SSD Nodes Learn Hosting plans →
Guides Matt ConnorBy Matt Connor

Client data in Claude: which plan?

Client data in Claude needs the plan with the paperwork. Compare Free, Pro, Max, Team and Enterprise on training defaults, the DPA and admin control.

Which Claude plan can hold client data

Putting client data in Claude is a contract question before it is a price question. If the material contains personal data about someone other than you, buy a plan Anthropic sells as a commercial product: Claude for Work (the Team and Enterprise plans) or the Claude API. Those carry a data processing agreement, the verwerkersovereenkomst your client will ask for, plus a written default that your content is not used to train models. Claude Free, Pro and Max are consumer products, and Anthropic's own help pages route business data questions away from them.

Every policy claim below names the Anthropic page it comes from. I read all of those pages on 2 September 2026. Terms change, so treat the page as the source and this post as a map to it. Where a page does not answer something, this post says so and names the page to read instead of guessing.

The tiers, in one pass

  • Free: consumer terms, and no processor agreement.
  • Pro: a personal account with more usage.
  • Max: the same personal account, from $100 per month.
  • Team: the cheapest plan Anthropic sells as a commercial product, with a minimum of two members.
  • Enterprise: Team plus custom data retention timelines and a negotiated contract, listed at $20 per seat plus usage at API rates.
ChartClaude list price per seat per month in USD, from claude.com/pricing, checked 2 September 2026
The data behind this chart
[
  {
    "plan": "Pro",
    "monthly_usd": 20,
    "annual_per_month_usd": 17
  },
  {
    "plan": "Team standard seat",
    "monthly_usd": 25,
    "annual_per_month_usd": 20
  },
  {
    "plan": "Team premium seat",
    "monthly_usd": 125,
    "annual_per_month_usd": 100
  }
]

A Team standard seat costs 25 dollars per member per month billed monthly, or 20 billed annually, against 20 for one Pro account. Team has a two member minimum, so the honest comparison for a one person business is two Team seats against one Pro account. Which plan suits you personally is a different question, answered in the plan chooser for personal use. This post only asks what changes once the data belongs to a client.

What Anthropic does with your inputs by default

Two pages describe the consumer plans, and they do not word it the same way. The privacy policy, effective 8 July 2026, says: "We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings." The help article Is my data used for model training?, updated 16 March 2026, describes training as something that happens if "You choose to allow us to use your chats and coding sessions to improve Claude", if a conversation is flagged for safety review, or if you join a program such as the Trusted Tester Program.

One page reads as opt out. The other reads as opt in. Do not settle that from any blog post, including this one. Open Settings, then Privacy, and read the state of "Help improve our AI models" in the account you actually use. That path comes from How do I change my model improvement privacy settings?. If the setting is on, Anthropic may keep the material in de-identified form inside its training pipelines for up to five years.

The commercial pages carry no such ambiguity. The commercial version of Is my data used for model training? says: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." The Commercial Terms of Service state it as an obligation on Anthropic: "Anthropic may not train models on Customer Content from Services", next to "Customer (a) retains all rights to its Inputs, and (b) owns its Outputs".

Both routes can end at the same practical outcome. They are not the same promise. On a consumer plan the protection is a switch inside one person's account, and that person can change it whenever they like, with nothing in your client contract to stop them. On a commercial plan it is the default written into terms you accepted. When a client asks who may train on their data, the written default is the answer that holds up.

One exception applies on every plan. Pressing thumbs up or thumbs down sends that conversation to Anthropic. The commercial page lists reporting feedback or bugs as a case where your data may be used, and the retention page keeps feedback conversations for five years. Tell everyone on the account to stop rating conversations that hold client material.

Is a verwerkersovereenkomst available, and on which plans

Article 28 of the AVG (Algemene verordening gegevensbescherming, the Dutch name for the GDPR) requires a written agreement whenever a processor handles personal data on your instructions. Anthropic's answer is the DPA (data processing addendum). The article How do I view and sign your Data Processing Addendum (DPA)?, updated 16 March 2026, says: "Anthropic's DPA with Standard Contractual Clauses (SCCs) is automatically incorporated into our Commercial Terms of Service", and "When you accept Anthropic's Commercial Terms of Service, you also accept our DPA." There is no form to request. The text of the DPA is public, effective 24 February 2025 as published.

The scope line is what decides your purchase. That help article describes the DPA as covering "commercial products (e.g. Claude for Work, Claude API)". It offers nothing for Claude Free or Pro. A Pro subscription therefore leaves you with no processor agreement to send when a client's privacy officer asks for one, however careful you are with the account.

