Confidentiality

Privilege, GDPR and AI

For a law firm, confidentiality is not a setting — it is the entry ticket. This page sets out where the files run, what the agreement covers, and exactly where the software’s role ends.

Privileged material cannot be pasted into a public AI tool.

The daily material of a law firm is client material: draft contracts, notes prepared for a dispute, transaction documentation. It is covered by professional secrecy — and it does not become so because the firm declares it to be.

Public AI tools do precisely what must not happen to such material: they send the document into a foreign provider’s infrastructure, where the firm can no longer say what happens to it, how long it stays, or who can reach it. For a law firm that is not a preference — it is a hard blocker.

Which is why user caution cannot be the answer — “let us only upload what is not sensitive” fails, because contract review is only worth doing on the sensitive material. The answer has to come from the architecture, not from a policy document.

Nothing leaves — because there is nowhere for it to go.

AI Szerződéselemző was built as private AI. The models run on our own EU hardware — or entirely on the firm’s own server. There is no external AI API: the system contains no point at which a contract would pass into a third party’s service. It is not a rule that forbids it; the architecture leaves no route.

What the firm gets

Six concrete items, not six promises.

Each one is verifiable: either it is written into the agreement, or it is visible in the system.

Private AI, no external AI API

The models run on our own EU hardware or on the firm’s own server. There is no call to a public AI service, so client files never reach a third-party model — neither for analysis nor for training.

EU hardware or your own server

The firm chooses where the files run: on ATAILA’s EU infrastructure, where the data stays in the country, or entirely inside the firm’s own walls.

A data processing agreement (DPA)

A written agreement sets out what we handle in the course of operating the system, for what purpose, for how long, and what we do not do with it. The firm remains the controller; we act as processor.

An audit trail of every operation

Who did what, when, and on which document — traceable, and visible to the firm as well. In a law firm, being able to reconstruct events matters as much as restricting access.

Data export at any time

Uploaded files and generated results can be exported whenever you want. No lock-in: if the firm leaves, it takes its material with it.

Access control

The firm decides who may work on which matter and which document. Internal information barriers are not weakened by a contract entering the system.

Responsibility

What the system deliberately does not take over.

Confidentiality has a second half that gets discussed less often: it is not enough that the file stays inside — it also matters who decides about it.

Nothing changes automatically

The system suggests and flags; a clause changes only when the acting attorney approves it. The approval step is not a convenience toggle that can be switched off — it is part of the workflow.

Not legal advice

AI Szerződéselemző is software. What it produces is preparatory material — extraction, flags, drafting suggestions — not a legal opinion, and no substitute for the lawyer’s own professional assessment.

Responsibility is not shared

Towards the client, professional responsibility stays with the acting attorney. The system does not take it over and never claims to — which is why the sixth step is the lawyer’s.

The system does five steps of preparatory work and stops where professional judgement begins. That is not a limitation — it is the design principle of the product.

Regulatory context

GDPR and the EU AI Act — as background

Towards its own clients the firm is the controller; we act as processor in the course of operating AI Szerződéselemző, and a DPA records that role. Where the files sit, how long they are retained and how they can be exported are set out in the same agreement — not in a separate statement.

The direction of EU AI regulation — transparency, human oversight, documentation — matches the way the product was built: you can see which clause a flag rests on, the decision stays in human hands, and every operation leaves a trace. That makes the firm’s own documentation easier; it does not replace it.

This is general background, not legal advice and not a compliance guarantee. What a particular firm’s particular use requires is for that firm to assess — typically in exactly the professional capacity in which it advises its own clients.

EU AI Act for law firms — more in the resources →

See where your files would actually run.

On a demo we walk the path of the data: where an uploaded contract goes, what the audit trail shows, and what the DPA covers.

Editions Privilege and AI