Last updated August 1, 2026
Data Policy
This Data Policy governs how datasets are sourced, vetted, listed, licensed, and transferred on the Dayda marketplace. It applies to all Sellers, Buyers, and datasets listed on the Platform.
1. Purpose
Dayda is a managed marketplace for proprietary AI training data. Our Data Policy ensures that every dataset listed on the platform meets rigorous standards for legal provenance, quality, and compliance. This policy protects Sellers, Buyers, and the data subjects whose information may be included in datasets.
2. Data Provenance and Vetting
Every dataset listed on Dayda undergoes a standardized vetting process before going live:
2.1 Legal Ownership Verification
Dayda verifies that the Seller has clear, unencumbered ownership of the dataset or the necessary rights to license it. This includes reviewing:
- Corporate records and data creation documentation.
- Terms of service and privacy policies in effect at the time of data collection.
- Consent mechanisms and user agreements.
- Any third-party rights or restrictions on the data.
2.2 Legal Provenance Review
Each Seller completes a standardized provenance questionnaire, which is reviewed by Dayda's data attorney. The review covers:
- How the data was collected and generated.
- The lawful basis for collection (consent, legitimate interest, contractual necessity, etc.).
- Whether data subjects were notified and given opt-out opportunities.
- Whether the data contains personal information, sensitive data, or protected health information.
- Whether the data involves minors or children.
2.3 Quality Spot-Check
Dayda performs a quality spot-check on a sample of the dataset to verify it matches the Seller's description. This includes checking for:
- Data format, structure, and completeness.
- Annotation consistency and label quality (if applicable).
- Relevance to the described domain and use case.
2.4 PII and Compliance Screening
Dayda screens datasets for:
- Personally Identifiable Information (PII) that has not been de-identified.
- Protected Health Information (PHI) under HIPAA.
- Sensitive personal data under GDPR (Article 9).
- Data involving minors (COPPA compliance).
- Embedded third-party licensed content.
Datasets containing PII that cannot be adequately de-identified or that lack proper consent documentation will be rejected.
3. Data Types Accepted
Dayda accepts the following types of proprietary datasets from startups:
- Text & Language: Customer support transcripts, knowledge bases, legal documents, Q&A pairs, RLHF preference data.
- Behavioral & Interaction: Clickstream logs, search queries, A/B test results, recommendation interactions.
- Domain-Specific Structured: Healthcare records, legal case data, financial transactions, HR outcome datasets.
- Multimodal: Image + label pairs, audio transcripts, video annotations, document scans with OCR.
- Processed & Annotated: Human-labeled datasets, cleaned corpora, fine-tuning-ready JSONL files.
4. Data Types Rejected
Dayda will not list datasets that:
- Were obtained through unauthorized web scraping with no provenance trail.
- Lack user consent documentation where consent was required.
- Contain heavy PII that cannot be de-identified.
- Involve data collected from minors (under 13) without COPPA-compliant consent.
- Contain embedded third-party licensed content (e.g., copyrighted articles, proprietary code).
- Contain trade secrets or confidential information of third parties.
- Primarily consist of synthetic data without significant human-generated components.
- Constitute malware, viruses, or malicious code.
5. Data Licensing
5.1 License Types
Datasets are licensed under the terms specified in the Data Purchase Agreement (DPA) for each transaction. License types include:
- Non-exclusive license: The Seller may license the same dataset to multiple Buyers.
- Exclusive license: The Buyer receives exclusive rights to the dataset for a specified period or perpetuity, typically at a premium price.
5.2 Permitted Uses
Permitted uses are defined in the DPA and typically include:
- AI model training, fine-tuning, and evaluation.
- Research and development.
- Internal analytics and benchmarking.
5.3 Prohibited Uses
Unless explicitly permitted in the DPA, the following are prohibited:
- Resale or redistribution of the raw dataset.
- Use of the dataset to train models that compete with the Seller's business.
- Extraction of individual data subjects' personal information.
- Use in violation of applicable laws or regulations.
6. Data Transfer and Delivery
Data is transferred securely between Buyer and Seller through Dayda's facilitated process:
- Data is delivered via encrypted transfer methods (e.g., SFTP, encrypted cloud storage, secure file transfer).
- Dayda does not permanently store or retain copies of transferred datasets.
- Sample data (1–5% of the dataset) is provided under NDA for evaluation only.
- Buyers confirm receipt before payment is released to the Seller.
7. Data Retention and Deletion
Sellers may request that their listing be removed at any time. Dayda will:
- Remove the listing from the marketplace within 5 business days of the request.
- Delete any sample data held by Dayda within 30 days.
- Not require Buyers who have already executed a DPA to delete data (subject to the terms of that DPA).
Dayda retains transactional records (not the data itself) for 7 years for tax and accounting purposes.
8. Data Ownership
Dayda never holds permanent ownership of datasets listed on the Platform. The Seller retains full ownership until a Data Purchase Agreement is executed with a Buyer. Dayda acts solely as a facilitator and intermediary.
9. Compliance with Regulations
Dayda is committed to compliance with applicable data protection laws, including:
- GDPR (EU/UK): Datasets containing EU/UK personal data must have been collected with a valid lawful basis, and data subjects must have been provided with appropriate privacy notices.
- CCPA/CPRA (California): Datasets containing California resident personal information must comply with disclosure and opt-out requirements.
- HIPAA (US Healthcare): Datasets containing Protected Health Information must be properly de-identified in accordance with the HIPAA Privacy Rule.
- COPPA (US Children): Datasets containing data from children under 13 are not accepted unless fully COPPA-compliant.
- EU AI Act: Datasets are documented with provenance metadata to help Buyers demonstrate compliance with the EU AI Act's training data transparency requirements.
10. Changes to This Policy
We update this Data Policy as needed to reflect changes in our practices, legal requirements, or marketplace operations. Material changes will be communicated by posting the updated policy on this page.
11. Contact
Email: hello@dayda.co
Website: dayda.co