Customer conversation history can contain identity information, account records and complaints. Connecting that data to an AI tool requires more thought than adding a model API key.
Map the information flow
Draw a simple diagram of the customer message, messaging provider, application server, AI service, knowledge base, logging system and human inbox. For each step write what information is transferred and why. Identify where data may leave your normal storage environment.
Do not assume information stops being personal because it is presented as chat text. A message may include an email, order number, name or address without being labeled as a form field.
Reduce exposure before storing anything
Collect only the information necessary to solve the request. Avoid using messages containing passwords, authentication codes or payment-card numbers as test prompts. Where possible, redact sensitive fields before routing content to analytics or quality review.
Separate training examples from identifiable live transcripts. If a provider wants to retain messages for model improvement, understand and configure the relevant contract and privacy settings before connecting production traffic.
Limit access and actions
Use separate permissions for the AI service, support staff and administrators. A chatbot should not gain broad customer-record access just because the company uses one shared API credential. Any sensitive action needs server-side authorization that does not trust the model's own assertion.
Protect log exports, secrets and backups too. A secure chat screen is not enough if data is casually emailed or accessible in an unprotected debug endpoint.
Set retention and customer-request processes
Agree how long conversations and backups are retained, what is deleted when a ticket closes, and how a customer can request access or correction when applicable. This is a policy and legal review question; the correct requirements depend on jurisdiction and business context.
If you operate in South Africa, review the Protection of Personal Information Act with qualified counsel and the Information Regulator rather than relying on a generic AI platform's marketing statement.
Test incident and provider failure paths
Run tabletop exercises: a model returns another customer's details; an employee mistakenly pastes a token into chat; a third-party AI service is unavailable. Who is notified, what logs exist, what access can be revoked and how does the service continue with humans?
Ask vendors for a written data-flow description and a list of subprocessors where applicable. Treat privacy and availability as acceptance criteria in the AI agent setup plan.
Draw a data map before connecting an AI agent
For each support channel, record where customer messages enter, where they are stored, whether a third-party model processes them, who can read the transcripts and when records are deleted. This simple map exposes gaps that a privacy policy alone cannot fix. A supplier saying that data is "encrypted" does not answer the separate questions of retention, access or legal basis.
| Data | Default handling question |
|---|---|
| Contact name and number | Do we need it for this enquiry, and for how long? |
| Free-text message | Could it contain passwords, account or medical details? |
| Conversation transcript | Who can access it and when is it deleted? |
| AI model request | Which provider processes it and under what agreement? |
| Support analytics | Can we report using aggregate rather than personal data? |
Test your incident response
Ask the team to run a scenario: a customer pastes a password or identity number into a WhatsApp message. Can the agent discourage it? Can staff restrict access, remove it according to policy and document the event? Another useful scenario is a staff member leaving the business. Check whether their access to the inbox and connected systems is revoked promptly.
For businesses subject to POPIA or other privacy legislation, have a qualified adviser verify consent, lawful processing, cross-border transfers and retention obligations for the actual deployment. These are context-dependent legal questions, not settings a generic template can answer.
Turn privacy into a launch gate
Before going live, verify account ownership, access roles, a deletion process, audit logs, backup handling, human escalation and a customer-facing explanation of what the agent can do. Compare that checklist with our AI support agent setup guide and knowledge base controls.