Data governance
How study data is structured.
Bracket Bridge runs contract-based AI training data acquisition. This page describes the operating controls expected around participant booking, collection, quality review, de-identification, delivery, and regional compliance.
Last updated: July 18, 2026
Operating model
- Every data acquisition project should be scoped through a written agreement or project authorization.
- The client normally controls the purpose, dataset requirements, acceptance criteria, and permitted use.
- Bracket Bridge structures recruitment, booking, collection, validation, quality control, de-identification, anonymization, and delivery according to the agreed scope.
Project lifecycle
- Scoping: define purpose, data categories, countries, languages, participant criteria, sensitive-data exclusions, quality rules, and transfer path.
- Notice: publish a project-specific participant notice before collection where the general privacy notice is not enough.
- Collection: collect only what the project needs and log consent or acceptance events where required.
- Validation: check duplicates, format, fraud signals, quality markers, and collection instructions.
- Delivery: hand off client-controlled datasets using the agreed format, access controls, and deletion or retention schedule.
Dataset categories
Projects may include language, accent, voice, transcript, translation, annotation, ranking, preference, human feedback, agent trajectory, tool-use, prompt-response, screen-flow, task completion, and model-evaluation data.
De-identification and anonymization
Project outputs are designed around anonymized or de-identified delivery where the agreed scope allows it. Raw identifiers should be minimized, separated, access-limited, or removed once they are no longer needed for scheduling, payment, quality control, security, or contractual records. Voice, audio, images, and detailed trajectories can remain personal data if a person is still identifiable, so project wording should avoid overclaiming anonymity until the actual workflow supports it.
European project checklist
- Identify the controller, processor, joint-controller, and subcontractor roles before collection.
- Publish participant information covering identity, purpose, legal basis, data categories, recipients, retention, transfers, rights, and contact route.
- Use a DPA or Article 28-style processing terms when Bracket Bridge processes data for a client controller.
- Use Standard Contractual Clauses, EU-U.S. Data Privacy Framework participation, or another transfer mechanism where personal data moves from Europe to the United States or another third country.
- Run a DPIA or privacy risk assessment before high-risk processing, sensitive data, biometric identification, minors, large-scale monitoring, or extensive behavioral tracking.
- Keep consent, withdrawal, deletion, quality-control, access, and breach-response records appropriate to the project risk.
Security posture
Access to raw project data should be limited to people and systems that need it for study operations, quality control, delivery, security, or compliance. Project data should be stored in controlled environments, transferred through approved channels, and deleted or archived according to the applicable contract.
Booking-flow measurement
The participant booking tool uses first-party, privacy-minimized journey events to understand completion, timing, and broad validation problems. These events exclude names, phone numbers, email addresses, notes, and contact-field contents. A random browser-session flow ID is used for up to 30 minutes, event records are retained for up to 90 days, and the data is not used for advertising or participant profiling.
Participant requests
Participants can contact support@bracketbridge.com to ask about access, correction, deletion, withdrawal, or project-specific privacy questions. Requests may need to be coordinated with the client controller where the client controls the project data.