"What happens to my data?" is the first question we get from almost every business owner we talk to. And it's the right question to ask — you should understand what you're putting into any AI system before you use it for business purposes.
This post gives you a plain-language explanation of how AI data handling actually works, what the real risks are, and how to protect yourself. It's not legal advice — if you have specific compliance concerns, talk to a lawyer — but it should give you a clear enough picture to make informed decisions.
The key distinction: consumer tools vs. API/enterprise tools
This is the most important thing to understand, and almost nobody explains it clearly. There's a fundamental difference in how your data is handled depending on which version of an AI tool you're using.
Consumer tools (free / low-cost web apps)
When you use ChatGPT.com, Claude.ai (free tier), or similar consumer products, your conversations may be used to improve the AI. The exact policies vary and change over time, but the default for most consumer tools is that your inputs can be reviewed by the company and potentially used for training. Many tools let you opt out — but you have to know to look for that setting.
This doesn't mean your data is being broadcast publicly — it means Anthropic or OpenAI employees might review conversations to improve the model. For most general tasks, this is probably fine. For confidential client information, proprietary business data, or anything sensitive, it's worth being more careful.
API and enterprise tiers
When businesses build automations using the Claude or OpenAI APIs — which is how Waypoint AI builds solutions for clients — the data handling is different and substantially more protective. Both Anthropic and OpenAI have enterprise agreements and API terms that explicitly state your data is not used for training their models. Your inputs and outputs are processed and discarded. There's no human review of your business data.
This is the tier we use for all client work. When we build an automation for your business, your customer data, your documents, and your workflows are processed through the API with no training use, and we can sign data processing agreements to formalise this if needed.
The simple rule: free consumer apps = data may be used for training. API / enterprise tier = data is not used for training. Know which one you're using.
What about PIPEDA and Canadian privacy law?
Canada's federal privacy law (PIPEDA) requires that businesses collecting personal information about Canadians do so with consent and for a clear purpose. If you're using AI to process personal information about your customers — names, contact info, transaction history — PIPEDA applies to how you handle that data, not just how the AI vendor handles it.
Practically, this means: if you're feeding customer personal information into an AI system, you should be satisfied that the AI vendor has appropriate data protection practices, and that this use is consistent with your privacy policy. For enterprise API use with major AI providers, this bar is generally met. For consumer tools, it's less clear-cut.
This isn't meant to scare you — most small businesses using AI for internal workflows (drafting their own communications, processing their own invoices) aren't running into material PIPEDA issues. But if you're processing customer personal data at scale, it's worth a conversation with someone who knows privacy law.
Practical rules of thumb
Here's how we advise clients to think about what goes into AI tools:
Generally fine for consumer AI tools:
- Drafting your own marketing copy, emails, or internal documents
- Asking general business questions or getting advice
- Summarising publicly available information
- Generating ideas or brainstorming
Use API/enterprise tier or be cautious:
- Documents containing client names, contact info, or financial data
- Proprietary business processes, pricing models, or trade secrets
- Employee personal information
- Anything subject to professional confidentiality (legal, medical, accounting)
A word of caution for professionals: If you're a lawyer, accountant, doctor, or other regulated professional, your obligations around client confidentiality may impose additional restrictions on what you can put into AI tools. Check with your professional body if you're unsure.
What we do for clients
When we build automations for businesses, we have a standard set of data protection practices:
- All AI processing uses the Claude API — no consumer tools, no training use of your data
- We can sign a Data Processing Agreement (DPA) if you or your clients require it
- We don't store client data on our own systems beyond what's needed to build and test the solution
- We'll walk you through Anthropic's privacy and security documentation before any project begins
We're not lawyers and we're not a compliance firm, but we take data handling seriously and we're happy to answer questions about how a specific workflow would handle your data.
If you have specific questions about how AI would handle data in your industry or business context, raise them on your free consultation call. We'd rather address those concerns upfront than have you worry about something that's either not a real issue, or is an issue we should be designing around.