Skip to content

Home services and trades

AI policy for contractors: rules for staff using ChatGPT with customer data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An AI policy for contractors tells staff which AI tools they may use and what they may put into them. The core rule: generic writing is allowed in approved accounts, anything with customer names, addresses or job details needs approval, and gate codes, alarm codes, card numbers and call recordings never go into a chatbot. Fit it on one page.

Key takeaways

  • Staff are likely already using chatbots for estimates, emails and review replies, so a policy sets limits on habits that already exist.
  • Sort data into allowed, ask-first and never-paste lists that use the trades' own record names.
  • Approved business accounts with reviewed data settings are safer than personal accounts.
  • Automated redaction tools miss things, so they support the policy rather than replace it.
  • Sharing company records with an AI developer is a separate, owner-approved decision, never an individual one.

Why contractors need an AI use policy#

Contractors need an AI use policy because office staff and technicians are likely already using chatbots to write estimate descriptions, customer emails, review replies and job summaries, often in personal accounts. Without a policy, nobody knows which customer details have been pasted where.

The risk in a trades company is specific. Job notes carry home addresses, gate and alarm codes, notes about vulnerable customers and photos of the inside of homes. Call recordings capture voices and payment conversations. A policy that names those records works better than a generic rule about confidential information.

This is general information, not legal advice. Privacy, recording and employment laws vary by state, so have counsel review the final policy.

What goes on the one page#

A one-page AI policy for a trades company has eight short parts, written so a dispatcher or technician can read it in one sitting. Adapt each part to your company, name real people and tools, and keep the language plain.

Post the finished page where work happens. A policy pinned in the dispatch office and saved on technicians' phones gets read; one buried in the employee handbook does not.

  • Purpose: we use AI tools to save time on writing and research without exposing customer or company information.
  • Approved tools: only the company AI accounts listed here may be used for work; personal accounts are never used for work content.
  • Allowed: tasks on the allowed list may be done in approved tools without asking.
  • Ask first: tasks on the ask-first list need approval from the office manager or COO.
  • Never: items on the never-paste list may not be entered into any AI tool, including approved ones, unless a system has been approved specifically for them.
  • Human review: a person checks every AI-written estimate, message or document before it reaches a customer.
  • Mistakes: if something on the never list is pasted, report it right away to the named contact; reporting is expected and not punished.
  • Owner and review: the COO owns this policy and reviews it whenever tools, vendors or laws change.

Allowed, ask-first and never-paste lists#

The three lists are the core of the policy, and they work best when they use the record names your team already knows. The table is a starting point for an HVAC, plumbing or electrical company; move items between lists to match your own risk tolerance and tools.

Write the lists as examples, not categories. A dispatcher knows what a gate code is, but fewer people can say whether a gate code counts as personal information. Where staff are unsure which list an item belongs on, the default is ask first.

Allowed, ask-first and never-paste lists
Data or taskRuleReason
Marketing posts, job ads, generic how-to explanationsAllowedNo customer or confidential company data involved
Estimate descriptions written without customer names or addressesAllowedDescribes the work, not the people
Summarizing a job note or complaint for a customer replyAsk firstNotes often hold names, addresses and private details
Price book, margins and supplier pricingAsk firstConfidential commercial information
Employee performance or HR mattersAsk firstEmployee personal data and legal sensitivity
Photos and videos taken inside customers' homesAsk firstCan show addresses, family members and belongings
Gate codes, alarm codes, lockbox combinations, key locationsNeverA direct physical security risk to customers
Payment card numbers and bank detailsNeverCard security and fraud risk
Call recordings and transcriptsNever, outside approved systemsVoices, consent rules and spoken payment details
Health or accessibility notes about customersNeverSensitive personal information

Automated redaction is a backstop, not a permission#

Automated redaction tools help catch personal details before text reaches a chatbot, but they are a backstop to the policy, not a reason to relax it. Tools that detect names, addresses and phone numbers work from patterns and models, and they miss things.

Presidio, an open-source toolkit for finding and removing personal information in text and images, is candid about this. Its maintainers note that automated detection can miss sensitive information and advise layering other systems and protections on top. A gate code typed casually into a job comment is exactly the kind of detail a pattern can miss.

Keep the never list absolute, even where a redaction step exists, and keep a person in the loop for everything on the ask-first list.

Rolling the policy out to the office and the field#

Rolling out an AI policy works best as a short conversation with real examples, not an emailed attachment. Dispatchers, customer service staff and technicians respond to scenarios from their own day far better than to definitions.

  • Set up the approved business accounts first, with data-sharing and history settings reviewed by whoever manages your software.
  • Walk the office team through the three lists using a real job note with the personal details removed.
  • Cover technicians in a toolbox talk focused on photos, notes and texting customers from personal phones.
  • Ask everyone to acknowledge the policy in writing, and add it to onboarding for new hires.
  • Move gate codes and access details into a restricted field in the field service platform so they stop appearing in notes.
  • Revisit the lists whenever a new AI feature or tool is added.

Illustrative: a gate code, a chatbot and a policy fix#

Illustrative: a fictional plumbing and drain company finds that a customer service representative has been pasting full job notes into a personal chatbot account to draft follow-up emails. Several notes include gate codes, and one mentions a customer's medical equipment.

The COO does not discipline the representative, who was trying to save time. Instead the company sets up an approved business account, writes the one-page policy and moves gate codes into a restricted field so they no longer appear in notes. Follow-up emails are now drafted from a template that pulls only the job type and date, and counsel advises on whether any customer notice is needed.

When company data leaves on purpose#

Company data that leaves on purpose, such as job records licensed to an AI developer, needs its own approval path, separate from day-to-day staff use. The staff policy should say plainly that no employee shares company records with an AI company, data buyer or researcher on their own initiative.

A licensing decision belongs to the owner or authorized signer, after a rights review and privacy preparation. SourceX runs it through the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery, and the SourceX Evidence Packet holds the privacy record and release authorization, so the company can show exactly what left, in what form and who approved it.

Frequently asked questions

Can employees paste customer information into ChatGPT?

Not under a sound policy, unless the tool is an approved business account and the task is on your ask-first list with approval given. Personal accounts should never receive customer names, addresses, job details or access codes. Check the data settings and terms of any account you approve.

What about AI features built into our field service software?

Those are governed by your contract with the vendor, not by the chatbot rules. Ask the vendor what data the feature uses, whether it trains shared models and where the data is processed, and record the answer. Then add the feature to your approved tools list if you are comfortable.

Should technicians use AI tools on their phones?

Only approved tools on company-managed accounts. Technicians are the people most likely to photograph homes and dictate notes, so the photo and note rules matter most for them. A short toolbox talk covers it better than a long document.

What should we do if customer data was already pasted?

Find out what was shared and in which tool, delete the conversation where the tool allows it, and record what happened. Depending on the data and your state, notification duties may apply, so involve counsel quickly. Then fix the cause, which is often a missing field or template.

Do we need a lawyer to write the policy?

You can draft it yourself from a template like this one. Have counsel review it, because privacy, recording and employment laws vary by state and may affect what the policy says about monitoring and discipline.

Sources

  • Presidio is an open-source, MIT-licensed SDK for PII identification and anonymization in text and images. Source
  • Presidio's own documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and that additional systems and protections should be employed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify