September 30, 2026

AI Privacy Checklist: 12 Questions to Ask Any AI Vendor

AI privacy checklist for business, featured image with diagonal orange gradient

An AI privacy checklist gives a small business twelve questions to put to any AI vendor before staff start pasting customer emails, contracts or spreadsheets into a chat window. Most vendors will answer them in a few minutes if you ask, and the answers tell you more than any marketing page: where data is stored, whether it trains models, who else touches it and whether you can get it back or have it deleted.

This is a practical guide, not legal advice. It uses EU data protection thinking, because that is where our readers work, but the questions apply anywhere.

Why AI tools need their own privacy check

You probably already vet your accounting software and your cloud storage. AI assistants deserve the same, and a little more, for three reasons.

  • People paste everything. A chat box invites unstructured input: full emails, client names, salary lists, source code.
  • Data may be used to improve the product. Some services use conversations for training by default, others only if you opt in, and terms vary by plan.
  • The chain is long. An assistant may pass your text to one or more model providers, a search service and a hosting company. Each is a possible point of exposure.

Our overview of what not to share with AI covers the human side. This checklist covers the vendor side.

The twelve questions

1. Is my data used to train models?

Good answer: No, for all plans, stated in writing. Watch for: “not on business plans” (meaning yes on personal ones), or an opt-out buried in settings. Our explainer on AI training data opt-outs covers what these promises actually mean.

2. Where is my data stored and processed?

Good answer: A named region and company. Watch for: “global infrastructure” without detail. For EU businesses, storage inside the EU simplifies transfer questions, though it is not the only lawful route. Ask Mio’s servers are in Germany.

3. Which other companies process my data?

Ask for the list of sub-processors: model providers, hosting, analytics, payment. Good answer: a published list with notice of changes. Watch for: no list, or “trusted partners”.

4. Is there a data processing agreement?

If you put personal data into a tool, the vendor is normally your processor and GDPR expects a contract covering purpose, security and deletion; Article 28 describes what it must contain. Good answer: a standard agreement available on request. Watch for: none offered.

5. How long is data kept?

Ask about chats, uploaded files and backups separately. Good answer: defined periods and deletion on request. Watch for: “retained as long as needed”.

6. Can I export and delete everything?

Good answer: self-service export and deletion, with a stated timeframe. Ask Mio users can export or delete chats and files at any time. Watch for: deletion only by support ticket with no timeline.

7. Who at the vendor can read my conversations?

Some services allow staff to review chats for abuse or quality. Good answer: limited, logged access with clear conditions. Watch for: unrestricted human review.

8. How are files and connected accounts handled?

If the assistant can read your drive, mail or repository, what scope does it get and can you revoke it? Good answer: minimal, revocable permissions, read-only where possible. Our explainer on read-only connectors describes what to look for.

9. What security measures protect the data?

Encryption in transit and at rest, access controls, incident notification. Good answer: specific, verifiable statements. Watch for: only badges and buzzwords. Where a vendor cites a certification, ask for the report or certificate number instead of relying on a logo.

10. What happens in a breach?

Under GDPR you may have to notify the authority within 72 hours of becoming aware, so you need the vendor to tell you quickly. Good answer: a stated notification commitment.

11. Can I control who in my team uses it and how?

For teams: seat management, shared projects, roles and usage limits. Ask Mio’s Business plan offers 50 seats with team and shared projects. Watch for: shared accounts, which remove accountability.

12. What are the terms if things change?

Prices, policies and model providers change. Good answer: notice before material changes and a way to leave with your data. Read the vendor’s terms for change clauses, as described in our article on AI terms of service red flags.

The checklist at a glance

# Question Where to look Red flag
1 Training on my data? Privacy policy, plan terms Opt-out only, or differs by plan without saying so
2 Storage location? Privacy policy, security page No named region
3 Sub-processors? Published list No list
4 Data processing agreement? Legal page or sales contact Not available
5 Retention periods? Privacy policy Vague or indefinite
6 Export and deletion? Account settings Support-ticket only
7 Staff access to chats? Privacy policy, support Unrestricted review
8 Connector scope? Connector settings Broad write access by default
9 Security measures? Security page Badges only
10 Breach notification? DPA, terms No commitment
11 Team controls? Plan features Shared logins
12 Change terms? Terms of service Silent unilateral changes

How Ask Mio answers

We would rather state our position than make you dig, so here is where Ask Mio stands on the points we can answer plainly. Chats and files are the user’s. They can be exported or deleted at any time. Data is not used to train models. Servers are in the EU, in Germany. Ask Mio is made by Internet Solutions, UAB, the team behind Talkmio and PostRSS. The full details sit in the privacy policy and terms, and those documents, not this article, are the binding source.

For questions this article cannot settle, such as a data processing agreement for your company, ask directly through the contact page. We would rather you asked than assumed. A fair checklist is also one you should run on us.

Turning the checklist into a process

A checklist is only useful if it runs every time. For a small business, a workable process takes about an hour per tool.

