Website representations

Before support staff paste a customer conversation into an AI tool

Treat every paste as a transfer of customer data to another system, and authorize the transfer pattern before staff improvise it. Define the actual support purpose and the minimum content that purpose requires, verify the specific tool and plan's retention, training, and access terms from its current official documentation, and have the responsible owner record an authorized use decision. A paid account, a disabled-training toggle, or a vendor slogan does not by itself establish that the transfer is appropriate. Until that decision exists, customer-derived content stays inside existing approved systems; any drafting practice outside those systems uses invented, non-customer inputs only, and redaction by itself is not permission to transfer.

For: A support lead or owner at a research-only merchant whose staff want to use an external AI tool to draft, summarize, or translate customer conversations.

Updated 2026-10-01

Define the purpose and the minimum content first

Start with the task, not the tool. Summarizing a complaint theme, drafting a reply, and translating a message each need different content, and none of them obviously needs a customer's full name, address, order identifiers, or payment references. Under the UK ICO's articulation of the data minimisation principle, personal information should be adequate, relevant, and limited to what the purpose requires. That principle is UK guidance under review, but the underlying discipline travels well: if the purpose works with a redacted extract, the full conversation is not justified. The extract is still customer-derived information, so moving it to an outside tool needs the same authorization as any other transfer; redaction shrinks what is exposed without deciding whether the transfer is permitted.

Write down what a minimized working extract would look like for each task under evaluation: the issue type, the relevant order facts without identifiers, the customer's question in substance. While authorization is pending, staff can develop and test their drafting approach with invented, non-customer material only. What they cannot do is place customer-derived content, however heavily redacted, into a tool the owner has not approved.

Verify the actual tool, plan, and role before trusting it

ICO guidance on controller and processor roles makes a structural point that matters here: roles depend on who determines the purposes and means of each processing activity, not on what the vendor calls itself. When your staff paste conversations into a tool, you need to know what the provider does with that input under the specific product and plan you hold: whether inputs are retained, for how long, whether they train models, who can access them, and what the contract says. Those facts vary between products and tiers and change over time, so verify them from the provider's current official documentation for your exact plan.

Do not accept indirect evidence as a substitute. A colleague's assurance, a marketing page headline, or a remembered settings screen are not the current terms. If the retention and training behavior of your plan cannot be established from official documents, that is an unresolved finding, and unresolved means the transfer is not authorized yet.

Check authority on both sides of the transfer

Your own published privacy statements and any notices given at collection describe what you told customers about how their information is handled. A support-drafting use that sits outside those statements is a representation problem as well as a data-handling one. The policy owner should compare the intended tool use against the promises the store has actually made, with qualified privacy advice where the lawful basis or jurisdiction is uncertain.

Also confirm the tool's terms permit the use you intend and that your account is a business arrangement rather than a personal account an employee signed up for. An individual employee's personal AI account holding customer conversations is an access and retention problem regardless of that tool's terms.

Record the authorized pattern and the fallback

The owner's decision should be written as an operational rule: which tasks, which tool and plan, what content may be included, what must be redacted, and who approved it. Staff need a concrete permitted pattern, not a principle. Include the fallback: when a task does not fit the pattern, staff work inside existing support systems or escalate for a decision rather than improvising, and any experimentation outside those systems uses invented, non-customer material only.

Revisit the decision when the tool's terms change, the plan changes, or the tasks expand, and record the review date. If you want help aligning what your public privacy and policy pages say with a documented internal practice, that is a scoped website-review question you can raise with Prism; confirm the pages, scope, fees and terms before work begins.

Support-data handoff sheet

Complete before any customer material is transferred, and review on tool or plan change. Record evidence references and settings states, never conversation content. A tool is usable for a task only when every row is resolved for that task, and redaction alone does not resolve one.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Support-data handoff sheet. The last column is for temporary notes.
Handoff elementWhat it must establish before transferYour finding
Support task and its minimum contentThe defined purpose and the redacted extract that satisfies it, so full conversations are not transferred by default.
Specific tool, product and planThe exact service and tier under evaluation, since retention and training behavior differ between them.
Retention and training termsFrom current official documentation: whether inputs are kept, how long, and whether they train models.
Access and account typeWho can see the inputs, and that the account is an authorized business arrangement, not a personal signup.
Role analysisWho determines purposes and means for this activity, and what the contract says, assessed per activity rather than by vendor label.
Consistency with published noticesWhether your privacy statements and collection notices cover this use, flagged for qualified review if not.
Authorized pattern and ownerThe approved task/content/tool combination, the approver, and the review date.
Fallback for unapproved tasksThe instruction staff follow when a task is outside the pattern: customer-derived content stays in existing approved systems or is escalated for a decision; work outside those systems uses invented, non-customer inputs only, and redaction is never treated as permission to transfer.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • This page does not verify any specific AI product's retention, training, or access behavior; confirm your exact plan from its current official documentation.
  • UK ICO guidance cited here is jurisdiction-specific and under review; lawful bases and obligations elsewhere need qualified review.
  • A paid plan, a disabled training option, or vendor marketing language does not by itself establish suitability.
  • Never place conversation content, customer identifiers, payment data, or credentials in worksheets, public forms, or unapproved tools.

Sources

  • ICO: Data minimisation — checked 2026-10-01. Personal information should be adequate, relevant and limited to what the purpose requires, which supports defining the minimum content before any transfer.
  • ICO: Controller or processor roles — checked 2026-10-01. Controller and processor roles depend on who determines the purposes and means of each processing activity, not on an organization's label, so each actual activity and contract needs assessment.

Request a website review

Want a second look at your own storefront pages?