ChatGPT, Claude, Gemini and Grok are truly exceptional tools. They write fast, well and precisely. But every exchange with them produces data. And they store that data and use it.
So you have to watch what goes into these chats. In this article, I explain where your data goes, why you should think about it now, and what you can do from tomorrow.
Where does your data go when you use ChatGPT?
Short answer: to an external server, often abroad.

Last month, I was talking with a friend who works in a fairly regulated sector. They showed me a sales proposal made with the help of Claude Cowork. They were amazed by the result, by the power and precision of the tool, and by its speed.
I asked: “Aren’t you worried the data goes to foreign servers? It’s quite confidential.”
The answer: “No, no, it’s fine, it’s just on my computer.”
That is not true. Everything you do with an online tool goes to an external server. Even if the tool shows up on your screen.
This may seem obvious to many, but there are sometimes gaps in our understanding of these tools. That’s normal. But they need filling. If not for you, then maybe for your employees or colleagues.
You might also think: “My data is tiny.” But depending on your settings, that data can be reused. Not word for word. But for other people who ask the same questions as you. Your competitors, for example. Without meaning to, we share a little of our secret sauce with them. That is hard to square with the nFADP and the GDPR.
The exception here is Enterprise or API contracts, which usually protect you from this. But few SMEs have these costly contracts.
Why ask the question now?

Because now is when we lay the foundations. We are all making our transition to AI, more or less planned. And we are building a dependency.
The numbers show it. According to the AXA SME study (2025, carried out by Sotomo), 34% of Swiss SMEs have built AI into the way they work. Another 37% are testing it.
But only one third of the SMEs using AI have clear rules on data protection. In companies with 5 to 9 employees, it is only 23%.
And yet the risk is known. In a 2026 EY survey of Swiss companies, 19% of respondents named security and data protection as their biggest obstacle.
AI is arriving fast. Rules are arriving slowly. Things have to be in place from the start. You need to learn about the subject and understand why data must stay with us, safely. And not go off to a foreign server, sometimes with sensitive data.
The most common mistake: no AI policy

The mistake I see most often is sharing data without thinking about it.
And it’s not only the boss. Your employees take initiatives too. They use these tools. And the company’s data walks out the door.
This is what’s called shadow AI. An employee produces a very good report. But to get there, the company’s data went to external servers. Sometimes on their personal account, with their own ChatGPT or Claude subscription.
The answer is an AI policy. It’s like an HR code of conduct: what we do, what we don’t do. Here the question is simple: what can and can’t we do with the company’s data?
It’s a matter of protection. Not physical protection, but protection of your intellectual property.
And there is an upside. Give your employees the keys to tools the company has approved. An approved tool is one you agree to trust with some of the company’s data. So the results will be even more powerful and better.
The real price of AI is not 20 dollars a month

I’m quite strict about data protection myself. I check which server it is processed on and with which model.
That has a price. Sometimes I can’t use the most advanced models. Swiss and European models are less advanced, because they respect privacy a lot. You can see it in the benchmarks (the tests that compare models). And you feel it as a user. The very top models in terms of performance are American, or Chinese.
But you can still run very good, very powerful models in Switzerland or in Europe, without training on your data. It may cost a little more, but do we really need a hyper-powerful model for tasks that are often basic?
You don’t need a Ferrari to go and buy your bread.
And make no mistake: a 20-dollar-a-month subscription doesn’t let you do everything, almost without limits, for nothing in return. We all know it: “If it’s free, you’re the product.”
Today, that price is subsidised. These companies sell their models at a loss and create a dependency. My prediction: before long, the bill will go up, to 50 or 100 dollars a month.
What to do from tomorrow? And what not to do?

- Write an AI policy. Put down what can and can’t be done with the company’s data.
- Train yourself, and train your employees. Everyone needs to know where and how data leaves.
- Avoid shadow AI. Give your teams tools the company has approved.
- Look at your processes. What information goes into these chats? What shouldn’t?
- Consider the local option. A model running on your premises or in Switzerland may be the right answer for your sensitive data. Do a feasibility study first.
And one thing not to do: connect everything at once.
Today you can connect your email, calendar, drive, Slack and other tools to these platforms. Even your accounting or ERP. That really hands over all the keys to the company’s data. Yes, it’s powerful. But it’s also risky.
Before each connection, ask yourself two questions: is it useful? Is it necessary?
In short: get on the AI train, but get on it right
You have to get on the AI train. You have to adopt it. But you have to do it right.
Bringing one or more AI tools into your company is now a very important, very strategic decision. You are choosing a very close business partner. That choice must be made wisely and after careful thought.
That’s why I support companies: to show where the data goes, how it is processed, and how to keep it with us while doing just as much as with these powerful tools.
FAQ
Is it legal for a Swiss SME to use ChatGPT with client data?
Using ChatGPT is legal, but under the nFADP you stay responsible for the client data you put into it: you must know where it is processed, and data sent abroad needs adequate protection. In practice, keep client personal data and confidential documents out of consumer chats unless a contract covers them.
Can I stop ChatGPT from training on my data?
Yes. Most AI tools have a setting that stops your chats being used for training, and business plans usually have it off by default. It does not stop your data leaving for the provider's servers; it only limits how it is reused.
What goes into an AI policy for a small company?
One or two pages are enough: which tools are approved, which data must never go in (client personal data, contracts, finances, passwords), which tools may be connected, and who to ask when in doubt. Review it regularly, because the tools change fast.
Is a local AI model realistic for an SME?
Yes, for many everyday tasks. Summarising, drafting and sorting emails run well on open models hosted in Switzerland or on a company server. A feasibility study tells you which tasks need it and what the hosting or hardware costs.

