Access and training are different contracts
When an AI provider says it "uses your data", it can mean two very different things. Using your data to answer a question, then forgetting it, is access. Using your data to improve its models, so that what it learned from you stays in the model, is training. Most contracts blur the two. The difference decides who ends up owning what your company knows.
Access: reading at the moment of need
With access, the AI reads the records a task needs at the moment it runs, from your systems, under your permissions. When the task ends, nothing of your data remains in the model. What the system learns comes from the results, the corrections your staff make and the outcomes of its work, all of which stay in your records.
Training: learning that stays
With training, your data becomes part of the model. It can shape answers given to other customers of the same provider. It cannot be withdrawn: deleting the source files does not remove what the model learned from them. Training on company data can be legitimate, but only on chosen, cleaned, anonymised data, under a contract written for that purpose.
Five clauses to put in writing
Retention: how long the provider keeps your data and the logs of its use.
Training rights: whether the provider may use your data to train or improve any model, including its general models.
Deletion: how fast and how completely your data is deleted on request, and how you can verify it.
Audit: your right to see what the provider holds about you.
Isolation: whether anything learned from your use is kept separate from what serves other customers.
The default to assume
If these five points are not written in the contract, assume the answer is the least favourable one: the provider keeps your data, may train on it, and decides when to delete it. Marketing pages and settings screens change; contracts are what you can enforce.
Read the contract before the first real document is sent, not after. It takes an hour, and it decides whether your know-how stays yours.