Give the team company accounts on a business AI plan that doesn't train on your data, write down which customer data may go into it, and teach one redaction habit for everything else. Switch off features you don't need, such as third-party apps and public share links, then check every quarter that staff actually use the approved accounts.
Most leaks aren't hacks. They're a well-meaning employee pasting a complaint thread, complete with the customer's phone number and door code, into a free chatbot on their own phone to get help with a reply. So the aim is to make the safe route the easy one: an approved tool that's quicker to open than the free one, and rules short enough to remember at 4.45 on a Friday.
Step 1: Find where customer data meets AI in your business
Start with a list, not a policy. For an illustrative 26-person courier firm, customer data turns up in more places than the owner expected:
- The shared inbox: names, addresses, phone numbers, complaint details.
- Delivery job notes: "key safe code 4471", "dog in garden", "leave with neighbour at 12".
- Proof-of-delivery records: signatures and doorstep photos, sometimes showing house numbers and cars.
- Account customers' spreadsheets: recipient lists for regular contract deliveries.
- Call recordings and voicemails in the phone system.
- Software with built-in AI: the help desk's reply suggestions, the phone system's transcripts.
Other businesses find their hot spots elsewhere. An import-export business's riskiest documents are customers' shipping paperwork, which can carry company registration and tax identification numbers and the names of individual consignees. A laboratory's are client results that haven't been released yet, sometimes with the sampling site named. A wholesaler's are trade account files holding credit limits, directors' names and bank details. Write your own list before choosing any tool.
Then ask staff, anonymously, what AI they already use. Three questions are enough: "Which AI tools have you used for work in the last month?", "What did you use them for?" and "Have you ever pasted in a customer's details?" The courier firm's answers: seven people used free chatbots, two had pasted in complaint emails, and one controller used a browser extension that summarised every web page he opened, including the customer portal. None of them had done anything they thought was wrong. Stopping staff pasting client data into free tools covers this "shadow AI" problem in more depth.
Step 2: Sort the data into three classes
Staff won't read a data-classification document, but they will remember three colours. Here's the courier firm's filled-in version:
| Class | Examples in this business | Rule for AI |
|---|---|---|
| Green: no customer data | Rate cards, blank templates, route planning principles, marketing copy | Any approved tool |
| Amber: ordinary customer data | Names, business addresses, order and tracking numbers, complaint text | Company AI account only; remove what the task doesn't need |
| Red: sensitive or risky | Door and key-safe codes, "house empty until the 20th", ID documents, payment details, anything about health | Never into a chat assistant; handle in the core system only |
Red is where a courier's real risk sits. A door code in a chat log is a burglary risk, not just a privacy one. Your own red list will differ: a laboratory would add clients' unpublished test results; a wholesaler, customers' credit limits and bank details. Classifying business data before using AI tools goes into more detail on building the classes.
Step 3: Move everyone onto company accounts
Personal accounts are the root of most problems: the company can't see them, can't set their privacy options and loses the history when the person leaves. Business plans fix that. ChatGPT Business, Claude Team, Microsoft 365 Copilot and Gemini in Google Workspace don't train on business content by default, and they give you an admin console to add and remove people.
The courier firm gave seats to the nine people who handle customer correspondence (controllers, office and accounts), not the drivers. On ChatGPT Business Standard at $20 a user a month on annual billing, that's $180 a month; on monthly billing, $225. Claude Team is priced the same way. Both plans need at least two seats, so a sole trader either pays for two (about $40-$50 a month) or uses a personal plan with the model-training switch in privacy settings turned off. If you're already on Microsoft 365 or Google Workspace business plans, check what's included before buying anything: Copilot Chat comes with Microsoft 365 business plans, and Gemini is built into Workspace plans. Setting up company AI accounts instead of personal logins walks through the switch.
Make the approved tool easy to reach: pin it in the browser, add it to phones, and put the login in the password manager. If the free app is one tap away and the company one needs a hunt for a password, people will use the free one.
Step 4: Switch off what you don't need
Business plans ship with features that widen what the AI can reach. Go through the admin settings once, and write down what you chose:
- Connected apps. ChatGPT's connected apps (formerly called connectors) and similar integrations in other tools let the assistant read email, drives and calendars. Enable only the ones with a clear use, for the people who need them.
- Public share links. Turn off or restrict sharing of chats outside the company, so a conversation containing customer details can't be forwarded as a link.
- Memory. Features that remember details across chats can carry a customer's information into unrelated conversations. Consider switching memory off for shared or customer-facing roles.
- Browser extensions and third-party add-ons. Block or review extensions that read every page, like the one the courier firm's controller had installed.
- Retention. Check how long chats and uploaded files are kept and whether you can shorten it on your plan.
Write the choices down where the next person can find them. The courier firm's record was a five-row table in the shared drive:
| Setting | Choice | Why |
|---|---|---|
| Connected apps | Shared drive only, office manager and accounts | Nobody else needs the assistant reading files |
| Email connection | Off | Drafts are pasted in, so the tool never sees the whole inbox |
| External share links | Off | No reason to share chats outside the company |
| Memory | Off for controllers | They handle many customers a day |
| AI browser extensions | Blocked unless approved | One had been reading the customer portal |
Setting names change often, so work from the vendor's current admin documentation rather than an old screenshot. For a one-off amber task on ChatGPT, Temporary Chat keeps the conversation out of history and memory, though OpenAI still retains it for up to 30 days.
