Data handling
What data the tool may receive, where it may go, retention/training signals and what workflows become exposed.
AI PROCUREMENT · PRE-SIGN REVIEW · EU SMES
For Spanish and EU SMEs evaluating AI-enabled tools that may touch customer, employee, operational or sensitive business data.
WHAT I LOOK AT
I review the tool, use case, data path, vendor claims and public evidence so you can decide whether to proceed, constrain the use case, ask for more information or walk away.
What data the tool may receive, where it may go, retention/training signals and what workflows become exposed.
Public docs, security/compliance materials, subprocessors, terms and unresolved unknowns.
Practical notes oriented around likely AI Act roles, data protection concerns and obligations to discuss with counsel.
Access controls, logging, admin settings, human review points and failure modes in the intended workflow.
Signals around HR, support, customer records, commercial decisions and confidential company information.
The specific questions to send the vendor before signature, rollout or renewal.
WHAT YOU GET
HOW IT WORKS
The work is designed for a live buying decision: enough depth to reduce avoidable risk, without turning procurement into a multi-week audit.
You send the vendor, the buying context, the workflow and the categories of data the tool would touch.
I review vendor materials, public documentation, data-handling claims, controls and gaps.
You get an evidence-backed report and a call to walk through the recommendation, risks and open questions.
WHO IT IS FOR
Useful when a vendor offering AI features will touch information that matters and the team needs a sober technical view before signing.
Customer dataEmployee dataOperational workflowsSensitive business information
SCOPE
This is a technical and procurement review to support a better buying decision. It is deliberately limited in scope.
Send the tool name, intended use case and the data or workflow it will touch. I will confirm whether this review fits before we start.