Legal

Privacy notice

Last updated: 28 July 2026

This notice explains how personal data is handled across the DataVerse website, the data marketplace, our data-request and contact forms, and the communications that follow from them. DataVerse is based in Zurich, Switzerland, and this notice is written primarily under the Swiss Federal Act on Data Protection (FADP) and its implementing Ordinance.

1. Who we are

DataVerse, operated by LatentWorlds, based in Zurich, Switzerland (“DataVerse”, “we”, “us” or “our”), is the controller for the personal data described in this notice, unless a separate contract between us states otherwise — for example where we process personal data on a customer’s or provider’s instructions.

Privacy contact: abdul@latentworlds.ai.

Our formal corporate particulars and registered address will be published and kept current here as the business is formally constituted and as legal requirements apply. We have not appointed a data protection officer; privacy enquiries should be sent to the address above.

2. Scope

This notice applies to personal data about:

  • visitors to the DataVerse website;
  • prospective and current buyers of data;
  • data providers and hosts who list, contribute or host datasets;
  • collaborators and collection partners;
  • people who submit data requests, sample requests or enquiries; and
  • business contacts at organisations we work with or approach.

Datasets offered through the marketplace may be supplied by independent providers. This notice governs DataVerse’s handling of personal data relating to users and business contacts. The roles, responsibilities and permitted uses attached to any specific dataset are governed by the applicable listing terms, provider agreement, order terms or data processing agreement. See also our Terms of service and Acceptable use policy.

3. Personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and contact data — name, work email address, job title and company.
  • Request and project requirements — request title, intended task or use, environment, collection method, modalities, volume, format, camera or recording device, hardware platform, geography, technical specifications, annotation requirements, timeline, budget, sample preference and any additional context you provide.
  • Provider, hosting and collaboration information — details you submit when discussing listing, contributing, hosting or collecting data with us.
  • Marketplace and communications data — enquiries, sample requests, product configurations you build in the interface, items you add to a basket in your browser, and negotiation or order correspondence. The current site does not take payments or store basket contents on our servers.
  • Device, log and security data — limited technical information generated when you use the site or submit a form, including IP address, browser and device information supplied by your browser, request timestamps and server or security logs. Your IP address is used, among other things, to rate-limit form submissions and reduce abuse.
  • Correspondence and feedback — the content of emails and messages you send us.

Accounts: the site does not currently offer self-service accounts or sign-up. The sign-in page invites you to contact us for access, so any related personal data is contact data handled as described above. If account and authentication functionality is introduced, this notice will be updated first.

Please do not submit unnecessary sensitive personal data, personal data about other individuals, raw credentials or access keys, confidential source data, or unlawful content through our general forms. Send only what is needed for us to respond.

4. Where the data comes from

  • Directly from you, when you complete a request or contact form or email us.
  • From your organisation or authorised colleagues, where they involve us in a shared project or introduce you as a contact.
  • Automatically from the website, limited to the device, log and security data described above; we do not currently run analytics or advertising scripts.
  • From marketplace providers, buyers and collection partners in the course of matching, verifying or fulfilling a request.
  • From public professional or business sources, where reasonably necessary for business-to-business outreach. You can ask us to stop at any time by emailing us.

5. Purposes and justification

Under the FADP, lawful processing of personal data does not generally require a specific statutory basis in the way GDPR requires an Article 6 basis. Instead, processing must comply with the Act’s principles: lawfulness, good faith, proportionality, purpose limitation, recognisability, accuracy and data security. Where processing would otherwise breach a data subject’s personality rights — for example certain disclosures to third parties or processing against an express objection — we rely on a justification: consent, an overriding private or public interest, or a legal requirement.

