How we handle data

Processor, not storage party

And AI does not store client data. We configure and implement AI tools in your environment. You retain full control over your own data.

GDPR-compliant

All solutions we implement comply with European privacy legislation. For Team and Enterprise accounts this is contractually guaranteed.

Encrypted communication

All data transfer occurs via encrypted connections (TLS). Data at rest is stored encrypted at the provider.

No training on your data

With the right settings, your conversations and files are not used to train AI models. More on this below.

What AI can and cannot do

Claude operates within clear boundaries. This is what it can and cannot do in your work environment.

Claude can...

  • Read and write files in your designated folder
  • Perform web searches for up-to-date information
  • Execute multiple tasks in sequence

Claude cannot...

  • Access system files or passwords
  • Take any action without your permission
  • Permanently delete files without confirmation

Training on your data?

Whether your data is used to train AI models depends on your account type and settings.

Account Training on your data?
Team / Enterprise No, never. Contractually guaranteed.
Pro / Max (personal) On by default. Disable via Settings > Privacy.
Free Yes.

For Pro and Max accounts you will find the "Help improve Claude" setting under Settings > Privacy. Disable this to prevent your conversations from being used for model training. For Team and Enterprise accounts this is off by default and contractually guaranteed.

Certifications

Anthropic (maker of Claude) holds the following certifications and standards.

SOC 2 Type I & II

Independent audit of security controls and processes.

ISO 27001:2022

International standard for information security management.

ISO/IEC 42001:2023

Standard for AI Management Systems.

CSA STAR Level 2

Cloud Security Alliance certification for cloud security.

Frequently asked questions

Is it safe to use sensitive business documents?

With the right settings, conversations are not used for training and are deleted after 30 days. All data travels via encrypted connections.

Be aware that data routes through US servers. For organisations with strict EU requirements we recommend a Team account or a solution via AWS Bedrock in an EU region.

Can Claude see my entire laptop?

No. Claude only works in the folders you designate. It cannot access system files, passwords or other sensitive locations.

Every sensitive action (such as deleting files) requires explicit permission. The sandbox prevents AI from accessing anything outside your working directory.

What if I accidentally share something sensitive?

Conversations can be deleted via claude.ai. When the training toggle is off, your data is not used for model training and is wiped from servers within 30 days.

For Team and Enterprise accounts, data is never used for training regardless of individual settings.

Is Claude GDPR-compliant?

Anthropic offers a Data Processing Agreement (DPA) and Standard Contractual Clauses (SCC) for European customers. Data is processed on servers in the United States.

Need full EU data residency? That is possible via AWS Bedrock or Google Vertex AI, keeping your data within a European region.

Questions about data security?

We are happy to help you set up a secure AI environment for your organisation.

Get in touch