01Consent is the product
Scraped data is cheap and getting more expensive by the lawsuit. Consented data costs more to gather and is worth more precisely because of it. Surdatics only produces the second kind.
- Every respondent is shown what the survey is for and what they will be paid before they answer.
- Nobody is enrolled without agreeing. There is no passive collection, no tracking pixel harvest, no purchased contact list.
- Consent is specific. Agreeing to answer a survey is not agreeing to identity verification, and agreeing to either is not agreeing to marketing.
- Consent can be withdrawn, and withdrawing it severs future use.
02The law we work to
We operate across more than one jurisdiction, so more than one regime applies. These are the ones that bind us, not a list of logos:
- Nigeria Data Protection Act 2023 (NDPA) — our home regime. Lawful basis, data subject rights, breach notification, and the Nigeria Data Protection Commission as supervisory authority.
- EU / UK GDPR — where a respondent is in the EEA or UK. Article 9 governs the biometric data used for identity verification, and is why that consent is asked for separately and explicitly.
- ePrivacy / PECR — cookies and electronic communications.
- Research ethics convention — informed consent, the right to stop part-way, no deception about purpose, and fair payment for time given.
We do not claim certifications we have not earned. Where we are independently audited, this page will name the standard, the auditor and the date. Until then it says nothing, which is the honest thing for it to say.
03Provenance: how a buyer checks us
A claim about how data was collected is worth nothing if the person making it can revise it later. So every response carries a provenance record — what was asked, when it was answered, whether the respondent was verified, and what they were paid — and a cryptographic digest of that record is anchored so it cannot be rewritten afterwards.
The digest is a fingerprint. Anchoring it publishes no personal data and cannot be reversed into anyone's answers. What it gives a buyer is the ability to verify that the dataset in front of them is the one that was collected, unchanged, and that the people in it were actually paid.
04Two kinds of data, never mixed
The marketplace carries datasets we witnessed being collected and datasets a seller brought with them. Presenting these as the same thing would be the single easiest way to mislead a buyer, so they are labelled distinctly everywhere they appear.
- Collected on Surdatics. Gathered here, from consenting respondents, who were paid, with a verifiable provenance record. We stand behind how it was obtained.
- Brought by the seller. Collected elsewhere and listed here. It passes our automated checks and the seller warrants its lawful origin — but we did not witness its collection and we say so on the listing, not in a footnote.
A buyer always knows which they are buying before they pay.
05Anonymisation, and its limits
Before any dataset is listed, direct identifiers are removed — including from free-text answers, which is where a real name most often ends up. Each response carries a per-dataset pseudonym, so a buyer holding two datasets cannot join them to follow one person across both.
And the honest caveat: anonymisation is not absolute. A small dataset with rare demographic combinations can in principle narrow to an individual. We flag those at listing time, we bar re-identification contractually, and we end access to anyone who attempts it. We would rather tell you that than imply a guarantee nobody in this industry can actually make.
06Our position on AI training
- We do not scrape, and we do not buy scraped data.
- We do not train models on your personal data.
- We do not sell personal data to anyone who trains models on it. Datasets sold through the marketplace are anonymised.
- We use AI to draft survey questions, transcribe video, and draft reports. In each case a person reviews the output before it has any effect.
- No automated system alone decides whether you are paid.
If a buyer intends to use a dataset for model training, that is permitted for anonymised data and stated in the licence they accept. It is not permitted for anything that could identify a respondent, because we never sell that in the first place.
07Paying people properly
A consent framework that pays badly is a consent framework in name only. So:
- The reward is shown before a respondent starts, and does not change once they begin.
- Rewards are funded into escrow before a survey goes live, so payment does not depend on the researcher still being around afterwards.
- A rejected response can be disputed and is reviewed by validators who are not the researcher who rejected it.
- Payout methods that cannot actually settle are withheld rather than offered and then failed.
08Telling us something is wrong
If you believe a dataset was collected improperly, that a listing contains personal data, or that someone has attempted re-identification, tell us at ethics@surdatics.com. We investigate every report and suspend a listing while we do.
Security issues go to security@surdatics.com. We will not pursue anyone who reports a genuine vulnerability to us in good faith and gives us reasonable time to fix it.
Questions about this document, or a request about your own data? Write to privacy@surdatics.com.