Guide7 min read

Is It Safe to Use AI for Tradespeople? (Plumbers, Electricians, Builders)

Yes to draft quotes and invoices, no with an address, access code and schedule together: anonymise the customer before you paste a job into a consumer AI.

By Pierre de ONYRI

The answer fits in one line. AI can draft your quotes, schedules and invoices, but never with the customer's real details. A tradesperson knows three sensitive things. The job address. How to get in, sometimes the alarm code. And when the occupants are out. Bundled into a consumer ChatGPT, these turn into a burglary brief, not just a privacy issue. Under the GDPR, you are also the controller of that data. There is a clean method: anonymise the customer's identifiers, and the AI will still write your text.

A job holds more than an address

Your plumbing or wiring job notes go beyond a customer list. You record the exact address. The gate to bypass, the keypad code, where the safe sits. The slot when you visit, so the hour the house is empty. You add the detail of the fault. A broken alarm. A failing lock. The layout of the rooms and where the valuables are kept.

Each line is useful for the work. But their sum changes in nature. A burglar wants exactly that trio: where, how to get in, and when nobody is home. Putting the address, the access and the schedule in one place turns plain job notes into a physical-security exposure. It is no longer only a data risk. It is a risk to your customer's home.

The law: you are the data controller

EU law is clear. Under the GDPR (Regulation (EU) 2016/679, Article 4), personal data is any information relating to an identified or identifiable person. A customer's name, home address, phone and email all count the moment you record them.

The same article defines the controller. It is the party that decides why and how the data is processed. A plumber, electrician or builder who holds customer records is therefore the controller for that data. You are not a casual holder of it. You carry concrete duties.

  • A lawful basis to process the customer's data.
  • Security: protecting that data against access or leaks.
  • Minimisation: handling only what the task needs.

Pasting a full customer file into a consumer AI strains each of these duties. You are not minimising. You no longer control where the data goes. The NCSC (National Cyber Security Centre, the UK cyber authority) makes the point in its guide for small firms. Customer details, quotes, orders and payment details are business assets, to be protected like the rest.

Photos and card data: two blind spots

Before/after job photos look harmless. They are not. Tied to an identifiable customer, they are personal data under the GDPR. A photo reveals the layout, the security equipment, the valuables, sometimes the location in its metadata. Treat them with the same caution as a written note.

Card data follows an even stricter rule. The PCI DSS standard governs card data. The PCI SSC is the council that writes that standard. Per its "Data Storage Do's and Don'ts" guidance, sensitive authentication data must never be retained after a payment is authorised. Even encrypted. This covers the card-validation code (the 3- or 4-digit code), the full track data, and the PIN.

The name, the card number and the expiry date may be stored only with a genuine legal or business reason, and protection to PCI DSS level. Pasting a raw card number into a general AI meets neither condition. The rule is simple: never a card number in a prompt.

What you pasteThe real risk
Address + access code + scheduleA burglary brief, gathered in one place
Broken alarm or safe locationYou mark out the home's weak point
Before/after photo of the homePersonal data: layout, security, valuables, location
A customer's card numberBarred without PCI DSS protection; never in a chatbot
The danger isn't discussing a job with an AI — it's the concrete identifiers you leave behind.

The fix: anonymise before you send

Good news: AI is still a strong job-site tool. It drafts a clear quote. It phrases an appointment reminder. It shapes the wording of an invoice. For all of that, it needs none of the customer's real data. The model works just as well on anonymised identifiers. You lose nothing in the result.

Two-part diagram. At top, a job card beside a wrench and a house: the access/alarm row is amber (exposed) and flows to an AI card that receives the file with an alert. At bottom, the same card anonymised shows only cobalt tokens, and the AI receives only tokens with a checkmark under a shield.
After the GDPR (Regulation (EU) 2016/679, Article 4), the NCSC's Small Business Guide, and the PCI SSC's "Data Storage Do's and Don'ts" guidance.

The method is mechanical. You replace each sensitive value with a token before you send. The AI reasons about the shape of the job, without ever seeing the real values. You restore the real values afterwards, locally, in your browser.

  1. 1Never bundle address, access and schedule into one prompt.
  2. 2Leave the alarm and access details out entirely.
  3. 3Replace the customer's name, address and contact with tokens.
  4. 4Never paste a card number, and use vetted tools.

That's what ONYRI Sanitize is for. The engine detects a job's sensitive data — name, address, contact, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI drafts your quote or invoice without ever seeing where your customer lives, or how to get in. You keep the help, without turning your job notes into a risk to the home.

Frequently asked questions

Is it safe to use AI for tradespeople?
Yes to draft, no with real details. AI can write your quotes, schedules and invoices with no customer data at all. But never bundle a job's address, access code and schedule into a consumer ChatGPT: that trio is a burglary brief. Under the GDPR, you are also the controller of that data. Anonymise the customer's identifiers before you send.
Can I paste a customer's card number into an AI?
No. The PCI DSS standard governs card data. The card-validation code, the track data and the PIN must never be retained after payment, even encrypted. The number, name and expiry may be kept only with a legitimate reason and PCI DSS protection. A general AI chatbot meets neither. Never paste a card number into a prompt.
Are before/after job photos sensitive?
Yes. Tied to an identifiable customer, they are personal data under the GDPR. A photo reveals the home's layout, the security equipment, the valuables, sometimes the location in its metadata. Treat them with the same caution as a written note, and keep them out of a consumer AI.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next