  1. Name an owner. One person, not a committee, sends the questions and files the answers.
  2. Classify your use. Will only public text go in, or also customer data? The stricter the data, the fewer red flags you can accept.
  3. Send the questions and save the replies. Store them with the contract. Vendors’ policies change; dated answers are evidence of what you were told.
  4. Write a one-page staff rule. Which tool, which data, which never. Include examples people recognise: client lists, passwords, health details, unreleased financials.
  5. Review yearly. Re-run the questions when the vendor changes terms, adds a model provider or when your use expands.

The European Data Protection Board publishes guidelines and recommendations that help interpret GDPR duties in practice, and the European Commission’s data protection pages give the overview. If your tool handles special categories of data such as health information, get proper legal advice before you start.

A one-page staff rule you can adapt

The checklist protects you from a bad vendor. A short staff rule protects you from a good vendor used badly. Adapt this wording to your company.

  • Approved tools. Only use the assistant the company has approved, with your work account, never a personal one.
  • Never paste: passwords, API keys, payment card numbers, national ID numbers, health details, unreleased financial figures, anything covered by a confidentiality agreement.
  • Replace, then paste. Swap client names and identifiers for placeholders such as “Client A” when the task does not need them.
  • Check before you send. AI output that will reach a customer is read by a human first.
  • Report mistakes. If you paste something you should not have, say so immediately so the deletion request and any breach assessment can start on time.

Keep it to one page and put it where people will see it: the onboarding pack, the team wiki and the top of the shared project instructions.

A quick worked example

Imagine a ten-person design studio choosing an assistant for drafting client emails and summarising briefs. The owner runs the checklist. Training on data: the vendor says no, in the terms. Location: EU, named. Sub-processors: a published list. Data processing agreement: available on request. Retention: chat history kept until the user deletes it. Export and deletion: self-service. Staff access: limited to abuse investigation. Connectors: none needed. Security: described on a security page. Breach: notification commitment in the agreement. Team controls: seats and shared projects on the team plan. Change terms: notice by email.

That vendor passes. The studio writes a staff rule, signs the agreement and starts with the briefs that contain no personal data, moving to client emails once the team is comfortable. Had the vendor answered “not on business plans” to the first question, the studio would have known that the free plan, which one designer already uses, is the problem, and could have moved that person to the approved account the same week.

What to do when the answers are poor

Not every vendor will pass, and not every use needs a perfect vendor. Match the risk to the use.

  • Public or low-sensitivity text (marketing drafts, brainstorming): a vendor with mediocre answers may be acceptable if staff follow a strict “nothing confidential” rule.
  • Internal business data (plans, pricing, contracts): require clear answers on training, storage, deletion and access.
  • Personal data of customers or staff: require a data processing agreement, a named location and a working deletion process, and record the decision.
  • Special categories, children’s data, legal privilege: do not proceed without specialist advice.

A related point: even with an excellent vendor, minimise what you paste. Replace names with placeholders, remove account numbers and paste only the paragraph that matters. Prevention is cheaper than deletion.

Common mistakes small businesses make

  • Letting staff sign up with personal accounts and paste company data into them.
  • Assuming “EU-hosted” means “no other countries involved” without asking about sub-processors and support access.
  • Reading a marketing page instead of the terms.
  • Believing a checklist answer given by chat support is a contractual commitment. Get important answers in writing in a form you can file.
  • Never revisiting. Vendors add features, models and partners over time.

Frequently Asked Questions

What should I ask an AI vendor about privacy?

Ask whether your data trains models, where it is stored, which sub-processors handle it, whether a data processing agreement exists, how long it is kept, how you export and delete it, who can read chats, how connectors are scoped and what happens in a breach. Get answers in writing.

Does GDPR apply when I use an AI assistant?

If you enter personal data of people in the EU, yes, GDPR applies to that processing and you are usually the controller. The vendor is normally a processor and should offer a data processing agreement. This is general information, not legal advice; consult a professional for specific cases.

Is EU hosting enough for GDPR compliance?

No. EU hosting simplifies data transfer questions but does not replace a lawful basis, a processing agreement, security measures or deletion rights. It is a useful factor, not a certificate. Ask about sub-processors and support access from outside the EU as well.

Does Ask Mio train on my chats?

No. Chats and files belong to the user, are not used to train models, can be exported or deleted at any time and are stored on servers in Germany. The binding details are in the privacy policy and terms on the site.

Can I use a free AI plan for business data?

Check the terms first. Free plans sometimes have different data handling from paid ones, and features like team controls are missing. If you handle customer personal data, get a written answer on training, storage and a processing agreement before using any plan.

How often should I review my AI vendors?

At least once a year, and whenever the vendor changes its terms, adds a model provider or when your use expands to more sensitive data. Keep dated copies of the answers you received so that you can show what you checked and when.

The Bottom Line

An AI privacy checklist turns a vague worry into twelve questions with answers you can file. Run it before staff adopt a tool, write a one-page rule about what never goes in, and review it yearly. To see how Ask Mio answers, read the privacy policy and start on the free plan, which needs no card, before deciding whether to move real work over.


Try Ask Mio free

Free plan, no card required.

Start free
Ask Mio
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.