What to check with every provider
Where data is processed and stored. How long prompts and outputs are kept. Whether your data is used to train models, and whether you can opt out. Which sub-processors are involved. What security certifications the provider holds. How you can delete data. These details are usually in the business terms or data-processing addendum, not the marketing pages.
Design to minimise exposure
Keep your master records in your own systems, such as your CRM, accounting software and file storage, and send the AI only what a task needs. Remove or mask identifiers where possible. For overseas transfers of personal data, the PDPA requires you to ensure comparable protection, which business-grade contracts are designed to provide.
In ForceMX departments, data stays in the client's own accounts and access is controlled and logged.