Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Artificial Intelligence

Where should you draw the line when giving company data to AI?

Your employees are probably already pasting customer emails, proposal texts or spreadsheets into AI tools. The real question is not whether to ban it, but which data may be entered and under what conditions.

A sales rep pastes a difficult customer email as-is into a chat tool to draft a reply. Someone in accounting uploads the customer account list and asks the tool to "summarize this." Both are trying to work faster, but both may be transferring company data and personal data to a third party without realizing it. Sharing company data with AI tools is not forbidden outright; what matters is knowing which data goes to which tool and under what conditions. In this article we lay out the basic framework from a privacy and KVKK (Türkiye's Personal Data Protection Law) perspective in plain terms. It is not a substitute for legal advice; we recommend consulting a lawyer about your own situation.

Where does data typed into AI go?

The text you type into a chat tool is sent to the service provider's servers to generate the answer. From that point on, three questions matter:

  • Where is it processed? The servers are usually outside Türkiye.
  • How long is it kept? Conversation history, logs kept for abuse monitoring and backups may be subject to different retention periods.
  • Is it used for model training? In some free or personal editions, the default setting may allow data to be used to improve the service. In business editions this is usually turned off, but you should always verify it against the current contract and privacy terms.

In other words, the free and business editions of the same brand can lead to very different outcomes for your data. When deciding, look at the terms of the edition you use, not the product name.

What changes under KVKK?

If the text entered into an AI tool contains information that identifies a person (name, phone number, email, address, health information and so on), this counts as data processing under Law No. 6698 on the Protection of Personal Data. Your company is the data controller for that processing. The main points are:

  • Legal basis and purpose. Personal data must be processed in a way that is linked to the purpose it was collected for and proportionate to it. Sending information a customer gave you for a proposal to an AI service for another purpose may conflict with this principle.
  • Duty to inform. The person whose data is processed must be told for what purpose and to whom their data may be transferred. If your privacy notices do not cover transfers to AI services, they may need updating.
  • Cross-border transfer. Sending personal data to a service whose servers are abroad may count as a cross-border transfer. Article 9 of the law was restructured by an amendment in 2024; transfers now rely on routes such as an adequacy decision, appropriate safeguards (for example standard contractual clauses) or limited exceptional cases. Check the current text on the website of the Turkish Personal Data Protection Authority.
  • Data security. Who can access which tool, how accounts are managed and how records are deleted are also part of the measures the data controller must take.

Classify your data: green, yellow, red

Rather than deciding on each piece of data one by one, a simple classification works in most companies:

ClassExampleIn an AI tool
GreenPublished website text, general industry information, drafts with no personal dataMay be entered into approved tools
YellowInternal correspondence, anonymized reports, proposal templates without pricesOnly in the business edition, with care
RedCustomer personal data, health data, salary information, contracts, passwords, source codeNot entered unless there is an approved private setup

This table also forms the skeleton of a written AI usage policy for your team.

Is anonymization always the answer?

Removing names, phone numbers and addresses before giving data to a tool is a good habit. But deleting only the name from a text is not always enough; when job title, city and event details come together, the person can still be identified. Trade secrets (cost structure, special pricing, supplier lists) also need protection even though they are not personal data. See anonymization as a useful step, but not as the only safeguard.

What if off-the-shelf tools are not enough?

If you need AI that works with red-class data (for example, searching a contract archive or answering questions from ERP data), a controlled setup should be considered instead of a general chat tool. In this setup the data stays on your own infrastructure, only the necessary passage is sent to the AI service, ideally stripped of personal data, access rights are defined per user and every query is logged. A structure like this is a custom software and integration job; it is hard to achieve with an off-the-shelf plugin.

Checklist

  • The edition and data terms of every AI tool in use are known.
  • The setting for sending data to model training has been checked.
  • The data classes (green, yellow, red) have been shared with the team.
  • Privacy notices have been reviewed to see whether they cover transfers to AI services.
  • The legal basis for cross-border transfer has been assessed.
  • Tool accounts are managed by the company, not held personally.

How we do it at Globya

In every AI solution we build, we first map the data flow: where the data comes from, where it goes, who sees it and how long it stays. If personal data is not needed we do not send it at all; if it is, we work with the minimum. Under our approach to KVKK, requirements such as privacy notices and record-keeping are built into the project at no extra charge. If a broader effort is needed, we handle it as a single point of contact through our KVKK compliance service.

Frequently asked questions

If we use a business edition, can we enter any data?

No. Business editions generally offer better data terms, but KVKK's rules on purpose limitation, informing data subjects and cross-border transfer still apply. Red-class data needs a separate assessment.

How do we stop employees from using AI with personal accounts?

Stopping it completely is hard; the most effective approach is for the company to provide an approved tool and explain in a clear policy what may and may not be entered. A ban on its own usually leads to hidden use.

Can data sent to an AI service be deleted?

That depends on the service provider's terms. Retention periods and the ways to request deletion are set out in the contract or privacy terms; they should be checked before choosing a tool.

Anything on your mind about this article?

The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.

Ask the assistant

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.