The most common way a small business ends up with an AI problem is not a chatbot going wrong on the website. It is somebody pasting something into a chat window because it was faster than doing it by hand.
That is a reasonable instinct and I am not going to tell you not to use these tools. I use them constantly. But it is worth knowing where the text goes, because the moment you press enter it has left your business, and most people have never been told that in plain terms.
What actually happens when you paste something in
Your text is sent over the internet to the provider's servers, processed there, and a reply comes back. It is not happening on your computer. That is true of ChatGPT, Claude, Copilot, Gemini and effectively every general AI tool, whether you reach it through a website, an app, or a feature inside software you already use.
Three things then vary, and they vary by product and by which tier you are on:
- Whether it is kept. Most providers retain conversations for some period, commonly for abuse monitoring, even where they are not used for anything else.
- Whether it trains the model. This is the one that differs most. Consumer tiers have historically been more likely to use your input for training than business and enterprise tiers, and several providers make opting out possible but not the default.
- Whether a human might read it. Providers generally reserve the right to have staff review flagged conversations.
I am deliberately not listing which provider does what here, because those policies change often enough that a printed answer would be wrong within months. The durable advice is to check the terms for the specific tier you are actually on, rather than the one you assume you are on.
If your team uses free consumer accounts for work, you are probably on the most permissive terms the provider offers. Moving to a paid business tier is often the single quickest improvement available, and it is usually a smaller bill than people expect.
The things people paste without thinking
Nobody sets out to leak anything. It happens because the task in front of you is boring and the tool is right there. In practice the recurring ones are:
- A customer's email thread, pasted in to get a reply drafted.
- A CV or application, pasted in to get it summarised.
- A spreadsheet of names, addresses or phone numbers, pasted in to get it tidied up.
- A contract or quote from a supplier, pasted in to get the terms explained.
- An error log or a database extract, pasted in to work out what broke.
Every one of those is a sensible thing to want help with. The first three are also personal data belonging to somebody who did not agree to it being sent anywhere, and the last two frequently carry confidentiality terms you have signed up to.
The problem is not the tool, it is the pasting. The same task usually works fine with the names swapped for placeholders, or the account numbers removed, and you get the same quality of answer back.
Where UK GDPR comes into it
If the text contains personal data, sending it to an AI provider is a processing operation like any other. It does not stop being one because it happened in a chat window rather than a database.
Practically, that means you need a lawful basis for it, you should only be sending what the task actually requires, and your privacy notice should be honest about the fact that an AI provider processes data on your behalf. If the provider is outside the UK, there are transfer considerations too.
I want to be straight about the limits of what I am telling you here. I build systems to meet these requirements and I can tell you what the technical side looks like. I am not qualified to advise on your specific obligations, and if you handle anything sensitive, that conversation belongs with someone who is.
A workable policy for a small team
Long AI policies do not get read. A short one that people can remember does. This is roughly what I suggest, and it fits on a single side:
- Use the business account, not a personal one. One account per person, paid tier, on terms somebody has actually read.
- No customer or staff personal data goes in. Names, addresses, phone numbers, health or financial details. Replace them with placeholders if the task needs the shape of the data.
- Nothing under a confidentiality agreement goes in. Supplier contracts, client documents, anything marked confidential.
- Nothing it writes goes to a customer unread. It drafts, you send.
- If you are unsure, ask before pasting. Make it clear that asking is welcome, because the alternative is people quietly guessing.
That last point does more work than the rest combined. Most bad pastes happen because somebody did not want to look like they were making a fuss over something small.
A five-line policy that everybody follows beats a five-page one nobody opens. Write it, put it where people will see it, and revisit it when you change tools.
The exception worth knowing about
Not every AI setup sends your data to somebody else. Where the sensitivity genuinely warrants it, a system can be built so the data stays on your own machines, or so only the minimum needed for a specific task ever leaves.
That is more work and it is not the right answer for most businesses most of the time, so I would not push you toward it by default. It is worth knowing the option exists, because people often assume the choice is between using AI on the provider's terms or not using it at all.
If you want the shape of this worked out against what your team actually does rather than in the abstract, that is what the AI Setup Package is for. The wider picture sits in my guide to using AI safely in a small business.
