An AI support system needs enough information to answer the customer's question and, when authorized, carry out the requested action. Planning that data flow makes the system easier to operate: the right context reaches the right tool, and the team knows who owns access, retention and follow-up.
This guide is an operational starting point. The applicable privacy requirements depend on the business, customers, data and jurisdiction; a product label or security assessment does not settle those questions on its own.
Map the information used for each task
Start with one workflow, such as an order-status request. List the customer's message, the order information retrieved, the response and any support record created. Distinguish public product knowledge from account-specific data.
For each step, record:
- The information needed to complete the task.
- The system that supplies it and the vendor that processes it.
- Which people or tools can access it.
- Whether it appears in support history, diagnostic logs or analytics.
- The retention rule and the person responsible for it.
An order lookup may need an order reference and identity verification. It does not normally need the customer to type payment-card details into chat. Design the questions around the task rather than collecting a broad profile just because fields are available.
Define how account access works
Separate general questions from requests for personal order information. Test whether a person can retrieve another customer's details by changing an order number or claiming a different identity. Use dedicated accounts and permissions for integrations, and review what happens when an employee leaves or a connection is revoked.
For actions such as changing an order, also confirm who may authorize the action and what evidence of completion is retained. A tool returning an error should not produce a response saying the change succeeded.
Ask precise vendor questions
Use the same workflow when evaluating vendors so the answers are comparable. Ask where processing occurs, which subprocessors are involved, how customer data is used, and what controls apply to model training. Request the relevant contractual and technical documentation rather than inferring the answers from general marketing language.
Check encryption in transit and at rest separately. Neither phrase automatically means end-to-end encryption, where intermediaries cannot read the message. Also distinguish a security assessment's scope from the configuration of your particular integration.
For Chad-specific information, start with Chad's privacy policy and contact the team about the workflow and documentation your business needs.
Set retention and review responsibilities
Decide how long each category of record is needed and where that rule is implemented. Include backups, exported tickets and diagnostic systems in the discussion. Test the documented process for a data request using an approved test record, with someone responsible for confirming the result across connected systems.
Keep support purposes distinct from optional uses such as marketing or model development. The ICO's guidance on lawfulness in AI explains that different purposes need appropriate lawful bases; consent is not the only possible basis. Have the responsible privacy owner assess the actual use rather than treating consent as a universal answer.
Test useful service and data controls together
Build a small set of realistic cases using synthetic records. Include a normal lookup, an incorrect identifier, missing permissions, a revoked connection and a request requiring a human decision. Confirm both the answer and the information exposed along the way.
Review the handoff too: a human needs enough context to continue, but unrelated customer details should not be copied into every escalation. Re-run the relevant cases when an integration or workflow changes.
Assign an owner before expanding
Record who maintains knowledge, approves actions, reviews permissions and investigates failures. Use the AI agents versus chatbots guide to distinguish answering from acting, then evaluate support outcomes alongside those operating controls. The goal is a service that answers accurately with the context it needs and a process your team understands.


