July 22, 2026
ChatGPT at Work: What Data Really Reaches the AI Provider?
Prompts, files, and chat history: what ChatGPT sends to its provider, how Free, Plus, Team, and Enterprise differ, and when Swiss hosting matters.
ChatGPT has become part of everyday work at many Swiss SMEs. Summarising a proposal, drafting a client letter, explaining a spreadsheet: the value is immediate. At the same time, one central question often goes unanswered: which data actually leaves the company, and what happens to it next?
The short answer is that everything employees enter into a chat or upload must be processed for the service to respond. Whether that content is also retained, reviewed by people for quality purposes, or available to improve models depends on the product in use, its settings, and the contract. For businesses, that distinction is decisive.
This article provides practical context for Swiss companies. It is not legal advice and does not replace a review of your provider’s current terms—yet that review belongs before any broad rollout.
What data is sent to ChatGPT?
The service receives more than the words in your question. Depending on how it is used, this can include earlier messages in the same chat, uploaded files, images, spreadsheets, voice input, content retrieved from connected services, and technical usage data. The model’s response is also generated as part of the interaction and may appear in the chat history.
- Prompts and responses: names, customer numbers, contract excerpts, or internal figures remain personal or confidential data, even when they appear in only one sentence.
- Chat context: when a new question is asked in an existing conversation, the context needed to answer it is generally sent as well.
- Metadata: account, timestamp, IP and device information, and usage data can be collected for operation, security, and billing.
- Connected sources: with connectors or GPTs linked to external services, further data flows to the respective third parties may arise.
The most important rule for employees is therefore simple: a prompt is not a fleeting note on a personal laptop. Treat it as a disclosure to an external service provider.
What happens to uploaded documents?
When you upload a PDF, Word document, or spreadsheet, the provider has to read and process the file or its content to summarise it, answer questions about it, or extract information. Depending on the feature, text, tables, images, and metadata may be involved. The file can also remain associated with the chat or a configured GPT until it is deleted under the applicable retention rules.
That matters especially for HR files, contracts, customer data, financial records, and material subject to professional secrecy. Before uploading, ask not only whether the document is useful, but whether it contains personal data, trade secrets, or information subject to confidentiality; who can access it afterwards; and how deletion can be demonstrated.
What does the revised Swiss Data Protection Act require?
The revised Swiss Data Protection Act (FADP, or DSG) does not impose a blanket ban on AI tools. It does require companies to process personal data lawfully, proportionately, and transparently, and to take appropriate technical and organisational security measures. A company that uses an external AI provider remains responsible for its own data processing.
- Purpose limitation and data minimisation: send only data needed for the specific purpose. A customer text can often be worked on with names and references replaced.
- Processing by a third party: clarify which data the provider processes on your behalf, which instructions and security measures apply, and which sub-processors are involved.
- International disclosures: examine where data is stored and processed and whether transfers abroad require appropriate safeguards.
- Sensitive personal data: health data, HR information, and other sensitive categories call for especially careful risk assessment and access control.
Additional rules may apply by industry, including professional secrecy, FINMA guidance, contractual confidentiality obligations, or the GDPR. A tool that is acceptable for an innocuous marketing idea may be inappropriate for a patient report or a personnel file.
What are the practical risks?
- Shadow AI: employees use personal Free or Plus accounts without the company knowing the rules, contracts, or data flows involved.
- Too much context: a complete contract or an entire email thread often contains far more data than the question requires.
- Unclear access: shared chats, GPTs, connectors, and administrator roles can expand the set of people and systems able to see or process content.
- False reassurance: disabling training does not resolve questions about data residency, foreign jurisdiction, retention, or confidentiality.
- No traceability: without central policies and audit logs, it is difficult to establish later who entered which data into an AI tool and why.
When is ChatGPT enough?
ChatGPT can be highly useful for individual tasks involving public, anonymised, or deliberately non-sensitive content: structuring ideas, improving general copy, summarising a publicly available guide, or explaining code with no customer connection. Clear guidance, trained employees, and the appropriate account and data settings are prerequisites.
A personal chat account is not the default route for documents that must be centrally governed, regularly updated, released by role, or processed with traceability. Once real business processes, confidential knowledge, or multiple teams are involved, more than a chat tab is needed.
When do you need a platform like yeos?
An enterprise platform makes sense when AI should work on approved company documents, be embedded in existing workflows, and remain controllable. The decisive factors are not just the model, but permissions, data location, citations, logs, and the entire data lifecycle.
- yeos separates knowledge collections and roles, so an agent can access only the documents approved for its task.
- Source-backed answers show which documents support a response instead of asking teams to trust an unsupported summary.
- Audit logs help establish what was asked, which sources and tools were used, and what actions took place.
- With Swiss hosting and processing at Infomaniak, infrastructure remains in Switzerland and under Swiss jurisdiction.
A simple decision rule
The more sensitive the data and the more repeatable the use case, the less a solution should depend on individual copy-and-paste decisions. Use a general chat for general content. For internal documents and real business workflows, establish a controlled platform, a reviewed contract, and clear accountabilities.
That turns AI from an unexamined data outflow into a tool that demonstrably serves your business—under rules you set yourself.