Service

Data Privacy for Companies Using AI

How do I keep customer data private when using AI tools?

Know exactly what goes into each AI tool, where that data lives, whether the vendor trains on it, and which jurisdiction's rules apply. Then put controls and records around the flows that matter.

Most privacy failures with AI come from tools nobody mapped, not tools nobody approved — the embedded copilot in your CRM, the transcription bot in your meetings, the shadow subscription on a company card.

Who this is for

Companies handling customer data under GDPR, US state privacy laws, or sector rules, whose teams already use AI tools — approved or not. Delivered for clients in the US, EU, Canada, and Australia.

What the engagement delivers

  • A data-flow map for every AI touchpoint: what goes in, where it lives, whether it trains
  • Vendor-by-vendor training and retention posture, documented
  • Controls for the flows that carry customer data, wired into the systems
  • Audit records that show the diligence happened — the artifact that matters in an enforcement action

How the process works

  1. A 15-minute fit call establishes what data you handle and under which rules.
  2. Inventory and data-flow mapping across every AI tool, including shadow and embedded ones.
  3. Control design for the flows that matter, with records built in.
  4. Readout: what changed, what to show a regulator or customer, and what to watch.
The matching engagement

Data-flow mapping is a core deliverable of the AI Risk & Security Review — $3,500 / $5,500 / $8,500 by company size. Full scope and limits on the services page.

Book a 15-minute fit call