While the company debates whether to use AI, someone is already asking it to summarise a contract.
They have work to finish. The tool is helpful. The privacy settings are three menus deep. You can see how this goes.
Our advice: ask what people use, approve a company account, and make the rules easy to follow. Make it easy to report mistakes, too. You want to hear “I pasted the wrong file” while you can still do something about it.
48%
of employees surveyed had uploaded sensitive company information to public AI tools.
And that’s just “surveyed” employees... The reality is much darker.
Follow the document, not the logo.
“We use ChatGPT” tells us very little. Whose account? Which plan? Connected to what?
Reading a file to answer your prompt isn’t the same as training on it. Training reuses that content to improve future models. Your account determines whether that’s allowed, who else can read the file, and how long it stays. Pick your setup below.
A free personal AI app
ChatGPT Free, Claude Free, the Gemini app, Meta AI, Grok, DeepSeek, Perplexity
Fine for public information, brainstorming and rewriting a job advert. Keep confidential company data out.
Where the document goes
Personal sign-in
The employee uploads the file.
Provider servers
Consumer terms apply.
Assume training is on
Your chats can become training material.
A paid subscription isn’t a privacy policy.
A personal upgrade buys more AI. It doesn’t put your company in charge of the account.
We recommend a business workspace with training off by default and an admin who can remove access when someone leaves. A work email address alone doesn’t make an account company-managed. Neither does a receipt on an expense claim.
Use your company’s Team or Enterprise workspace. Enterprise adds custom retention and audit controls.
Delete is a button. Not a time machine.
Training, storage and sharing are separate things. Turning off one doesn’t turn off the others.
“I turned off training.”
Good. Your ChatGPT history is still stored. And submitting a thumbs-up or thumbs-down can make the associated conversation available for training. Skip feedback on sensitive chats.
“I deleted the chat.”
Deletion takes time. It doesn’t recall a copy someone saved or undo training already started. A legal hold can also keep data past the usual deletion deadline.
“It’s only a share link.”
Anyone with a ChatGPT share link can read it. Treat the share button like sending the conversation outside the company.
“The business plan stores nothing.”
Business chats still have a history. Even the OpenAI API keeps safety logs for up to 30 days by default. Get a deletion deadline for chats, files and logs before uploading sensitive documents.
Different products, different clocks. “Temporary” describes the chat experience, not instant erasure.
Change these settings before uploading.
Start with training controls. Then check what your AI tools can connect to.
On a personal account
Switch off training if you use the account for work. Move company documents to the approved work account; the toggle alone doesn’t give your employer control.
ChatGPT: Improve the model for everyone
Profile icon
Settings
Data Controls
Improve the model for everyone: off
Change thisSwitch it off. New chats will no longer be used to train the model.
Keep in mindYour chat history stays. Avoid thumbs-up/down feedback on sensitive chats: it can share the whole conversation for training. Codex has a separate training switch.
Change thisSwitch it off to stop your new chats and coding sessions being used for model training.
Keep in mindIt won’t undo training already started. Chats flagged for safety review and conversations you submit as feedback can still be used.
The AI you didn’t buy separately.
It’s in your meetings, inbox, CRM and browser. Include those tools in the conversation.
01
Meeting bots
Approve the bot, tell the guests, and choose who gets the transcript. Check recurring invites when someone leaves. Your calendar should not run the offboarding process.
02
Connected apps
“Allow access” can give an app a lasting key to mail, files or customer records. Require approval in Microsoft 365 or Google Workspace, and revoke old connections.
03
Files and browser extensions
Clean up folders shared with everyone before an assistant makes them easier to search. Review extensions that can read page contents: the AI provider’s privacy promise doesn’t cover a separate app watching your browser.
Check individual tools: Zoom, Slack, HubSpot, Notion and more
Know which apps have access and how to cut them off.
The paperwork still matters.
An AI subscription doesn’t cancel your existing responsibilities to customers, staff or patients.
01
Get the right contract.
For UK personal data, a vendor acting as your processor needs a data processing contract. For US health information covered by HIPAA, check whether a business associate agreement is required before sharing it.
02
Teach the team. Check sensitive uses.
Show people the approved tools and their limits. The EU’s AI literacy guidance is a useful starting point. Get specialist advice before using AI for decisions about hiring, credit or health.
03
Read beyond the badge.
SOC 2 and ISO certifications help you assess a vendor’s controls. They don’t tell you which settings your account uses. Ask for the scope, the contract and the actual configuration.
A policy your team might actually read.
Name the owner. Name the tools. Say what stays out. Give people somewhere to ask.
Fill in the details below, adjust the rules to your business, and share them with the team. A policy works better in a conversation than in a folder called “Final_v7”.
AI use policy for Our company
Owner: to be named. Adopted: the date you copy or print it. Review: every six months.
Approved tools: Microsoft 365 Copilot Chat (work sign-in).
One person owns this. A named person is accountable for how we use AI. Questions and problems go to them.
Approved tools, work accounts. We use the approved tools through our company-managed accounts. Signing up with a work email is not enough. Personal accounts are not for confidential company information.
