Home/AI & your data

AI & your data

Last updated: 2026-08-17

Onebase has two AI surfaces, and they handle data very differently. This page explains exactly what is sent where, how long we keep it, and who is responsible for what under GDPR.

1. Two AI surfaces

  • The help assistant (built-in): answers questions about how Onebase works. It has no tools and no access to your records — it cannot read, count or change anything. Ask it “how many projects do I have?” and all it can do is show you where to look yourself.
  • Bring your own Claude (MCP/API): you may connect your own Claude account to Onebase. The AI then acts as you (your role, your company, your access) and can read and change your own data. This is optional and must be connected actively.

2. What is actually sent to Anthropic

From the help assistant: your question, the help-article index, your locale, and your workspace’s name, country, currency and local date (so it can answer in the right language with the right dates). Plus any files you choose to attach to a message — images, PDFs and text files. Attach a document containing personal data and that personal data is what gets sent. Nothing is pulled from your records on its own.

From bring-your-own-Claude: the records the AI fetches to answer what you asked — customers, projects, hours, HR. It pulls on demand, not in bulk.

3. What the AI can reach

  • The help assistant reaches nothing. It has no tools.
  • Your own connected Claude never sees more than you can see — it runs through exactly the same role, tenant and access checks as your browser does.
  • Blocked from the AI surface regardless of your role: platform administration, billing, privacy tooling (export/DSAR/erasure), API keys and the assistant itself — plus a handful of irreversible actions (transferring ownership, removing a member, deleting your own account, GDPR-erasing a contact).
  • If you only want Claude to read, connect the read connector alone. No write tools exist on it at all.
  • Special categories (health, sick leave) are not technically blocked — the AI does what you can do. As the controller you decide what gets queried. We recommend keeping them out.
  • Everything your connected AI changes lands in the audit log with source “mcp” or “api” — attributed to you, with a timestamp and a before/after.

4. How it is protected at Anthropic

  • Anthropic is a data processor under a DPA with EU Standard Contractual Clauses (SCCs), transferring via the EU-US Data Privacy Framework where applicable.
  • Anthropic does not train its models on commercial/API data, and holds SOC 2 Type II, ISO 27001 and ISO 42001.
  • Important: neither surface runs with zero data retention at Anthropic. What you send — including an attachment in the help assistant — is retained by them under their standard retention. So share as little as needed.

5. How long we keep the conversations

  • Conversations and attachments are stored in Onebase so you can read your history back.
  • You can delete a conversation yourself, at any time, from the history in the side rail. Its messages and attachments go with it.
  • A conversation untouched for 24 months is deleted automatically by the daily sweep — the same window as the audit log.
  • A file you put in the composer but never send is cleared by the daily sweep — it is never kept more than a day.
  • Delete your workspace and the conversations go with it. Note that what has already been sent to Anthropic follows their retention — our deletion does not reach in there.

You can request a machine-readable export of your workspace data — including the assistant conversations — and of everything we hold on one individual, at any time (Settings → Privacy).

6. Who is responsible for what

  • You (the business) are the data controller. You decide what data is shared with AI, hold the lawful basis, and inform your employees.
  • For the help assistant, Shopsy AS is the processor and Anthropic the sub-processor — that use is covered by our data processing agreement.
  • For bring-your-own-Claude, it is your own agreement with Anthropic that applies. We provide the gateway: access as you, a block-list for the sensitive parts, and an audit trail.

7. What you should do

  • Have a lawful basis for the data you let the AI process.
  • Tell employees/customers in your privacy notice that AI may be used and that data may go to Anthropic in the USA.
  • Keep health/sick-leave and national ID numbers out of the AI — including out of attachments in the help assistant.
  • Ask narrowly — minimize what is shared.

See also our sub-processor list, our data processing agreement and Anthropic’s DPA. This page is information, not legal advice.

Shopsy AS

Org. no. 933 666 603

Gustav Bjerkes veg 4 E

2040 Kløfta, Norway

post@shopsy.no