All posts

What happens to your customer data with an AI chatbot

By How Do AIPublished 5 min read

A straight-talking explainer for UK small businesses on where AI chatbot conversations go, how they are stored, whether they train third-party AI models, and what UK GDPR actually requires you to have in place.

When a customer talks to an AI chatbot on your website, their message travels through three or four places before you see a transcript in your inbox. Where those places are, who can read the messages, whether the conversation trains someone else's AI model, and what your legal obligations are as the business running the chatbot โ€” that is the honest answer to "what happens to my customer data".

Here is the plain-English version, structured around the questions we get asked most.

Where does the conversation actually go?

A typical UK small-business chatbot conversation takes this path:

  1. Customer types a message into the chat widget on your website. The widget is JavaScript running in the customer's browser.
  2. The message is sent to the chatbot vendor's server (usually UK or EU-hosted for reputable providers), which stores the conversation transcript against your account.
  3. The vendor calls an AI provider (OpenAI, Anthropic or similar) to generate the reply. Your training data plus the customer's message is sent to that provider.
  4. The reply comes back through the same path in reverse and displays in the customer's browser.
  5. The full transcript is emailed to you (or dropped into your dashboard) usually within a few seconds.

Two things are worth understanding here. First, the AI provider (step 3) sees the message but does not know who your customer is unless they typed their name and address into the chat. Second, the vendor (step 2) does have your customer's details if they were captured โ€” that is why the vendor's data-handling practices matter.

Does my customer's data train someone else's AI model?

Not if the vendor uses the enterprise APIs, which is what any reputable UK chatbot provider should be using.

OpenAI and Anthropic both offer two API tiers: a consumer tier where prompts and responses can be used for model training (with opt-outs), and a business/enterprise tier where prompts and responses are contractually never used for training. Reputable UK chatbot vendors default to the enterprise tier. Your customer's conversation is used to answer their question and then not used for anything else.

If you are choosing a chatbot vendor, this is one of the specific questions to ask: "Which API tier do you use, and can you confirm in writing that customer conversations are not used to train third-party models?" A vendor who cannot answer clearly should not have your customer data.

What about UK GDPR?

If your chatbot captures any personal data (name, email, phone, or free-text describing a personal situation like a medical concern or a legal question), UK GDPR applies. In practice you need:

  • A privacy notice that mentions the chatbot, what data it collects, how long it's kept, and who it's shared with. Your existing website privacy policy usually needs a paragraph added.
  • A lawful basis for processing โ€” for enquiry chatbots this is almost always "legitimate interests" (responding to a customer enquiry you can prove they initiated). Not consent โ€” you don't need a cookie banner just for a chatbot the user themselves opened.
  • A Data Processing Agreement (DPA) with your chatbot vendor. Reputable vendors provide a standard DPA on request; if you have to chase them for it, walk.
  • A retention policy โ€” how long you keep transcripts. Six to twelve months is typical for enquiry data. If you keep transcripts forever "just in case" you will fail a data audit.

None of this is scary or expensive. It is fifteen minutes updating your privacy policy and one email to your vendor to get the DPA. But it is genuinely required and skipping it exposes you to a real complaint risk.

What if the AI answers something it shouldn't?

Reputable chatbots are boxed in to your business content and are told to escalate anything outside their scope rather than guess. So a chatbot for a plumber will not diagnose a plumbing problem, prescribe a fix or agree a firm price for a job it has never seen โ€” it will say "I'll take your details and get someone to call you back."

That does mean you need to keep an eye on transcripts, especially in the first month, to spot places the bot is answering something it shouldn't. Every reputable vendor emails you every transcript so you can spot problems fast. If a bot is drafting answers on serious topics (medical, legal, safety), you should be able to add rules that hard-escalate to a human every time.

What about clinical, legal or financial advice?

If your business is in a regulated sector โ€” medical, dental, legal, financial โ€” the chatbot must be scoped tighter than a normal enquiry bot:

  • Never gives clinical, legal or financial advice. Any question that touches those is escalated to a human.
  • Handles admin only โ€” appointment booking, opening hours, service pricing, general FAQs about what you offer.
  • Explicitly identifies itself as an assistant, not a professional. Every conversation opens with a line making clear it's a booking and admin helper, not a clinician / lawyer / adviser.

If a vendor offers to build you a "medical chatbot that can answer patient questions", ask for their MHRA registration status. If they don't have one, they should not be offering that product.

What happens if the vendor goes bust?

This is the question nobody asks until it's too late. Two things protect you:

  1. Your data lives in your account โ€” the vendor should be able to export your transcripts, lead list and training documents to a CSV or JSON file on request. If they can't, they are holding your data hostage.
  2. Your training data is portable โ€” the prompts, FAQs and content that make the bot "yours" should be readable text you can hand to another vendor. If it's locked in a proprietary format, you can't move.

Ask both questions on the discovery call. Reputable vendors answer both with "of course" and can send you an example export before you sign.

The one-line summary

Your chatbot vendor should be able to send you a DPA in writing, a data flow diagram, confirmation that customer conversations don't train third-party models, and an example transcript export โ€” within 24 hours of you asking. If any of those are hard to get, that's the answer to whether you should trust them with your customers.


How Do AI runs its own chatbot on the enterprise-tier Anthropic API, provides a standard DPA on request, keeps transcripts in UK-hosted systems, and exports all client data to CSV/JSON on 24 hours' notice at any point. Ask on the free discovery call at /contact if you want to see the DPA before committing to anything.

Want a chat about any of this?

Book a free 30-minute discovery call. We'll walk through your setup, tell you honestly what fits, and quote a fixed price if it makes sense.

Book a free discovery call