Before your business switches on any AI tool, here is what happens to your data, what the Privacy Act expects of you, and the questions to ask any vendor.
The question we hear most about AI is not "what can it do" but "where does my data go". It is the right question, and the honest answer is: it depends entirely on which tool you use and how it is set up. The difference between a free consumer chatbot and a managed business platform is not a detail. It is the whole ballgame.
Free tools versus a managed business platform
When someone pastes customer details, financials or staff information into a free consumer AI tool, that text typically travels offshore, may be stored on shared infrastructure, and depending on the provider's terms, may be used to improve the underlying model. Many of those tools say so plainly in their terms; almost nobody reads them. There is a second, quieter problem too: when the work happens in a personal account, it walks out the door with the staff member. The prompts, the pasted customer details and the useful outputs belong to their login, not your business, and when they leave you have no record and no way to switch it off. A managed business platform works differently: business accounts, dedicated or properly separated infrastructure, contractual commitments about what happens to your data, and an audit trail of who did what.
What the Privacy Act expects of you
If your business handles personal information, and if you are a clinic, an accountant, a school or any business with customer records, it does, the Australian Privacy Act and the Australian Privacy Principles apply to how that information is collected, stored and disclosed. The Office of the Australian Information Commissioner (OAIC) oversees this. In plain words: you are responsible for where your customers' and patients' information ends up, even when a third-party tool is doing the processing. This is not legal advice, and for your specific obligations it is worth talking to a professional, but the direction is clear. Choosing an AI tool is a privacy decision, not just a technology one.
Health, legal and finance businesses: extra care
If you run a clinic, an allied health practice, a law firm or an accounting practice, the bar sits higher. The Privacy Act treats health information as sensitive information, with stricter rules around how it is collected, used and disclosed, and legal and financial records carry their own confidentiality duties on top. In practice that means the consumer-grade tools and the default settings are simply not an option for anything touching patient, client or financial files, and the written answers to the vendor questions below stop being nice-to-have and become essential. This is general information, not legal advice, but the safe rule is simple: no sensitive information goes near any AI tool until the privacy side is settled in writing.
Questions to ask any AI vendor
Before your business switches anything on, ask these, and treat vague answers as answers:
- Where is our data stored, and in which country?
- Is our data used to train AI models, now or in the future?
- Who inside your company can see our data, and under what controls?
- How long is our data kept, and can we have it deleted?
- Is there an audit trail showing what the AI did and when?
- Is there an Australian entity we can actually deal with if something goes wrong?
How our arrangement answers those
We deploy XoomAgent™ through our partnership with XoomAI precisely because the answers hold up. XoomAI is Australian-owned, runs on dedicated infrastructure rather than a shared public service, and does not use your business data to train models. Every action the agent takes is recorded in an audit trail, and access is permissioned so the agent only touches the systems and mailboxes you have explicitly allowed. When you ask the six questions above, those are the kinds of answers you want to hear from any vendor, not just ours.
How long is it kept?
One question deserves its own moment: retention. Every conversation your business has with an AI tool is stored somewhere, for some length of time. You should know how long, and why. Kept forever, a conversation history becomes a growing pile of records you are responsible for protecting, including things pasted in by mistake. Deleted too aggressively, you lose the audit trail you would want if a customer dispute or a privacy question ever arose. There is no single right answer, but there is definitely a wrong one: not knowing. Ask the vendor, decide a period that suits your obligations, and write it into your rule sheet.
The staff side of the equation
Most AI privacy problems in small businesses do not come from the platform. They come from a well-meaning team member pasting something into a personal account on a free tool to save ten minutes. Three habits close that gap. First, give staff business accounts on the approved platform so the right way is also the easy way. Second, write a one-page rule sheet: what AI tools are approved, what they may be used for, and what never gets pasted in, such as health information, full financial records, passwords and anything you would not want read back to you in public. Third, say it out loud at a team meeting. A policy nobody has heard is not a policy.
A short readiness checklist
- List the information your business holds that would hurt if it leaked: customer records, health details, financials, staff files.
- Check which AI tools staff are already using, including personal accounts, without judgement, just honestly.
- Get written answers to the six vendor questions for any tool that will touch business data.
- Put business accounts and the one-page rule sheet in place before switching anything on.
- Decide who reviews what the AI does in the first month, and how often after that.
Red flags in an AI vendor's answers
Walk carefully if you hear: "we may use data to improve our services" with no opt-out, storage "in the cloud" with no country named, no audit trail available, no way to delete your data, or no local entity to hold accountable. Any one of those is a reason to pause.
AI done properly is safe enough for a regional clinic or a busy accountant, and we would not deploy it otherwise. The trick is doing it in the right order: questions first, guardrails second, switch on third. Our free AI Workflow Audit includes exactly this privacy walk-through alongside the workflow mapping.
Want to use AI with your data handled properly? Start with a free, no-obligation AI Workflow Audit.
Book a free AI audit- ai
- privacy
- data security
- small business
