Data governance
How study data is structured.
Bracket Bridge runs contract-based AI training data acquisition. This page describes the operating controls expected around participant booking, collection, quality review, de-identification, delivery, and regional compliance.
Last updated: July 22, 2026
Operating model
- Every data acquisition project should be scoped through a written agreement or project authorization.
- The client normally controls the purpose, dataset requirements, acceptance criteria, and permitted use.
- Bracket Bridge structures recruitment, booking, collection, validation, quality control, de-identification, anonymization, and delivery according to the agreed scope.
Project lifecycle
- Scoping: define purpose, data categories, countries, languages, participant criteria, sensitive-data exclusions, quality rules, and transfer path.
- Notice: publish a project-specific participant notice before collection where the general privacy notice is not enough.
- Collection: collect only what the project needs and log consent or acceptance events where required.
- Validation: check duplicates, format, fraud signals, quality markers, and collection instructions.
- Delivery: hand off client-controlled datasets using the agreed format, access controls, and deletion or retention schedule.
Dataset categories
Projects may include language, accent, voice, transcript, translation, annotation, ranking, preference, human feedback, agent trajectory, tool-use, prompt-response, screen-flow, task completion, and model-evaluation data.
Compensation and referral controls
- Participant honoraria and referral rewards should be stated before participation with the amount, eligibility rules, payout timing, and disqualification conditions.
- Payments should be released only after eligible participation, valid completion, consent checks, and reasonable quality or fraud review.
- Referral rewards should require a qualifying referred participant, not merely link sharing, traffic, or a booking request.
- Referral activity should prohibit spam, scraped contact lists, misleading posts, pressure tactics, self-referrals, fake bookings, and guaranteed-income claims.
- Payment, payout, and referral records should be access-limited and retained only as needed for accounting, tax, audit, dispute, fraud-prevention, and legal obligations.
Voluntary participation and consent controls
- Treat booking as scheduling only, not consent to participate or record.
- Provide the current project-specific participant information and consent form in a language each participant understands before collection.
- Give participants a reasonable opportunity to ask questions, decline, or request a pause without pressure from moderators, referrers, friends, or clients.
- Require separate affirmative consent from every recorded person and verify signed forms before the moderator can start recording.
- Document the form version, study, date, participant or coded identifier, and verification event; store consent records separately with restricted access.
- Explain in advance how withdrawal affects compensation, data already collected or delivered, and data already irreversibly anonymized.
De-identification and anonymization
Project outputs are designed around anonymized or de-identified delivery where the agreed scope allows it. Raw identifiers should be minimized, separated, access-limited, or removed once they are no longer needed for scheduling, payment, quality control, security, or contractual records. Voice, audio, images, and detailed trajectories can remain personal data if a person is still identifiable, so project wording should avoid overclaiming anonymity until the actual workflow supports it.
European project checklist
- Identify the controller, processor, joint-controller, and subcontractor roles before collection.
- Publish participant information covering identity, purpose, legal basis, data categories, recipients, retention, transfers, rights, and contact route.
- Use a DPA or Article 28-style processing terms when Bracket Bridge processes data for a client controller.
- Use Standard Contractual Clauses, EU-U.S. Data Privacy Framework participation, or another transfer mechanism where personal data moves from Europe to the United States or another third country.
- Run a DPIA or privacy risk assessment before high-risk processing, sensitive data, biometric identification, minors, large-scale monitoring, or extensive behavioral tracking.
- Publish compensation and referral rules before collection and avoid pressure, misleading recruitment, or rewards so high that they undermine freely given consent.
- Keep consent, withdrawal, deletion, quality-control, access, and breach-response records appropriate to the project risk.
Security posture
Access to raw project data should be limited to people and systems that need it for study operations, quality control, delivery, security, or compliance. Project data should be stored in controlled environments, transferred through approved channels, and deleted or archived according to the applicable contract.
Participant requests
Participants can contact support@bracketbridge.com to ask about access, correction, deletion, withdrawal, or project-specific privacy questions. Requests may need to be coordinated with the client controller where the client controls the project data.