Guide · AI agents
Use AI at work. Keep your data in the office.
What happens to company data in public AI tools, what on-premise AI changes, what PDPA expects — and what to ask any vendor.
Your office
- The AI model
- Document reading (OCR)
- Your files and records
- Staff, in a browser
- The audit trail
No cloud AI by default
Public AI services
- Pasted text and uploads
- Their logs and history
- Bills that grow with use
In short
Private AI means the AI runs where you control it — on a server in your office or in your own cloud account — so documents, prompts and answers don't go to a public AI service. On-premise AI keeps the model and the files inside your network. Either way, PDPA still applies to personal data: use it for a proper purpose, protect it, keep it only as long as needed, and know where it goes. Ask every vendor where the AI runs, what it logs and whether your data trains its models.
01The problem
What happens when staff paste company data into public AI tools
Staff already use public AI chat tools to summarise contracts, draft replies and read spreadsheets. Whatever they paste or upload leaves the company: it is processed on the provider's servers, may be kept in logs or chat history, and — depending on the plan and its settings — may be used to improve the provider's models.
- A contract is pasted inTo get a quick summary.
- It leaves the companyProcessed on the provider's servers.
- It may be keptIn logs or chat history, by plan and settings.
- Out of your recordsWho sent what, and when, isn't in your own audit trail.
That matters for personal data (NRIC numbers, salaries, customer details), for confidential terms in contracts and quotes, and for anything a client asked you to keep private.
02Three options
Public AI, private cloud AI or on-premise AI?
There are three ways to give staff AI. The right one depends on the data they'll put into it.
| Public AI tool | Private cloud AI | On-premise AI | |
|---|---|---|---|
| Where the AI runs | The provider's servers | A cloud account you control | A box in your office |
| Where your files go | To the provider | To your cloud account | Nowhere — they stay on your network |
| Without internet | Stops | Stops | Built to keep working on the office network |
| How it's billed | Per user, or per use | Usually per use | Usually a fixed fee |
| Best for | Public information and general writing | Teams with cloud engineers | Confidential, personal and regulated data |
03PDPA
What Singapore's PDPA expects when AI touches personal data
The Personal Data Protection Act doesn't ban AI. It applies to personal data wherever that data is processed — including inside an AI tool. Five of its obligations matter most here.
Use personal data only for purposes people were told about, or that an exception covers.
Make reasonable security arrangements — including over who, and what, can read the data.
Don't keep personal data longer than you need it.
Personal data sent outside Singapore must get a comparable standard of protection.
Be able to show what you did with the data, and why.
PDPC's advisory guidelines on the use of personal data in AI recommendation and decision systems (March 2024) explain how consent and its exceptions apply when AI systems are built and deployed. Keeping AI and data in your own office doesn't remove these duties, but it makes them much easier to show. This is general information, not legal advice.
04Inside the box
What on-premise AI looks like
With on-premise AI, a small server sits in your office. The AI model, the document reading and the files all live on it, and staff use it in a web browser on the office network.
- Staff ask in a browserOn the office network.
- The agent reads the filesOn the box, within that person's access.
- The model answersOn the box — no cloud AI by default.
- Approvals and the audit trailKept on the box, too.
Collie works this way. Each department gets its own agent on the box, nothing goes to a cloud AI by default, and any module that would send something out — such as emailing a report through your own mail server — says so before you switch it on.
05Protections
Protections to expect from any private AI
Ask for these whoever you buy from. Collie has all six built in.
Each team's agent sees only that team's sources. IT sees the system's health, never its content.
NRIC/FIN, card and bank account numbers masked in what the AI shows and logs.
Each entry chained to the last and sealed daily, so any change shows. It records who, what and when — not the content.
Anything that moves money waits for a person, who approves the exact action, once.
Staff chats stay private, even from the owner, unless the person chooses to share.
Files encrypted at rest on the box.
06Vendor questions
Questions to ask any AI vendor
Put these in writing before anyone uploads a document.
0 of 8 checked
Sources
- PDPC — Data protection obligations under the PDPA
- PDPC — Advisory Guidelines on the use of personal data in AI recommendation and decision systems (PDF)
- PDPC — Model AI Governance Framework
Checked 12 October 2026. Rules and prices change — confirm what applies to your business with the official source.
FAQ
Common questions.
What is private AI?
AI that runs where you control it — on a server in your office or in your own cloud account — so prompts, documents and answers don't go to a public AI service.
Is it safe to use public AI chat tools with company data?
It depends on the tool's plan and settings, and on the data. Personal data and confidential documents pasted into a public tool leave your company and may be kept by the provider. Set a policy, use business plans with data controls, or use private AI for anything sensitive.
Does PDPA allow using AI on personal data?
Yes, within its obligations: a proper purpose and consent (or an exception), reasonable protection, limited retention, and comparable protection for transfers abroad. PDPC's 2024 advisory guidelines explain how this applies to AI systems. This is general information, not legal advice.
What is on-premise AI?
AI that runs on hardware inside your own premises: the model, the document reading and the data stay on your network, and staff use it through a web browser.
Does Collie send our data to the cloud?
No. Collie runs on a box inside your office. Nothing leaves by default, and HeySheep doesn't train AI on your data.