Last updated August 1, 2026
Data Processing Addendum
This page describes Dayda's Data Processing Addendum (DPA) and Data Purchase Agreement (DPA) framework. These are the standard agreements governing how datasets are transferred, licensed, and processed on the Dayda marketplace.
1. Overview
Dayda facilitates transactions between Sellers and Buyers of proprietary AI training data. Each transaction is governed by a set of legal agreements designed to ensure clarity, compliance, and enforceability. The two primary agreements are:
- Data Purchase Agreement (DPA): The commercial contract between the Seller and Buyer governing the specific data transaction.
- Data Processing Addendum (DPA/DPA Addendum): The addendum addressing data protection and privacy compliance when personal data is involved.
These agreements are executed for each transaction and are separate from the platform-level Terms of Service.
2. Data Purchase Agreement
The Data Purchase Agreement is the binding contract between the Seller and Buyer for each transaction. It covers the following key terms:
2.1 Data Description
- Identification of the dataset being transferred.
- Data format, volume, and structure.
- Any relevant metadata, quality scores, and provenance documentation.
2.2 License Grant
- Non-exclusive license: Buyer receives a license to use the data, but Seller may license it to others.
- Exclusive license: Buyer receives exclusive rights for a defined period or in perpetuity.
- Permitted use cases (e.g., AI model training, research, benchmarking).
- Prohibited uses (e.g., resale of raw data, competitive use).
2.3 Representations and Warranties
- Seller warrants it has clear title and the right to license the data.
- Seller warrants the data was collected with appropriate consent or lawful basis.
- Seller warrants the data is free from malware and meets the description.
- Seller indemnifies Buyer against third-party claims arising from the data.
2.4 Purchase Price and Payment
- Total purchase price and payment terms.
- Dayda's commission is deducted at close.
- Payment is released to Seller upon Buyer's confirmation of receipt.
2.5 Delivery and Acceptance
- Data transfer method (encrypted file transfer, secure cloud storage, etc.).
- Buyer's acceptance period and right to reject for material non-conformity.
- Dispute resolution process for data quality issues.
2.6 Confidentiality
- Both parties agree to keep the terms of the transaction confidential.
- Seller identity remains confidential to the general public.
- Buyer's use case and model details remain confidential.
2.7 Limitation of Liability
- Each party's liability is capped at the purchase price (or a mutually agreed amount).
- Neither party is liable for indirect or consequential damages.
- Exceptions for breach of confidentiality, indemnification, and IP infringement.
3. Data Processing Addendum (DPA Addendum)
When a dataset contains personal data (as defined by GDPR, CCPA, or other applicable privacy laws), the transaction requires a Data Processing Addendum. This addendum addresses:
3.1 Roles and Responsibilities
- Data Controller: The Seller is the Data Controller of the personal data contained in the dataset.
- Data Processor: The Buyer is the Data Processor, processing the data for the permitted purposes defined in the DPA.
- Dayda: Dayda is a data intermediary/facilitator, not a Controller or Processor of the dataset content.
3.2 Processing Instructions
The Buyer agrees to process the personal data only for the specific purposes enumerated in the DPA and in accordance with the Seller's documented instructions.
3.3 Data Security
- Buyer must implement appropriate technical and organizational security measures.
- Encryption of data at rest and in transit.
- Access controls limiting data access to authorized personnel.
- Incident response procedures for data breaches.
3.4 Sub-processing
Buyer may engage sub-processors (e.g., cloud computing providers) with prior notice to the Seller. Buyer remains fully liable for sub-processor compliance.
3.5 Data Subject Rights
Buyer must assist the Seller in responding to data subject access requests (DSARs) and exercising other rights under applicable privacy laws.
3.6 Data Breach Notification
Buyer must notify the Seller of any personal data breach without undue delay and in any case within 48 hours of becoming aware of the breach.
3.7 Data Retention and Deletion
Upon termination of the DPA, Buyer must delete or return the personal data in accordance with the Seller's instructions, unless retention is required by law.
3.8 International Transfers
If the Buyer is located in a different jurisdiction than the Seller, the DPA Addendum includes Standard Contractual Clauses (SCCs) or other approved transfer mechanisms for cross-border data transfers.
4. Standard NDA
Before a Buyer gains access to a data sample, both parties execute Dayda's standard Non-Disclosure Agreement (NDA). The NDA covers:
- Definition of confidential information (including sample data, seller identity, and listing details).
- Permitted use of confidential information (evaluation only).
- Duration of confidentiality obligations (typically 2–5 years).
- Return or destruction of sample data upon request.
5. Indemnification Agreement
Sellers are required to sign an indemnification agreement as part of the listing process. This agreement provides that the Seller will indemnify Dayda against claims arising from:
- The Seller's breach of ownership or consent representations.
- Third-party IP infringement claims related to the dataset.
- Violations of applicable privacy or data protection laws.
6. Governing Law
All Dayda transaction agreements are governed by the laws of the State of Delaware, United States, unless otherwise agreed between the parties in writing.
7. Requesting a Copy
If you are a Buyer or Seller and would like to review Dayda's standard DPA, DPA Addendum, or NDA templates before initiating a transaction, contact us at hello@dayda.co. These documents are provided to qualified users during the transaction process.
8. Contact
Email: hello@dayda.co
Website: dayda.co