Private AI for business: three ways to get it and what each protects
Private AI is AI that runs on your company’s data without that data training someone else’s model or leaving your control. Where your records are stored and where a model processes them are separate questions, and you need a written answer to each. If you run a smaller manufacturer or distributor, you can get private AI in three ways: a business plan of a public assistant such as ChatGPT or Copilot, a private deployment on a cloud account you control, or a model on your own server. This guide sets out what each one protects and what it leaves open, and ends with a checklist for any vendor.

What private AI means for a business
For a business, private AI is an AI system that reads your quotes, drawings, orders and email while your company keeps control of that data. Four terms decide how private a setup is:
- Training means a provider uses your prompts and files to build future versions of its model.
- Inference is “the processing step when an AI model executes the prompt to produce an output or response,” in Microsoft’s words. It runs on the provider’s servers unless the model runs on yours.
- Retention is how long a provider keeps a copy of your prompt and its answer after the answer comes back, for example to check for abuse.
- At rest describes stored data, such as chat history and uploaded files.
Private AI for a business does not need to retrain a model on your files. It can use retrieval: the system finds the records that answer a question and hands them to the model with the question. AWS describes this method, retrieval-augmented generation (RAG), as working “all without the need to retrain the model.”
In Statistics Canada’s survey for the second quarter of 2026, 19.2% of businesses used AI to produce goods or deliver services. Among businesses with 20 to 99 employees, 22.3% named cybersecurity or privacy concerns as a barrier, and at 100 employees or more, 30.0% did.
Two questions decide whether a setup is private
The Canadian Centre for Cyber Security’s generative AI guidance tells users to “Avoid providing PII or sensitive corporate data as part of the queries or prompts.” PII is personally identifiable information. When you do want AI to read that kind of data, two questions test the setup.
The first is where your records sit when nobody is using them: which company holds them, in which country, and who can open them. The second is what happens to a prompt after the answer comes back: where the model ran, whether a copy was kept and for how long, and whether the copy can be used for training. A vendor that answers the first question with “hosted in Canada” may still send every prompt to a model in the United States.
Business plans of public assistants: a private ChatGPT for your team
The quickest route is a business plan of an assistant your staff may already use. ChatGPT Business, Claude Team, Microsoft 365 Copilot Business and Gemini in Google Workspace put staff on company accounts, and each vendor says it does not train on business content by default. Google’s Workspace privacy hub, for example, says Workspace does not use customer data for training “without customer’s prior permission or instruction.”
| Plan | What the vendor says about training | How it charges, checked September 27, 2026 |
|---|---|---|
| ChatGPT Business | Not used for training or improving models by default (OpenAI) | Per user per month, billed monthly or annually, with at least two paid seats (OpenAI) |
| Claude Team | Model training “None by default” (Anthropic) | For teams of 2 to 150. A standard seat is charged per member per month, billed annually or monthly (Anthropic). Viewed from Canada, the pricing page showed its prices without naming the currency (Anthropic) |
| Microsoft 365 Copilot Business | Prompts, responses and the email, chats and documents Copilot reads through Microsoft Graph are not used to train the large language models behind Copilot (Microsoft) | Per user per month, paid yearly. It is an add-on to an eligible Microsoft 365 Business plan (Microsoft) |
Personal accounts follow other rules. OpenAI says of its services for individuals, “we may use your content to train our models,” with an opt-out, and Claude’s pricing page lists training as “Opt-out” on its personal plans. A business plan moves staff off those accounts, and Shadow AI covers finding the ones already in use.
What a business plan protects
Training is off by default, and staff work in accounts the company controls and can close. Microsoft adds that Copilot “only surfaces organizational data to which individual users have at least view permissions,” so it follows the file permissions you already have.
What a business plan does not protect
- Storage in Canada is limited to some plans. OpenAI’s data residency article offers storage at rest in Canada to “Eligible API customers and new ChatGPT Enterprise/Edu customers.” API customers are companies whose own software sends requests to OpenAI’s models. ChatGPT Business is not on that list.
- The model may run outside Canada. OpenAI’s inference residency, which keeps the model’s processing in one region, is available for Europe, the United States and the United Arab Emirates. Microsoft’s Copilot privacy page says customers outside the EU “may have their queries processed in the US, EU, or other regions.” Its November 2025 announcement on in-country processing, as updated in April 2026, says support for Canada is expected “to follow in 2027.”
- Feedback can be kept. On Anthropic’s business plans, a thumbs up or down stores the whole conversation for up to 5 years, and Anthropic may use that feedback to train its models after removing the user and customer IDs from it. An owner of a Team or Enterprise plan can turn off the thumbs up and down button with the Rate chats setting.
- A court order can override normal retention. In 2025, a preservation order (a court order to keep records) in the New York Times lawsuit reached ChatGPT Free, Plus, Pro and Team, and API customers without a zero data retention agreement (a contract under which the provider keeps no copy of a request or its answer). OpenAI’s account of the order says it did not affect ChatGPT Enterprise or Edu, and that the obligations ended on September 26, 2025. OpenAI says it still stores a limited set of user data from April to September 2025, because the Times still demands it.