Step 5: Teach one redaction habit
Even in a company account, send only what the task needs. The habit to teach: replace identifying details with labels before pasting, and put them back afterwards. Before:
"Help me reply to this. From: (customer's full name), 14 Elm Road, (mobile number). She says our driver left her parcel by the bins even though the note said key safe 4471 and she's furious, she's disabled and can't get to the bins."
After:
"Help me reply to this complaint. [CUSTOMER] says our driver left her parcel by the bins instead of using the agreed secure location in the delivery notes. She's upset and says she can't easily reach that spot. We've spoken to the driver. Draft an apology offering a free redelivery tomorrow morning."
The draft reply is just as good, and nothing red or unnecessary left the building: no name, address, phone number, key-safe code or health detail. It takes about 30 seconds. For longer documents, a redaction prompt inside the company account can do the first pass:
Replace every person's name with [PERSON1], [PERSON2]..., every address
with [ADDRESS], every phone number and email with [CONTACT], and any
access code or security detail with [REMOVED]. Return the text only.
Then list what you replaced, so I can check nothing was missed.
The list at the end is the check. In an illustrative test, the model missed a phone number written as words ("oh seven seven...") and a door code described as "the usual four digits, 4-4-7-1". Automated redaction is a first pass, not a guarantee. Anonymising client data before you paste it into AI has more techniques, including consistent placeholders for longer threads.
Step 6: Lock down automations and connected apps
Automations move customer data without anyone pasting it, so they need the same thought. Three rules cover most cases:
- Send only the fields the AI step needs. A Zapier or Make step that classifies an email needs the subject and body text, not the whole thread with signatures and attachments. The courier firm cut its triage automation's input from full emails to the first 1,500 characters of the body, which also made it cheaper.
- Use the business API, not a consumer account. OpenAI's API doesn't use your data for training by default, and Anthropic's commercial terms work similarly. Check retention: Anthropic keeps prompts and outputs for 30 days on its most capable "covered" models even for customers who normally have zero retention, with an application route back to zero retention added in September 2026.
- Least access for connected accounts. Connect automations with an account that can see only what the automation needs, not the owner's login that can see everything.
A realistic automation mistake, and how it showed up: the courier firm's enquiry automation asked the AI step to "summarise the email" and saved the summary as a CRM note. Two weeks later the office manager noticed a note reading "Customer asks us to use key safe 4471 for future deliveries." The summary had faithfully kept the one detail that should never sit in a CRM note visible to every user. The fix was one instruction in the prompt ("never include access codes, security details or health information; write [REMOVED] instead") and a search of existing notes for four-digit numbers near the words "code" or "safe".
For every AI vendor that touches customer data, keep its data processing agreement on file and read the parts that matter: what it does with your data, where, for how long and with which subcontractors. What to check in an AI vendor's data processing agreement lists the clauses.
Step 7: Put the rules on one page and get them signed
Short beats complete. The courier firm's version fitted on one side:
Using AI with customer information. 1. Use only the company ChatGPT account for work involving customers. Free or personal AI apps are for green information only. 2. Green (no customer data): any approved tool. Amber (names, addresses, tracking numbers, complaints): company account only, and remove anything the task doesn't need. Red (door and key-safe codes, "away until" details, ID, payment details, health information): never into any AI chat. 3. Replace names and contact details with labels before pasting. 4. Don't install AI browser extensions or apps without asking the office manager. 5. Check every AI draft before it goes to a customer. 6. If you think customer information has gone somewhere it shouldn't, tell the office manager the same day. You won't be in trouble for reporting it.
Point 6 matters most. People hide mistakes they expect to be punished for, and a hidden mistake can't be contained. Read the page through with each team, answer questions, and have everyone sign it. For a fuller document, writing an AI usage policy builds on this.
Step 8: Check it's working every quarter
A 30-minute quarterly check keeps the setup honest:
- Seats against staff: compare the admin console's user list with your current staff list. Anyone who has left should already be removed; if not, fix the leaver process.
- Usage: if nobody on a seat has used it in weeks, ask why. Often the answer is "the free one's easier", which tells you what to fix. Microsoft 365's admin centre has a Copilot usage report for this; other business plans have similar admin views.
- A spot check: with staff aware that it happens, look at a handful of recent chats in shared projects for red data.
- Extensions and apps: review which AI add-ons and connected apps are active.
- Vendor changes: skim your main vendors' update notes. Defaults do change: one clinical note-taking vendor switched new users to keeping de-identified transcripts by default in June 2026, and an AI calendar tool that shut down in March 2026 deleted user data rather than transferring it.
At the courier firm, the first quarterly check found two things: a former controller still had an active seat, and the help desk's own AI reply feature had been switched on in an update, sending ticket text to the vendor's model under terms nobody had read. Both took ten minutes to deal with once someone looked.
