Skip to content

Free checklist · Data Capital

Where is your data going?

Every AI tool your team uses sees some of your data, and some are allowed to keep it. This checklist finds each one, shows what its terms allow, and lists the contract clauses and settings that close the gaps.

  • 30 checks across tools, terms, contracts, people, controls, and value
  • A 10-question self-assessment with an instant score
  • Written for owners and managers, not lawyers

Get the data exposure checklist free

The download opens on the next page.

Self-assessment

Score your exposure in two minutes.

Ten questions. Your answers stay in your browser, and nothing is sent anywhere.

  1. 01 Do you have a complete list of the AI tools your team uses, including free accounts?
  2. 02 Do you know which of those tools may keep your inputs or train on them?
  3. 03 Are training opt-outs or business plans in place for every tool that handles client data?
  4. 04 Do you have a written AI-use policy that your team has read?
  5. 05 Have you checked client contracts and NDAs for limits on sharing their data with AI vendors?
  6. 06 Do your AI vendors have signed data processing agreements, and business associate agreements where needed?
  7. 07 Do meeting recorders and note-takers follow a clear rule for client calls?
  8. 08 Can you see who is using AI tools with company data?
  9. 09 Is sensitive data masked, or kept in a private deployment, before it reaches an outside model?
  10. 10 Do you know which of your data is valuable enough that you’d want to control or license it?

Answer all ten questions. Your answers stay in your browser.

Preview

What the checklist covers.

Six sections, thirty checks. Here are the first two from each section.

01

Inventory: where AI touches your data

You can only protect what you can see.

  • 1List every AI tool your team uses, including free accounts opened with personal email addresses.
  • 2Include AI features inside software you already pay for: email, documents, CRM, helpdesk, accounting.
  • + 4 more checks in the full checklist
02

Terms: what vendors may do with it

The same tool can have very different terms on different plans.

  • 7For each tool, check whether your inputs may be used to train the vendor’s models.
  • 8Check how long inputs and outputs are kept, and whether you can delete them.
  • + 4 more checks in the full checklist
03

Contracts: what you’ve promised, and what you’re owed

Your clients’ contracts may limit what you can share.

  • 13A data processing agreement is signed with every AI vendor that handles personal data.
  • 14Vendor contracts include no-training and deletion terms where the vendor offers them.
  • + 4 more checks in the full checklist
04

People and policy

Most exposure starts with a well-meaning copy and paste.

  • 19A short written AI-use policy says which tools are approved and what may go into them.
  • 20Approved tools are available, so nobody needs a personal account to get work done.
  • + 2 more checks in the full checklist
05

Controls

Settings and safeguards that hold even on a busy day.

  • 23Approved AI tools use single sign-on and company-controlled admin settings.
  • 24You can see who is using AI tools with company data.
  • + 2 more checks in the full checklist
06

Value: know what you’re protecting

Your data may be one of the most valuable things your business owns.

  • 27Identify the data that is uniquely yours: records, expert decisions, corrections, and outcomes.
  • 28Note where any of that data is already leaving the business.
  • + 2 more checks in the full checklist

Who it is for

Owners and managers responsible for client data.

  • Your team uses AI tools, and nobody has a complete list of them.
  • You hold client, health, or financial records with privacy obligations attached.
  • Client contracts or NDAs limit what you may share with third parties.
  • You want one named person to approve new AI tools.

How to use it

Work through it in order.

Each section builds on the one before it.

  1. Take the self-assessmentYour score points to the sections that need attention first.
  2. Finish the inventoryList every tool, account, feature, and contractor that touches your data.
  3. Check terms and contractsFor each tool, record what its terms allow, and compare that with what your clients’ contracts permit.
  4. Set policy and controlsWrite a short AI-use policy, name the person who approves new tools, and switch on account-wide settings.
  5. Record what is valuableNote the data that is uniquely yours, and who may approve any future use of it.

Get the full checklist.

A printable PDF with all thirty checks, ready to download on the next page.

The download opens on the next page.

Questions

Are my self-assessment answers sent anywhere?

No. The ten questions score in your browser, and nothing is sent. Only the email form sends information, so the checklist can reach you.

Is the checklist legal advice?

No. It is a practical checklist for owners and managers. Have your counsel review contract questions and any privacy obligations that apply to you.

Does it name tools or vendors?

No. It works by category, such as meeting recorders, writing assistants, and AI features inside software you already pay for.

How often should we repeat it?

Keep it on a quarterly calendar, and review terms whenever a vendor changes its plans.

What happens in a data exposure review?

A senior engineer spends fifteen minutes with you, free, on where your data is going and which gaps to close first.

Book a time