PurposeData usedBasis / justification (FADP)
Operate, maintain and secure the websiteDevice, log and security dataProportionate processing for our overriding private interest in running and protecting the service
Respond to data requests, prepare samples and identify matching supplyIdentity and contact data; request and project requirementsPerformance of a contract or pre-contractual steps taken at your request
Facilitate marketplace enquiries, configurations, orders and provider relationshipsIdentity and contact data; marketplace and communications dataContract or pre-contractual steps; overriding private interest in operating the marketplace
Hosting, contribution and collaboration discussionsProvider, hosting and collaboration informationContract or pre-contractual steps; overriding private interest
Administer relationships, contracts and supportIdentity and contact data; correspondenceContract; overriding private interest
Improve the service using aggregate or de-identified insightAggregated request and usage informationOverriding private interest in service improvement; data minimised or de-identified
Prevent fraud, misuse, spam and security incidentsDevice and log data, including IP address used for rate limitingOverriding private interest in security and abuse prevention; legal requirements where applicable
Maintain legal, accounting and compliance recordsIdentity, contact and transaction recordsCompliance with legal obligations (including Swiss retention duties) where they apply
Send relevant business-to-business service updates or marketingIdentity and contact data; communication preferencesOverriding private interest in B2B communication, or consent where required by law. You can opt out at any time

Where you submit a request, we do not rely on consent to respond to it — responding is necessary to take the steps you have asked for. The confirmation you give on the request form records that we may contact you about that request.

6. GDPR and UK GDPR, where they apply

The EU General Data Protection Regulation or the UK GDPR may additionally apply to particular processing activities — for example where we offer services to, or monitor the behaviour of, people located in the EEA or the United Kingdom. Where they apply, we rely on the following Article 6 bases, mapped to the purposes in the table above:

  • Article 6(1)(b) — performance of a contract or pre-contractual steps, for responding to requests, samples, orders and provider relationships.
  • Article 6(1)(f) — our legitimate interests in operating, securing and improving the marketplace and in business-to-business communication, balanced against your rights.
  • Article 6(1)(c) — compliance with a legal obligation, for records we are required to keep.
  • Article 6(1)(a) — consent, where consent is required (for example certain electronic marketing or non-essential cookies). You can withdraw consent at any time.

This section does not extend GDPR or UK GDPR to processing that is governed by Swiss law alone.

7. Marketplace datasets and roles

DataVerse is a marketplace and infrastructure service. We do not automatically become the controller of all personal data that may be contained within datasets supplied by third parties.

  • Providers are responsible for ensuring they have the rights and lawful authority to list, supply and permit use of the data they offer, and for accurately describing any restrictions.
  • Buyers are responsible for the lawfulness of their downstream use, including any further processing or model training.
  • Where we process personal data for a customer or provider as a processor, the relevant agreement or data processing agreement governs that processing.
  • We may review listing metadata, samples and documentation for marketplace operations, verification, safety and quality purposes, subject to the applicable agreements.

Not all listed data contains personal data, and we do not guarantee any provider’s compliance with data protection law.

8. Disclosures and service providers

  • Service providers (processors) acting for us, in categories such as cloud hosting and infrastructure, email delivery, security, and professional advisers. We do not currently use analytics or advertising providers. Processors are bound to process personal data only as we instruct and to maintain appropriate security.
  • Relevant buyers, providers or collection partners where necessary to match or fulfil a request. Your requirements and contact details are shared only to the extent reasonably necessary for that purpose.
  • Advisers, auditors, insurers and, where required, authorities, courts or regulators, including where disclosure is necessary to establish, exercise or defend legal claims.
  • Business transfers — if DataVerse or LatentWorlds is involved in a reorganisation, financing, merger, acquisition or transfer of assets, personal data may be disclosed to the counterparty and its advisers, subject to appropriate confidentiality protections and to this notice continuing to apply.

We do not sell personal data.

9. International transfers

We are based in Switzerland and use service providers that may process personal data outside Switzerland, including in the EEA, the United Kingdom and the United States.

  • Where the destination country is on the Swiss Federal Council’s list of states with adequate data protection, the transfer may take place on that basis.
  • Otherwise we rely on recognised safeguards under the FADP, in particular standard contractual clauses recognised or approved by the Federal Data Protection and Information Commissioner (FDPIC), with any Swiss-specific amendments, or other safeguards permitted by the Act.
  • Where GDPR or UK GDPR applies to a transfer, we additionally rely on an adequacy decision or on appropriate safeguards such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum.

