Privacy Policy
Version 2026-10-09 · Effective 9 October 2026
This policy explains how Dataset By Humans ("we", "us") handles personal data when you visit datasetbyhumans.com, fill in a form, order from us or email us. We apply the same high standard to every visitor, wherever you are.
Who is responsible
Dataset By Humans is the controller of the personal data described here. Contact: privacy@datasetbyhumans.com. This mailbox is monitored by the person responsible for privacy at Dataset By Humans.
What we collect and why
| Activity | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Request a dataset form | Description of your needs, optional details (quantity, deadline, budget), name, company, work email | To reply with samples and a quote | Steps taken at your request before entering a contract |
| Free sample request | Work email, company, optional use case, dataset topic | To send you sample data | Steps taken at your request |
| Customer account | Name, email, company, password (stored only as a salted scrypt hash), sign-in times, a session cookie, password reset requests | To let you sign in, place orders and see their status | Performance of a contract; legitimate interests (account security) |
| Orders placed on the site or by email | Name, email, company, the person or organisation the license is issued to, billing country and address, notes you add, tax ID if you give one, item and license ordered, order status, invoice and payment status | To confirm the order, invoice you, deliver the files and license certificate, and keep accounting records | Performance of a contract; legal obligation (tax and accounting records) |
| Optional newsletter tick box | Email address, date of consent | To email you about new datasets and tutorials | Your consent, which you can withdraw at any time |
| Emails we send | Recipient, type of email, delivery status | To confirm requests and orders and to check that emails arrive | Legitimate interests |
| Security and abuse prevention | Truncated IP address (network prefix only) stored with form submissions; full IP address, browser type and requested page in server logs | To protect the site and forms from spam and abuse | Legitimate interests |
| Website analytics (Google Analytics) | Pages viewed, referring site, approximate location (country/city, derived from your IP address, which Google Analytics does not store), device and browser type, and a random cookie identifier if you accept analytics cookies | To understand which pages are useful and improve the site | Your consent (cookies); without consent only cookieless, non-identifying signals are sent |
| Email correspondence | Content of emails you send us | To answer you | Legitimate interests / pre-contract steps |
Google Analytics advertising features, Google signals and ad personalisation are switched off. We do not sell or share personal data for cross-context behavioural advertising, and we do not use your data to train AI models.
Cookies
If you sign in, we set one strictly necessary session cookie (dbh_session) that keeps you signed in for up to 30 days. We use Google Analytics cookies only if you accept them in the cookie banner, and no advertising cookies. You can change your choice at any time with Cookie settings in the footer. See the cookie policy.
Who we share data with
We use a small number of service providers (processors) who handle data on our behalf under data processing agreements, such as our hosting provider and our email service. They are listed on the subprocessors page. We may also share data with our accountants and tax advisers where needed for invoicing, and disclose data if required by law.
Where your data is stored and international transfers
Our website and database run on servers in Singapore. Our email and analytics providers may process data in other countries, including the United States and Japan. Where data from the EU, EEA or UK is transferred, we rely on Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.
How long we keep data
| Data | Retention |
|---|---|
| Dataset and sample requests that do not lead to an order | 24 months after our last contact |
| Customer accounts | Until you ask us to delete the account, or 36 months after your last sign-in or order |
| Orders, invoices and related correspondence | As long as tax and accounting law requires, generally up to 10 years |
| Newsletter consent | Until you unsubscribe, plus proof of consent for 3 years |
| Email delivery records | Up to 24 months |
| Server logs with full IP addresses | 14 days |
| Rate-limiting counters (truncated IP) | Up to 24 hours |
| Google Analytics data | 14 months, then deleted automatically by Google Analytics |
| Other correspondence | Up to 24 months |
Your rights
Depending on where you live, you have the right to:
- access your data and receive a copy in a portable format;
- correct inaccurate data;
- delete your data, unless we must keep it, for example invoices for tax purposes;
- object to or restrict processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier processing;
- opt out of the sale or sharing of personal data (California and other US states). We do not sell or share personal data, and we honour Global Privacy Control signals;
- not be discriminated against for exercising your rights;
- complain to your data protection authority.
Email privacy@datasetbyhumans.com to exercise any right. We respond within one month (GDPR / UK GDPR) or 45 days (US state laws), and may ask you to confirm your identity first.
People who appear in our datasets
Our photo and video datasets are processed so that people cannot be identified: faces and license plates are blurred, GPS is removed and every image or clip is reviewed by a person. Text datasets (reasoning, tests, Q&A, conversations) are written for the dataset and contain only invented personal details. If you believe you can be identified in one of our images, use our takedown process.
Children
This website is intended for businesses and adults. We do not knowingly collect data from children under 16.
Security
We use HTTPS everywhere, keep the database reachable only from our own server, use access controls with two-factor authentication on administrative accounts, and minimise data, for example by truncating IP addresses stored with form submissions. No system is perfectly secure; if a breach affecting you occurs, we will notify you and the authorities as required by law.
Changes
We will post any changes on this page with a new version date and, for material changes, notify people we are in contact with.
Questions about this page? Contact privacy@datasetbyhumans.com. The English version of this document is the legally binding one; translations are provided for convenience.