GDPR

Using AI with customer data without breaking the rules

A plain-language checklist for using AI with customer data in Europe.

You can use AI with customer data in Europe without breaking the rules, as long as you store the data in the EU, know which parts of the service process it elsewhere and under what safeguard, keep each client’s data separate, never let it train a shared model, keep personal details away from the model where you can, and tell people they are dealing with AI. None of that is exotic. It is just discipline, and most vendors either have it or they do not.

Where your data lives

Start with two questions rather than one: where is the data stored, and where is it processed? Storage is the straightforward part, and a vendor should be able to say the EU without qualifying it. Processing is where the carve-outs sit, because most language models and voice engines run outside the EU. The GDPR allows that under transfer safeguards. What you want is a vendor who names which parts leave, under which safeguard, and what is never sent to the model at all.

Kept separate, never shared for training

Your customer data should be yours alone. That means it is kept separate from other clients, and it is never used to train a shared model that other businesses benefit from. This is one of the most common quiet problems with cheap AI tools: your data becomes part of someone else’s product. Ask directly whether your data trains a shared model, and accept only a clear no.

Keep personal data away from the model

The strongest protection is to not send personal data to the model at all when you can avoid it. A lot of useful work does not actually need the personal details. You can prepare the wording and the logic around general business information, and merge the personal parts in at the last step, locally, without them ever reaching the AI. Where that is possible, it should be the default.

Tell people they are talking to AI

Under the EU AI Act, people should know when they are dealing with an AI rather than a person. This is not a burden. Being upfront builds trust, and it is easy to do well: a clear line at the start of a call or a chat. A vendor who is cagey about disclosure is a vendor who has not thought this through.

Questions to ask any AI vendor

Before you sign anything, ask these five. Where is my data stored, and which parts of the service process it outside the EU? Is it kept separate from other clients? Is it ever used to train a shared model? Do you send personal data to the model, and can you avoid it? How is the AI disclosed to my customers? Good answers are short and confident. Vague answers are your signal to keep looking.

If you want to see how we answer all five, our Trust page lays it out.

Questions

Is customer data used to train the AI?

It should not be. Ask any vendor directly. With Cadre, your data is kept separate for every client and is never used to train a shared model.

Reactivation is pay-for-results. Everything else is month to month, with no lock-in.

See it in a 30-minute call

We show you how Cadre would work in your business.