Things that never go into an unapproved tool. Customer and staff personal details, health or card data, financials, contracts, source code, passwords, and anything under a non-disclosure agreement.
Check before you rely. AI output is a draft. A person checks facts, numbers and anything that goes to a customer, a regulator or a court.
Meetings. Only approved note-takers may join our meetings. Guests are told when a meeting is recorded, and transcripts are not sent automatically to people outside the company.
Connections. Nobody connects an AI app to company email, calendars, files or the CRM without the owner’s approval.
Tell people when it matters. Customers are told when they are dealing with AI. A person approves AI-generated advice, decisions and documents before they reach a customer.
Vendors. The owner approves new AI tools after checking no-training terms, retention, access and deletion. Vendors handling personal data must have an appropriate data processing agreement.
Leavers and mistakes. When someone leaves, their AI accounts, app connections and recurring invites are removed the same day. If something is pasted by mistake, tell the owner; nobody is blamed for reporting.
Training and review. Everyone gets a short session on this policy when they join and once a year. The policy is reviewed every six months as tools and laws change.
Run a 20-minute introduction with your team
Why we have a policy: what happens to a document in a personal AI account (five minutes).
Our approved tools, and how to sign in with the work account (five minutes).
The never-paste list, with three real examples from our own work (five minutes).
Meeting bots, app connections and share links: what to do and what to ask (five minutes).
Use examples from their actual work. Leave time for questions and keep a note of who attended.
Put your AI vendor on the spot. Us included.
“We take security seriously” is a sentence, not an answer. Ask these five questions and get the answers in writing.
01Who gets our data, and can they train on it?
What to look for
The names of every company receiving your prompts and files, plus a written no-training commitment covering both the vendor and its model providers.
Our answer
We build in your cloud account or on your hardware. We use business services that exclude model training and show you which providers handle your data.
02Where does it live, and who can open it?
What to look for
The storage and processing regions, the staff roles that can open your files, and a record of every access. “Secure cloud” is not a location.
Our answer
In your account, in the region we agree with you. We keep client workflow data out of Hexaa systems. You approve our access, know who has it, and can inspect the logs.
03How long do you keep our files and prompts?
What to look for
An actual deadline for each copy: uploaded files, prompts, logs and backups. If a provider keeps nothing, ask whether that includes the app’s own database.
Our answer
We agree deletion periods for files, logs and backups before launch. We remove details the model doesn’t need, and enable zero retention where supported. You can inspect the configuration in your account.
04What do we actually own?
What to look for
You own your inputs and outputs. The contract also says who owns the custom software, who else processes data, and what you receive if you leave.
Our answer
A few last questions.
Is AI secure enough for confidential company documents?
Yes, when you use a company-managed workspace with training off and approve the kinds of documents allowed there. We recommend your own cloud account for custom workflows that need tighter control over access and storage. A personal account is the wrong home for confidential files.
Does paying for ChatGPT Plus or Claude Pro make it private?
No. You’re paying for more capability. Training is on unless you turn it off, and the employee still controls the account. Buy a company plan for confidential work and turn off training on personal accounts too.
Are our employees already putting company data into AI tools?
Work on the assumption that they are. Ask which tools they use and what they paste in. Make it a practical conversation, not a confession. People are much more useful to you when they aren’t trying to avoid a telling-off.
Should we just ban AI at work?
No. Give people approved tools and clear limits. A blanket ban with no useful alternative encourages people to hide what they use. Block specific risky tools, and give the team a workable replacement.
If we delete a chat, is the data gone?
Not immediately. ChatGPT normally schedules deleted chats for removal within 30 days. Gemini can keep human-reviewed chats for up to three years. Deleting a chat also won’t recall copies someone saved or undo training already started.
Can the AI leak our data to a competitor?
Yes, confidential data can leak through an AI service. Uploading a file does not instantly teach it to every other user, but training can make a model memorise information. Shared links, software bugs and connected apps are also routes out. Keep training off, share less, and limit what the assistant can access.
The terminology, translated
Training
Using examples to change what a model has learned. Reading a file to answer your prompt is processing; reusing it to improve a future model is training.
No by default on the major paid business APIs. Get the app vendor’s own no-training promise in writing too.
The same models inside your own cloud account
Azure OpenAI in Microsoft Foundry, Amazon Bedrock, Google Cloud
Use models through your company’s cloud account. We recommend this for custom document workflows: your team controls access, storage and the application.
No external training when the workflow stays local. Disable cloud features and outside connections to keep it that way.
Our recommendation: a company-managed plan for everyday work. Use your own cloud account when you need control over storage, permissions and the workflow. Keep it on your own hardware when the data must stay inside your network.
Sign in with your work account and look for the enterprise data protection shield. A personal sign-in doesn’t qualify.
Check what you already pay for.Microsoft 365 and Google Workspace include AI with business data protection on eligible plans. Ask your admin which tools are included and get access before paying for another subscription.
Microsoft Copilot (personal account): Training on conversation activity
Profile icon
Privacy
Training on conversation activity: off
Change thisThe current Copilot app already excludes prompts, answers and files from foundation-model training. Switch this off if you still use the older app.
