// guide · data and AI

Your business data and AI: what you can upload safely

By Trinity · MariVisionSeptember 1, 20267 min read
Ale from MariVision inside an enormous nighttime vault, with glowing holographic business documents lined up behind glass walls
2026 · 09 · 01 — GUIDE: DATA AND AIWhat you can really upload to an AI chat

You have a customer's quote open on your screen and you'd like the AI to tidy it up. Your finger is on copy, and you stop: but can I paste this? It's the most frequent question freelancers and small business owners ask me since they started using these tools every day, and it usually gets two answers, both useless. The first is “relax, nobody's looking.” The second is “AI is banned by GDPR.” Both are false. The truth is that there's a clear line between what you can paste without a second thought and what must never leave the company — and in between there's a gray area that's settled with thirty seconds of work. This guide gives you the line, the method and the settings to check tonight.

1 · Where what you paste into a chat really ends up

Enormous nighttime server room with a glowing stream of documents rising from a desk toward the racks

When you hit enter, the text leaves your computer and lands on the provider's servers. Three different things happen there, and it's worth keeping them separate. First: the conversation is saved, because it lets you pick up where you left off, and it stays in your history until you delete it. Second: in some cases your content is used to train the models — that's the part that scares people, and it's also the only one you can switch off with a toggle. Third: a share of conversations may be read by human reviewers for quality and safety checks, usually in reduced and anonymized form.

The practical rule: on free and personal plans, training is almost always on by default; on paid business plans it almost never is, but the word “almost” has to be resolved by looking at your account settings, not at an article — the terms change every few months. Look for the item that talks about model improvement or training and switch it off. On the same screen you'll usually also find history retention: if you can shorten it, shorten it.

Why it matters to you: it's the only move in this guide that takes five minutes and covers everything you'll do for the next two years. Do it now on every assistant you use, including the ones inside the tools you already pay for, and do it again when you change plans — settings don't carry over on their own when you go from free to paid. And if there's more than one of you in the company, check their accounts too: confidentiality is a chain, and the distracted link is the one that breaks it.

2 · The blacklist: what never to paste

Large dark archive with a steel safe sealed by a glowing red edge and sensitive documents locked behind it

This part is short on purpose, because it has to stick in your head without revision. Always and in any case, these stay out of the chat: complete contact records of customers, suppliers and employees (name, address, tax code, phone number, IBAN put together); medical certificates, test results, payslips, employment contracts, data on lawsuits and criminal records — they're the categories GDPR protects most and that expose you most; passwords, API keys, login credentials and two-factor codes, which shouldn't be pasted anywhere, AI or not; documents covered by a non-disclosure agreement, third-party price lists and contracts, because there the problem isn't the data protection authority but the signature you put on the NDA. I'll add an item that always slips through: screenshots. A screenshot of your management software contains the customer's entire row even if all you cared about was the total column.

Why it matters to you: the single criterion to remember when you're in a hurry is this — if you wouldn't email it to a polite stranger, you don't paste it into a service you don't control. It applies to email too: an assistant connected to the company mailbox reads everything in it, not just the email you're writing. If you're considering giving it that kind of access, AI agents for businesses are set up the opposite of how they're sold: minimum permissions, approved actions, a log of what they've done.

3 · Anonymizing in thirty seconds: the method

Dark studio with an enormous holographic contract in which names and numbers are replaced by neutral glowing labels

Here's the trick that solves 90% of real cases, and it's trivial: the model doesn't need your customer's name. Replace “Rossi Costruzioni srl” with “Customer A,” “Bianchi” with “Supplier B,” remove VAT numbers, addresses, phone numbers and IBANs, and if the amounts are sensitive round them or scale them all by the same factor. Then paste. The answer you get is identical — the AI is working on the structure of the text, not on the contact details — but what left the company can no longer be traced to anyone.

Two things to get it right. First: anonymize before pasting, not after. Asking the AI to “remove the sensitive data” from a text you've already given it is like turning off the tap after the flood — you've sent it anyway. Second: watch out for data that identifies even without a name. In a town of three thousand people, “the only restaurant with a terrace on the lake” is a first and last name. If the case is so specific that it identifies itself, change the details or change the tool.

