An employee asks an AI tool to summarise a contract, prepare a quotation, or turn construction site notes into a report. The time savings are real, but one question often remains unanswered: where does the information go, who can access it, and how can the company retrieve it if it switches tools? For a Swiss SME, data sovereignty is first and foremost about retaining the ability to decide. Here are the points to check before entrusting business data to an artificial intelligence service.
With AI, data does not stay in the chat window
The request leaves the computer or phone and travels over the internet to the provider's servers. It may pass through an authentication service, an application programming interface, and filtering tools. The model then processes it on the provider's infrastructure or that of a cloud service provider.
Depending on the service and contract, the request, the response, and technical data may be retained for a certain period. This may include conversation history, connection logs, IP address, account identity, error diagnostics, or security logs. Backups may follow a different deletion schedule. If the tool connects to an email system, document repository, or management application, data may also move between these services.
The main provider is not always the only party involved. Hosting providers, technical support teams, and other subprocessors may also have a role. Ask the provider to describe the data flow that applies to the selected plan rather than assuming a destination country.
An example from a construction site in French-speaking Switzerland
A construction manager uploads the minutes of a meeting to an AI assistant to extract a list of tasks. The document contains the client's name, the construction site address, subcontractors' contact details, a dispute over a defect, and perhaps photos showing workers or vehicle licence plates.
The AI can prepare a useful action list. But the information sent is not limited to technical notes. It may include personal data, contractual information, and commercial details. Before using the tool, the SME needs to know whether this information is retained, where it is processed, who can view it, and whether it is used to improve the service.
Sovereignty, security, and compliance: three different issues
These concepts overlap, but they are not interchangeable.
Sovereignty is about the ability to decide
For an SME, data sovereignty means controlling the information lifecycle: where data is processed, which parties are involved, authorised uses, access, export, and exit from the service.
A solution hosted in Switzerland can make some governance choices easier, but the location of the data centre does not answer every question. The SME must also know which entity signs the contract, which subprocessors are involved, where support is provided, who has remote access, and which laws apply to the various parties.
Security protects against incidents
Security aims to preserve data confidentiality, integrity, and availability. It relies, among other measures, on encryption, multifactor authentication, access rights management, and backups.
A service can be well secured while giving customers little choice over data location or portability. Conversely, local hosting does not make up for shared passwords or poorly configured access rights.
Compliance addresses specific obligations
Compliance means following the rules that apply to the company and the processing activity concerned. In Switzerland, the Federal Act on Data Protection (FADP) applies when personal data is processed, including through AI. The FDPIC notes that the FADP is worded in a technologically neutral manner.
The FADP sets out principles including transparency, purpose limitation, proportionality, and security. It governs outsourced processing and the disclosure of data abroad. Processing that is likely to result in a high risk to an individual's personality or fundamental rights may require a data protection impact assessment.
This is general guidance and does not replace legal advice tailored to a specific situation.
Which data requires the most attention?
Risk depends on the content and how it is used, not just on the name of the tool. In a construction company, several categories call for particular care:
- personnel records, medical certificates, salaries, or performance reviews;
- contact details for clients, tenants, suppliers, and employees;
- plans showing access points, alarm systems, or sensitive equipment;
- construction site photos in which people, vehicles, or homes can be identified;
- contracts, quotations, purchase prices, margins, and negotiated terms;
- correspondence relating to a dispute, loss event, or expert assessment;
- usernames, passwords, access keys, and construction site access codes.
The first step is simple: do not share anything the AI does not need. When rewriting a letter, the client's name can often be replaced with "Client A". When classifying construction site comments, the exact address or access code is generally unnecessary. Remove this information before sending the data.
Anonymisation still requires caution. The FDPIC notes that combining several datasets can sometimes make it possible to reidentify an individual. Removing a name is not always enough if the address, role, and context make the person recognisable.
Eight questions to ask before choosing an AI service
1. Where is the data processed and stored?
Ask which regions may be used for primary processing, logs, backups, and support. Check whether the location is contractually guaranteed. A statement such as "hosted in Europe" remains vague if it does not specify a country or transfer mechanism.
2. Which subprocessors may be involved?
The FDPIC notes that a company remains responsible when it entrusts processing to a processor. The company needs to know the cloud provider, any further subprocessors, and how changes to them are communicated.
