Introduction
AI chatbots have become a part of our daily lives. From writing emails and creating code, to organizing trips and solving questions, tools like ChatGPT, Gemini, and Claude have become our digital assistants.
However, this convenience hides a significant pitfall: excessive familiarity. The way we communicate with Artificial Intelligence is so natural that we often forget that we are not talking to a trusted friend, but to a cloud infrastructure that processes and, depending on the service, may store our data.
Εμείς εδώ στη Fixit βλέπουμε καθημερινά τα ζητήματα ασφαλείας που προκύπτουν από την αλόγιστη χρήση της τεχνολογίας. Γι’ αυτό συγκεντρώσαμε όσα πρέπει να γνωρίζετε για την προστασία των δεδομένων σας όταν συνομιλείτε με ένα AI.
What happens to the data we give to AI?;
Every time you write a message (prompt) to a chatbot, that data doesn't disappear. In the free and consumer versions of most services, your texts can be used to:
Training future models. Your prompts may be included in the training data of the next generation of the model. In rare cases, unique information such as passwords, API keys, or snippets of proprietary code can be «remembered» by the model and theoretically appear in future responses. This phenomenon is known as training data memorization and has been research-based.
Human evaluation. In many cases, quality controllers read sample conversations to improve the security and accuracy of the system, especially when there is a report of a violation of usage policies.
Storage for compliance. Even when data is not used for training, it is typically retained for 30 days for security and legal compliance reasons.
The most famous AI leak occurred in 2023, when Samsung employees posted confidential source code and meeting minutes on ChatGPT. The company immediately banned its employees from using public AI tools. Similar bans have been imposed by Apple, JPMorgan, and Amazon.
Consumer vs Enterprise: The big difference we ignore
Here is the most important information in this guide: Professional versions of AI services have a fundamentally different data policy than the free ones.
| Service | Training on user data | Suitable for corporate data |
|---|---|---|
| ChatGPT (Free / Plus) | Yes, unless you opt-out | No |
| ChatGPT Team / Enterprise | No, never. | Yes |
| Claude.ai (Free / Pro) | Not by default | With care |
| Claude for Work / API | No, never. | Yes |
| Gemini (consumer) | Yes | No |
| Gemini for Workspace | No | Yes |
If you use AI for your work or handle customer data, professional edition is not a luxury — it's an obligation. The cost starts at around 25 euros per user/month and is insignificant compared to the risk of a leak.
Fixit's Golden Rules for Safe Use of AI
1. Never share sensitive personal data
Avoid writing full names, addresses, ID numbers, tax numbers, passwords, bank card numbers, or medical histories. The AI does not need your real name to write you a letter template.
2. Be careful with corporate data
Do not attach confidential documents, company financials, customer data, or source code that contains credentials, API keys, database connection strings, or proprietary logic. If you must use AI on such data, use only an enterprise solution with contractual data protection assurances (DPA).
3. Anonymize the information
If you need help writing an email or parsing a text, replace real names with placeholders. Instead of «Customer George Papadopoulos from 45 Tsimiski Street,» write «Customer X from address Y.» The same goes for company names, VAT numbers, and invoice numbers.
4. Check your privacy settings
Take two minutes to set up your accounts correctly:
- ChatGPT: Settings → Data Controls → disable «Improve the model for everyone»
- Claude: Settings → Privacy → check your data usage settings
- Gemini: myactivity.google.com → Gemini Apps Activity → Turn Off
5. Clean your history regularly
Even with an opt-out, older data remains. Periodically delete conversations that contain sensitive content.
6. Think about the geography of the data
Most AI services process data on servers outside the EU, mainly in the US. For Greek businesses that handle data of European citizens, this has GDPR implications and requires appropriate Standard Contractual Clauses.
Your rights under GDPR
As EU citizens, you have specific rights even when using American AI services:
- Right of access (Article 15): You can request a copy of all the data the service has stored for you.
- Right to erasure (Article 17): You can request the permanent deletion of your data. OpenAI and Anthropic have specific forms for GDPR requests.
- Right to object (Article 21): You can opt out of using your data for model training.
If you are a business using AI to process customer data, you need a signed Data Processing Agreement (DPA) with the provider. Consumer plans not offer DPA.
AI is a tool, not your confessor
Artificial Intelligence is here to make our lives easier, but the security of our data remains our sole responsibility. Treat the chat box like a public square: don't say anything you wouldn't shout out loud in a crowded room.
For businesses that want to leverage Artificial Intelligence without exposing their data, there are solutions: enterprise plans with contractual guarantees, on-premise self-hosted models, or specialized AI tools where the data remains on your own servers.
Need guidance on how to safely integrate AI tools into your business or protect your networks and computers? The Fixit team designs solutions that comply with GDPR rules and keep your data where it belongs — under your control.