You can ask us for information about the safeguards applied to a specific transfer by emailing abdul@latentworlds.ai.

10. Retention

We keep personal data only for as long as it is needed for the purpose it was collected for. In deciding how long that is, we consider:

  • whether the purpose is still live — for example an open request, an active enquiry or an ongoing provider or buyer relationship;
  • contractual and legal duties, including Swiss accounting and record-keeping obligations that apply to business and transaction records;
  • whether the data may be needed to establish, exercise or defend legal claims, or to handle a dispute;
  • security, audit and abuse-prevention needs, where logs are kept for shorter periods; and
  • any request you make to delete data, subject to the exceptions above.

We do not publish fixed retention periods for every category, because the appropriate period depends on the factors above. When data is no longer needed, we delete, destroy or anonymise it. Aggregated or de-identified information that can no longer be linked to an individual may be retained.

11. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege access, restricted handling of samples and provider material, rate limiting of public forms, logging, and confidentiality obligations for people acting for us.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your data or an account has been compromised, contact abdul@latentworlds.ai promptly. Please report suspected vulnerabilities responsibly and in accordance with our Acceptable use policy.

12. Your rights under the FADP

Subject to the conditions and exceptions in the Act, you may:

  • request information about, and access to, the personal data we process about you, including the purposes, categories of recipients and retention criteria;
  • ask us to correct inaccurate or incomplete personal data;
  • ask us to delete or destroy personal data, where we no longer have a legitimate reason to keep it;
  • request data portability — the handover or transfer to another controller of personal data you have disclosed to us, where processing is automated and based on your consent or a contract;
  • object to particular processing, or ask that it be restricted, that a disclosure be blocked, or that a note of dispute be attached where accuracy cannot be established; and
  • ask that an automated individual decision be reviewed by a natural person, and state your point of view, where such a decision has legal or significant effects.

Exercise any of these by emailing abdul@latentworlds.ai. We generally respond within 30 days. Where we cannot meet that timeframe, or where an exception in the Act allows us to refuse, restrict or defer a request — for example to protect the overriding interests of third parties, professional secrecy, or our own overriding interests — we will tell you and explain why. Requests are free of charge in normal circumstances. We may need to verify your identity.

13. Complaints

If something has gone wrong, please contact us first at abdul@latentworlds.ai so we can try to put it right.

You can also report the matter to the Swiss Federal Data Protection and Information Commissioner (FDPIC), our primary supervisory authority, at www.edoeb.admin.ch. Where EU or UK data protection law applies to the processing concerned, you may instead complain to the supervisory authority in your country of residence, place of work or the place of the alleged infringement — in the United Kingdom, the Information Commissioner’s Office at ico.org.uk. You may also have recourse to the civil courts.

14. Cookies and similar technologies

We keep the site deliberately light. We use only what is necessary to make the site work and keep it secure, including strictly necessary storage such as your browser’s local storage for the basket you build in the interface. We do not currently use analytics, advertising or cross-site tracking technologies.

If we introduce non-essential cookies or similar technologies, we will update this notice and, where the law requires it, obtain your consent first. You can control storage and cookies through your browser settings; blocking them may affect how parts of the site work.

15. Children and business audience

DataVerse is a business-to-business marketplace and is not directed to children or to consumers. Please do not submit children’s personal data through our general forms unless there is lawful authority and suitable safeguards agreed with us in advance, as further described in our Acceptable use policy.

16. Automated individual decisions

We do not currently make decisions that produce legal effects, or similarly significant effects, about individuals solely by automated means. If that changes, we will inform you, explain the logic involved, and honour your right to state your point of view and to request review of the decision by a natural person.

18. Changes to this notice

We may update this notice from time to time. Updates are posted on this page with a revised “last updated” date, and where changes are material we will communicate them through appropriate channels.

19. Contact

For any question about this notice or your personal data, contact abdul@latentworlds.ai. DataVerse is operated by LatentWorlds and based in Zurich, Switzerland.

This notice should be reviewed whenever DataVerse introduces new analytics, payment, account, dataset-hosting or email systems.