enforce.

9. Documents available for review

Document What it defines
Statement of WorkScope, instructions, deliverables and acceptance criteria
Data Processing AgreementRoles, instructions, data categories and Article 28 terms
Security and technical measuresThe controls applied to the project environment
Subprocessor informationThe subprocessors used for the engagement and their roles
Data-flow and residency informationWhere data is stored and processed, and who can access it
Transfer mechanism or SCC informationThe legal mechanism for any relevant transfer
Retention and deletion scheduleHow long data is kept, and how it is returned or deleted
Consent or source-rights frameworkThe rights basis for collected or licensed data
Incident-cooperation processHow incidents are notified and handled between the parties
Quality and acceptance specificationHow quality is measured and accepted
Dataset licenceRights and restrictions for licensed datasets
Delivery manifestWhat was delivered, when, and in what form
Scope a project
EEA data residency in depth

Start with the requirement, not a predefined package.

Bring the objective, current system or dataset, and known operating constraints. YPAI will map the appropriate service line, delivery structure and first validation step.

Contact us Scope a pilot

AI systems, data and evaluation under one accountable delivery model.

New projects · accepting data and AI requirements
Engagement scoped before build
Acceptance defined before delivery
Services
AI Data & Evaluation AI Implementation Controlled Delivery Dataset Licensing
Capabilities
Speech & Audio Image, 3D & Sensor Data Video Data Annotation & Evaluation
Company
About YPAI Partnerships Contact Become a Contributor
Resources & Legal
AI Blog Privacy Terms Cookie Policy Data processing
YPAI · Org. nr. 933 915 778 · Oslo, Norway · Global delivery
Disclaimer LinkedIn ↗ GitHub ↗
EEA-BASED PROCESSING AVAILABLE WHERE REQUIRED · ARTICLE 28 DPA TERMS AVAILABLE
© 2026 YPAI
Install YPAI Faster reopens, offline shell, share-target ready.

Add YPAI to your home screen

Tap the Share button, then Add to Home Screen.