Guides

Data protection in daily work

What belongs in a chat, how to check pseudonymisation, when security mode fits and how to handle images, web search and shared chats.

Custodos protects personal data technically: detected details are pseudonymised, models run in the region your admin sets, and sensitive conversations can be held in security mode. The rest comes down to habits. This page sums up the most important ones, for members and for whoever sets the rules in the team.

This page is not legal advice. Whether you may process certain data with an AI service depends on your profession, your contracts and your industry.

What belongs in a chat and what does not

Kind of contentExampleRecommendation
General, no personal dataDraft text, Excel formula, translationNormal chat
Business content with some personal dataEmail to a client, minutes with namesNormal chat with pseudonymisation
Client and personnel files, health details, payroll dataEmployment reference, payroll list, a client's contractSecurity mode, if your admin offers it
CredentialsPasswords, e-banking codes, keysNever, in any mode
Data you may not pass on under a contractDocuments under a non-disclosure agreementClarify first, then decide

Only include what the task needs. For an email about missing documents, the model needs neither a date of birth nor an AHV number.

Using pseudonymisation well

In the Pseudonymise protection mode, which is recommended for most workspaces, Custodos replaces detected names, addresses, email addresses, phone numbers, IBANs, AHV numbers and card numbers with placeholders before sending. In the reply it puts the real values back. You can see your workspace's settings in Account settings under How your data is handled here.

How to work with it:

  • Watch the notice below the message box. It shows how many values were detected. A click opens the list.
  • Expect gaps with names. A surname without a first name or salutation can be missed, and company names are usually not detected. Write "Ms Keller" instead of "Keller". Or open the list from the notice and add the value with Add, or by selecting it in your message. A value added this way is pseudonymised throughout the chat, including in attachments.
  • Have recurring values set up as a rule. An admin can store client names, customer numbers or project names under Settings in Custom rules, for example as Exact text or Prefix + digits. Then nobody has to remember them.
  • Use Send original only for a reason. If a product or company name is wrongly detected as a name, you can send it unchanged for this chat with Send original.
  • Check when in doubt. If something in your message was pseudonymised, Show what the model received below it shows exactly what the model saw.

How detection works in detail and where its limits are is in How pseudonymisation works.

When security mode fits

Security mode is for conversations where nothing should be left to chance. You turn it on in a new chat with the lock in the message box, if your admin offers it. Then:

  • Only the model your admin chose for it answers. The model menu is locked.
  • Pseudonymisation is always on, even if the workspace is otherwise set to Off.
  • No web search, no images, and the model does not search Outlook or cloud storage on its own.
  • Send original is disabled.

After the first message, the mode cannot be switched off in that chat. So decide before you start whether a conversation will be sensitive. In fiduciary and law firms it pays to have new chats start in security mode automatically. An admin sets that up. See Security mode.

Client data and professional secrecy

If you work under a statutory duty of professional secrecy or a contractual confidentiality obligation, clarify with your own legal or data protection adviser whether and under which conditions you may process client data with Custodos. Take with you:

  • the Custodos data processing agreement and privacy policy,
  • your workspace's processing region and where the allowed models run, see Where your data lives,
  • your settings for protection mode, security mode and retention.

Record the outcome in writing, for example as a short internal rule, and share it with the team. Answers to typical questions from IT and data protection are in Questions from IT and data protection.

Attachments, images and screenshots

  • Documents such as PDF, Word or Excel are checked just like your message. In Pseudonymise mode, detected values go to the model as placeholders.
  • Images and screenshots cannot be checked. The model sees whatever is in an image, unchanged. Crop out or black out names, account numbers and addresses beforehand. For that reason you cannot attach images at all in the Block protection mode or in security mode.
  • Scanned PDFs without a text layer cannot be read in chat. Attach the pages as images, with the same care as for screenshots.

With a web search, only the query the model writes goes to the search service, never the conversation. If a query contains an AHV, IBAN, card or UID number, Custodos does not send it in Pseudonymise or Block mode. Even so, do not have the model search for private individuals or clients by name unless you need to. Security mode never searches. See Web search.

Share chats with care

A shared chat is read-only, and that includes new messages you write later. Attached files stay with you; others only see their names.

  • Share with Selected people rather than Everyone in the workspace when the chat contains client data.
  • For a new, sensitive topic, start a separate chat instead of continuing a shared one.
  • Remove the share with Only me when it is no longer needed.

Admins can turn sharing off for the whole workspace. See Sharing and finding chats.

Brains and integrations

  • A brain has its own data protection level, independent of the workspace protection mode. Only put documents with personal data in brains with the matching level and access. See Building a good brain.
  • Emails from Outlook and files from cloud storage are checked in chat like attachments. Your connection belongs to you alone; nobody else can use it.

Tidy up

  • Delete chats you no longer need from the chat's menu in the sidebar.
  • Admins can set, under Settings in Retention, that conversations are deleted automatically after a number of days.

Frequently asked questions

Next steps

On this page