If customer data has already gone into the wrong tool
It happens. Handle it calmly and quickly:
- Find out what went where: which tool, which account, what data, when.
- Delete the chat or file in that tool, and note that deletion may not be immediate on the vendor's side; check its retention terms.
- Assess the risk: a tracking number is minor; a door code or ID document may put someone at risk, and the customer may need to change a code or be told.
- Record it in a simple incident log: date, what happened, what you did. An illustrative entry: "12 Sept. Controller pasted a complaint email including the customer's mobile number into a personal free chatbot. Chat deleted same day; vendor retention checked; no red data involved; customer not at risk. Cause: company login not saved on the controller's phone. Fixed: login added to the password manager app."
- Get advice from your data-protection adviser if the data was sensitive or the incident might need reporting under data-protection law such as the GDPR. Some breaches have short reporting deadlines, so don't wait.
- Fix the cause: usually a tool that's too hard to reach, or a rule nobody understood.
For the courier firm, the whole programme took the office manager about a day to set up, plus $180 a month in seats that replaced a patchwork of personal subscriptions two people had been expensing. The result isn't perfect privacy; it's a setup where the easy way to use AI is also the safe one, and where a mistake gets reported and fixed the same day.
Customer data and AI: follow-up questions
Is ChatGPT Plus private enough for customer data?
Plus is a personal plan. You can switch off the model-training setting, but the account belongs to the individual, not the company, so you can't manage access, see usage or keep the history when someone leaves. For customer data, a business plan such as ChatGPT Business or Claude Team is the better fit: no training on your content by default and admin control, at about $25 a seat on monthly billing with a two-seat minimum.
Do we need customers' consent before using AI on their data?
Not always, but you do need a lawful reason and honest information for customers. Under data-protection law such as the GDPR, using an AI tool as a service provider to help reply to a customer usually fits the same basis as handling their enquiry at all, provided the vendor has a proper data processing agreement. Update your privacy notice to mention AI tools, and ask your data-protection adviser about anything unusual.
What about AI features inside software we already use?
Treat them like any other AI tool. Help desks, CRMs, accounting packages and phone systems increasingly switch AI features on by default, and some can't be turned off individually. Check what data each feature sends, whether the vendor uses it for training, and what the admin settings allow. Record the answers in the same register as your chat assistants, and recheck after major product updates.
Further reads
- Is It Safe to Put Customer Data Into ChatGPT? — The short answer for ChatGPT specifically, plan by plan.
- How to Stop AI Tools Training on Your Business Data — Where the training switches are in each major tool.
- Staff Offboarding Checklist for AI Tools and Shared Accounts — Close AI accounts properly when someone leaves.
- ChatGPT Temporary Chat: When Your Staff Should Use It — When Temporary Chat helps and when it doesn't.
- How to Redact Personal Data From Documents With AI Before Sharing — Redact whole documents before sharing them, not just prompts.
- Where Is Your Data Stored When You Use AI Tools? — Where your prompts and files end up, and for how long.
- GDPR and AI Tools: What a Small Business Must Do — The data-protection duties behind these steps.
- How to Clean Up Customer Records Before You Add AI — Four clean-up passes that stop AI emailing people twice, or at all when they said no, with matching rules and a merge log.
- What Business Data Should You Start Collecting Now for AI? — Seven datasets worth capturing from today (enquiries, quotes, job actuals, questions, complaints, prices, feedback), with the fields that make them usable.
- How Dog Groomers Can Use AI to Collect Pet Details Before Booking — Collect breed, coat condition, temperament and health details before the booking, and let AI turn them into a pet card and suggested slot you approve.
- How Spas Use AI to Personalise Offers From Treatment History — Six treatment-history patterns worth their own offer, the prompts to write them, where personal turns creepy, and a holdout test to prove it worked.
- How Personal Trainers Can Use ChatGPT Safely for Client Programmes — What to type and what to leave out, a prompt that builds in each client's limits, a five-minute check before sending, and where ChatGPT must stop.
- How to Answer Etsy Customer Messages Faster With AI — Quick replies for the repeat questions, AI drafts for the rest, and a tone check for the hard ones, so Etsy messages get answered well inside 24 hours.
- How Dry Cleaners and Laundries Use AI for Orders and Collections — Where AI fits between the counter and collection: phone agents that book pickups, ready texts, an uncollected-garment ladder and calmer claim replies.
- How to Use Booking Data and AI to Fix Your Class Timetable — Five numbers per class slot, a prompt that finds the patterns, and a six-week test so timetable changes don't cost you regulars.
- Should AI Handle Membership Freezes and Cancellations? — Which freeze and cancellation requests an AI can process alone, where a save offer becomes an obstacle, and the billing check that stops chargebacks.
- How Business Coaches Use AI Without Losing the Personal Touch — Where AI belongs in a coaching practice and where it doesn't, with a client memory file, recap before-and-afters and voice rules.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI and Anthropic business plan pages and help articles (training defaults, retention, admin controls, seat minimums); Microsoft 365 admin centre documentation on the Copilot usage report; vendor privacy settings as summarised in the facts sheet. The courier firm and its figures are illustrative.