Last updated: 28 July 2026
This notice explains how personal data is handled across the DataVerse website, the data marketplace, our data-request and contact forms, and the communications that follow from them. DataVerse is based in Zurich, Switzerland, and this notice is written primarily under the Swiss Federal Act on Data Protection (FADP) and its implementing Ordinance.
1. Who we are
DataVerse, operated by LatentWorlds, based in Zurich, Switzerland (“DataVerse”, “we”, “us” or “our”), is the controller for the personal data described in this notice, unless a separate contract between us states otherwise — for example where we process personal data on a customer’s or provider’s instructions.
Privacy contact: abdul@latentworlds.ai.
Our formal corporate particulars and registered address will be published and kept current here as the business is formally constituted and as legal requirements apply. We have not appointed a data protection officer; privacy enquiries should be sent to the address above.
2. Scope
This notice applies to personal data about:
- visitors to the DataVerse website;
- prospective and current buyers of data;
- data providers and hosts who list, contribute or host datasets;
- collaborators and collection partners;
- people who submit data requests, sample requests or enquiries; and
- business contacts at organisations we work with or approach.
Datasets offered through the marketplace may be supplied by independent providers. This notice governs DataVerse’s handling of personal data relating to users and business contacts. The roles, responsibilities and permitted uses attached to any specific dataset are governed by the applicable listing terms, provider agreement, order terms or data processing agreement. See also our Terms of service and Acceptable use policy.
3. Personal data we collect
Depending on how you interact with us, we may collect:
- Identity and contact data — name, work email address, job title and company.
- Request and project requirements — request title, intended task or use, environment, collection method, modalities, volume, format, camera or recording device, hardware platform, geography, technical specifications, annotation requirements, timeline, budget, sample preference and any additional context you provide.
- Provider, hosting and collaboration information — details you submit when discussing listing, contributing, hosting or collecting data with us.
- Marketplace and communications data — enquiries, sample requests, product configurations you build in the interface, items you add to a basket in your browser, and negotiation or order correspondence. The current site does not take payments or store basket contents on our servers.
- Device, log and security data — limited technical information generated when you use the site or submit a form, including IP address, browser and device information supplied by your browser, request timestamps and server or security logs. Your IP address is used, among other things, to rate-limit form submissions and reduce abuse.
- Correspondence and feedback — the content of emails and messages you send us.
Accounts: the site does not currently offer self-service accounts or sign-up. The sign-in page invites you to contact us for access, so any related personal data is contact data handled as described above. If account and authentication functionality is introduced, this notice will be updated first.
Please do not submit unnecessary sensitive personal data, personal data about other individuals, raw credentials or access keys, confidential source data, or unlawful content through our general forms. Send only what is needed for us to respond.
4. Where the data comes from
- Directly from you, when you complete a request or contact form or email us.
- From your organisation or authorised colleagues, where they involve us in a shared project or introduce you as a contact.
- Automatically from the website, limited to the device, log and security data described above; we do not currently run analytics or advertising scripts.
- From marketplace providers, buyers and collection partners in the course of matching, verifying or fulfilling a request.
- From public professional or business sources, where reasonably necessary for business-to-business outreach. You can ask us to stop at any time by emailing us.
5. Purposes and justification
Under the FADP, lawful processing of personal data does not generally require a specific statutory basis in the way GDPR requires an Article 6 basis. Instead, processing must comply with the Act’s principles: lawfulness, good faith, proportionality, purpose limitation, recognisability, accuracy and data security. Where processing would otherwise breach a data subject’s personality rights — for example certain disclosures to third parties or processing against an express objection — we rely on a justification: consent, an overriding private or public interest, or a legal requirement.
| Purpose | Data used | Basis / justification (FADP) |
|---|---|---|
| Operate, maintain and secure the website | Device, log and security data | Proportionate processing for our overriding private interest in running and protecting the service |
| Respond to data requests, prepare samples and identify matching supply | Identity and contact data; request and project requirements | Performance of a contract or pre-contractual steps taken at your request |
| Facilitate marketplace enquiries, configurations, orders and provider relationships | Identity and contact data; marketplace and communications data | Contract or pre-contractual steps; overriding private interest in operating the marketplace |
| Hosting, contribution and collaboration discussions | Provider, hosting and collaboration information | Contract or pre-contractual steps; overriding private interest |
| Administer relationships, contracts and support | Identity and contact data; correspondence | Contract; overriding private interest |
| Improve the service using aggregate or de-identified insight | Aggregated request and usage information | Overriding private interest in service improvement; data minimised or de-identified |
| Prevent fraud, misuse, spam and security incidents | Device and log data, including IP address used for rate limiting | Overriding private interest in security and abuse prevention; legal requirements where applicable |
| Maintain legal, accounting and compliance records | Identity, contact and transaction records | Compliance with legal obligations (including Swiss retention duties) where they apply |
| Send relevant business-to-business service updates or marketing | Identity and contact data; communication preferences | Overriding private interest in B2B communication, or consent where required by law. You can opt out at any time |
Where you submit a request, we do not rely on consent to respond to it — responding is necessary to take the steps you have asked for. The confirmation you give on the request form records that we may contact you about that request.
6. GDPR and UK GDPR, where they apply
The EU General Data Protection Regulation or the UK GDPR may additionally apply to particular processing activities — for example where we offer services to, or monitor the behaviour of, people located in the EEA or the United Kingdom. Where they apply, we rely on the following Article 6 bases, mapped to the purposes in the table above:
- Article 6(1)(b) — performance of a contract or pre-contractual steps, for responding to requests, samples, orders and provider relationships.
