Free guide · Before you sign up

8 questions to ask any AI vendor before you share data

A new AI tool looks great in the demo. The sales rep says your data is safe. Your team is excited. Before anyone uploads a donor list or a client file, ask eight questions, and get the answers in writing. This guide tells you what to ask, what a good answer sounds like, and what Canadian guidance says.

The short answer

Before you share data with any AI tool, ask the company eight things: Do you train your AI on our data? Where is our data stored, and who else handles it? How long do you keep it, and can we delete it? Who can see it? How do you keep it secure? Will you tell us about a breach, and how fast? How did you test the tool, and what are its limits? Can a person check the work first? Get every answer in writing, in the contract or terms, not just on a sales page.

Get the free Vendor Question Sheet →

Why this is your job, not the vendor's

Here's the part that surprises a lot of leaders. When you send personal information to a company to process for you, you're still responsible for it. Canada's privacy commissioner says an organization stays responsible for information it hands to another company, and should use contracts to make sure it gets a similar level of protection (Office of the Privacy Commissioner of Canada).

In plain words: "the vendor said it was safe" won't protect you, your donors or the people you serve. Asking good questions will.

And this isn't only about new tools. AI is showing up inside tools you already pay for, like your email, your donor database and your design software. Sometimes it's switched on without anyone telling you. The same questions apply.

The 8 questions

Send these to the company before its AI touches your work. Ask for answers in writing. A good vendor won't mind. Our free Vendor Question Sheet has a longer version with space for their answers.

1Do you use our data to train your AI?

This is the first question for a reason. If your data trains their AI, pieces of it could shape answers other people get. Free and personal versions of AI tools often have different privacy terms than business versions, so check the version your staff actually use.

Good answer"No. It's in our terms, and it's off for your account by default."
Ask more if"Only to improve the service," or you have to find a hidden setting to turn it off.

2Where is our data stored, and who else handles it?

Ask which country your data is stored and processed in, and which other companies (often called subprocessors) touch it. Many AI tools send your data to another company's AI model behind the scenes.

Good answerA named country and a published list of subprocessors.
Ask more if"In the cloud" or "It depends," with no list.

3How long do you keep it, and can we delete it?

You should be able to download all your data and have it deleted when you leave. Ask what happens to your data if the company is sold or closes.

Good answer"We keep it for [set time]. You can export and delete it anytime."
Ask more ifThere's no way to delete, or deleting means emailing support and hoping.

4Who at your company can see our data?

Some companies let staff read your conversations to check quality. That might be fine for public information. It's not fine for a client file.

Good answer"Only a small, named team, only to fix a problem, and every access is logged."
Ask more if"Our team reviews conversations to improve quality," with no limits.

5How do you keep it secure?

Ask whether an outside firm has checked their security. Common checks are called SOC 2 and ISO 27001. Also ask if you can turn on two-step sign-in for your team.

Good answerA recent outside audit report, and two-step sign-in you can require.
Ask more if"We take security very seriously," with no proof.

6Will you tell us about a breach, and how fast?

If something leaks, you may have to tell the people affected. You can't do that if the vendor doesn't tell you first.

Good answer"Yes, within a set number of days. It's in the contract."
Ask more if"We'd let you know if it affected you," with nothing in writing.

7How did you test it, and what are its limits?

Every AI tool makes mistakes. A trustworthy company can tell you how it tested the tool, which version, in which languages, and where it tends to go wrong. If you serve people in French or other languages, ask about those languages specifically.

Good answerA plain description of the testing, its known limits, and who did it.
Ask more if"It's very accurate," with no details or limits.

8Can a person check the work before anything goes out?

The tool should never send, post, delete or change records on its own unless you decide that. Ask whether its AI features are on by default, and whether you can turn off the ones you don't need.

Good answer"Yes. Nothing goes out without a person approving it, and you choose which features are on."
Ask more ifIt can act on its own, and you can't switch that off.

Red flags: stop and take a closer look

If you see any of these, pause. Talk to your AI lead before anyone shares data.

