The short answer
Buyers ask AI vendors a set of questions they do not ask conventional software vendors, and those questions arrive at the point where a deal is close.
Preparing the answers once is a day of work. Improvising them per deal costs far more and produces inconsistencies reviewers notice.
The questions that always come
| Question | What they need |
|---|---|
| Is our data used for training | A clear yes or no, in writing |
| Where is it processed | Specific regions |
| Which subprocessors see it | A current list |
| How long is it retained | Including logs and caches |
| Can it be deleted on request | And how that is verified |
| What happens on an incident | Notification timeframe |
The first row decides some deals on its own. A vague answer is read as a yes, so if the answer is no, say so plainly and unconditionally.
Prepare the document once
- Write the answers plainly, in one document.
- Have someone technical confirm each is actually true.
- Keep the subprocessor list current, with a review date.
- Note where an answer differs by plan or region.
- Review it whenever the architecture changes.
Point two is the one that matters. An answer that is aspirational rather than accurate is a serious problem if discovered during diligence or after an incident.
Answers that stall deals
- We are not sure, we will check
- It depends on the configuration, without explaining how
- Training is disabled by default, without saying whether it can be enabled
- Subprocessors listed but not dated
- Retention described for the main store but not for logs
The last one comes up repeatedly. Reviewers know customer content frequently sits in logs and traces, and a retention answer covering only the database is incomplete.
Be honest about what you cannot commit to
Saying a commitment is not available on this plan is a normal answer. Claiming one you cannot meet creates a contractual problem later.
Buyers generally accept clear limits. What they do not accept is discovering the limit after signing.