Vendor questions: retention, processing and audit
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
The questions worth asking any AI vendor, and what a good answer looks like. Written as questions because the answers change and yours may differ.
Procurement questionnaires for AI vendors tend to be either a generic SaaS form that misses everything specific, or forty pages nobody answers well. A short list of the questions that actually distinguish vendors serves better.
Ask these in writing, for the plan you are buying, and keep the answers with the date attached.
Training and retention
Are our inputs used to train models? The one question where consumer and commercial offerings usually diverge sharply, and where a per-user toggle may exist that your users control rather than you. Establish which contract governs your accounts, since people frequently assume the wrong one.
How long is data retained, and under what circumstances does that change? Retention often varies with the training answer. Get both numbers together.
What happens on deletion? A good answer distinguishes removing content from an account, removing it from backups, and the fact that no provider can retroactively remove data already incorporated into model weights. A vendor that promises complete erasure has told you something useful about their candour.
Processing and location
Where does processing happen, and can we constrain it? For agentic products the answer may differ per mode, and a default can put local files on the vendor's servers without anyone choosing that.
Who are the subprocessors, and how are we told when they change? Notice periods on subprocessor changes are worth more than the current list.
Is there a zero-retention or regional option, and what does it cost in capability? Sometimes a restricted posture rules out specific models or features. Better to learn that during procurement.
Audit and evidence
What is captured in an audit trail, and what is not? The gap matters more than the coverage. Ask specifically whether every execution mode is captured, because local or on-device modes often are not.
Can we export it, and can we delete it centrally? These are separate questions with separately disappointing answers.
Is observability tooling offered as audit logging? Streaming events to a SIEM is useful and is not the same as a compliance record. A vendor who says so unprompted is being straight with you.
Contract and change
How are terms changed, and what notice do we get? Terms in this sector have changed materially and at short notice.
What are the security and incident commitments? Notification timelines, not adjectives.
What is the exit path? Export format, timescale, what survives.
What a good answer sounds like
Specific, dated, and willing to name a gap. "Local sessions are not captured in the compliance API and deletion endpoints for them are not yet available" is a better answer than a paragraph about commitment to privacy, because you can act on it.
Treat vagueness on retention or audit coverage as a finding rather than as sales language.
What goes wrong
Assuming the plan you bought is the plan your people use. Personal accounts sit under different terms, which is a provisioning problem before it is a contractual one.
Accepting a marketing page as an answer. Ask for it in writing, against your plan.
Asking only about the current subprocessor list. The change-notice mechanism outlasts the list.
Confusing observability with audit.
Filing the answers without a date. These change, and an undated answer cannot be checked for currency.
How to check it worked
Pick the three answers that most affect your risk assessment and see whether each names a specific mechanism, a number, or a timescale. Answers that survive rephrasing as "so, concretely, what happens when…" are the ones you can rely on.
Sources
- How long do you store my data? — Anthropic Privacy Center Tier 1 2026-08-31
- Updates to our Consumer Terms and Privacy Policy — Anthropic Tier 1 2026-08-31
- EDPB Opinion on AI models and personal data (Dec 2024) Tier 1 2026-08-31
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.