"Is AI safe?" is the wrong question. "Where does my data physically go, and who keeps a copy?" is the right one — and it has a concrete, checkable answer. This article follows a single customer message through every hop it makes after someone hits send, and shows you the four settings that decide whether that journey is fine or a problem.
If you want the policy view — what to write down, what to tell staff, what never to paste in — that is our guide to using AI safely in your business. This one is about the plumbing underneath it.
The five hops a message makes
Someone on your team types "Mrs Patel on 0121 496 0000 is chasing her order, can you draft a reply". That sentence now travels: out of your building, optionally through a filter that strips personal details, into the AI model that reads it, then into a log of the conversation, and finally into storage somewhere. Five hops. Each one is a place a copy can exist.
Hop 1 — it leaves your building
Unless you are running a model on your own hardware, the text goes to someone else's computer. This is the hop most people never think about, and it is the one where you have the most control: you can strip out the name and the phone number before it goes, and send "a customer is chasing an order" instead. The model answers just as well, and Mrs Patel never left the building.
Hop 2 — the model reads it, and may remember it
The model processes the text and sends back an answer. The question that matters here is whether your provider may use what you typed to train future models. On consumer tiers this is often on by default; on business and enterprise tiers it is normally off and contractually excluded.
This is the single setting we would check first, because it is the only one you cannot undo. Delete your account tomorrow and the text that has already gone into a training set does not come back out.
Hop 3 — it gets logged
Nearly every provider keeps a copy of the conversation for a while, for abuse monitoring and debugging. Thirty days is a common and reasonable default. "Indefinitely" is not: every retained conversation is a record you would have to search and hand over if a customer made a subject access request.
Hops 4 and 5 — where the copy comes to rest
Finally there is the question of where — geographically. Sending personal data outside the UK is a restricted transfer, and it needs a lawful route. Transfers to the EEA are currently covered by UK adequacy regulations; for somewhere like the US you are relying on your provider's terms to supply that route.
Try it — change the settings and watch the lights
Below is the same five-hop pipeline, live. It starts on roughly the settings a free consumer account uses out of the box. See how green you can make it, and note how few changes it takes.
Follow one message through the pipeline
Change the four settings and watch where a single customer message actually ends up. It starts on the settings a free consumer account typically uses — see how green you can get it.
- Your team Writes the message
- Hide details Off
- AI model United States
- Logs Kept forever
- Storage Outside the UK
- Real customer names, numbers and addresses leave your building. Stripping them first is usually the single biggest change you can make.
- Processing happens outside the UK. That is allowed, but it needs a lawful transfer route — check what your provider’s terms actually commit to.
- Your provider may use what you type to improve its models. Consumer tiers often do this by default; business and enterprise tiers normally do not. It is the one setting you cannot undo later.
- Conversations are kept indefinitely. Every one is a record you would have to find and hand over if a customer made a subject access request.
This is roughly what a free consumer chatbot account looks like out of the box.
This illustrates how AI data flows are normally configured. It is not legal advice — for the rules that actually apply, see the ICO's guidance on AI and data protection.
The four settings that decide almost everything
Everything above collapses into four questions you can put to any supplier, in writing, before you sign anything:
- Do you train on our data? You want a clear no, in the contract.
- Where is it processed? UK or EEA is the simple answer. Anywhere else, ask which transfer route they rely on.
- How long do you keep conversations, and can we set that? A number, not "as long as necessary".
- Can we strip personal details before they reach you? The best answer is that you never need to send them at all.
A supplier who cannot answer these quickly has not thought about it, which is its own answer. There is more on separating the good from the bad in how to choose an AI agency in the UK.
The rules moved recently — here's the short version
Two things changed that are worth knowing about, though neither should alarm you.
The Data (Use and Access) Act 2025 amended the international transfer rules in the UK GDPR, and the ICO published updated transfer guidance in January 2026 to match. The practical effect for a small business is small: the routes are still adequacy, appropriate safeguards such as the UK IDTA, or a narrow set of exceptions. Separately, the European Commission renewed the UK's own adequacy status in December 2025, which keeps data flowing between the UK and the EU without extra paperwork.
The one thing worth noting is that UK and EU transfer rules have started to diverge, so if you operate under both, one analysis no longer automatically satisfies the other. If that is you, take proper advice — this article is not it.
What "properly configured" actually looks like
It is unglamorous. Personal details are stripped before anything leaves. Processing happens in the UK or the EEA. Training on your data is contractually off. Conversations are kept for a set number of days and then deleted. That is the whole list, and every item is a setting or a clause rather than a technology.
None of it requires building your own model. It requires choosing a tier that offers the right terms and then actually configuring it — which is the step that most often gets skipped. It is the default shape of the AI work we build, and where a business genuinely cannot let data leave at all, that is a case for custom software running somewhere you control.
Sources & further reading
This article explains how AI data flows are normally configured. It is general information, not legal advice — for anything specific to your business, the ICO is the authority and a data protection specialist is the right call.
Frequently asked questions
Keep reading
Have a project in mind?
Tell us what you're trying to solve and we'll come back within 24 hours — no hard sell.
Start a Conversation