Data Practices
AI Data and Client Information Practices
How is client information handled when AI tools are involved?
Client information shared during engagements is not used to train public AI models. Martin Zialcita applies explicit controls to which AI tools receive client data, under what conditions, and for how long. This page documents what information is collected, which third-party tools may process it, how long it is retained, and what access controls are in place. Clients retain ownership of their information throughout.
64-word direct answer
What this page is, and what it is not
This page documents how Martin works with data and AI systems: the practices he holds himself to, and the ones he asks clients to hold him to. It is a statement of practice, not a legal notice.
For what this website collects, see the privacy policy. For how data is handled inside a paid engagement, the governing document is the written agreement with AI Marketing Box, which is where commercial work is delivered.
Scope of this document
This document covers how client and project information is handled when AI tools are used during consulting, implementation, and workshop engagements delivered by Martin Zialcita. It applies to information shared directly with Martin and to information that may be processed by third-party AI tools used in the course of that work.
It does not cover martinzialcita.com site-visitor data, which is addressed in the Privacy Policy. AI Marketing Box, which handles commercial scoping, contracting, and billing, maintains its own data practices.
What client information is collected
The information collected during an engagement depends on the scope of the work. Typical categories include:
Categories of client information
- Organizational context: structure, workflows, team roles, and process documentation shared to enable the work.
- System and integration details: names of tools, platforms, APIs, and data sources used in the client’s environment, discussed or documented for integration purposes.
- Business goals and constraints: priorities, timelines, and resource considerations shared to inform strategy and design.
- People information: names and roles of internal team members participating in the engagement, to the extent necessary to design training or handover.
- Documents and artifacts: content, templates, process guides, or data samples shared to inform the work, governed by the engagement agreement.
- Communications: emails, messages, and meeting notes generated during the engagement.
Model-training posture
Client information is not used to train public AI models.
When AI tools are used in an engagement, the selection of those tools considers whether the provider’s terms allow them to use submitted data for model training. Tools that do not offer API or enterprise access with appropriate data-use restrictions are not used with client data without explicit client consent.
Specific controls applied:
Controls on model-training use
API or enterprise tier preferred
AI tools are accessed via API or enterprise tiers where the provider’s terms restrict data use for model training, rather than through consumer-facing interfaces that may have different terms.
Provider terms reviewed before use with client data
Before using a new AI tool with client information, the data-use provisions of its current terms of service are reviewed.
Sensitive data minimized
Client data is scoped to what is necessary for the task. Personally identifiable information, financial details, and confidential business data are not submitted to AI tools unless the tool and the engagement agreement support that use.
Client-owned accounts where practical
Where an AI tool requires an account and will process client data regularly, using the client’s own account for that data is the preferred approach, keeping processing under the client’s direct relationship with the provider.
Current AI tool subprocessors
The following AI platforms may process client information in the course of engagements. This list is updated when tools are added or removed.
| Tool / Provider | Typical use | Data-use provision relied on |
|---|---|---|
| OpenAI (API) | Drafting, summarization, workflow analysis | API terms: data is not used to train models by default as of current terms. |
| Anthropic Claude (API) | Analysis, structured document work | API terms: data submitted via API is not used for training by default. |
| Google Gemini (Workspace / API) | Document processing, search integration | Workspace Admin terms where applicable; API terms otherwise. |
| Make / Zapier (automation platforms) | Workflow and integration automation | Data processor under automation contract; data passes through, not stored long-term by default. |
Provider terms change. This table reflects conditions as of the reviewed date. Clients may request the current provider terms for any tool used in their engagement.
Retention and deletion
Engagement documents and communications are retained for the duration of the engagement plus a reasonable period for follow-up and dispute resolution, typically twelve months after engagement close unless a longer period is required by contract or law.
At the end of the retention period, client materials are deleted from working systems. Where cloud storage is used, deletion follows the provider’s data removal procedures, which are confirmed before use.
Clients may request deletion of their information at any time. Requests are handled within 30 days. Deletion cannot extend to information that must be retained under a legal obligation or an active dispute.
Access control
Client information is handled by Martin Zialcita personally. Access to client files, communications, and AI tool outputs is limited to the personnel directly involved in the engagement.
The following controls are applied:
Access control measures
- Client documents are stored in password-protected cloud accounts with two-factor authentication enabled.
- Sharing permissions are scoped to the engagement; no client’s files are accessible to another client.
- Subcontractors or collaborators who require access to client information sign confidentiality agreements before access is granted.
- Access is revoked at engagement close.
Client rights and contact
Clients retain ownership of their information throughout an engagement and after. They may request access to, correction of, or deletion of their information at any time. Requests can be made through the contact page at /contact/.
Questions about AI tool selection, data handling for a specific engagement, or this document can also be directed through that route.