Data & Privacy

Is your business data safe when you use AI tools? Here's what you actually need to know.

May 2024 · 5 min read · By Waypoint AI

"What happens to my data?" is the first question we get from almost every business owner we talk to. And it's the right question to ask — you should understand what you're putting into any AI system before you use it for business purposes.

This post gives you a plain-language explanation of how AI data handling actually works, what the real risks are, and how to protect yourself. It's not legal advice — if you have specific compliance concerns, talk to a lawyer — but it should give you a clear enough picture to make informed decisions.

The key distinction: consumer tools vs. API/enterprise tools

This is the most important thing to understand, and almost nobody explains it clearly. There's a fundamental difference in how your data is handled depending on which version of an AI tool you're using.

Consumer tools (free / low-cost web apps)

When you use ChatGPT.com, Claude.ai (free tier), or similar consumer products, your conversations may be used to improve the AI. The exact policies vary and change over time, but the default for most consumer tools is that your inputs can be reviewed by the company and potentially used for training. Many tools let you opt out — but you have to know to look for that setting.

This doesn't mean your data is being broadcast publicly — it means Anthropic or OpenAI employees might review conversations to improve the model. For most general tasks, this is probably fine. For confidential client information, proprietary business data, or anything sensitive, it's worth being more careful.

API and enterprise tiers

When businesses build automations using the Claude or OpenAI APIs — which is how Waypoint AI builds solutions for clients — the data handling is different and substantially more protective. Both Anthropic and OpenAI have enterprise agreements and API terms that explicitly state your data is not used for training their models. Your inputs and outputs are processed and discarded. There's no human review of your business data.

This is the tier we use for all client work. When we build an automation for your business, your customer data, your documents, and your workflows are processed through the API with no training use, and we can sign data processing agreements to formalise this if needed.

The simple rule: free consumer apps = data may be used for training. API / enterprise tier = data is not used for training. Know which one you're using.

What about PIPEDA and Canadian privacy law?

Canada's federal privacy law (PIPEDA) requires that businesses collecting personal information about Canadians do so with consent and for a clear purpose. If you're using AI to process personal information about your customers — names, contact info, transaction history — PIPEDA applies to how you handle that data, not just how the AI vendor handles it.

Practically, this means: if you're feeding customer personal information into an AI system, you should be satisfied that the AI vendor has appropriate data protection practices, and that this use is consistent with your privacy policy. For enterprise API use with major AI providers, this bar is generally met. For consumer tools, it's less clear-cut.

This isn't meant to scare you — most small businesses using AI for internal workflows (drafting their own communications, processing their own invoices) aren't running into material PIPEDA issues. But if you're processing customer personal data at scale, it's worth a conversation with someone who knows privacy law.

Practical rules of thumb

Here's how we advise clients to think about what goes into AI tools:

Generally fine for consumer AI tools:

Use API/enterprise tier or be cautious:

A word of caution for professionals: If you're a lawyer, accountant, doctor, or other regulated professional, your obligations around client confidentiality may impose additional restrictions on what you can put into AI tools. Check with your professional body if you're unsure.

What we do for clients

When we build automations for businesses, we have a standard set of data protection practices:

We're not lawyers and we're not a compliance firm, but we take data handling seriously and we're happy to answer questions about how a specific workflow would handle your data.


If you have specific questions about how AI would handle data in your industry or business context, raise them on your free consultation call. We'd rather address those concerns upfront than have you worry about something that's either not a real issue, or is an issue we should be designing around.

← Back to Blog Book a Free Consultation