BUYER_DOCS / DATA_HANDLING_&_DELETION
Data handling, chain of custody and deletion
Goldset — vetted human data for AI Version 1.0 · July 2026 · Review cycle: every 6 months or on material change
This is the document a security reviewer asks for. It states what happens to client data from the moment it arrives to the moment it is destroyed, who can touch it, and what we can prove afterwards.
Statements are marked [In place], [Policy] (committed and contractual, evidenced per engagement) or [Roadmap] (not yet — stated so nobody has to guess).
1. Custody chain
| Stage | What happens | Control |
|---|---|---|
| 1. Pre-transfer | Mutual NDA executed. DPA executed where personal data is in scope. Scope, retention period and deletion date agreed in writing before any data moves. | [In place] |
| 2. Intake | Client data received into a named, access-controlled workspace hosted in the UAE. Encrypted in transit and at rest. Logged on arrival: what arrived, when, from whom, and the agreed deletion date. | [In place] |
| 3. Preparation | Data is segmented into batches. Where the task permits it, identifying content is stripped or pseudonymised before annotation — annotators see the minimum necessary to do the task. | [Policy] |
| 4. Annotation | Access is granted per project, per contributor, for the duration of the project only. Contributors work inside the controlled workspace; local download is not part of the workflow. All access is logged. | [In place] |
| 5. Review and QA | Multi-pass review and adjudication by named senior reviewers under the same access controls. | [In place] |
| 6. Delivery | Labelled data, IAA report and QA scorecard delivered by the agreed channel. Delivery is logged. | [In place] |
| 7. Retention | Default retention is zero beyond delivery. Client data is deleted after delivery unless you ask us in writing to retain it for a defined period. | [In place] |
| 8. Deletion | Deletion performed across the working store, and — on request — a written certificate of deletion issued stating what was deleted, when, and by whom. | [Policy] |
No subcontracting. Work is not passed to third-party vendors, downstream crowd platforms, or unvetted labour pools. Every contributor on your data has passed the screening in 01-annotation-methodology.md and is engaged directly. [In place]
2. Where data lives, and who is where
- Client data is hosted in the UAE. For Gulf programmes with data-sovereignty
requirements, this is a deliberate design choice rather than an accident of hosting.
- Contributors are screened and based in India, working against UAE-hosted data
through the controlled workspace.
- This means the arrangement involves a cross-border access pattern, and we say so
plainly rather than burying it: data is hosted in the UAE and accessed from India. Where that matters to your regulator or your policy, it must be addressed in the DPA before work begins — not discovered afterwards.
3. Access control
- Least privilege. Access is per project and time-boxed to the engagement.
- Named individuals. No shared or generic accounts on client data.
- Revocation. Access is withdrawn when a contributor leaves a project, fails to hold
the quality threshold, or the project closes.
- Logging. Access and activity are logged; logs are retained after client data is
deleted so that an access history can still be produced. Log retention is stated in the DPA.
- Device and workspace. Work is performed inside the controlled workspace. Contributor
devices are not a storage location for client data.
4. Personal data
- Where the work involves personal data, a DPA is executed before transfer
(04b-dpa.md). Goldset acts as processor; the client remains controller.
- Our practice is GDPR-aware and India DPDP-aware, and operates under UAE PDPL
as the entity's home jurisdiction. Being "aware" is not the same as being certified, and we do not claim certification.
- Data minimisation is a design rule, not a preference. If a task can be completed on
redacted or synthetic-substituted content, we will propose that at scoping.
- Sub-processors: none for annotation (no subcontracting). Infrastructure
sub-processors — cloud hosting and the workspace platform — are named in the DPA and you are notified before any change.
5. Incident handling
- [Policy] A suspected breach affecting client data is notified to the client
without undue delay and within 48 hours of becoming aware, with what is known at that point, what is not yet known, and what is being done.
- The client is not asked to wait for a complete picture before being told.
- Post-incident: written account of cause, scope, remediation and prevention.
- [Roadmap] A formally exercised incident-response runbook. It is written; it has not
been through a live tabletop exercise, and we will not describe it as tested until it has.
6. Certifications — the honest position
| Status | |
|---|---|
| NDA before any data exchange | In place |
| DPA available, executed pre-transfer | In place |
| Data hosted in UAE | In place |
| Encrypted, access-controlled workspace | In place |
| No subcontracting | In place |
| Deletion after delivery, retention on request | In place |
| Certificate of deletion on request | Policy |
| Cyber / professional indemnity insurance | Roadmap |
| ISO 27001 | Roadmap |
| SOC 2 Type I → II | Roadmap |
We would rather lose a deal on a missing certificate than win one on an implied one. If your vendor review requires ISO 27001 or SOC 2 today, we are not yet the right supplier, and we will tell you that on the first call rather than the fifth.
7. What we ask of you
Symmetry matters, and it also protects you:
- Send the minimum data the task requires. If a sample would answer the question,
send a sample.
- Tell us if personal data, regulated data or export-controlled content is in scope
before transfer, not during.
- Name your deletion date at scoping. Our default is deletion on delivery; if your
policy requires a different period, it belongs in the DPA.
Goldset is the AI-data venture of PMC DXB. Entity: PMCDXB Corporate Services Provider (CSP) L.L.C S.O.C, Dubai commercial licence 1638875, Dubai Department of Economy & Tourism. RAK ICC Registered Agent RA20260332.