adira security

Adira Security and Data Handling (No Training on Your Contracts)

Adira EditorialLegal AI desk13 min read

If you are close to uploading a contract into Adira, you probably have three questions first: does the AI train on what I upload, where does my data actually sit, and what happens if something goes wrong. This page answers all three directly. Adira, which publishes this page, sells contract lifecycle management software, so the honest way to use this page is to read the specific claims below and then verify each one yourself, in writing, before you rely on it. That is the same standard this page asks you to hold every AI legal vendor to, including Adira.

The short answer: Adira does not use your contract content, uploads, drafts, or edits, to train any AI model, its own or its underlying provider's, under its standard commercial terms. Adira is built on Anthropic's Claude models. Confirm the current wording of this commitment in your signed Data Processing Agreement (DPA) rather than relying on this page or Adira's marketing site alone, since that is the only version that is actually enforceable.

Two vendors, one question

Every AI legal tool sits on top of a foundation model it did not build. When you ask "does this tool train on my data," you are really asking about two separate companies: the application layer (Adira, which handles your documents, your clause tree, your workflow) and the model provider underneath it (Anthropic, which trains and runs Claude). A vendor can answer honestly for its own layer and still be vague about the layer below it. Ask both questions separately.

For the model layer: Anthropic's published policy for commercial products states, "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." Anthropic's commercial terms go further, stating that Anthropic may not train models on customer content from its commercial services. This is the commitment Adira's own no-training policy sits on. Ask Adira, in writing, to confirm which product tier and terms apply to your account, since Anthropic's consumer products (Claude Free, Pro, Max) carry different rules.

For the application layer: Adira states that it does not use customer contract content to train its own models or fine-tune the underlying Claude models on your documents. Ask for this to be stated as a clause in your signed DPA, with a defined term for "Customer Content" and a survival clause that outlasts termination of your subscription, not left as a general statement on a webpage that can be edited at any time.

The Indian legal position on data security

India does not yet have a single, fully operative data protection statute the way the EU has the GDPR. Two things currently govern a vendor's data-security obligations, and a third is being phased in.

First, Section 43A of the Information Technology Act, 2000 makes a body corporate liable for negligence: "Where a body corporate...is negligent in implementing and maintaining reasonable security practices and procedures and thereby causes wrongful loss or wrongful gain to any person, such body corporate shall be liable to pay damages by way of compensation to the person so affected." This is a compensation right, not a licensing regime. It means a vendor that mishandles your data can be sued for the loss it causes, but it does not by itself define what "reasonable security practices" must look like.

That definition comes from the second source: the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, framed under Section 43A. Rule 5(8) requires that "body corporate or any person on its behalf shall keep the information secure as provided in rule 8." Rule 8 then does something specific and genuinely useful to a buyer: it names an actual international standard as the legal benchmark. A body corporate that has implemented IS/ISO/IEC 27001, certified by an independent auditor approved by the Central Government, "shall be deemed to have complied with reasonable security practices and procedures" under Indian law. This is worth knowing precisely because it means asking a vendor for ISO/IEC 27001 certification is not just international best practice, it is the specific standard Indian law itself points to as the safe harbour. Adira has not published a current ISO/IEC 27001 or SOC 2 Type II certificate on its public site as of this writing. If you need to see one, request it directly through adiralaw.com or your Adira contact and get a dated copy, not a verbal assurance.

Third, the Digital Personal Data Protection Act, 2023 (DPDP Act) is notified along with the DPDP Rules, 2025, but its substantive obligations, consent, breach notice, security safeguards under Section 8(5), are commencing in stages through 14 May 2027 on the government's own timeline. For what this means for the contracts you sign with any vendor, including the clauses your own DPA with Adira should carry, see our detailed guide to the DPDP Act for contracts. On cross-border transfer specifically, Section 16(1) of the DPDP Act takes a "negative list" approach: "The Central Government may, after an assessment of such factors as it may consider necessary, notify that the transfer of personal data by a Data Fiduciary to any country or territory outside India shall not be made." No such restricted-country notification exists yet, so cross-border transfer is currently permitted by default rather than blocked, which is a different rule than many buyers assume.

International privacy coverage: GDPR, UK-GDPR, CCPA, PIPEDA and Australia

Adira serves teams outside India as well, through Clausio LLP, so its data agreement is written to speak to the major frameworks an international customer's own counsel will ask about. State plainly to your own compliance team which of these actually applies to you, since most Indian buyers only need the DPDP and IT Act analysis above.

Under the EU GDPR, Article 28 requires that "a controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures" and sets out the mandatory terms of a processor contract, security, sub-processor consent, deletion or return of data on termination, audit rights. A DPA that tracks Article 28's list is the practical test of GDPR alignment; ask to see the specific clauses, not just a claim of "GDPR compliant."