3. Is content used for training?
The word "training" may cover model improvement, response evaluation, or test datasets. Terms vary between plans. Check the default setting, what an opt-out covers, and whether it is included in the contract for the plan purchased.
4. How long is the data retained?
Distinguish between visible history, logs, uploaded files, and backups. Ask what is deleted when a conversation or account is removed, and within what timeframe.
5. Who can access what?
Each employee should have an individual account. Permissions should reflect job responsibilities: a project manager does not need access to HR records, and an external contractor should see only the construction site relevant to their work. The company must be able to revoke access quickly, enforce multifactor authentication, and review activity logs if necessary.
6. Does the provider use the data for its own purposes?
The contract should state whether the provider acts only on the SME's instructions or reserves the right to use the data for other purposes, such as profiling, statistics, or support.
7. Can the data be exported and deleted?
Test portability before signing. In what format can conversations, documents, settings, and logs be retrieved? Can they be reused elsewhere? How does the provider confirm deletion after the customer leaves? Without clear answers, the SME becomes operationally dependent on the service.
8. What happens if the service changes or shuts down?
Prices, features, and models may change. The SME must be able to maintain a manual process, switch providers, and keep its business instructions outside the tool.
Lightweight governance suited to an SME
There is no need to create a fifty-page policy. A short policy can establish four levels: public, internal, confidential, and sensitive personal data. For each level, it can specify the authorised tools, the information that must be removed, and the required approval.
The SME can then appoint someone to oversee AI tools, maintain a list of approved services, and periodically review accounts and access rights. Employees need to know that a personal subscription may not offer the same terms as a business contract.
On a construction site, the assistant can structure voice notes, prepare a report, identify missing information in a request for quotation, or draft a follow-up email. It prepares the material. Before anything is sent, the person responsible checks the facts, amounts, contractual commitments, and technical decisions. This rule prevents a plausible response from being treated as a construction site instruction.
Retaining control without giving up useful applications
Data sovereignty does not require companies to host everything themselves. It means making informed choices about which data enters the tool, which parties handle it, which rules apply, and how the company can retrieve it.
A properly governed AI system remains an operational assistant. It sorts, summarises, prepares, and sends reminders. The SME retains decision-making authority and final approval. This is a practical way to put "AI that keeps your business running" to work in day-to-day operations without surrendering control of the information that gives the company its value.
Do you want to retain control of your AI and your data?
At NeoService, we operate our own servers and work with AI models fine-tuned for specific business needs. This approach gives us greater control over infrastructure, access, and data processing, rather than relying solely on consumer AI tools.
We can also design this type of environment for your company: hosting on suitable infrastructure, a model specialised for your use cases, and clear rules on permitted data. The aim is not to add yet another AI tool, but to give you an operational assistant that works within a defined framework and includes human validation.
Let us discuss your use cases and the data you want to keep under control.
Institutional sources
- Fedlex, Federal Act on Data Protection (FADP), SR 235.1: https://www.fedlex.admin.ch/eli/cc/2022/491/fr
- FDPIC, AI and data protection: https://www.edoeb.admin.ch/fr/ia-et-protection-des-donnees
- FDPIC, Using artificial intelligence in everyday life, practical examples: https://www.edoeb.admin.ch/fr/ia-au-quotidien
- FDPIC, Data processing in cloud computing: https://www.edoeb.admin.ch/fr/traitement-de-donnees-dans-un-nuage-informatique
- FDPIC, Outsourcing (processing by third parties): https://www.edoeb.admin.ch/fr/externalisation-sous-traitance
- FDPIC, Disclosure of data abroad: https://www.edoeb.admin.ch/fr/communication-de-donnees-a-letranger
- FDPIC, Data protection impact assessment: https://www.edoeb.admin.ch/fr/analyse-dimpact-relative-a-la-protection-des-donnees-personnelles
- FDPIC, Information security: https://www.edoeb.admin.ch/fr/securite-de-linformation
- Federal Office for Cyber Security (FOCS/NCSC), Information for businesses: https://www.ncsc.admin.ch/ncsc/fr/home/infos-fuer/infos-unternehmen.html
Un projet en tête ?
Discutons de vos besoins et voyons comment nous pouvons vous aider à gagner du temps grâce à l'automatisation et l'IA.
