The short answer

Pasting a customer export into a chatbot hands over every column — names, emails, phone numbers, notes — to a tool you may not control, with no audit trail and no way to take it back. Under UK and EU data protection law that's processing personal data, so it needs a lawful basis, only the data you need, and the right agreement with the provider.

The safer pattern is to let the AI ask questions of your customer system through a governed connection: each person gets their own named access, sees only what they could already see, receives the minimum answer to each question rather than raw records, can add suggestions but not change or delete anything, and loses access the moment it's revoked.

AI assistants are genuinely good at the questions a sales team asks every morning. Who's worth a call today? What did this customer look at before their appointment? Which quotes from last month are still open? So people use them, and the quickest way to give an assistant something to work with is to export a spreadsheet of customers and paste it in. It works. It's also the least safe way of doing it, and it's almost certainly already happening somewhere in your business.

What actually happens when someone pastes an export

  • Everything goes. An export has every column, including the ones the question didn't need: phone numbers, addresses, private notes, purchase history.
  • It's copied into places you don't control. Chat histories, possibly the provider's logs, possibly — depending on the plan and settings — material used to improve their models.
  • There's no audit. Nobody can say later who shared what, when, or with which tool.
  • There's no off switch. When the person leaves your business, the copy doesn't leave with them.
  • It's stale by lunchtime. The export is a snapshot; the answers get worse as the day goes on.

What data protection law expects

This isn't legal advice, and the details depend on your circumstances. But the principles in UK and EU data protection law are well established, and the UK regulator, the ICO, publishes guidance on AI and data protection. In short:

  • Putting customers' personal data into an AI tool is processing it, so you need a lawful basis for doing so.
  • Data minimisation applies: use only what the task needs.
  • Security and accountability apply: you should know where the data went and be able to show it was protected.
  • Your agreement with the AI provider matters: business plans typically come with data-processing terms that consumer plans don't.
  • Transparency matters: your privacy notice should reflect how you use customer data.

A spreadsheet pasted into a personal chatbot account struggles on almost every one of those.

Why AI is still worth it for a sales team

None of this means keeping AI away from your customers. The questions it answers well are exactly the ones a showroom team needs answering:

  • "Who's worth a call this morning?" — the abandoned baskets, the customer who has circled the same piece for three weeks, the good customer gone quiet.
  • "Brief me on my two o'clock." — what they're worth, what they've been looking at, their open quote, what they already own and what colleagues have noted. The preparation that usually takes a dozen browser tabs, or more often doesn't happen.
  • "Which quotes from last month are still open?"
  • "Draft a follow-up for the customer who asked about delivery." — a draft for a person to read, change and send.

The question isn't whether to use AI with customer data. It's how to let it in without handing over the database.

Five controls to insist on

  1. Named access per person. Every connection belongs to a specific person or a specific named agent. No shared, workspace-wide key that nobody owns.
  2. Scoped to what that person already sees. An associate who works in one showroom gets that showroom's customers through their AI, not the whole business.
  3. Minimum answers, not exports. The AI gets the answer to the question it asked, with only the fields that answer needs. Internal identifiers, technical data and raw records stay behind.
  4. Add-only. If the AI can write at all, it should only be able to add — a note, a suggested follow-up, a draft for a person to approve. It shouldn't be able to change, delete, send or publish anything.
  5. Revocable instantly. Switching off a person's access should stop it on the next request. When someone leaves your team, their AI access should go with their account.

And one more that ties them together: everything the AI writes is signed with the access that wrote it, so a note from an assistant is always distinguishable from a note from a colleague.

What MCP is, and why it helps

The Model Context Protocol (MCP) is an open standard for connecting AI assistants to tools and data. Instead of pasting data into the assistant, you connect the assistant to your system, and it asks questions through a set of defined tools — "find customers with open quotes", "get this customer's brief" — that your system answers.

That shift matters for safety because the rules live on your system's side of the connection. The system decides what each tool returns, strips what shouldn't leave, checks who's asking and what they're allowed to see, and can refuse. The assistant never holds the database; it holds answers. Connecting usually means pasting a URL into the assistant and signing in, with no keys to copy around.

A short policy your team can follow

AI and customer data: our rules

  • Never paste customer exports or lists into an AI tool.
  • Use the connected assistant, signed in as yourself, for questions about customers.
  • Don't enter sensitive details — health, finances, anything a customer told you in confidence — into any AI tool.
  • Treat AI suggestions as suggestions. Read every draft before you send it, and send it yourself.
  • If an answer looks wrong, say so. If something went where it shouldn't, tell your manager straight away.

Questions to ask any vendor about AI access

  1. Does the AI receive raw records, or shaped answers to specific questions?
  2. Can the AI write anything? Exactly what, and can it change or delete anything?
  3. Is access per person, and scoped to what that person can already see?
  4. How fast does revoking access take effect?
  5. Is everything the AI writes attributed to the access that wrote it?
  6. Are you running your own AI model on our customer data? If so, where, and under what terms?
  7. Can anything the AI does reach a customer without a person approving it?

Where Stitchwork fits

Stitchwork doesn't ship an AI model. It gives the one your team already uses a governed door into your customer data. Connect Claude, or any MCP client, by pasting one URL: sign in, approve, done, with no client IDs or secrets to copy.

Every connection is a named seat that an admin grants, and each seat sees exactly what its holder already sees — an associate's AI gets their store, not the estate. Every answer is stripped to the minimum for the question asked; private notes, hashed IP addresses and raw records never leave. The AI reads, and the three things it can write all add: a note on a customer's file, a follow-up on a colleague's list with a draft message the colleague sends from their own tools, and a proposed website nudge that can't appear until a person turns it on. It can't change, delete, send or activate anything, and nothing it writes reaches a customer without a person carrying or approving it. Revoke a seat and it's off on the next request; seats are never metered on questions.

Whether your AI provider uses what it's shown for training is that provider's policy, set by your plan with them, not ours to promise. What Stitchwork controls is how little it's shown. See how the connection works, or read the AI agents documentation.

Questions people ask

Is it safe to put customer data into ChatGPT or another chatbot?

Pasting customer lists into a consumer chatbot account is the riskiest way to use AI with customer data: everything goes, it can't be audited or withdrawn, and the provider's terms may allow more than you'd expect. Business plans with data-processing terms are safer, and a governed connection that returns minimum answers under named, revocable access is safer still.

Does using AI with customer data break GDPR?

Not in itself. It's processing personal data, so the usual rules apply: a lawful basis, only the data you need, appropriate security, the right agreements with providers, and transparency with customers. How you connect the AI makes a large difference to how easily you can meet those rules. Take advice on your own situation.

What is an MCP server?

A service that exposes tools and data to AI assistants using the Model Context Protocol. The assistant connects to it, discovers the tools available, and calls them to answer questions, while the server decides what each tool returns and who may use it.

Can an AI assistant send messages to our customers?

It depends on the system. A safe design lets the AI draft a message and puts it in front of a colleague, who reads it, changes it and sends it from their own email or phone. Nothing reaches the customer without a person deciding it should.

Will our customer data be used to train AI models?

That depends on your AI provider and your plan with them; business plans commonly exclude your inputs from training by default. Check your provider's terms. Independently of that, the less the AI is shown, the less there is to worry about, which is why minimum answers matter.

Sources

  1. Information Commissioner's Office, "Guidance on AI and data protection".
  2. Model Context Protocol, the open specification.

The Stitchwork teamWe build clienteling software for showroom retail: one record of each customer across your website, your floor and your sales team. See what Stitchwork does.