The roles are stated as well. In Does Anthropic act as a data processor or controller?, updated 16 March 2026: "the customer is the 'Controller' of the data submitted by its Users" and "Anthropic acts as a 'Processor' of the data on behalf of the customer". Read that as your relationship with Anthropic. Toward your own client the chain usually has one more link: the client is the controller, you are the processor, and Anthropic is your sub-processor. Article 28(2) of the AVG says a processor may not engage another processor without prior written authorisation from the controller, general or specific. Getting that authorisation into your own contract is your job, not Anthropic's.

The DPA itself sets the terms for changes underneath you. Anthropic will "provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data", and you may object "within fifteen (15) days of the date of such notice". That clause is only useful if somebody reads the notice, so send it to an address a human checks. The current list of subprocessors sits in the Anthropic Trust Center.

What those pages do not answer: whether Anthropic will sign your client's own template agreement, or a Dutch language version of it. Nothing on the DPA page addresses bespoke paper. If a client insists on their template, ask Anthropic's sales team directly, and send the published DPA plus the subprocessor list while you wait.

Where the data is stored, and what you may promise a client

The page Where are your servers located? Do you host your models on EU servers?, updated 15 June 2026, says: "By default, we may route customer traffic to select countries in the US, Europe, Asia and Australia, unless otherwise agreed upon or at your instructions." The same page adds: "Note that data is stored in the US."

Storage in the US is a transfer out of the EEA (European Economic Area), and the standard contractual clauses inside the DPA are the mechanism that covers it. So do not promise a client that their data stays in Europe. The same page describes US-only inference for Enterprise customers on usage-based billing, which pins processing to one country rather than moving it to Europe. If a client genuinely requires EU residency, read that page before you sign anything, the same way you would check which laws reach a server before choosing where it lives.

Who owns the workspace when someone leaves

On a personal plan the account belongs to the person. Their chats and their login. Nobody above them can export the work, and when they leave the company the client history leaves with them.

Claude for Work moves that ownership to the organisation. Who owns and manages the data of my team?, updated 16 March 2026, says: "Your organization's designated Primary Owner manages your Work account and all associated data", and that Primary Owners can request data exports which "may contain your conversations with Claude, uploaded files, and usage patterns".

Removal behaves in a way worth planning around. What happens to a user's data when they are removed from a Team or Enterprise organization? says remaining members "will no longer be able to access their chats", and a shared link to one then returns:

Conversation not found. The requested conversation either doesn't exist or you don't have permission to access it.

At the same time, "the removed user's data will still be included in any data exports run by your organization's Primary Owner". Private projects stay closed to the rest of the organisation after the person goes. Shared projects stay open to whoever they were shared with.

The lesson is concrete: keep client work in shared projects. A private project belonging to a freelancer who left is reachable only through an export request, which is slow on the day the client wants their file back.

One thing I could not confirm from either page: whether an owner can open a named member's chat inside the interface, rather than pulling an export. The ownership page describes exports and the removal page describes loss of access, and neither states an in-product reading right. If your client contract promises supervision of who read what, read both pages and ask Anthropic before you promise it.

Admin controls, and what they are worth to two people

What is the Team plan? lists admin tools and billing management, role-based permissioning, single sign-on and spend controls at the organisation and user level. At a large company those are procurement checkboxes. In a BV (besloten vennootschap, the Dutch private limited company) with two staff, two of them do real work: one bill instead of two personal cards, and an owner who can cut off a leaver's access the same afternoon. The rest of the small business case sits in what a Team plan changes for a two person company.

Whatever plan you land on, the controls stop at the edge of what you paste in. No plan can un-see an API key or a client's BSN (burgerservicenummer, the Dutch citizen service number). Keeping credentials out of an agent's context is separate work, and if you point Claude Code at client repositories then knowing what a coding agent sends home belongs in the same review. If the volume is small and the contract is the only thing you need, the API is a commercial product too, so weigh the cost of API calls against a monthly seat before buying seats.

How long the text sits somewhere

ChartPublished retention limits in days, from Anthropic's data storage pages, checked 2 September 2026
The data behind this chart
[
  {
    "label": "Deleted chat, back end",
    "retention_limit": 30
  },
  {
    "label": "API input and output",
    "retention_limit": 30
  },
  {
    "label": "Flagged by trust and safety",
    "retention_limit": 730
  },
  {
    "label": "Conversation you rated",
    "retention_limit": 1825
  },
  {
    "label": "Trust and safety scores",
    "retention_limit": 2555
  }
]

A chat you delete leaves your history at once and clears back-end storage within 30 days. Inputs and outputs sent through the API are deleted within 30 days of receipt. Material that automated systems flag for trust and safety can be held up to 730 days, which is two years, and the classification scores up to 2555 days, which is seven. A conversation you rate with thumbs up or down is stored for 1825 days. All of that comes from How long do you store my organization's data?, updated 1 July 2026. Enterprise customers can set custom retention timelines, and zero data retention is described there as a separate agreement.