Vendor-by-vendor detail is in ChatGPT alternatives for business in Canada, and the settings to switch on or off in each tool are in secure AI at work.
A private deployment on a cloud you control: a private LLM
A large language model (LLM) is the kind of model behind ChatGPT, Claude and Copilot. A private LLM deployment means your company, or a vendor working in your name, opens an account with a cloud provider such as Amazon Bedrock, Microsoft Foundry on Azure, the OpenAI API or the Anthropic API. Your own application sends requests to the model through an API, a connection one program uses to call another, and your account settings decide what the provider keeps.
The providers say they do not train on this traffic: AWS for Bedrock, Microsoft for Azure, where prompts are also “NOT available to OpenAI,” OpenAI for its API unless you opt in, and Anthropic for its API by default. What each request costs is covered in Claude API pricing.
What a private deployment protects
The main gain is a retention setting you can write down and check. Amazon Bedrock has a data retention mode, set per account or project in each region. In the mode called “none,” “No request or response data is written to durable storage by AWS or shared with the model provider.” If you then call a model that requires retention, “Amazon Bedrock will block the request and return an error,” so a model that keeps copies cannot be used by mistake. New accounts start at “inherit,” which falls back to each model’s own default, so the mode has to be set on purpose. A service control policy, an AWS rule an organization applies to its member accounts, can stop anyone in those accounts from changing it. It does not cover the organization’s management account.
OpenAI and Anthropic offer zero data retention on their APIs by agreement. OpenAI’s is “subject to prior approval by OpenAI,” and without it, OpenAI keeps API abuse monitoring logs for up to 30 days. Anthropic’s is “subject to Anthropic’s approval,” and requests are “reviewed and applied on a per-organization basis.” Under it, Anthropic still keeps its safety classifier results and may store data where it needs to comply with the law or combat misuse.
What a private deployment does not protect
- Processing in Canada. AWS says a request sent from its Canada (Central) Region is routed to one of the destination regions set in the inference profile (the AWS setting that lists which regions may run the request), while data at rest, including logs and knowledge bases, “remains exclusively within the Canada (Central) Region.” The Bedrock model card for Claude Sonnet 5 lists no in-region option for either Canadian region. Its US profile “Keeps data within US and Canada regions,” and its global profile “Routes worldwide with no residency constraints.”
- The other APIs. OpenAI’s Canada API region stores data in Canada and does not process it there. Anthropic’s API lets you pin processing to the United States or leave it global, and stores workspace data in the United States. On Azure, Microsoft says prompts are processed in the geography you choose unless you pick a deployment type labelled Global or DataZone, which can send them outside that geography. Check which models your Canadian region offers without either label.
- Models that require retention. Anthropic names four Covered Models: Claude Fable 5 and 5.1, and Claude Mythos 5 and 5.1. Their prompts and outputs are “retained for at least 30 days,” and zero data retention is not available for them in Anthropic workspaces, Claude Enterprise or third-party platforms, apart from a time-limited option for Fable 5 and 5.1 that Anthropic is offering some eligible customers for internal business applications. On Bedrock, an account set to “none” cannot call Fable 5 or 5.1. AWS’s retention guide adds that when these requests use cross-region inference, “retained inputs and outputs are stored in destination Regions,” the regions that processed them, so from Canada the retained copy can sit outside Canada. The retention promise depends on the model, so name the model in the contract.
- Foreign law. A cloud region in Canada does not end foreign-law exposure. The Government of Canada’s white paper on data sovereignty says that “Regardless of where the cloud resources are physically located,” data stored in a cloud “may be subject to the laws of other countries.” Sovereign AI covers that question in more depth.
- The application itself. An API account gives you a model to call. Someone still has to build the tool your staff use, connect it to your records and keep it running.
A model on your own server: private GPT and self-hosted AI
The third way removes the model provider. You run an open-weight model, meaning one whose weights (the numbers the model learned in training) are published so anyone can download and run it, on a server that you or your vendor operate. The server needs a GPU, the graphics chip that does the model’s arithmetic.
OpenAI’s gpt-oss models are one example, released under the Apache 2.0 licence. OpenAI says gpt-oss-120b “achieves near-parity with OpenAI o4-mini on core reasoning benchmarks” while running on a single 80 GB GPU, and that gpt-oss-20b “can run on edge devices with just 16 GB of memory.” The name “private GPT” is also used by PrivateGPT, an open-source project that describes itself as an “API layer for private AI applications on local models.”
The server can sit in your building or in a data centre. DigitalOcean, for example, lists an NVIDIA H100 GPU with 80 GB of memory and an RTX 4000 Ada with 20 GB, each charged per GPU per hour on demand, and its availability table shows both in its Toronto region. DigitalOcean bills in US dollars. A GPU left on all month is billed for every hour, about 730 of them. DigitalOcean bills a GPU Droplet until it is destroyed, even when it is powered off. Cohere sells private deployments in which prompts, outputs and fine-tuned models (copies of a model further trained on your own data) “stay entirely within your environment,” in a virtual private cloud (a walled-off section of a cloud account) you manage or on premises, including air-gapped setups with no outside network connection. Running a model on your own hardware is covered in more depth in local LLM.
