Arhimede.
← All articles

What happens to your customers data when you add an AI assistant

September 9, 2026

The question comes up in almost every conversation, sometimes right at the end and half under the breath: “Fine, but where does our customers’ data end up?”. It is the best question a business owner can ask, and it is a pity it gets asked last.

The short answer: the data stays yours, and a vendor who cannot explain in plain words who is responsible for it does not deserve your signature. Here is the long version.

Which data an assistant actually touches

Usually far less than people imagine. An assistant answering customers in a shop needs the catalogue, stock levels, delivery terms and the current conversation. It does not need your full customer database, your accounting or your contract archive.

The rule we work by: the agent gets the minimum access it needs to do the job, not the maximum access we could configure. If somebody proposes “let’s connect everything and see later what we use”, say no.

Who is legally responsible

To the customer, you are: you are the data controller. The vendor processing data on your behalf is the processor, and that relationship goes on paper, not on trust.

We work under Law 195/2024: we sign a data processing agreement with you, notify incidents within 72 hours and delete data on request. If a vendor does not offer such an agreement on their own initiative, that is the first thing to question.

Where the requests to the model go

This is the most common confusion. People assume that if the bot uses an AI model, everything customers write “goes into ChatGPT” and stays there forever.

Requests go through the API, and in that mode model providers do not use them for training. Our infrastructure sits in the EU, at Hetzner in Germany, with role-based access. That is not a marketing promise but a configuration you can verify and write into the contract.

What a bot must never do

An assistant does not make decisions with legal effects for the customer. A refused booking, a rejected return, a credit decision — all of it passes through an employee who confirms it. The bot prepares, the human signs.

That is not only legal caution but commercial common sense: the decision that upsets a customer should be made by someone who can also explain it.

What the customer has to see

Customers have the right to know they are talking to an AI assistant and to ask for a human at any point. A bot pretending to be a live operator buys ten minutes and loses the customer for good when the truth surfaces — and it always surfaces.

Transparency does not hurt conversion. People are fine with a bot that answers well and is honest about what it is.

The questions to ask any vendor

Use this list with us and with anyone else:

  • Do you sign a data processing agreement, and within what deadline do you report an incident?
  • Which systems does the solution ask access to, and why each one?
  • Where is the data hosted and who on your team can reach it?
  • Are requests to the AI model used to train it?
  • What happens to the data when we terminate, and how quickly?
  • Which decisions does the bot make alone and which must reach a human?

If the answers come back vague or late, the problem is not the questions.

The right order of steps

Security is not added at the end as a chapter in the proposal. It is decided at the start, when you choose which process to automate and which data to hand the agent. A well-chosen process needs little data, and most of the worry falls away on its own.

If you want to work through which data an assistant would touch in your case and where the limits are, we run a free process audit: 30 minutes online. And if you already work with someone, take the list of questions above and put it to them.

We’ll call you back

Leave your number. I’ll call at a time that suits you and we’ll map out your task in 15 minutes.