BUYER_DOCS / DATA_HANDLING_&_DELETION

Data handling, chain of custody and deletion

Goldset — vetted human data for AI Version 1.0 · July 2026 · Review cycle: every 6 months or on material change

This is the document a security reviewer asks for. It states what happens to client data from the moment it arrives to the moment it is destroyed, who can touch it, and what we can prove afterwards.

Statements are marked [In place], [Policy] (committed and contractual, evidenced per engagement) or [Roadmap] (not yet — stated so nobody has to guess).


1. Custody chain

StageWhat happensControl
1. Pre-transferMutual NDA executed. DPA executed where personal data is in scope. Scope, retention period and deletion date agreed in writing before any data moves.[In place]
2. IntakeClient data received into a named, access-controlled workspace hosted in the UAE. Encrypted in transit and at rest. Logged on arrival: what arrived, when, from whom, and the agreed deletion date.[In place]
3. PreparationData is segmented into batches. Where the task permits it, identifying content is stripped or pseudonymised before annotation — annotators see the minimum necessary to do the task.[Policy]
4. AnnotationAccess is granted per project, per contributor, for the duration of the project only. Contributors work inside the controlled workspace; local download is not part of the workflow. All access is logged.[In place]
5. Review and QAMulti-pass review and adjudication by named senior reviewers under the same access controls.[In place]
6. DeliveryLabelled data, IAA report and QA scorecard delivered by the agreed channel. Delivery is logged.[In place]
7. RetentionDefault retention is zero beyond delivery. Client data is deleted after delivery unless you ask us in writing to retain it for a defined period.[In place]
8. DeletionDeletion performed across the working store, and — on request — a written certificate of deletion issued stating what was deleted, when, and by whom.[Policy]

No subcontracting. Work is not passed to third-party vendors, downstream crowd platforms, or unvetted labour pools. Every contributor on your data has passed the screening in 01-annotation-methodology.md and is engaged directly. [In place]


2. Where data lives, and who is where

requirements, this is a deliberate design choice rather than an accident of hosting.

through the controlled workspace.

plainly rather than burying it: data is hosted in the UAE and accessed from India. Where that matters to your regulator or your policy, it must be addressed in the DPA before work begins — not discovered afterwards.


3. Access control

the quality threshold, or the project closes.

deleted so that an access history can still be produced. Log retention is stated in the DPA.

devices are not a storage location for client data.


4. Personal data

(04b-dpa.md). Goldset acts as processor; the client remains controller.

as the entity's home jurisdiction. Being "aware" is not the same as being certified, and we do not claim certification.

redacted or synthetic-substituted content, we will propose that at scoping.

sub-processors — cloud hosting and the workspace platform — are named in the DPA and you are notified before any change.


5. Incident handling

without undue delay and within 48 hours of becoming aware, with what is known at that point, what is not yet known, and what is being done.

been through a live tabletop exercise, and we will not describe it as tested until it has.


6. Certifications — the honest position

Status
NDA before any data exchangeIn place
DPA available, executed pre-transferIn place
Data hosted in UAEIn place
Encrypted, access-controlled workspaceIn place
No subcontractingIn place
Deletion after delivery, retention on requestIn place
Certificate of deletion on requestPolicy
Cyber / professional indemnity insuranceRoadmap
ISO 27001Roadmap
SOC 2 Type I → IIRoadmap

We would rather lose a deal on a missing certificate than win one on an implied one. If your vendor review requires ISO 27001 or SOC 2 today, we are not yet the right supplier, and we will tell you that on the first call rather than the fifth.


7. What we ask of you

Symmetry matters, and it also protects you:

  1. Send the minimum data the task requires. If a sample would answer the question,

send a sample.

  1. Tell us if personal data, regulated data or export-controlled content is in scope

before transfer, not during.

  1. Name your deletion date at scoping. Our default is deletion on delivery; if your

policy requires a different period, it belongs in the DPA.


Goldset is the AI-data venture of PMC DXB. Entity: PMCDXB Corporate Services Provider (CSP) L.L.C S.O.C, Dubai commercial licence 1638875, Dubai Department of Economy & Tourism. RAK ICC Registered Agent RA20260332.

← All documents Start a pilot