Customer data in ChatGPT and Claude: prepare the document first
Which details does the model need? A complaint example, the difference between anonymisation and pseudonymisation, and the cost of implementation support.
Syntalith
The model needs to help draft a response to a complaint. Does it need the customer's address, bank details and two years of correspondence? A smaller input is often enough: the relevant facts, timing and an approved extract from the returns policy.
Reduce the data before submitting it to the tool. Uploading a complete document and asking the model to anonymise it has already transferred that document to the provider. The company must approve that processing arrangement beforehand. GDPR requires personal data to be limited to what is necessary for the purpose. Article 5 GDPR
Worked example: preparing a complaint response
This is an illustrative workflow, without real customer data. An employee needs a draft about a damaged product and will review it before sending.
| Part of the case | Needed for this draft? | Preparation |
|---|---|---|
| Name, email and delivery address | Usually no | Remove before submission; the employee adds the recipient details later |
| Description of damage | Yes | Keep product facts and remove unrelated information about individuals |
| Purchase and complaint dates | If they determine the applicable response | Include only the necessary date or established time interval |
| Order number | Usually unnecessary for drafting | Use a local case reference if the output must be matched to a record |
| Returns policy | The relevant section | Provide the current version and a source reference |
| The customer's entire correspondence history | No | Select the messages relevant to this case |
An instruction could say: “Draft a response using the case description and policy extract. Identify the clause supporting your suggestion. List any missing fact an employee must check. Do not state that a refund has been approved.”
The expected output is clear: a proposed reply, its source and any unresolved questions. The employee still checks the facts, the policy version and their authority to make the decision.
Removing a name does not establish anonymity
If the company keeps a table linking a case reference to a customer, the information may be pseudonymised and still subject to GDPR. This can reduce exposure without removing data protection obligations. An unusual event, job title or combination of locations and dates may also identify someone.
The European Commission distinguishes data that can be linked back to an individual from irreversibly anonymous information. Covering two fields is not enough to promise anonymity. European Commission guidance
Documents can also contain comments, tracked changes, hidden sheets, metadata and attachments. Inspect the file that will actually be sent. Placing a coloured rectangle over text in a PDF may leave the underlying text retrievable.
When manual preparation becomes a bottleneck
For a few cases, an agreed template and employee review may be sufficient. At higher volumes, an integration can retrieve only the necessary fields, prepare an input and save the result for review. Access to the key linking a case reference to a customer should be restricted and separated from the data sent to the model.
That integration needs representative tests. Include personal data in comments, unexpected formats and messages mentioning a third party. Automated detection can miss details or remove useful information. Uncertain cases need a manual review path; a promise of perfect automatic anonymisation would be inappropriate.
Track correction work, preparation time and instances where unnecessary data enters the model input. A shorter prompt alone does not establish that the workflow is correct.
How Syntalith helps, and what to budget
When employees follow inconsistent practices, AI team training starts at €600 net per day. We can agree exercises covering document preparation and output review, using materials approved for the workshop.
When the data flow itself needs changing, an AI process audit starts at €600 net. Its core deliverables are a process map, architecture, implementation plan and fixed build quote. We agree the preparation and data-control scope for the particular task. Software subscriptions, integration development and legal advice are not automatically included in that fee.
Syntalith combines training with implementation work. Once the manual workflow has been tested, we can quote for automating it. This gives the company an opportunity to assess a smaller solution before commissioning a larger system. Book a free 30-minute process scan and describe the document types without sending customer records.
Related decisions
- Using personal AI accounts with company information
- DPA and GDPR decisions for an AI deployment
- Training opt-out and data retention
Sources and service prices checked on 30 September 2026. The company must establish the lawful basis and approved data scope with its responsible owner, involving its DPO or legal adviser where appropriate.
Syntalith is an OpenAI Select Partner in the OpenAI Partner Network.
We help your team respond to customers faster and find information in company documents. We choose and set up the right AI tools, then teach your team how to use them.
How to introduce ChatGPT and OpenAI at workFree process scan
Start with a free process scan.
- A 30-minute call with the engineer who would lead the work.
- A review of the processes that cost you the most time and money.
- A written summary: a possible direction, missing information and the next step.
The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.
€0
30 minutes · written takeaway within 2 business days
Times are shown in your own time zone. We work with clients across time zones.
Describe the process in the form