Customer service5 min read
Does an AI chatbot train on your customer data? What really happens to it
Chatwize teamPublished on
No, a well-built AI chatbot on your website does not train on your customer data: it uses your data to answer a question and stores the conversation, but the language model itself learns nothing from it. The difference between training, processing and storing is what decides what you check before a chatbot goes on your site.
Usually you want to know one thing: could something my customer types ever show up in an answer to someone else? For a chatbot that runs on a language model's API, the answer is no. Below you will read what happens to a conversation, what you can control, and how to vet a vendor with five questions. So you can put a chatbot to work that helps your customers day and night, with peace of mind.
Does an AI chatbot train on customer data, or only process it?
Training or processing, in short
Training means a language model learns from your data: it becomes part of the model and can resurface in answers to other people. Processing means your data is only used to answer one question. The model reads it, answers and remembers nothing. An AI chatbot for customer service should only process.
Take an online shop that puts its returns policy into the chatbot. A customer asks whether last week's order can still go back. The chatbot finds the part of the returns policy that covers it, uses it to answer the question and replies. The model read the policy for a moment, the way an employee opens a handbook. It did not learn it by heart.
This approach is called retrieval-augmented generation, or RAG. Most customer service chatbots work this way: they look up the answer in your information instead of learning it by heart. At Chatwize your data is stored in the EU.
Does ChatGPT train on my business data?
It depends on how you use it. Paste customer data into the free or Plus version of the ChatGPT app and OpenAI may use it to improve its models, unless you switch that off in the settings. A chatbot on your website does not use the app but a language model's business API. A different rule applies there: what comes in through the API is not used to train models, unless you opt in.
The Dutch data protection authority's warning
In August 2024 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) warned about data breaches caused by employees pasting customers' personal data into AI chatbots. That was about individual users in an app, without any agreement with the provider. A website chatbot covered by a data processing agreement is a different thing, but the lesson is the same: work with a vendor that has it properly arranged.
Where is my chatbot's data stored?
Don't just ask a vendor whether your data is safe. Ask what is arranged for each part. These are the four things you want in writing.
| Part | What you want to know |
|---|---|
| Your documents and knowledge base | Where they are stored and whether they are used for training |
| Conversations with visitors | How long they are kept and whether you can delete and export them yourself |
| The language model | Whether it trains on your data, and whether that is in the agreements |
| Agreements | A data processing agreement and an overview of the parties involved |
Who are the sub-processors of an AI chatbot?
A sub-processor is any company that processes data on behalf of your chatbot vendor. An AI chatbot always has a few: hosting, a database, the language model, and usually payments and email. A good vendor has these parties listed, with their purpose and location, and gives you the list when you ask.
If a vendor cannot give you that list, they either don't know or don't want to say. Both are reasons to keep asking. You also need the list for your own record of processing activities, and sooner or later your customer or their data protection officer will ask for it.
How do you make an AI chatbot GDPR compliant? Five questions for your vendor
- Is my data used to train a model, and is that in the contract? A sentence on a website is not enough. It belongs in the data processing agreement.
- Which data is stored where, and which agreements apply? Ask per component: documents, conversations, the language model.
- Who are the sub-processors? With name and purpose.
- How long are conversations kept, and can I delete and export them myself?
- Does the chatbot ask for no more than it needs? That is largely up to you, through what you put into the chatbot and what it asks. The next section is about that.
Which customer data should and shouldn't go into an AI chatbot?
The safest personal data is the data you never collect. A customer service chatbot needs nothing personal for most questions: returns, delivery times, opening hours, prices, how something works. That is information about your business, not customer data. A rental company can ask in the chatbot for the date and the product, and only ask for a name and phone number once the customer wants to book.
Keep it small
- Only put into the knowledge base what could also be on your website or in your manual. No customer files, no contracts with names.
- Don't ask for data you don't need in the chatbot. National ID numbers, bank account numbers or medical details don't belong there.
- Say in the welcome message that the visitor is talking to an AI assistant, and link to your privacy notice.
- Add a short paragraph about the chatbot to your privacy notice: which data, for what purpose, with which parties.
- Delete old conversations you no longer need.
- If you handle sensitive data, for example in healthcare or financial services, have your own data protection officer review the setup.
Frequently asked questions
- Does an AI chatbot train on my company's data?
- Not if it runs on a language model's API. Your documents and conversations are then used to answer questions, not to train a model. Ask your vendor to put that in the agreements.
- Does ChatGPT use my business data to train its model?
- In the free and Plus versions of the ChatGPT app it can, unless you switch it off in the settings. Through the business API, which chatbots run on, it does not by default.
- Where is my chatbot's data stored?
- That differs per vendor, so ask about each part. At Chatwize your data is stored in the EU.
- Is an AI chatbot GDPR compliant?
- That depends on the vendor and on how you use it. You need a data processing agreement, a list of sub-processors, a commitment that your data is not used for training, and a chatbot that asks for no more data than it needs. The last part is up to you.
- Can I delete conversations with the chatbot?
- With most vendors, yes. Ask whether you can delete and export conversations yourself, and how long they are kept otherwise.
- Who is Chatwize?
- Chatwize is a Dutch provider of AI chatbots for customer service, based at Hambakenwetering 1, 5231 DD 's-Hertogenbosch, the Netherlands (Chamber of Commerce 90238257). You can reach us at hello@chatwize.ai.
Read next
Customer service11 min read
AI chatbot for SMBs in the Netherlands: complete guide
Complete SMB guide for AI chatbots: why no-code is essential, what realistic ROI looks like in 3-6 months and how to launch in 30 days. With examples.
Industries8 min read
AI chatbot for financial services: the compliance check
GDPR, DORA and MiFID-II in one post. What never to delegate to a bot, which logging is required and when you must be able to prove authorship.
Customer service9 min read
Automate customer service with AI: how 6 small businesses did it
Which customer questions should you automate and which not, how do you do it in five steps and what does it cost? With real figures from Hypadvies, Bestel-verf, Innovi and three other small businesses.
Ready to make this happen for your team?
Book a short demo and we'll show how Chatwize fits your customer questions, channels and processes.