Data handling: fifteen questions to ask an AI vendor before you sign
Where your customer data goes, who can see it, whether it trains anyone's model, how long it is kept, and how you get it back. The questions, what a good answer sounds like, and the answers that should end the conversation.
Frontiva · · 4 min read
Before an AI vendor handles your customer conversations, you need answers to fifteen questions about where the data goes, who can see it, whether it is used to train models, how it is protected, how long it is kept, and how you get it out. A good vendor answers all fifteen in writing without hesitation. A vendor who answers "that is handled by our provider" to most of them has not asked the questions themselves.
Where the data goes
1. Where is my data stored, geographically? A named region. "The cloud" is not an answer.
2. Which third parties process it? The model provider, the messaging provider, the hosting provider, any analytics tools. Named, with what each receives.
3. Does any of my data, or my customers' data, train anyone's models? The answer you want is no, in writing, covering the vendor and every third party. "We use it to improve our service" needs to be pinned down: improve how, using what.
Who can see it
4. Which of your staff can access my customers' conversations, and under what conditions? Support access should be limited, logged and, ideally, require your permission per incident.
5. Is access logged, and can I see the log? For medical and legal practices, this is not optional.
6. Can the AI see any customer's data other than the one it is talking to? No is the only acceptable answer.
How it is protected
7. Is data encrypted in transit and at rest? Yes, with the standards named.
8. How are staff and API credentials managed? You are listening for named practices, not "industry standard".
9. What happens if there is a breach? Notification timeline, in writing, and who is responsible for notifying your customers.
10. Will you sign a business associate agreement (for HIPAA) or a data processing agreement? If you need one and they will not, stop here.
How long it is kept
11. What is the retention policy, and can I set my own? Conversations, recordings, transcripts, logs. You should be able to shorten it.
12. What happens to my data when I cancel? Deleted, when, and can you get a confirmation.
How you get it out
13. Can I export everything, in a readable format, at any time? Ask for a test export before signing. Our post on exporting your data says what to check in it.
14. Can a customer's data be exported or deleted individually on request? Some jurisdictions require it.
15. Who owns the phone number, the knowledge base, and the conversation history? You should, all three, in the contract.
Answers that should end the conversation
"We cannot say where it is stored." "Our model provider may use it for training." "Everyone at the company can see conversations for support." "We do not sign BAAs." "Export is on our roadmap." Any of these means the vendor has not built for businesses that are accountable for customer data.
Putting it in the contract
Good verbal answers are worth writing down. The data processing terms should cover the fifteen points, and the ones that matter most (no training, access limits, export, deletion on cancellation) should be explicit. A vendor who answers well will not mind.
Frequently asked questions
Is a small vendor riskier than a large one?
Not necessarily. Ask the fifteen questions of both. Small vendors often give clearer answers because one person knows the whole system.
What about the model provider's own terms?
Ask which provider, and read their business terms on training and retention. The vendor should have chosen a provider whose terms match the answers they gave you.
Do I need to ask all fifteen for a text-only receptionist?
Yes. Text conversations contain names, numbers, health details customers volunteer, and the record of what your business said. That is customer data by any definition.
What Frontiva does here
Ask Frontiva the fifteen too. The security page answers several in writing, including what we have not earned yet: Frontiva is not SOC 2 certified and not HIPAA certified. Contacts export to CSV, and every analytics screen exports the CSV behind it. For the controls inside the AI itself, see the real risks of an AI receptionist.
The answers worth having are the ones you can check. In Frontiva what the agent can say comes from the knowledge you loaded, and the playground lets you try a question before a customer asks it.