1. We prioritize lawful provenance
Every dataset should be traceable to the organization that generated it, the systems that recorded it and the period it covers. We document provenance as part of preparing a dataset, and we do not source data by scraping or from parties who cannot show how it was generated.
2. We do not knowingly license information without appropriate rights
Before a dataset is offered, we work with the data owner to establish that they have the right to license it for the intended scope. Where rights are unclear, the dataset is not offered until they are resolved.
3. We distinguish ownership from licensing permission
Holding data is not the same as being free to license it. Customer contracts, confidentiality obligations, consents, regulations and export controls can all limit what may be licensed — even for data an organization created itself.
4. We evaluate privacy and confidentiality
We identify personal information, customer-confidential information and trade secrets early, and plan exclusion or de-identification dataset by dataset. Removing names alone does not guarantee anonymization. Combinations of dates, locations, product codes or rare events can re-identify people or customers, so de-identification is planned dataset by dataset.
Datasets involving the following may require additional review or may not be eligible:
- Personal consumer data
- Patient-identifiable medical information
- Payment-card information
- Passwords or authentication data
- Restricted defense information
- Export-controlled technical information
- Government-classified information
- Information the seller has no right to license
5. We seek transparency between suppliers and buyers
Buyers should understand what a dataset is, how it was produced and what its limitations are. Suppliers should understand who is licensing their data and for what purpose, to the extent confidentiality allows.
6. Licensing scope is defined contractually
Permitted uses, duration, exclusivity, field of use, onward-transfer restrictions and deletion obligations are set out in a written license between the parties. Nothing is transferred without the data owner's authorization. [Counsel review]
7. Cross-border transactions
We work with data owners and AI teams worldwide. Cross-border transactions are subject to applicable laws and regulations, including data-transfer and export-control rules. [Counsel review]
8. Specialist review
DataNexx does not provide legal advice. Data licensing transactions may require independent legal, privacy, regulatory, or export-control review. We work with data owners and appropriate legal and compliance specialists to determine what can be licensed.