The number that matters in a client conversation is the shortest one. Nothing published promises faster than 30 days, so "we deleted it immediately" is not a sentence you can put in an email.

The invoice, and the register

Set the billing fields before the first charge. On Team an organisation Owner opens Billing settings, clicks Update next to the payment method, and enters the tax or VAT ID, which for a Dutch business is the BTW-identificatienummer. The same screen carries a "Use a different name on invoices" box, and that is what puts the BV or eenmanszaak name on the document instead of a personal name. Invoices then appear under Settings, then Billing, and go to the billing email address. Pro and Max show a tax or VAT ID field too, depending on your location.

The trap is that none of it is retroactive: "Previously completed invoices cannot be updated retroactively", per Add or update your Team plan's tax or VAT ID, updated 16 March 2026. An invoice issued to your own name with no BTW number stays that way, and you find out while preparing the quarterly BTW-aangifte, when it is too late to fix. How that invoice is treated for BTW and what to do with it in the return is covered in reading a Claude invoice for your BTW administration.

The second Dutch detail is the register. Article 30 of the AVG asks you to keep a register of processing activities, and the exemption for organisations under 250 people falls away when the processing is regular rather than occasional. Client work is regular. So write the entry: which client data goes into Claude, which plan and which legal entity, that storage is in the US, that the transfer runs on standard contractual clauses in Anthropic's DPA, and where the subprocessor list lives. Then tell the client before the work starts, not after. Once their data is in the tool, an objection has nowhere to go.

The decision rule

Prices move, plan names change, and privacy pages get rewritten. One rule survives all of it. If the work involves identifiable client data, buy the plan whose written terms say so, not the cheapest one that technically works. Four questions to re-run against whatever the pricing page says next year:

  1. Does this plan come with a processor agreement I can forward to a client?
  2. Does a written term, rather than a setting in one person's account, say my content is not used for training?
  3. If the person doing the work leaves tomorrow, can somebody else still get the files out?
  4. Can the invoice carry my company name and my BTW number?

Claude Pro will run the same model over the same document as Claude for Work. What it will not produce is a chain of paperwork ending at your client. When capability and paperwork disagree, buy the paperwork.

FAQ

Can I use Claude Pro for client work?

For client material with no personal data in it, such as public documents or your own code, Pro is an ordinary tool and the consumer terms apply. For identifiable personal data belonging to a client, Pro has a gap you cannot close from the account settings: Anthropic offers its DPA for "commercial products (e.g. Claude for Work, Claude API)" and not for Free or Pro, per its DPA help article, read on 2 September 2026. Article 28 of the AVG expects a written processor agreement, and on Pro there is none to show.

Does Anthropic provide a verwerkersovereenkomst, and how do I get it?

Yes, on commercial plans, and you do not have to request it. "Anthropic's DPA with Standard Contractual Clauses (SCCs) is automatically incorporated into our Commercial Terms of Service", and accepting those terms accepts the DPA, per the help article updated 16 March 2026 and read on 2 September 2026. Read the published text at anthropic.com/legal/data-processing-addendum and keep a copy with the client file. Whether Anthropic will sign a client's own template instead is not addressed on that page, so ask their sales team rather than assuming an answer.

Is my Claude data used to train models?

On commercial products the published default is no: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." On consumer plans it depends on a setting in your own account, and the privacy policy and the help article word that default differently, so open Settings, then Privacy, and read "Help improve our AI models" for yourself. On every plan, rating a conversation with thumbs up or down sends it, and feedback conversations are kept for five years.

Where is Claude data stored, and does it leave the EU?

Anthropic's server location page, updated 15 June 2026, says traffic may be routed to "select countries in the US, Europe, Asia and Australia" and that "data is stored in the US". That is a transfer out of the EEA, covered by the standard contractual clauses inside the DPA. No EU-only residency option is described on that page, so do not promise one to a client. Enterprise customers on usage-based billing can enable US-only inference, which restricts the country without moving processing to Europe.

What happens to a colleague's chats when they leave our Team plan?

Remaining members lose access to that person's chats, and shared links return "Conversation not found." The Primary Owner can still reach the content through a data export, because "the removed user's data will still be included in any data exports run by your organization's Primary Owner". Private projects stay closed to everyone else, while shared projects remain available to the people they were shared with. Keep client work in shared projects, so a departure does not turn routine access into an export request.