Why it matters to you: with anonymization the gray area almost entirely disappears. Quotes, offers, difficult emails, contracts to explain, sales analyses: everything becomes uploadable, as long as it's cleaned up. And it's a habit you learn in a week — after that you do it without noticing, like fastening your seatbelt.

4 · GDPR in practice: who's liable if something gets out

Vast nighttime archive hall with towering stone filing cabinets and a large glowing holographic folder hanging at the center

The most important thing to know is also the least intuitive: before the Italian data protection authority, your company is liable, not the AI provider. In GDPR language you are the data controller, whoever supplies the tool is the processor. Three concrete obligations follow from this, and none of the three is complicated. One: if people's data passes through the AI — customers, employees, contacts — you need a contract appointing the provider as data processor (serious services make one available to sign online, often only on business plans). Two: the privacy notice and the record of processing activities need updating, because a new tool that processes that data has appeared. Three: you need to look at where the servers are and whether the data leaves the European Union, because in that case the safeguards required for transfers apply.

Then there's the part GDPR doesn't cover but that costs you just the same: the European AI Act requires transparency about when content is AI-generated, and the strictest duties concern high-risk uses — hiring, credit scoring, things like that. If you use AI to write and organize, you're miles away from that zone. If you use it to make decisions about people, that's the moment to talk to a real lawyer: I write software, not legal opinions, and the difference matters.

Why it matters to you: this isn't abstract red tape, it's the difference between an inspection that wraps up in half an hour and one that becomes a problem. If you're a small business the real effort is less than it seems: one contract to sign, two paragraphs to add to the privacy notice, one line in the record. If you'd rather start from a map of what you're already processing and how, that's exactly the first piece of AI consulting for SMEs done right.

5 · When the data is truly sensitive: the alternatives

Large nighttime control room with a glowing panel of switches, some off, and a small isolated machine on a pedestal

There are jobs where the data is needed in full and anonymizing it makes no sense: the medical practice, the payroll consultant, anyone handling legal cases, anyone working on a complete customer database. In those cases it's not about being more careful, it's about changing the tool. There are three options, in order of effort. Business plan with contract: it costs a few dozen euros a month per user, and in return you get the processor appointment, no training on your content and centralized administration. Zero retention: some providers, on business plans or via API, let you keep nothing after the answer — the conversation disappears, the history doesn't exist. A model running in-house: an open model installed on the office computer or on a server of your own; today the quality is more than enough for summarizing, classifying and rewriting, and the data physically never leaves the room.

Why it matters to you: the third option is the one almost nobody considers and the one that solves the problem at the root, especially if the sensitive work is always the same and repetitive. You set it up once, connect it to what you already use, and then the question “can I paste this?” simply stops existing. It's the same reasoning behind how we design AI automation for your business: the data stays where it is, only the result moves.

In short

Switch off training and shorten history in the settings, keep complete contact records, health and judicial data, credentials and documents under NDA out of the chat, anonymize everything else before pasting it, remember that you're the data controller and get contract, privacy notice and record in order, and when the data is truly sensitive change the tool instead of hoping. The point isn't using AI less: it's knowing at every moment what leaves the building. If you do one thing tonight, open the settings of the assistant you use most and check how the training toggle is set. In most of the cases I've seen it was on, and nobody knew.

Frequently asked questions

Can I paste customer data into ChatGPT?

Not complete customer records: name, address, tax code, phone number and IBAN put together stay out, as do health data, payslips, credentials and documents under a nondisclosure agreement. The rest can go in if you anonymize it first: “Client A” instead of the name, no VAT number or IBAN, sensitive amounts scaled. The AI's answer stays the same.

How do I turn off AI training on my data?

In your account settings, look for the option about model improvement or training and switch it off; on the same screen, if you can, shorten how long your history is kept. On free and personal plans, training is almost always on by default. Do it on every assistant you use, and do it again when you change plans: the settings don't carry over.

If I use AI with personal data, who answers to the Italian data protection authority?

Your business does, not the provider: you're the data controller, the provider is the processor. If personal data goes through the AI, you need a contract that appoints the provider as your data processor, you have to update your privacy notice and your record of processing activities, and you have to check whether the data leaves the European Union.

Want to figure out which of your business data you can feed to AI, and which you absolutely can't?
A half-hour chat, no strings attached, in plain language, no legalese
Let's talk →