Skip to content

Where Does My Data Go? The Question to Ask Every AI Vendor

Most AI vendors answer the data question with reassurance rather than architecture. Here is what to ask instead, and what a genuinely private design looks like.

By Karani Geoffrey, Founder & CEO, Upeosoft
In short

Ask any AI vendor exactly which data leaves your premises and which stays. The safest architecture keeps your records on your own server and sends only computed totals to the AI service, so raw invoices, customer details and transactions never travel. A vendor who can describe this precisely is safer than one who answers with reassurance about encryption.

Key takeaways
  • Vague answers about encryption are not answers to the data-location question.
  • The strongest designs send only aggregates - totals and rankings - to the AI service.
  • Ask what specifically leaves your building, and expect a precise reply.
  • A structural guarantee beats a contractual promise, because code paths do not change their mind.
  • Kenyan data protection law makes this a compliance question, not only a comfort one.
  • Check whether the design also protects the vendor - shared interests outlast goodwill.

The question that usually gets a non-answer

Every business owner asks it, right after the price: where does my data go?

What comes back is usually a reassurance rather than a description. Something about bank-grade encryption, something about certifications, and no actual account of what travels where. That is not necessarily dishonesty. Often the salesperson genuinely does not know, because nobody framed the architecture that way internally.

But you need the description, not the reassurance. "We take security seriously" tells you nothing you can act on. "Your invoices stay on your server and we receive only totals" tells you everything.

The three shapes an AI tool can take

Almost every AI product you will be offered falls into one of three patterns, and they differ enormously in what you are exposing.

  • Fully hosted: you upload or sync your data to the vendor's platform, and everything is processed there. Most convenient, most exposed.
  • Fully on-premise: everything runs on your own hardware. Most private, and you now operate an AI platform, with the cost and maintenance that implies.
  • Split: the intelligence is hosted, a small component on your server fetches data locally, and only computed results travel. Practical privacy without becoming an operator.

What a split design looks like in practice

The split pattern is worth understanding, because it is the one most likely to suit a Kenyan business that wants both privacy and someone else to keep the system running.

The hosted part holds the reasoning: how questions map to business measures, how advice is generated, how reports are phrased. The part installed on your server is deliberately simple. It authenticates, receives a plan describing what to fetch, runs that plan against your own database, and returns the result.

So the direction of travel is: your question goes up, a plan comes down, your own server does the work, and a small table of totals goes back up to be phrased into an answer. Your invoices, customer records and individual transactions never make the trip - because there is no code path that would send them.

Why structure beats promises

Any vendor can promise not to look at your data. The promise is worth what the company is worth, and companies get acquired, run short of money, and change their terms.

A structural guarantee is different. If the software installed on your server has no capability to transmit raw records, then no policy change at the vendor's end alters what happens on your premises. You could have it reviewed and confirm it for yourself.

There is a second thing to look for, and it is a good sign when you find it: does the architecture also protect the vendor? In a split design, the valuable intellectual property stays on the vendor's servers where it cannot be copied. That means their commercial interest points the same direction as your privacy interest - and arrangements built on shared interest survive pressure far better than ones built on goodwill.

The questions to put in the email

Send these to any AI vendor you are evaluating and ask for written answers. The quality of the replies will sort your shortlist faster than any demonstration.

  • Which specific data fields leave my premises, and in which direction?
  • Is any customer personal data transmitted or stored on your infrastructure?
  • Where is that infrastructure physically located?
  • How long is anything retained, and can I have it deleted?
  • Is my data used to train or improve anything, for any customer?
  • If part of the system is installed on my server, may I have it reviewed?

The compliance angle you own

It is worth being clear about who carries the risk. Under Kenya's Data Protection Act, the business holding personal data has obligations about how it is processed and where it goes. Your vendor has obligations too, but the exposure does not transfer away from you by signing a contract.

This makes the architecture question a compliance question rather than a preference. If customer personal data never leaves your premises, a large part of the assessment simply does not arise. If it is being shipped to a platform abroad, you need a lawful basis, a processing agreement, and a clear view of what happens to it - and you need those before the tool goes live, not after.

How Upeosoft builds this

We build business systems that run on our clients' own infrastructure, and when we add AI to them we keep the same principle: the reasoning can be hosted, the records stay home.

In practice that means the component we install on your server does data access and nothing else - no intelligence, no storage of your data elsewhere, only computed results going back. You can read it. Several of our clients have.

If you are weighing an AI tool and cannot get a straight answer about where your data goes, talk to us. We will tell you what to ask, and if the honest answer is that the tool you are looking at is fine for your situation, we will say that too.

Frequently asked questions

Isn't encryption enough to keep my data safe?

Encryption protects data while it travels and while it sits on a disk. It does nothing about who can read it at the other end, how long it is kept, or whether it is used for anything else. Encryption is necessary and it is not the answer to the question you asked. The question is what data arrives on someone else's server in the first place.

What does sending only aggregates actually mean?

It means the AI service receives a small table of totals - revenue by item last month, stock levels by category, the count of overdue invoices - rather than the underlying records. Your customer names, individual sales and supplier invoices stay where they are. Almost every business question is a question about totals and rankings anyway; the individual rows are how you compute them, not what you wanted.

Does Kenyan law require me to care about this?

The Data Protection Act places obligations on you as the business holding personal data, including where it goes and who processes it. Sending customer records to a service abroad without a proper basis is your exposure, not just your vendor's. Choosing an architecture where personal data never leaves your premises removes most of the question rather than answering it.

Is an on-premise AI the only private option?

No, and full on-premise brings its own costs - you maintain it, you patch it, you carry the hardware. The middle path is more practical: the intelligence runs as a hosted service, a small component on your server does the data access, and only results travel. You get privacy without becoming the operator of an AI platform.

How do I verify what a vendor tells me?

Ask for the answer in writing and in specifics: which fields, which direction, retained for how long. If part of the system is installed on your own server, ask whether you may have it reviewed. A vendor confident in their design will not object. Reluctance to be specific is itself information.

Karani Geoffrey
Karani Geoffrey
Founder & CEO, Upeosoft

Karani Geoffrey is the Founder & CEO of Upeosoft, a software and automation company rooted in Kenya. He builds custom software, AI systems, and production-grade ERPNext for businesses across East Africa, and writes about the Kenyan realities - eTIMS, M-Pesa, SHIF, unreliable internet and power - that make or break real systems.

Next step

Want this working in your business?

Upeosoft builds and hardens the systems behind this article - for real Kenyan operations, with eTIMS, M-Pesa and offline realities handled.

Keep reading

Kenyan Compliance and Integrations

The Kenya Data Protection Act: What Every Business Must Know

The Data Protection Act governs how Kenyan businesses collect and use personal data. It is not just for big tech - any business holding customer details has obligations.

6 min readRead article →
AI and Automation for BusinessBuyer's guide

An AI Business Analyst for Your Shop: What It Can Actually Tell You

Your shop already produces the data that would answer your hardest questions. An AI analyst is the thing that finally lets you ask them in plain language and get a real answer.

7 min readRead article →
Choosing Technology

How to Avoid Being Locked In by a Software Vendor

How founders keep the freedom to leave a software vendor, protecting data ownership and the ability to switch before lock-in makes it impossible.

9 min readRead article →