Keep in mindThis is a personal account. Your employer cannot remove its chat history or manage it when you leave. Use your work sign-in for company files.
Prioritise work sign-ins, approval for connected apps, and meeting recording rules. Then review existing access. Closing the front door doesn’t collect the spare keys.
Microsoft 365 administrators: Stop personal Microsoft accounts on work devices
Microsoft Entra admin center
Tenant restrictions v2
Block personal Microsoft account sign-in
Change thisBlock personal Microsoft sign-ins on your managed work devices and network. Have IT deploy tenant restrictions v2.
Keep in mindThis is a device and network control. It does not stop someone using a personal phone on home Wi-Fi.
Extracted document content cached for up to 12 hours; saved files are separate
Approve it for the document types your team handles. Delete saved cloud files when you no longer need them.
“No training” doesn’t mean “no storage”. Where only the model provider keeps nothing, the app can still save your chats, files or recordings.
Your inputs, outputs and the custom work we build for you belong to you. We put that in the contract, sign an NDA before receiving confidential files, and agree the data processing terms.
05Can we check the setup and take our data with us?
What to look for
A demonstration: show the settings, open the access log, export a file and explain how to disconnect the vendor. A promise on a slide is cheaper.
Our answer
You own the account and keys. You can read the settings and access logs, audit us, and remove our access without losing your data. Hexaa is ISO 27001:2022 certified.
Bring us your awkward questions.
Looking at document automation? Bring your IT lead and a workflow. We’ll walk through where the data goes and who controls it.
How long a company keeps your data after you send it, including after you press delete.
Zero data retention
An agreement that the model service won’t keep prompts and answers after processing. Confirm the covered features: your app’s saved files and logs need separate deletion rules.
Abuse monitoring
Automated checks, and sometimes human checks, that a provider runs on prompts to catch misuse. This is why "no training" does not mean "nobody can read it".
Human review
A provider employee or contractor reading a sampled chat or one flagged for review.
Consumer terms
The agreement an individual accepts when signing up for a free or personal plan. Your company is not a party to it.
Business terms
The agreement your company signs for a work plan or an API. Insist on a no-training promise and terms covering how your data is handled.
Data processing agreement
The contract that sets out how a vendor handles personal data for your company, including security, deletion and the other companies it uses.
Sub-processor
A company your vendor uses behind the scenes, such as the model maker. Your contract should name them.
Tenant
Your company’s own space inside a cloud service such as Microsoft 365 or Google Workspace, with its own administrators and rules.
Region (data residency)
Where data is stored or processed. Ask about both: choosing a storage region doesn’t automatically keep every processing step there.
API
The way one piece of software talks to another. When a vendor "uses the API", its product sends your text to the model maker and gets an answer back.
Connector
A link between an AI app and your email, files, calendar or CRM, so the AI can read them. Granted by clicking "allow" on a permissions screen.
OAuth consent
The “allow this app to access your account” screen. That permission can keep working until someone revokes it, long after you close the app.
Share link
A web address that gives other people access to a chat. With a personal ChatGPT share link, anyone who has it can read the conversation.
Temporary chat
A chat that is not saved to your history. Providers still keep it for days or weeks for safety checks.
Memory
A feature where the AI remembers details from earlier chats and uses them later.
Agent
An AI that can take actions, such as sending emails, editing files or running commands, rather than only answering.
Prompt injection
Hidden instructions inside an email, document or web page that an AI reads and follows as if they came from you.
Open-weight model
A model whose files you can download and run on your own computers, such as Llama, Gemma or Mistral.
On-premises
Running software on servers in your own building rather than in someone else’s cloud.
Shadow AI
AI tools staff use for work without the company knowing or approving.
Single sign-on
Using one company login across your work tools. It makes access easier to manage; leavers still need their app connections and sessions revoked.
Audit log
A record of who did what and when inside a system, which administrators can search.
SOC 2
An independent audit report on a vendor’s controls. Read which systems it covers and any exceptions. The badge alone doesn’t tell you how your account is configured.
ISO 27001
A certificate that a company runs a managed information security programme.
ISO 42001
A certificate that a company runs a managed programme for responsible AI.
HIPAA business associate agreement
A contract for a vendor handling protected health information on behalf of a US healthcare organisation covered by HIPAA.
Yes on ChatGPT, Claude and Gemini unless you opt out. Paying for Plus or Pro doesn’t switch training off.
People you share with, authorised admins through the plan’s audit tools, and provider staff for limited support or safety checks. No training does not mean nobody can read it.
Your authorised team. Cloud-provider safety review is a separate permission; on Azure, removing human review requires approved modified abuse monitoring.
Some Bedrock models keep prompts for up to 30 days for safety checks. Your application’s files and backups stay until you delete them. Set deadlines for those too.
Your own cloud account (Azure): Verify approval to disable human-review storage
Azure portal
Your subscription
The Foundry resource
Overview
JSON View
Capabilities: ContentLogging
Change thisAsk Microsoft for modified abuse monitoring. After approval, confirm ContentLogging is false: Azure is no longer saving your prompts for human review.
Keep in mindThis is an approval process, not a switch anyone can flip. Automated safety checks still run. Turn off prompt logging in your own application too.