Before adopting any AI tool for your business, ask the vendor four questions up front: does your input get used to train their models by default, where is your data stored and processed, can you have it deleted on request, and will they sign a data processing agreement — a vendor that can't answer all four clearly is a privacy risk, not just a formality.
What questions should you ask an AI vendor before rolling out a new tool?
Every AI tool you connect to your business touches data in some way — a chat prompt, an uploaded document, a customer record synced through an integration. Before signing up or upgrading a plan, get clear answers to a short set of questions. Ask the vendor:
- Does my data train your models by default, and can I opt out? Many free and consumer tiers use conversations for training unless you turn this off manually.
- Where is data stored and processed geographically? This determines which data protection laws apply to it.
- Can I request deletion of my data, and how long does that take?
- Is there a data processing agreement (DPA) I can sign? No DPA generally means no enforceable privacy commitment.
- Who at your company can access raw conversation logs, and under what circumstances?
What does 'prompt leakage' actually mean?
Prompt leakage means sensitive information typed into an AI chat box can end up stored in logs, reviewed by a human trainer, or — in poorly built systems — surfaced to a different user entirely; the safest mental model is to treat any AI chat box like an email you can't fully unsend. Once you press enter, that text usually leaves your control the same way an email does the moment it's sent: it may be retained on a server you don't manage, seen by people outside your team, or used to improve a system you have no visibility into.
What's the real difference between a consumer AI tool and an enterprise-grade one?
The interface can look identical — same chat box, same layout — but the privacy terms underneath are usually very different.
| Consumer / free tier | Enterprise-grade | |
|---|---|---|
| Trains on your data by default | Often yes, unless manually disabled | Usually no, contractually excluded |
| Data retention | Set by the vendor, rarely adjustable | Configurable, often with a defined deletion window |
| Contract in place | A clickwrap terms-of-service page | A signed DPA / enterprise agreement |
| Admin controls & audit logs | Rare or none | Standard — who accessed what, and when |
| Support if something goes wrong | Community forum or none | A named account team and SLA |
What's a simple rule of thumb for what employees can paste into an AI tool?
One rule worth printing and pinning up
Never paste customer personal information, financial data, or trade secrets into a general-purpose AI tool until you've confirmed its data policy in writing. If a task genuinely needs that information, use only a tool your business has vetted — ideally with an enterprise agreement and a signed DPA — not whichever AI chat window happens to be open.
How do you turn this into a policy your team will actually follow?
- List the AI tools your team is already using — official or not — and check each one's privacy terms.
- Write a one-page rule stating which data categories are off-limits in unvetted tools.
- Get a signed DPA for any tool that will regularly touch customer or financial data.
- Turn off model training on your account settings wherever that toggle exists.
- Revisit the list every time someone asks to add a new AI tool — not once a year.
Frequently asked questions
Does ChatGPT or other AI chatbots use my data to train their models?
It depends on the tier and account type. Many free, consumer-facing plans use conversations to improve their models unless you manually opt out in settings; business and enterprise plans typically exclude training by default and state this in a signed agreement. Always check the specific plan's data policy rather than assuming.
What is a data processing agreement (DPA) and do I need one?
A DPA is a legal contract that spells out how a vendor may use, store, and protect the data you share with it, including deletion timelines and any sub-processors involved. If an AI tool will regularly touch customer, employee, or financial data, you need a signed DPA — a general terms-of-service page is not a substitute.
Is it safe to paste customer information into ChatGPT or similar tools?
Not without confirming the tool's data policy first. Treat pasting sensitive information into a general-purpose AI chat box the same way you'd treat sending it in an email you can't unsend — assume it may be logged, reviewed, or retained, and only do it in a tool your business has specifically vetted for that purpose.
What's the difference between a free AI tool and a paid enterprise plan for privacy?
Free and consumer plans usually default to using your data for model training, offer limited or no admin controls, and run on standard terms of service. Enterprise plans typically exclude training by default, offer configurable data retention and deletion, and are backed by a signed data processing agreement with real accountability.