What your own server protects
When the server sends nothing out, the prompt and the answer never leave the machine, so no provider’s retention rule applies to them. The model reads your records on the same server that stores them, and no zero data retention agreement is needed because no outside provider sees the request.
What your own server does not protect
- Operations are yours. You or your vendor install security updates, test that backups restore, and add capacity when more people use the system.
- Capability is a trade. OpenAI measures gpt-oss-120b against o4-mini, an earlier model in its hosted lineup. Test an open model on your own documents before you commit to it.
- The host still matters. A rented server in Toronto is still a cloud resource, so the white paper’s point about foreign law applies to it too. Ask who owns the host as well as where the rack is.
The three ways to get private AI, side by side
The table sums up the sections above. The vendors’ pages were checked on September 27, 2026, and these settings change often.
| Way | Trains on your data | Where records are stored | Where prompts are processed | Who runs it | What it takes to staff |
|---|---|---|---|---|---|
| Business plan of a public assistant | Not by default, though feedback can be kept | With the provider, in Canada on some plans | May be outside Canada | The provider | An account administrator |
| Private deployment on a cloud you control | No, per AWS, Microsoft, OpenAI and Anthropic | The region you choose, including Canada on AWS | Depends on the model and region | Your team or vendor, in your account | An application builder and a written retention setting |
| Model on your own server | No outside provider sees the data | On your server | On the same server | You or your vendor | Someone for patching, backups, restores and capacity |
The ways also combine. Records can live on a server you control while a hosted model reads them under a written retention setting, and you can change the model later without moving the records.
Which way fits your records
Tell Derik which systems hold your records and which of them must stay in Canada. He will tell you which of the three ways fits and what it takes to run.
Start a conversationWhat Canadian law asks when AI reads personal information
Customer contacts and employee time records often contain personal information. Under clause 4.1.3 of PIPEDA, the federal privacy law for businesses, an organization “is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing.” It must use “contractual or other means to provide a comparable level of protection.”
The Privacy Commissioner of Canada’s guidelines for processing across borders add two points. What an organization cannot do through a contract “is to override the laws of a foreign jurisdiction.” It must also tell customers that while their information is in another jurisdiction, it “may be accessed by the courts, law enforcement and national security authorities.”
Quebec asks for more. Section 17 of its private-sector privacy act says: “Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment.” A privacy impact assessment is a written review of the risks to personal information. The transfer also needs a written agreement, and the same rule applies when an enterprise entrusts someone outside Quebec with keeping the information. The rule has applied since September 2023, according to the Commission d’accès à l’information. Section 3.3 requires an assessment for “any project to acquire, develop or overhaul an information system” involving personal information. In our reading, an AI system that reads personal information is such a project.
If your company is registered in the Controlled Goods Program, the program’s cloud guidance says registrants “should take note of any data residency options to ensure that their controlled goods data is stored on servers located in Canada.” That guidance speaks to storage, so ask your vendor about processing as a separate question.
Your counsel draws the conclusion for any particular deployment, and this guide is not legal advice. The wider legal picture for AI is in AI governance, and the rules for staff are in the AI policy template.
A private AI checklist for any vendor
Take these questions to any AI vendor, including ThriveAI. Each one should get a written answer. For the account settings inside each tool, use the checklist in secure AI at work, and for the wider security picture, see AI security.
Before you sign
- Where is our data stored at rest? Ask for the provider, the region and the country.
- Where does the model process our prompts? Ask for this as a separate written answer, because the region that stores data may not be the region that runs the model.
- Which retention mode applies, and to which model? Ask for the model and its retention setting by name, because some models require retention.
- Who holds the credentials? The accounts and keys the system uses should sit in your company’s directory, so you can switch them off.
In the contract
- No training or fine-tuning on your data without your written consent.
- Destruction of your data on request, with a deadline for confirming it.
- A named person at your company approves every write-back, meaning any email sent, record changed or order created by the system. Human in the loop explains how that approval step works.
- The retention mode and the model it applies to, written into the agreement, with notice before either one changes.
A vendor can store your files in a Canadian data centre and still send each prompt to a model in the United States. AWS documents that pattern for its Canada (Central) Region. When a vendor says “hosted in Canada,” ask which step is hosted there: storage, processing or both.
How ThriveAI builds private AI
ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data, for manufacturers and distributors in Ontario and Quebec. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: one that runs on that server, or a hosted model under a written zero data retention agreement. A hosted model may process requests outside Canada, so the contract names the model and its retention setting. A named person at your company approves every action before anything is sent or saved.
Working sessions run on site with your team, in French or English. ThriveAI also runs hands-on AI training on your own documents. For what AI does inside a plant, see AI for manufacturing. For how a full platform compares with a single tool, see enterprise AI platform, and for the company, About ThriveAI.