  • They won't say which country your data goes to.
  • They train on your data, and you can't turn it off.
  • You can't delete your data when you leave.
  • The AI can send, post or change records without a person saying yes.
  • The answers are only on a sales page, not in the contract or terms.
  • An AI feature was switched on without telling you.
Free tools need extra care. If a tool is free, ask how the company pays for it. Staff using free or personal accounts for work is one of the most common ways information leaves an organization without anyone noticing.

What Canadian guidance says

Canada doesn't have an AI law for nonprofits. But several Canadian sources say clearly what to ask vendors. Here's the short version.

  • Office of the Privacy Commissioner of CanadaYou stay responsible for personal information you send to another company to process. Use contracts to get a similar level of protection, and tell people if their information may be processed in another country (OPC guidelines).
  • Canada's privacy commissioners · December 2023Companies that offer generative AI should publish information about the data used to train their tools and tell you about known accuracy limits. Prompts shouldn't be kept or reused for other purposes unless that's required (Principles for responsible generative AI). So ask for that information.
  • Canadian Centre for Cyber SecurityContracts with AI vendors should include clear terms on how data is used, privacy, audits and who's liable, and you should ask for transparency and the right to audit (Top 10 AI security actions).
  • Canadian AI Safety Institute · July 2026Anyone reporting on AI safety testing should share five things: what the test was for, how it was done, the exact version tested, the limits of the results, and any conflicts of interest (CAISI). Use that list when a vendor says their tool is "tested."
  • QuebecIf you hold personal information about people in Quebec, Quebec's privacy law requires a privacy impact assessment before that information is sent outside the province, including to cloud services hosted elsewhere (McCarthy Tétrault).

Testing matters for another reason, too. In 2025, AI safety institutes from several countries, including Canada, tested AI helpers in nine languages. Safety results changed from language to language, and English wasn't always the safest (AI Security Institute, 2025). If you work in more than one language, ask about each one.

This guide is general information, not legal advice. For contracts that involve health, children's or other sensitive information, have a lawyer or privacy professional review the terms.

How to decide

You don't need a procurement department to do this well. Here's a simple way to run it.

AskSend the eight questions, or our longer Vendor Question Sheet, before anyone shares data. Ask for written answers.
CheckCompare the answers with the contract or terms. If the sales page says one thing and the terms say another, the terms win.
DecideYour AI lead says yes, yes with limits, or no. Write the decision and the limits in your AI register.

"Yes with limits" is often the right answer. For example: "OK for drafting public content. Never for client or donor information." That's a clear rule your team can follow.

If you don't have an AI lead or written rules yet, start there. Our guide to writing an AI policy walks you through it, and our board guide shows what your board should ask.

Sources worth your time

Questions people ask

Are tools like ChatGPT or Copilot safe for nonprofits?

It depends on the version and the settings. Business versions often have stronger privacy terms than free or personal ones. Ask the eight questions about the exact version your team uses, and keep personal information out of any tool you haven't approved.

Does our data have to stay in Canada?

Not always. But check your funding agreements and contracts, because some require it. If you hold information about people in Quebec, an assessment is required before it leaves the province. Either way, you should know which country your data is in.

What is SOC 2?

SOC 2 is a report from an outside auditor that checks a company's security controls. A Type 2 report checks that the controls worked over a period of time, not just on one day. ISO 27001 is a similar international certification.

What if a vendor won't answer?

That's an answer too. A company that won't say where your data goes or whether it trains on it shouldn't get your donors' or clients' information. You can still use it for public content if your policy allows.

Do these questions apply to AI features in tools we already use?

Yes. When your email, donor database or design software adds AI, ask the same questions. Check whether the feature was turned on by default, and turn it off if you haven't approved it.

We're a small nonprofit. Is this overkill?

No. Small organizations often hold the most sensitive stories with the fewest people. Eight questions and a written answer take less time than cleaning up after a leak.

Free Vendor Question Sheet

Send it before you sign up.

Our free AI Policy Kit includes a Vendor Question Sheet with sixteen questions, the red flags and a decision box, plus the policy, a staff card and an AI register to record what you approve.

Get the free kit →See Connected Systems

Want a second opinion on a tool before you commit? We help nonprofits choose and connect tools they can trust, now or when they're ready for AI. Book a Call →

If they won't put it in writing, don't put your data in it.

Updated October 2026. This guide is general information, not legal advice. Written with AI assistance. Reviewed by a person.