Skip to main content
YPAI
Services Data Industries Company
AI Data & Evaluation
Data collection and sourcing Consent-led multimodal collection. Dataset licensing Rights-cleared datasets, ready to license. Data annotation Boxes, masks, spans and tracks, reviewed. Data labeling Class definitions, tie-break and the record. Model and agent evaluation Human evaluation and regression testing. Explore AI Data & Evaluation Create, source and evaluate the data your AI depends on.
AI Implementation
Discovery and architecture Scope the use case and the system design. AI assistants and chatbots Customer-facing conversation, service and voice. RAG and knowledge systems Retrieval over your own knowledge. Document AI and workflows Documents read, checked, routed and written once. Agents and workflow automation Agents and automation in production. Private and enterprise deployment Private, controlled deployment. Explore AI Implementation Turn a defined AI use case into a system you can operate.
Delivery
Connected Delivery Data, evaluation and implementation under one structure. Pilots Validate the delivery method before scale.
Explore all services
AI Data & Evaluation
Speech & Audio Data Multilingual speech, acoustic environments and voice data. Image Data Still images under specified coverage, device, rights and residency. Image, 3D & Sensor Data Point clouds, depth and multi-sensor rigs, calibrated and time-synchronised. Video Data On-camera and conversational video, collection through delivery. Physical AI Data Demonstration, episode and real-world physical data. Dataset Licensing & Sourcing Rights-cleared datasets, bespoke sourcing and acquisition. Data Annotation & Review Ontology design, marking, review and model-ready delivery. Data Labeling Class definitions, tie-break and the record of who decided. Model & Agent Evaluation Human evaluation, multilingual testing and failure analysis.
Explore AI Data & Evaluation
Operating conditions
AI Companies & Model Developers Training data, preference data and evaluation loops. Automotive & Mobility In-cabin speech, perception, video and sensor data. Financial Services Document AI, knowledge systems and traceability. Healthcare & Life Sciences Specialist data, domain review and privacy-sensitive work. Industrial & Energy Field data, operational workflows and integration. Public Sector Controlled data operations and reviewable AI systems.
Explore industry solutions
Company
About YPAI Company, mission, operating model and delivery history. Partnerships Commercial, technology and delivery collaboration. AI Blog Research, technical perspectives and company updates. Contact Projects, partnerships, procurement and general enquiries.
Become a Contributor Contact us
YPAI
Start here Scope a project Start small Pilots
AI Data & Evaluation
Collect
Data collection and sourcing Speech & Audio Data Image, 3D & Sensor Data Video Data Physical AI Data
Produce
Data Annotation & Review Data Labeling
Model & Agent Evaluation
Dataset Licensing & Sourcing
AI Implementation
Discovery and architecture
Build
AI assistants and chatbots RAG and knowledge systems Document AI and workflows Agents and workflow automation
Private and enterprise deployment
Connected Delivery
Operating conditions
AI Companies & Model Developers Automotive & Mobility Financial Services Healthcare & Life Sciences Industrial & Energy Public Sector
Also
Image Data
About YPAI Partnerships AI Blog

AI data, evaluation and implementation under one accountable delivery model.

Contact us Become a Contributor

Legal

How YPAI processes customer and project data.

Last updated: July 2026

This page provides procurement, privacy and security teams with a company-wide overview of YPAI's data-processing model. The applicable roles, instructions, data categories, controls, subprocessors, transfer mechanisms and retention terms are defined for each engagement in the contract and, where required, the Data Processing Agreement.

On this page

  • 1. What this page covers
  • 2. Roles per engagement
  • 3. Data categories and purposes
  • 4. Processing lifecycle
  • 5. Access and security
  • 6. Subprocessors and transfers
  • 7. Retention and deletion
  • 8. Data subjects and incidents
  • 9. Documents for review

1. What this page covers

This is a public due-diligence overview.

It is not the privacy policy, which explains YPAI's own processing to the people whose data it concerns.

It is not the Data Processing Agreement.

The signed documents for a project take precedence over this page.

2. Roles are defined per engagement

Engagement pattern Typical starting point Documentation
The customer supplies data for annotation or evaluation The customer is the controller, YPAI is the processor SOW, DPA and security annex
YPAI collects participant data for the customer The role follows who determines the purposes and essential means DPA, data-sharing or controller terms, consent and releases
YPAI licenses or brokers existing data Roles and rights are settled per dataset and source Dataset licence, rights record and processing terms
YPAI builds a system with customer data Normally the processor for customer data handled under instruction SOW, DPA, security and residency annexes

The role cannot be settled by a label in the contract alone. It follows who actually determines why and how the processing happens.

3. Data categories and purposes

Depending on the engagement, processing can involve:

  • Customer and project data
  • Documents, images, video, audio, text and sensor data
  • Contributor and participant data
  • Annotations, evaluations and QA results
  • Consent, rights and provenance records
  • System logs and technical metadata
  • Business contact data

The purpose of processing is tied to the specific delivery the data belongs to, as defined in the contract. Data supplied or collected for one engagement is not repurposed for other work without a rights basis that covers it.

