Data protection in daily work
What belongs in a chat, how to check pseudonymisation, when security mode fits and how to handle images, web search and shared chats.
Custodos protects personal data technically: detected details are pseudonymised, models run in the region your admin sets, and sensitive conversations can be held in security mode. The rest comes down to habits. This page sums up the most important ones, for members and for whoever sets the rules in the team.
What belongs in a chat and what does not
| Kind of content | Example | Recommendation |
|---|---|---|
| General, no personal data | Draft text, Excel formula, translation | Normal chat |
| Business content with some personal data | Email to a client, minutes with names | Normal chat with pseudonymisation |
| Client and personnel files, health details, payroll data | Employment reference, payroll list, a client's contract | Security mode, if your admin offers it |
| Credentials | Passwords, e-banking codes, keys | Never, in any mode |
| Data you may not pass on under a contract | Documents under a non-disclosure agreement | Clarify first, then decide |
Only include what the task needs. For an email about missing documents, the model needs neither a date of birth nor an AHV number.
Using pseudonymisation well
In the Pseudonymise protection mode, which is recommended for most workspaces, Custodos replaces detected names, addresses, email addresses, phone numbers, IBANs, AHV numbers and card numbers with placeholders before sending. In the reply it puts the real values back. You can see your workspace's settings in Account settings under How your data is handled here.
How to work with it:
- Watch the notice below the message box. It shows how many values were detected. A click opens the list.
- Expect gaps with names. A surname without a first name or salutation can be missed, and company names are usually not detected. Write "Ms Keller" instead of "Keller". Or open the list from the notice and add the value with Add, or by selecting it in your message. A value added this way is pseudonymised throughout the chat, including in attachments.
- Have recurring values set up as a rule. An admin can store client names, customer numbers or project names under Settings in Custom rules, for example as Exact text or Prefix + digits. Then nobody has to remember them.
- Use Send original only for a reason. If a product or company name is wrongly detected as a name, you can send it unchanged for this chat with Send original.
- Check when in doubt. If something in your message was pseudonymised, Show what the model received below it shows exactly what the model saw.
How detection works in detail and where its limits are is in How pseudonymisation works.
When security mode fits
Security mode is for conversations where nothing should be left to chance. You turn it on in a new chat with the lock in the message box, if your admin offers it. Then:
- Only the model your admin chose for it answers. The model menu is locked.
- Pseudonymisation is always on, even if the workspace is otherwise set to Off.
- No web search, no images, and the model does not search Outlook or cloud storage on its own.
- Send original is disabled.
After the first message, the mode cannot be switched off in that chat. So decide before you start whether a conversation will be sensitive. In fiduciary and law firms it pays to have new chats start in security mode automatically. An admin sets that up. See Security mode.
Client data and professional secrecy
If you work under a statutory duty of professional secrecy or a contractual confidentiality obligation, clarify with your own legal or data protection adviser whether and under which conditions you may process client data with Custodos. Take with you:
- the Custodos data processing agreement and privacy policy,
- your workspace's processing region and where the allowed models run, see Where your data lives,
- your settings for protection mode, security mode and retention.
Record the outcome in writing, for example as a short internal rule, and share it with the team. Answers to typical questions from IT and data protection are in Questions from IT and data protection.
Attachments, images and screenshots
- Documents such as PDF, Word or Excel are checked just like your message. In Pseudonymise mode, detected values go to the model as placeholders.
- Images and screenshots cannot be checked. The model sees whatever is in an image, unchanged. Crop out or black out names, account numbers and addresses beforehand. For that reason you cannot attach images at all in the Block protection mode or in security mode.
- Scanned PDFs without a text layer cannot be read in chat. Attach the pages as images, with the same care as for screenshots.
Web search
With a web search, only the query the model writes goes to the search service, never the conversation. If a query contains an AHV, IBAN, card or UID number, Custodos does not send it in Pseudonymise or Block mode. Even so, do not have the model search for private individuals or clients by name unless you need to. Security mode never searches. See Web search.
Share chats with care
A shared chat is read-only, and that includes new messages you write later. Attached files stay with you; others only see their names.
- Share with Selected people rather than Everyone in the workspace when the chat contains client data.
- For a new, sensitive topic, start a separate chat instead of continuing a shared one.
- Remove the share with Only me when it is no longer needed.
Admins can turn sharing off for the whole workspace. See Sharing and finding chats.
Brains and integrations
- A brain has its own data protection level, independent of the workspace protection mode. Only put documents with personal data in brains with the matching level and access. See Building a good brain.
- Emails from Outlook and files from cloud storage are checked in chat like attachments. Your connection belongs to you alone; nobody else can use it.
Tidy up
- Delete chats you no longer need from the chat's menu in the sidebar.
- Admins can set, under Settings in Retention, that conversations are deleted automatically after a number of days.
Frequently asked questions
No. Admins see usage and cost, but no message content. The activity log never contains chat content either. Only people you share a chat with yourself can read it.
Name detection relies partly on a list of first names. A product or company name that looks like a first name is therefore replaced too. In the list below the message box, send it unchanged with Send original. If this happens all the time, an admin can switch off the name category for the workspace, but then real names are no longer replaced either.
Not necessarily. Detection finds typical details such as names, addresses and numbers, but not context. "The managing director of our biggest joinery client is ill" contains no name and can still identify a person. That is what security mode is for, and your own judgement.
That depends on your profession, your contracts and your company's rules. Clarify it with your own adviser and record the rule for the team. The technical basis is in Security and privacy overview.
Next steps
The notice, the list and restored answers in detail.
Security modeWhat the mode guarantees and when to turn it on.
Configuring data protectionProtection mode, categories and custom rules for admins.
Rolling out AI in your teamMake the data protection ground rules clear from the start.
Building a good brain
One brain per audience, only current documents, clear instructions, the right access and real test questions, then answers and sources are right.
Rolling out AI in your team
A plan for teams of 5 to 50 people, with a named owner, five tasks as a starting point, 30 days week by week, a kickoff, ready-made messages and measuring success.