The UK GDPR, retained and amended under the Data Protection Act 2018, uses its own adequacy and transfer framework, separate from the EU's. The ICO's current guidance sets out three lawful pathways for a restricted transfer out of the UK: an adequacy regulation, appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or a narrow situational exception. Ask which pathway Adira's DPA uses for UK customer data.

The California Consumer Privacy Act requires, under Civil Code Section 1798.100, that a business inform consumers "of the categories of personal information to be collected and the purposes for which the categories of personal information are collected or used," and separately requires a written contract restricting how a "service provider" may use personal information it processes on a business's behalf. Canada's PIPEDA takes an accountability approach: Schedule 1, Principle 4.1.3 states that "an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing," and requires "contractual or other means to provide a comparable level of protection while the information is being processed by a third party." Australia's Privacy Act 1988, Australian Privacy Principle 8, requires that before an entity discloses personal information to an overseas recipient, it must "take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles," subject to narrow exceptions such as express consent.

Adira's DPA is written to align with these frameworks for customers operating in these jurisdictions. Treat "aligned with" and "certified under" as different claims. Ask Adira's team to point you to the specific contractual mechanism, Standard Contractual Clauses, a UK Addendum, a service-provider restriction clause, that applies to your jurisdiction, and get it in the signed agreement.

Data residency: where does it actually sit

Data residency is a separate question from training, and it deserves its own scrutiny; our full guide to data residency for legal software walks through why storage location, processing location, and the sub-processor list are three different things a vendor can answer differently. As of this writing, Adira has not published a specific, named list of storage regions on its public site. If a named region, or data segregation for a specific jurisdiction, matters to your organisation, do not assume it from the "built for India" positioning; ask for it in writing and get the current sub-processor list attached to your DPA.

Apply the buyer checklist to Adira yourself

Our companion guide, does AI legal software train on your contracts, sets out the questions to put to any AI vendor before you sign. Applied to Adira: is the no-training commitment written into the signed DPA, not just stated on the website; which underlying model provider is used, and what is that provider's own retention policy; how long is data retained for support purposes even where it is not used for training; what is the current sub-processor list, with countries named; what breach-notification timeline does the DPA commit to; and is there a current, dated SOC 2 or ISO/IEC 27001 report you can actually read, rather than a badge on a marketing page. Send this list to Adira's team through adiralaw.com before you sign, and keep the written answers.

Red flags when evaluating any AI legal vendor's security posture

NormalRed flagWhy it matters
No-training commitment is a clause in the signed DPANo-training claim exists only on the marketing websiteA webpage can change overnight; only a signed clause is enforceable
Vendor names its underlying model provider(s) by nameVendor won't say whose model it runs onYou cannot check the model provider's own policy if you do not know who they are
Data retention period is a stated number of days or months"We only keep data as long as necessary" with no numberVague retention language is unenforceable and unverifiable
Current sub-processor list is published or provided on requestVendor refuses to disclose its sub-processorsYour data may pass through parties you never agreed to
Breach notice timeline is stated as a specific periodNo breach-notification clause at allUnder Indian and most international law, you bear liability even for your processor's breach
Vendor will negotiate a DPA to add specific protective terms"Our standard terms cannot be changed," even for a no-training clauseSignals the claim is a sales line, not a documented commitment
Vendor can name actual storage regionsVague references to "the cloud" with no region statedYou cannot assess cross-border exposure without knowing where data physically sits
Certification claims come with a current, dated report you can readCertification is claimed but no report is offered on requestAn unverifiable certification claim is worth exactly nothing

A bad-to-better clause rewrite

A data-use clause you will see in many vendor contracts, including some CLM and AI-drafting tools, reads like this.

Bad: "Vendor may use aggregated or anonymised data derived from Customer's use of the Service to improve its products and services."

This sentence sounds harmless but does almost no real work for the buyer. "Aggregated or anonymised" is undefined, so the vendor decides what counts. "Improve its products and services" is broad enough to cover model training. And it says nothing about the underlying model provider, sub-processors, or what happens to this permission after termination.

Better: "Vendor shall not, and shall ensure its sub-processors and underlying model providers do not, use Customer Content (defined as any document, clause, data field, or output uploaded, drafted, or generated by Customer within the Service) to train, fine-tune, or otherwise alter the weights of any machine learning model. This restriction survives termination of this Agreement. Vendor may collect de-identified usage metrics (such as feature-click counts or session length) solely for product analytics, as itemised in Schedule X, and such metrics shall exclude the content of any Customer document."

What changed: the rewrite defines "Customer Content" specifically instead of leaving "data" undefined, names the underlying model provider explicitly so the restriction cannot be argued away as "that's the model provider's decision, not ours," adds a survival clause so the promise does not expire with your subscription, and narrows the permitted exception (usage metrics) to a defined, itemised list instead of an open-ended "improve its products" carve-out.