4. Processing lifecycle

Every engagement follows one linear process:

Scope and instructions → provision or collection → preparation, annotation, evaluation or implementation → quality review → controlled delivery → return, deletion or agreed retention.

Step Access Purpose Governed by Evidence produced
Scope and instructions Project lead and the customer Define scope, instructions, roles and controls SOW and, where required, the DPA Signed scope and instruction set
Provision or collection Named project staff; contributors where collection applies Receive customer data or collect participant data under instruction SOW, DPA, consent and release framework Intake or collection log, consent records
Preparation, annotation, evaluation or implementation Named project staff and approved contributors Perform the contracted work on the data SOW and project guidelines Work records and QA inputs
Quality review QA reviewers Verify the work against the acceptance specification Quality and acceptance specification QA results and review records
Controlled delivery Delivery owner and customer recipients Deliver the agreed output through the agreed channel SOW and delivery terms Delivery manifest
Return, deletion or agreed retention Delivery owner Close out the engagement as contracted DPA and retention schedule Deletion or retention record

5. Access, security and confidentiality

Project environments apply these control categories:

  • Authorized users and least privilege
  • Environment and project separation
  • Access control and authentication
  • Encryption where the actual architecture supports the claim
  • Logging and audit where this exists for the environment
  • Confidentiality obligations for staff and contributors
  • Controlled delivery and deletion

Detailed technical and organizational measures are provided for review during due diligence.

6. Subprocessors, residency and transfers

Subprocessors are approved before use and documented for the engagement they serve. The actual list, the purposes they serve and the jurisdictions involved are defined or disclosed for the specific delivery, and changes are notified as agreed in the contract.

EEA-based processing is available where required. Residency, access locations and transfer mechanisms are defined per engagement. Where a relevant transfer requires it, standard contractual clauses or another valid mechanism is used.

Location, jurisdiction, access and transfer controls are covered in depth on EEA data residency.

A DPA is available where the processing relationship requires one. In data engagements where YPAI processes personal data, the DPA ships with the Statement of Work.

7. Retention, return and deletion

The retention period follows the purpose, the contract and legal requirements. There is no single fixed retention schedule across all projects.

  • The customer and YPAI agree return, deletion or limited further retention at closeout
  • Backup, audit and statutory exceptions are handled explicitly in the agreed terms
  • Deletion can be documented with a deletion record where the contract includes it
  • Extracts, downstream deliveries and derived artifacts are handled according to the actual dataset and its rights basis

8. Data-subject support and incidents

YPAI supports the parties it processes for with:

  • Access, rectification, erasure, restriction and objection requests
  • Withdrawal of consent where consent is the basis used
  • Identification of affected recordings or records
  • Security-incident handling, notification and cooperation
  • Audits and information requests

Where copies of data exist downstream outside YPAI's control, YPAI supports the request to the extent of its own systems and its contractual position, and does not promise outcomes it cannot enforce.

9. Documents available for review

Document What it defines
Statement of WorkScope, instructions, deliverables and acceptance criteria
Data Processing AgreementRoles, instructions, data categories and Article 28 terms
Security and technical measuresThe controls applied to the project environment
Subprocessor informationThe subprocessors used for the engagement and their roles
Data-flow and residency informationWhere data is stored and processed, and who can access it
Transfer mechanism or SCC informationThe legal mechanism for any relevant transfer
Retention and deletion scheduleHow long data is kept, and how it is returned or deleted
Consent or source-rights frameworkThe rights basis for collected or licensed data
Incident-cooperation processHow incidents are notified and handled between the parties
Quality and acceptance specificationHow quality is measured and accepted
Dataset licenceRights and restrictions for licensed datasets
Delivery manifestWhat was delivered, when, and in what form
Scope a project

EEA data residency in depth. The governance behind these terms is set out in the Ethical AI Policy.

Start with the system or the data.

YPAI builds production AI systems and delivers the multimodal data used to train, evaluate and improve them.

Contact us Scope a pilot

AI systems, data and evaluation under one accountable delivery model.

New projects · accepting data and AI work
Engagement scoped before build
Acceptance defined before delivery
Services
AI Data & Evaluation AI Implementation Controlled Delivery Dataset Licensing
Capabilities
Speech & Audio Image Data Image, 3D & Sensor Data Video Data Video Data Collection Physical AI Data Annotation & Evaluation Data Labeling
Company
About YPAI Partnerships Contact Become a Contributor
Resources & Legal
AI Blog Privacy Contributor Terms Cookie Policy Data processing
YPAI · Oslo, Norway · Global delivery
Disclaimer LinkedIn ↗
EEA RESIDENCY BY DEFAULT · ARTICLE 28 DPA TERMS AVAILABLE
© 2026 YPAI