Guide · AI agents

Use AI at work. Keep your data in the office.

What happens to company data in public AI tools, what on-premise AI changes, what PDPA expects — and what to ask any vendor.

By HeySheep · 7 min read · Last checked

Your office

  • The AI model
  • Document reading (OCR)
  • Your files and records
  • Staff, in a browser
  • The audit trail

No cloud AI by default

Public AI services

  • Pasted text and uploads
  • Their logs and history
  • Bills that grow with use

In short

Private AI means the AI runs where you control it — on a server in your office or in your own cloud account — so documents, prompts and answers don't go to a public AI service. On-premise AI keeps the model and the files inside your network. Either way, PDPA still applies to personal data: use it for a proper purpose, protect it, keep it only as long as needed, and know where it goes. Ask every vendor where the AI runs, what it logs and whether your data trains its models.

01The problem

What happens when staff paste company data into public AI tools

Staff already use public AI chat tools to summarise contracts, draft replies and read spreadsheets. Whatever they paste or upload leaves the company: it is processed on the provider's servers, may be kept in logs or chat history, and — depending on the plan and its settings — may be used to improve the provider's models.

  1. A contract is pasted inTo get a quick summary.
  2. It leaves the companyProcessed on the provider's servers.
  3. It may be keptIn logs or chat history, by plan and settings.
  4. Out of your recordsWho sent what, and when, isn't in your own audit trail.

That matters for personal data (NRIC numbers, salaries, customer details), for confidential terms in contracts and quotes, and for anything a client asked you to keep private.

02Three options

Public AI, private cloud AI or on-premise AI?

There are three ways to give staff AI. The right one depends on the data they'll put into it.

Public AI toolPrivate cloud AIOn-premise AI
Where the AI runsThe provider's serversA cloud account you controlA box in your office
Where your files goTo the providerTo your cloud accountNowhere — they stay on your network
Without internetStopsStopsBuilt to keep working on the office network
How it's billedPer user, or per useUsually per useUsually a fixed fee
Best forPublic information and general writingTeams with cloud engineersConfidential, personal and regulated data

03PDPA

What Singapore's PDPA expects when AI touches personal data

The Personal Data Protection Act doesn't ban AI. It applies to personal data wherever that data is processed — including inside an AI tool. Five of its obligations matter most here.

Purpose and consent

Use personal data only for purposes people were told about, or that an exception covers.

Protection

Make reasonable security arrangements — including over who, and what, can read the data.

Retention

Don't keep personal data longer than you need it.

Transfers abroad

Personal data sent outside Singapore must get a comparable standard of protection.

Accountability

Be able to show what you did with the data, and why.

PDPC's advisory guidelines on the use of personal data in AI recommendation and decision systems (March 2024) explain how consent and its exceptions apply when AI systems are built and deployed. Keeping AI and data in your own office doesn't remove these duties, but it makes them much easier to show. This is general information, not legal advice.

04Inside the box

What on-premise AI looks like

With on-premise AI, a small server sits in your office. The AI model, the document reading and the files all live on it, and staff use it in a web browser on the office network.

  1. Staff ask in a browserOn the office network.
  2. The agent reads the filesOn the box, within that person's access.
  3. The model answersOn the box — no cloud AI by default.
  4. Approvals and the audit trailKept on the box, too.

Collie works this way. Each department gets its own agent on the box, nothing goes to a cloud AI by default, and any module that would send something out — such as emailing a report through your own mail server — says so before you switch it on.

05Protections

Protections to expect from any private AI

Ask for these whoever you buy from. Collie has all six built in.

Department walls

Each team's agent sees only that team's sources. IT sees the system's health, never its content.

Masked numbers

NRIC/FIN, card and bank account numbers masked in what the AI shows and logs.

Tamper-evident audit trail

Each entry chained to the last and sealed daily, so any change shows. It records who, what and when — not the content.

Approvals

Anything that moves money waits for a person, who approves the exact action, once.

Private chats

Staff chats stay private, even from the owner, unless the person chooses to share.

Encrypted files

Files encrypted at rest on the box.

06Vendor questions

Questions to ask any AI vendor

Put these in writing before anyone uploads a document.

0 of 8 checked

Sources

Checked 12 October 2026. Rules and prices change — confirm what applies to your business with the official source.

FAQ

Common questions.

What is private AI?

AI that runs where you control it — on a server in your office or in your own cloud account — so prompts, documents and answers don't go to a public AI service.

Is it safe to use public AI chat tools with company data?

It depends on the tool's plan and settings, and on the data. Personal data and confidential documents pasted into a public tool leave your company and may be kept by the provider. Set a policy, use business plans with data controls, or use private AI for anything sensitive.

Does PDPA allow using AI on personal data?

Yes, within its obligations: a proper purpose and consent (or an exception), reasonable protection, limited retention, and comparable protection for transfers abroad. PDPC's 2024 advisory guidelines explain how this applies to AI systems. This is general information, not legal advice.

What is on-premise AI?

AI that runs on hardware inside your own premises: the model, the document reading and the data stay on your network, and staff use it through a web browser.

Does Collie send our data to the cloud?

No. Collie runs on a box inside your office. Nothing leaves by default, and HeySheep doesn't train AI on your data.