Data On Demand collects web data for businesses that use it to make better commercial decisions. We believe that work should be done in a way that respects the websites we collect from, the people whose information may appear on them and the law in every market we serve. This policy sets out the principles we apply to every project.
1. Publicly available data only
We collect information that is publicly available to any visitor without logging in. We do not bypass authentication, paywalls, CAPTCHAs designed to restrict access, or other access controls, unless the client holds its own lawful entitlement to that access, such as its own account on a supplier or partner portal, and has instructed us to act on its behalf within the limits of that entitlement.
2. Review of each source's terms
Before collection begins, we review each source's terms of use and any relevant published policies. We record what they say about automated access and reuse and consider them together with the purpose of the project and the nature of the data. Where terms or other factors make collection inappropriate, we adjust the scope, propose an alternative source or decline.
3. Consideration of robots.txt
We take robots.txt directives into account when scoping and configuring collection. They express the website operator's preferences, and we treat them as a relevant factor in deciding what to collect and how.
4. Considerate request rates
- Request rates are set per source so that collection does not place an undue burden on its infrastructure.
- We limit collection to the pages and fields in scope rather than crawling whole sites.
- We cache and collect incrementally where possible, to avoid repeated requests for unchanged pages.
- We monitor error responses and back off automatically when a source shows signs of strain.
5. Personal data minimisation
Our default is to design personal data out of datasets. If a field that identifies an individual is not needed for the client's stated purpose, we do not collect it. Where personal data is genuinely required, for example business contact details for a lawful B2B purpose, we document the purpose and the legal basis the client relies on, collect only the necessary fields, agree retention periods and act on the client's documented instructions.
Projects are scoped against the data protection laws that apply, including GDPR and UK GDPR, the UAE and Saudi PDPL, Singapore and Malaysia PDPA, India's DPDP Act, Indonesia's PDP Law, the Australian Privacy Act, CCPA/CPRA, PIPEDA, LGPD, Mexico's LFPDPPP, Colombia's Law 1581 and Chile's Law 19.628 and its 2024 reform.
6. No sensitive categories
We do not collect special category or sensitive personal data, such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sexual orientation, biometric or genetic data, or data about children, as part of our services.
7. Client vetting and use cases we refuse
We seek to understand who our clients are and what they will do with the data before we begin. We decline projects intended to:
- Profile, track or monitor identifiable individuals.
- Harass, intimidate or discriminate against any person or group.
- Circumvent security measures or gain unauthorised access to systems.
- Facilitate fraud, spam, counterfeiting or any other unlawful activity.
- Reproduce and republish a source's content in a way that substitutes for the source itself, without the right to do so.
We may suspend or end a project if we later learn that data is being used in any of these ways.
8. Security and retention
Delivered data is transferred only to agreed destinations, with access limited to named users. Collected data is retained only for as long as the Statement of Work requires and is deleted on request or at the end of the agreed period, subject to legal obligations.
9. Contact and takedown
If you operate a website and have concerns about our collection activity, or if you believe information about you has been collected in one of our projects, please contact us at info@dataondemand.net with the subject line "Responsible data". Include the website or data concerned and, if relevant, how we can verify your request. We will acknowledge your message promptly, investigate, and where appropriate reduce or stop collection, remove the data or coordinate with the relevant client.
10. Review
We review this policy and the controls behind it periodically, and whenever laws or our services change materially. Long-running projects are reviewed in case sources, terms or legal requirements have changed.
