Is it safe for AI to work with my customer data?
Lees dit in het Nederlands →$ trace --where-does-my-data-go
Is it safe when AI works with my customer data?
The honest answer has two parts. One: your data stays yours, in accounts under your own name, and that's the most important protection there is. Two: information does pass through third-party cloud services, because that's simply how AI works. Anyone claiming nothing leaves your business is telling you something other than how it actually works. Below is the route your data takes and what's locked down along the way.
This question is often answered with one word: encrypted. That's true, and it says almost nothing. Encryption protects data at rest or in transit; the question you're actually asking is about data being used.
Below is the answer without a reassurance up front. What stays yours, which parties get to see your information, what's locked down and how, where we've deliberately kept something out of the cloud, and which part of this question we simply cannot answer.
01 / the entry pointWhose data is the system actually working with?
Yours. The system is built inside accounts that are in your name: your CRM, your mailboxes, your calendar, your telephony. There's no environment of ours where your customer data moves to and where we hold the key.
That's not a detail, it's the core of the answer. The heaviest security question isn't which lock sits where, but who's standing at the door when the collaboration ends. If everything stays in your name, switching suppliers is an administrative act instead of a hostage situation.
Exactly how that separation works, and what stops when you cancel, is covered in who owns it once it's running.
02 / the routeWhere does my customer data actually go?
Through a chain of cloud services, and you should just know that. An AI system isn't a box in your attic: there's a CRM inside, a layer that strings tasks together, and a language model that produces the actual text. Every link sees something of what passes through.
In our own setup, the three main ones are: a CRM for contacts and conversations, an orchestration layer that ties the steps together, and Anthropic's AI for the thinking work. Around that sit smaller services for things like invoicing, telephony and document generation.
Every link is a party processing your customer information. A provider that can't produce that list doesn't have one.
What you're entitled to ask for here, from us or from anyone: a list of the parties processing your data, where those parties do their processing, and a data processing agreement that puts it in writing. Not as reassurance, but as a document.
03 / the lockdownSo what is actually secured, and how?
Access, and it's more tightly arranged than most people expect. The principle behind it isn't "lock everything down" but: every key does exactly one thing, and the more damage a key could do, the fewer places it's allowed to sit.
Three things we've done in our own environment that you can ask any provider about:
That last point is underrated. Most of the damage AI causes isn't a data leak but a wrong message to the right person. A system that doesn't send by itself, can't do that. Why we're so strict about that is in why we don't publish your posts automatically.
When choosing our own AI supplier, one party was ruled out because it trains on conversation data. That's exactly the kind of question you should ask yourself: is my material used to train a model, or not.
04 / the choiceWhat if something shouldn't go to the cloud?
Then you don't put it there, even if that's less convenient. For us that happened concretely with recorded phone calls: those are processed locally and deliberately don't go through the chain above. A conversation with a lead is more sensitive material than a calendar appointment.
What's interesting is what that costs. There's a proposal to merge that processing with the rest, because it's technically cleaner and saves work. That proposal is still just sitting there, because merging it would mean phone calls leaving the laptop. That trade-off wasn't resolved by waving it away but by writing it down and leaving it open.
That's the most honest example we can give of how a choice like this works. There's no architecture where everything is safe and everywhere convenient at once. There are trade-offs, and the question is whether a supplier names them or hides them.
05 / the limitWhat can we not answer here?
The legal part. Whether your specific situation requires a data processing agreement, who's the processor and who's the controller in that, and exactly what falls under your sector: that's work for a lawyer, and we're not one. We can describe how it's built; we can't determine whether it's legally compliant for you.
There's a second limit. There are things we haven't finished for ourselves yet, and it would be strange to stay silent about that in a piece about honesty. Retention periods per type of data, for instance: how long something stays stored and how deletion works isn't fully written out on our end yet. It should exist, and it's coming.
So the answer to "is it safe" is neither yes nor no. It's: we can tell you exactly where your data sits, who can access it, and what happens if you stop. Unbreakable doesn't exist, and anyone who promises that hasn't understood the question.
Where does my customer data actually go?+
Is it safe to have customer data processed by an AI system?+
Is my data used to train AI models?+
Can everything run locally instead of in the cloud?"+
Do I need to arrange anything around the AI Act?+
Want to know what route your data would actually take?
Schedule a call
We'll look at where your time is leaking and tell you honestly whether we can do anything about it. Often the answer is: you can do this yourself. If so, we'll say that, and you'll have spent thirty minutes getting a clear answer.
This text was produced with AI assistance and checked and approved by a human before publication.