Skip to content

Trust · Legal framework

How we handle the legal side of licensing data.

A plain-English overview of the legal and compliance checks we run before any data is licensed. Each deal is governed by its own signed agreement; this page is not legal advice.

Consent and ownership

Before any offer, we review whether your company has the right to license the data. That includes data about your own customers and your employees.

We look at your customer contracts, privacy notices and employee policies, and we leave out any data you don't have the right to share. You confirm ownership in writing.

Platform terms

Data often comes from tools such as Zendesk, Gong, Salesforce or GitHub. Each tool has its own terms about how exported data can be used.

We check the relevant terms for each source during review. If a tool's terms restrict a use, that data is excluded or the deal is scoped to fit.

Call recordings and consent

Some US states and other countries require every person on a call to agree to it being recorded. Recordings are only considered when the right consent was in place when they were made.

Where consent is unclear, recordings are left out or limited to text with personal details removed.

HIPAA (healthcare administration)

Health information covered by HIPAA is not licensed in identifiable form. For healthcare administration data, we require HIPAA de-identification, using either the Safe Harbor method or an expert determination, before anything is considered for a license.

CCPA and GDPR

Where California or European privacy law applies, we review the legal basis for sharing, respect individuals' rights requests, and use de-identified data. Data covered by GDPR is only included when there is a valid legal basis and the right transfer safeguards.

De-identification standard and verification

Personal details such as names, emails, phone numbers and account numbers are removed or replaced before delivery. The method used is recorded for each dataset.

A sample is checked after processing to confirm the removal worked. No method is perfect, so these checks reduce risk but can't remove it entirely.

License restrictions on buyers

Every buyer agreement prohibits trying to re-identify people, and prohibits reselling or passing the data on. It also limits use to the purposes written into the contract.

Buyers must delete the data when the license ends or if they breach these terms.

Questions: hello@sourcex.si

See if you qualify