Legal
Responsible Data Collection Policy
Last updated: 31 July 2026
This policy describes how YPAI collects, documents, reviews, stores and deletes data obtained from contributors for customer engagements. It applies to data collection activities conducted within AI Data & Evaluation and AI Implementation.
1. Purpose and scope
This policy describes how YPAI collects, documents, reviews, stores and deletes data obtained from contributors for customer engagements. It applies to data collection activities conducted within AI Data & Evaluation and AI Implementation. Controlled Delivery provides the shared operating framework for scope, rights, quality, security, change and acceptance from project definition to handover.
The policy applies to YPAI, contributors participating in a collection, and customers reviewing how collected data was obtained. Project-specific terms remain defined in the applicable project terms, data processing agreement, acceptance plan and transfer arrangements.
2. Principles
Purpose-specific collection. YPAI documents consent for each contributor and each stated purpose. Data rights and licence terms are linked to the purpose for which the data is collected.
Traceability. YPAI maintains a traceable connection between collected data, the contributor, the consent record and the applicable rights basis. Provenance records and dataset change logs preserve that connection through delivery.
Documented control. Collection, review and acceptance follow the scope and sampling plan agreed for the engagement. The resulting records allow the customer to examine how the dataset was assembled and reviewed.
Project-specific handling. Data residency, subprocessors and international transfer controls are defined for each project. European storage is the default position.
Withdrawal and deletion. YPAI maintains a documented withdrawal workflow and records the actions taken. At the end of a contract, YPAI applies its contractual 30-day erasure commitment.
3. How contributors are engaged
YPAI recruits contributors through its own channels rather than third-party marketplaces. Its contributor network includes 210,000+ contributors across 50+ countries.
Contributors participating in collection are identity-verified. YPAI uses its self-hosted annotation infrastructure for annotation work.
Contributor payments are made monthly by international transfer. Supported payment currencies are USD, EUR, NOK, BRL and SEK.
4. Consent and lawful basis
YPAI documents the lawful basis applicable to each collection purpose under GDPR Article 6. Where consent is the lawful basis, YPAI records consent per contributor and per purpose in accordance with Article 7. Where the collection involves special categories of personal data and Article 9 applies, YPAI documents explicit consent for the specified purpose.
Consent is not inferred from acceptance of general platform terms. The consent record is maintained separately and linked to the relevant purpose.
Each collected record is linked to its consent record through SHA-256 provenance manifests. This provides evidence of the connection between the record, the contributor, the stated purpose and the rights or licence basis associated with the dataset.
5. Provenance and traceability
YPAI maintains provenance information for collected records. For recorded data, this includes per-recording provenance linked to the contributor and the applicable consent record.
Rights and licence information remains traceable from the delivered dataset back to the consent on which collection and permitted use are based. Dataset versions are immutable and are accompanied by change logs so that changes between versions can be identified.
The provenance package is part of the documentation supplied for the engagement. It supports customer review of source, purpose, rights and dataset history.
6. Data subject rights and withdrawal
YPAI maintains a workflow for data subject rights and related restrictions under GDPR Articles 12 to 23, as applicable to the processing activity. The workflow records the request and the actions taken.
A contributor may withdraw consent through the withdrawal process. YPAI maintains an audit trail for withdrawal handling. The contractual 30-day erasure commitment at the end of a contract does not set a response period for an individual withdrawal request.
Where YPAI processes personal data on behalf of a customer, the respective responsibilities for handling requests are defined in the project terms and the applicable Article 28 data processing agreement.
7. Storage, residency and transfers
YPAI uses European storage by default. The agreed data residency position, authorised subprocessors and controls for international transfers are defined for each project.
YPAI provides standard Article 28 data processing agreement terms. Standard contractual clauses are available where the agreed processing or international transfer arrangement requires them. Article 28 controller-processor clauses and clauses for transfers outside the EEA address separate contractual functions.
Subprocessor information is included in the documentation supplied to the customer. The project terms define the processing arrangement that applies to the engagement.
8. Quality and human review
Human quality assurance is applied according to the acceptance and sampling plan agreed for each engagement. The plan defines where human review is used and how reviewed output is assessed for acceptance.
YPAI records QA artefacts and validation logs produced under that plan. These records document the review performed for the contracted scope without representing that every item receives the same review treatment.
Quality decisions, changes and acceptance are handled through Controlled Delivery and the terms agreed for the engagement.
9. Documentation provided to customers
For data collection engagements, YPAI provides documentation covering the controls applied to the dataset. The documentation includes, as applicable to the collected data:
- per-recording provenance;
- consent records per contributor and per purpose;
- demographic and dialect distribution metadata;
- QA artefacts and validation logs;
- immutable dataset versioning with change logs;
- subprocessor transparency;
- sampling methodology documentation.
YPAI aligns this documentation with the data governance subjects addressed by EU AI Act Article 10 for high-risk AI systems. The documentation is structured so a conformity assessment can use it.
10. Retention and deletion
At the end of the contract, YPAI applies a contractual 30-day erasure commitment. The commitment concerns end-of-contract erasure and is separate from the workflow used for individual withdrawal requests.
Deletion is handled within the contracted project scope. The relevant project documents define the data, processing arrangement, subprocessors, residency position and transfer controls to which the commitment applies.
YPAI records withdrawal actions through the withdrawal audit trail and maintains dataset change information through version records and change logs.
11. Boundaries and shared responsibility
Where the customer acts as controller, it retains responsibility for the purposes for which it uses the data, the instructions it gives to YPAI, the intended use of its AI system and its own conformity assessment. A processor acts on behalf of the controller and according to the controller's documented instructions.
YPAI is responsible for applying the controls stated in this policy within the agreed scope. YPAI provides the provenance, consent, distribution, quality, versioning, subprocessor and sampling documentation described above to support customer review.
Project terms, the data processing agreement, standard contractual clauses where applicable, and the acceptance plan govern the engagement alongside this policy.
12. Governance of this policy
This policy is reviewed according to YPAI's assigned review cadence and when material changes to services, evaluation methods, regulatory posture, subprocessors, residency controls or monitoring practices affect its content.
Questions about this policy are raised through the YPAI contact used for procurement, risk, security or the relevant engagement. YPAI records the question, provides a documented response and updates this policy where a change is required.
Version: 1.0
Effective date: 31 July 2026
Document owner: Data Protection Officer