- Article 6(1)(f) — our legitimate interests in operating, securing and improving the marketplace and in business-to-business communication, balanced against your rights.
- Article 6(1)(c) — compliance with a legal obligation, for records we are required to keep.
- Article 6(1)(a) — consent, where consent is required (for example certain electronic marketing or non-essential cookies). You can withdraw consent at any time.
This section does not extend GDPR or UK GDPR to processing that is governed by Swiss law alone.
7. Marketplace datasets and roles
DataVerse is a marketplace and infrastructure service. We do not automatically become the controller of all personal data that may be contained within datasets supplied by third parties.
- Providers are responsible for ensuring they have the rights and lawful authority to list, supply and permit use of the data they offer, and for accurately describing any restrictions.
- Buyers are responsible for the lawfulness of their downstream use, including any further processing or model training.
- Where we process personal data for a customer or provider as a processor, the relevant agreement or data processing agreement governs that processing.
- We may review listing metadata, samples and documentation for marketplace operations, verification, safety and quality purposes, subject to the applicable agreements.
Not all listed data contains personal data, and we do not guarantee any provider’s compliance with data protection law.
9. International transfers
We are based in Switzerland and use service providers that may process personal data outside Switzerland, including in the EEA, the United Kingdom and the United States.
- Where the destination country is on the Swiss Federal Council’s list of states with adequate data protection, the transfer may take place on that basis.
- Otherwise we rely on recognised safeguards under the FADP, in particular standard contractual clauses recognised or approved by the Federal Data Protection and Information Commissioner (FDPIC), with any Swiss-specific amendments, or other safeguards permitted by the Act.
- Where GDPR or UK GDPR applies to a transfer, we additionally rely on an adequacy decision or on appropriate safeguards such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum.
You can ask us for information about the safeguards applied to a specific transfer by emailing abdul@latentworlds.ai.
10. Retention
We keep personal data only for as long as it is needed for the purpose it was collected for. In deciding how long that is, we consider:
- whether the purpose is still live — for example an open request, an active enquiry or an ongoing provider or buyer relationship;
- contractual and legal duties, including Swiss accounting and record-keeping obligations that apply to business and transaction records;
- whether the data may be needed to establish, exercise or defend legal claims, or to handle a dispute;
- security, audit and abuse-prevention needs, where logs are kept for shorter periods; and
- any request you make to delete data, subject to the exceptions above.
We do not publish fixed retention periods for every category, because the appropriate period depends on the factors above. When data is no longer needed, we delete, destroy or anonymise it. Aggregated or de-identified information that can no longer be linked to an individual may be retained.
11. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege access, restricted handling of samples and provider material, rate limiting of public forms, logging, and confidentiality obligations for people acting for us.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your data or an account has been compromised, contact abdul@latentworlds.ai promptly. Please report suspected vulnerabilities responsibly and in accordance with our Acceptable use policy.
12. Your rights under the FADP
Subject to the conditions and exceptions in the Act, you may:
- request information about, and access to, the personal data we process about you, including the purposes, categories of recipients and retention criteria;
- ask us to correct inaccurate or incomplete personal data;
- ask us to delete or destroy personal data, where we no longer have a legitimate reason to keep it;
- request data portability — the handover or transfer to another controller of personal data you have disclosed to us, where processing is automated and based on your consent or a contract;
- object to particular processing, or ask that it be restricted, that a disclosure be blocked, or that a note of dispute be attached where accuracy cannot be established; and
- ask that an automated individual decision be reviewed by a natural person, and state your point of view, where such a decision has legal or significant effects.
Exercise any of these by emailing abdul@latentworlds.ai. We generally respond within 30 days. Where we cannot meet that timeframe, or where an exception in the Act allows us to refuse, restrict or defer a request — for example to protect the overriding interests of third parties, professional secrecy, or our own overriding interests — we will tell you and explain why. Requests are free of charge in normal circumstances. We may need to verify your identity.
13. Complaints
If something has gone wrong, please contact us first at abdul@latentworlds.ai so we can try to put it right.
You can also report the matter to the Swiss Federal Data Protection and Information Commissioner (FDPIC), our primary supervisory authority, at www.edoeb.admin.ch. Where EU or UK data protection law applies to the processing concerned, you may instead complain to the supervisory authority in your country of residence, place of work or the place of the alleged infringement — in the United Kingdom, the Information Commissioner’s Office at ico.org.uk. You may also have recourse to the civil courts.
15. Children and business audience
DataVerse is a business-to-business marketplace and is not directed to children or to consumers. Please do not submit children’s personal data through our general forms unless there is lawful authority and suitable safeguards agreed with us in advance, as further described in our Acceptable use policy.
16. Automated individual decisions
We do not currently make decisions that produce legal effects, or similarly significant effects, about individuals solely by automated means. If that changes, we will inform you, explain the logic involved, and honour your right to state your point of view and to request review of the decision by a natural person.
17. Third-party links
The site links to third-party websites and services, including provider and partner sites. Those operate under their own privacy notices and terms, and we are not responsible for their content or data practices.
18. Changes to this notice
We may update this notice from time to time. Updates are posted on this page with a revised “last updated” date, and where changes are material we will communicate them through appropriate channels.
19. Contact
For any question about this notice or your personal data, contact abdul@latentworlds.ai. DataVerse is operated by LatentWorlds and based in Zurich, Switzerland.
This notice should be reviewed whenever DataVerse introduces new analytics, payment, account, dataset-hosting or email systems.