In an automation conversation, the most common question is rarely technical. After the talk about how the system works, how many tasks it handles and which programs it connects to, one sentence usually arrives: "So where does my customer data go?"

The question is fair and often goes unanswered. Articles about automation explain what the system does, not where the data travels. Yet any business handling customer data carries obligations under data protection law. Setting up an automation does not remove that responsibility; it can sometimes widen it.

This article is not legal advice. Its purpose is to show which questions to ask when setting up an automation. For your own situation, consult a lawyer.

🔒 Keep in mind: When you set up an automation, responsibility for the data stays with you. The firm that builds the system processes data on your behalf, but the party answerable to your customer is you. If that distinction is not written into the contract, it stays unclear what each side is expected to do when something goes wrong.

Why does AI change this picture?

Processing personal data is not new. Customer names, phone numbers and addresses have been recorded for years. What AI adds comes down to three points.

Data can leave the building. A traditional accounting program keeps your data inside itself. A system using AI usually sends text to a language model to process it. That model may belong to another company and may run in another country.

Data gets combined. Automation gathers separate sources in one place: a web form, a WhatsApp message, a call record, an email. Details that look harmless on their own can form a far more detailed profile once brought together.

Decisions become automatic. If the system decides which offer goes to which customer, or how an application is prioritised, you may need to be able to explain how that decision was reached.

Who is the controller, who is the processor?

Data protection law distinguishes two roles, and that distinction is the foundation of the contract.

This distinction should not stay on paper alone. The relationship is expected to be captured in a written data processing document: which data, for what purpose, for how long, on whose instruction. Without that document, the boundaries of responsibility are unclear.

Three parts to the question "where does my data go?"

Where does the server sit?

Data physically resides somewhere. In your own country, in Europe, or elsewhere. Cross-border transfer follows its own rules and the same conditions do not apply in every case. This is the first question to put to the firm building your automation: in which country is the server that holds the data?

What does the AI model do with the data?

When you send text to a model for processing, what happens to it depends on the provider. Some providers commit not to use submitted data for training, some retain it for a defined period, some retain nothing. These terms sit in contracts and can change over time.

The question to ask: what is the data policy of the AI provider you use, and is my data used in model training?

Who else is in the chain?

An automation is rarely a single piece. Messaging infrastructure, database, email service, hosting provider. Each is a link in the chain and each may touch the data. Until that list is written out, where the data goes cannot be known.

Each link in that chain is also a security surface; where the threat can come from is covered in AI Cybersecurity.

Questions to ask in an automation conversation

Without going into technical detail, the following questions can clarify most of the picture:

Not getting answers is information too. If a question cannot be answered, that side probably does not know either.

These questions are the data side of the preparation list; the rest of that list is set out in Why Automation Projects Fail.

Notice and consent

If you process your customer’s data, you are expected to tell them. That is what a privacy notice is for: who processes which data, why, and what rights the person has.

Separate consent is not required for every processing activity. Processing necessary to perform a contract may rest on a different legal basis. For marketing communication, however, separate permission may be needed, and additional obligations can apply in that area.

The critical point when setting up an automation: on which legal basis does the system process which data, and is that written down?

Retention and deletion

Data is not kept forever. A retention period is expected for each data type, with deletion once that period ends. Automation can help here: the system can be built to track retention and delete records automatically once their time is up.

The question here is simple: does the system have a delete function at all, or does data merely accumulate? What happens in backups? Can a deleted record return from a backup?

What to look for in the contract

The data side is expected to appear under its own heading in an automation contract. At a minimum it is sensible to see the following in writing:

The non-data side of the contract can differ depending on whether the build is custom software or an off-the-shelf package; we compared the two routes in Custom Software vs Off-the-Shelf.

How we work

In the systems we build at Kılman Bilişim, data resides in the customer’s own installation. Our servers are hosted in Europe. A retention period is defined for chat records, and records past that period are deleted automatically.

Before any setup we map together which data goes where. The data processing side is handled as a separate heading in the contract, and we seek legal support on that point.

Frequently Asked Questions

Does an AI-based automation add data protection risk?

The risk usually comes not from automation itself but from not knowing where the data goes. Once you have written answers to which server holds the data, which third parties touch it and how long it is kept, the picture becomes clear. If those questions stay unanswered, the risk can remain no matter how well the system runs.

Will my customer data be used to train an AI model?

That depends entirely on the provider and the plan in use. Some providers contractually commit not to use business data for training, others retain it for a set period. It is reasonable to ask the firm setting up your automation to state in writing which provider is used and under which terms.

Is it a problem if my data sits on a server abroad?

Cross-border transfer follows its own rules and the same conditions do not apply in every case. What matters is the legal basis for the transfer and whether the required documentation exists. Learning which country the server is in is the first step; after that the matter may need review with a lawyer.

Should there be a separate data agreement with the firm that builds the system?

The relationship between the controller and the processor is expected to be put in writing. This usually takes the form of a data processing addendum to the main contract. It sets out which data is processed, for what purpose, for how long and on whose instruction. Without such an addendum the boundaries of responsibility can stay unclear.

Let Us Map Where Your Data Goes

Before proposing any setup, we walk through which data goes where. If a point stays unclear, we say so plainly.

💬 Get a Quote on WhatsApp

Conclusion

Setting up an automation does not remove responsibility for data. The firm that builds the system processes data on your behalf, but the party answerable to your customer is you. So alongside "what does the system do", the question "where does the data go" belongs too.

The good news: these questions are not complex and the answers can be obtained before setup. Where is the server, who touches the data, how long is it kept, how is it deleted. Four questions can clarify most of the picture.

Questions? Reach us on WhatsApp or Telegram.