Try before you commit

You do not need a paid account to see how a vendor actually behaves on your documents. You can mark up a single clause for free in Weave, Adira's free browser contract tool, without creating a paid account or uploading a full contract portfolio anywhere. Use that to test how a tool reads and redlines a real clause before you evaluate a CLM's data practices at scale.

FAQ

Does Adira train its AI on the contracts I upload? No, not under Adira's standard commercial terms. Get this stated as a clause in your signed DPA, with a defined term for the data it covers and a survival clause, rather than relying on a marketing page.

Which AI model does Adira use, and does that provider train on my data? Adira is built on Anthropic's Claude models. Anthropic's stated policy for commercial products is that inputs and outputs are not used to train its models by default; consumer and commercial Anthropic products carry different policies, so confirm which applies to your account.

Is Adira SOC 2 or ISO 27001 certified? Not published on its public site as of this writing. Under Indian law, ISO/IEC 27001 certification (audited by a Central-Government-approved auditor) is the specific standard that creates a deemed-compliance safe harbour under Rule 8 of the 2011 SPDI Rules, so it is a reasonable thing to request a current, dated copy of.

Where is my data stored if I use Adira? Adira has not published a named list of storage regions as of this writing. If a specific region or jurisdiction-specific segregation matters to you, ask for it in writing and get the storage region and sub-processor list attached to your DPA. See our data residency guide for what to check.

Does Adira comply with India's DPDP Act? Adira's data handling is designed to align with the DPDP Act, 2023, whose substantive obligations are commencing in stages through 14 May 2027. Ask specifically which DPDP-related clauses, consent language, breach notice, deletion, already appear in Adira's current DPA, rather than assuming full compliance simply because the Act has been notified.

What should I actually ask Adira's security team before I sign? The no-training clause in the signed DPA, the underlying model provider's own current data policy, the data retention period, the current sub-processor list with countries named, the breach-notification timeline, and any current SOC 2 or ISO 27001 report you can read. Put the answers in the contract, not just in an email.

This page explains the standard questions to raise with any AI legal vendor and states what Adira has published or confirmed as of September 2026. It is not a substitute for reading Adira's actual signed DPA, verifying current certification status yourself, or getting your own procurement or legal counsel's sign-off, particularly if your organisation is subject to sector-specific data rules such as RBI guidelines for regulated financial entities.

Frequently asked questions

Does Adira train its AI on the contracts I upload?
No, not under Adira's standard commercial terms. Adira does not use customer contract content to train its own models or to fine-tune the underlying Claude models. Get this stated as a clause in your signed Data Processing Agreement, with a defined term for the data it covers and a survival clause that outlasts termination, rather than relying on a marketing page.
Which AI model does Adira use, and does that provider train on my data?
Adira is built on Anthropic's Claude models. Anthropic's stated policy for commercial products is that inputs and outputs are not used to train its models by default, and Anthropic's commercial terms state Anthropic may not train models on customer content from its commercial services. Anthropic's consumer products carry different rules than its commercial API, so confirm with Adira which product terms apply to your account.
Is Adira SOC 2 or ISO 27001 certified?
Not published on Adira's public site as of this writing. Under Indian law, ISO/IEC 27001 certification, audited by a Central-Government-approved auditor, is the specific standard that Rule 8 of the 2011 SPDI Rules names as creating a deemed-compliance safe harbour for reasonable security practices. That makes it a reasonable, specific document to request. Ask Adira directly through adiralaw.com for a current, dated copy rather than accepting a general assurance.
Where is my data stored if I use Adira?
Adira has not published a named list of storage regions on its public site as of this writing. If a specific storage region or jurisdiction-specific data segregation matters to your organisation, do not assume it from Adira's India-first positioning; ask for it in writing and get the current storage region and sub-processor list attached to your signed DPA.
Does Adira comply with India's DPDP Act?
Adira's data handling is designed to align with the Digital Personal Data Protection Act, 2023, whose substantive obligations, consent, breach notice, security safeguards, are commencing in stages through 14 May 2027 on the government's own timeline. Because the operative provisions are still phasing in, ask specifically which DPDP-related clauses already appear in Adira's current DPA rather than assuming full compliance simply because the Act has been notified.
What should I actually ask Adira's security team before I sign?
Ask for the no-training clause in the signed DPA, the name of the underlying model provider and that provider's own current retention policy, the data retention period stated in days or months, the current sub-processor list with countries named, the breach-notification timeline, and any current SOC 2 Type II or ISO/IEC 27001 report you can actually read. Put every answer in the contract, not just in an email or a sales call.
Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom

Working through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.

Try Weave — free