Data Privacy and Security in AI-Powered BREEAM Analysis
Why data security matters for BREEAM assessors
BREEAM assessment involves much more than publicly available information. Assessors and their clients regularly work with project documentation containing detailed information about buildings, designs, specifications, energy systems, suppliers, construction methods, and other commercially sensitive information.
Furthermore, BREEAM assessors sign strict Non-Disclosure Agreements (NDAs) with their clients to protect sensitive commercial and project data. Software used in the assessment workflow must strictly align with these contractual confidentiality duties.
As AI becomes increasingly useful for reviewing this documentation, assessors are naturally asking:
What happens to our documents when we upload them to an AI tool?
Many BREEAM professionals now use basic, general-purpose AI tools (such as standard ChatGPT or Claude subscriptions) to review, summarise, or investigate project documentation. But AI capability alone does not answer the questions that matter to a business: Where is the data processed? Who can access it? Is it used to train AI models? How is it protected?
At Sustainabot, data protection and cybersecurity are foundational elements of the platform, specifically built to fulfill the NDA requirements between assessors and their clients.

How Sustainabot protects customer data
Sustainabot has been developed specifically for professional green-building assessment workflows. Our approach to customer data is based on key security and privacy principles:
Customer data is not used to train AI models: Documents and information uploaded by customers are used solely to provide the Sustainabot service. Your project documentation never becomes training material for improving models used by third parties.
Built to comply with client NDAs and data privacy: Because assessors sign NDAs with building owners and developers, Sustainabot’s cybersecurity infrastructure is architected to guarantee strict confidentiality. The platform automatically anonymizes all sensitive personal data during document upload and processing, ensuring full alignment with contractual non-disclosure duties and compliance standards.
Files are encrypted: Files uploaded to Sustainabot are encrypted both in transit and at rest to ensure maximum protection for commercially sensitive documentation.
Files are accessible only within the relevant organisation: Customer files are strictly isolated. Project documentation belonging to one organization is never accessible to users of another organization.
Servers are located in the EU: Sustainabot's servers are located within the European Union, guaranteeing compliance with local data sovereignty requirements.
Sustainabot is GDPR compliant: The platform operates in full accordance with the General Data Protection Regulation (GDPR).
Enterprise-grade infrastructure via Microsoft Azure: Sustainabot's AI models are deployed securely through Microsoft Azure within our dedicated infrastructure, rather than routing confidential documents through consumer-facing web applications.

The hidden risks of using basic general-purpose AI for BREEAM documentation
Standard AI tools like basic ChatGPT or Claude web applications are increasingly popular for everyday tasks. However, using basic consumer-facing AI tiers for professional BREEAM documentation poses significant data privacy risks.
(Note: While major AI vendors offer specialized Enterprise tiers or API arrangements with dedicated privacy controls, these corporate packages are designed for large-scale enterprise deployments requiring custom IT integration and high minimum seat commitments—making them impractical for standard assessment team setups. For standard and individual LLM accounts, data privacy defaults remain significantly weaker.)
When confidential BREEAM documents are uploaded to standard, general-purpose AI accounts, potential risks include:
Model Training on Client Data: By default, standard public AI models often use submitted text, files, and outputs to train and refine future iterations of their models. Confidential building specifications could inadvertently become part of a public dataset.
Breach of Client NDAs: Uploading confidential client evidence into public AI tools without explicit data processing guarantees often violates standard NDA terms signed with project developers.
Data Retention & Storage: Public AI tools frequently retain user conversations and uploaded files on internal servers for training, manual review, or safety auditing purposes.
Lack of Organisation-Level Access Control: Consumer AI tools are designed around individual accounts rather than structured, team-based access controls for corporate projects.
Data Location: Basic AI services process data across global data center networks, often routing sensitive European project data to servers outside the EU.
Before uploading confidential BREEAM project documentation to any AI service, assessors must carefully verify the specific data-processing arrangements of that account tier.
Why Sustainabot takes a different approach
Sustainabot was built specifically for BREEAM professionals and their documentation workflows. Instead of requiring assessors to manually submit confidential project documents to general-purpose AI chatbots, Sustainabot provides a secure, dedicated environment for AI-powered BREEAM analysis.
The platform combines:
Full alignment with assessor NDA and confidentiality commitments;
Complete isolation from model training datasets;
Encrypted file storage and organisation-level access controls;
EU-based servers and full GDPR compliance; and
Enterprise AI models deployed within Microsoft Azure.
This allows assessors to introduce AI efficiency into their workflow without compromising data control or breaching client trust.
Sustainabot vs. Standard Public AI Tools
Feature / Aspect | Sustainabot | Standard Public AI Tools (Non-Enterprise) |
Purpose-built for BREEAM workflows | Yes | No |
Automatic personal data anonymization | Yes (On upload & processing) | No |
Customer data excluded from model training | Yes | No (Default settings use inputs for model training) |
Built to satisfy Assessor–Client NDAs | Yes | No (Standard terms often conflict with client NDAs) |
Encrypted file storage | Yes | Typically No (or limited to session storage) |
Organisation-level team access controls | Yes | No (Designed for individual accounts) |
EU-based servers | Yes | No (Data routinely processed globally) |
Full GDPR compliance built-in | Yes | No (Requires manual compliance checks) |
Secure infrastructure (Microsoft Azure) | Yes | No (Uses public shared web endpoints) |
The bottom line
AI is becoming an essential tool for BREEAM professionals. But when AI is used to analyze real client documentation, data security and privacy must be part of the decision—not an afterthought.
Sustainabot combines AI-powered BREEAM analysis with a secure, NDA-compliant data-handling framework designed specifically for professional green-building documentation.
Analyse your BREEAM evidence with AI — while keeping your project data protected.



Comments