Blog
AI Data Privacy for Small Business: The Questions to Ask Before You Connect Anything
The moment an AI assistant starts answering your phone or reading your inbox, it's handling customer data. Names, numbers, appointment details, sometimes health or financial information. Most privacy advice is written for enterprises with legal departments. Here's the small business version: what actually matters, in checkable questions.
First, know what the assistant can see
Map it in one sitting. An assistant that books appointments sees names, contact details, and calendars. One that reads email sees everything in the inbox. One answering for a clinic may hear health information. The rule: an assistant should have access to exactly what its job requires and nothing more. If a booking bot has access to your accounting system, someone was lazy during setup. This "least access" principle is the single highest-value privacy habit, and it costs nothing.
The seven questions for any AI vendor
- "Is our data used to train your models?" The answer must be no, in writing. Reputable business AI providers offer this by default on business tiers; consumer tiers often don't. This is the sharpest separator of serious vendors from sloppy ones.
- "Where is data stored, and for how long?" You want a named region (relevant for GDPR and similar laws), a retention period, and a deletion path. "In the cloud" is not an answer.
- "Who at your company can see our conversations?" Support staff access should be logged and limited.
- "Can we delete a customer's data on request?" Privacy laws increasingly grant customers this right; your vendor must be able to execute it.
- "What happens if you're breached?" You want a notification commitment with a timeframe.
- "Do you sign data processing agreements?" If you're in a GDPR-style jurisdiction this is mandatory, and a vendor who's never heard of one has never served serious customers.
- "Which subprocessors touch our data?" Every AI product sits on other providers (model APIs, hosting, telephony). You're entitled to the list.
A vendor who answers all seven crisply is probably fine. A vendor who gets vague on question one or two is a walk-away.
Industry-specific lines
Clinics and anyone touching health data need vendors who explicitly support healthcare privacy requirements, not vendors who "should be fine." Same logic for legal and financial practices with professional confidentiality duties (our intake guide covers the boundaries). The good news: compliant options exist in every category now; you just have to ask the questions above instead of assuming.
Keep your own side clean
Two habits close most self-inflicted risks. Tell customers a virtual assistant may handle routine inquiries, in your privacy policy and anywhere honesty demands it; hiding it buys nothing and costs trust when discovered. And when you leave a vendor, actually delete: export what's yours, then invoke the deletion path from question two.
Privacy isn't a reason to avoid AI. It's a filter for choosing who you buy it from. We apply this checklist to every tool we deploy, and walking through it for your stack is part of any free assessment.