Ardela
Ardela
Help Centre
Security

UK Data & Compliance

Guidance for England and Wales firms using Ardela with confidential legal work.

Ardela provides technical and organisational controls that can support a firm's UK data protection, confidentiality, and professional obligations. Your firm remains responsible for deciding whether and how Ardela is used for each client and matter.

Before rollout

Your data protection lead, COLP, COFA, or other appropriate owner should:

  • Complete the firm's supplier and data protection assessment
  • Review Ardela's Legal Centre, terms, and current subprocessor details
  • Decide which practice areas and information types may be processed
  • Set retention, export, sharing, and deletion procedures
  • Confirm how client confidentiality and any required notices or consents will be handled
  • Document who may approve AI-generated drafts and changes

Recordings and documents are hosted in the UK by default, but transcription and AI subprocessors are not all UK-resident. Do not treat UK hosting as a promise that data never leaves the UK.

Configure the workspace

  • Require MFA where your plan supports workspace enforcement, and encourage every member to enable 2FA
  • Give each member the least access needed for their role
  • Use explicit Matter grants to limit access to relevant members or groups. Client access does not open every matter for that client.
  • Deactivate leavers promptly and review pending invitations
  • Review Clara permissions and the sharing boundaries of the resources it can use
  • Review activity records and integration access regularly

Use AI output safely

Transcripts, summaries, documents, form fields, findings, and redlines can contain mistakes or omit context. Check source material and citations, and require professional review before filing, signing, advising a client, or sending work outside the firm.

Ardela is not a law firm and does not provide legal advice. Its outputs are drafts for review by your legal team.

Devices and conversations

  • Follow the firm's rules for recording meetings and calls
  • Confirm any notice or consent required for the particular conversation and jurisdiction
  • Use approved devices, microphones, and networks
  • Avoid leaving recording controls, transcripts, or exported files visible on shared devices
  • Sign out after using a shared workstation

Policies and evidence

Keep internal records of access reviews, training, approved workflows, incidents, and deletion or export requests. Contact Ardela support for current security documentation or help with a supplier assessment.

This page is operational guidance, not legal advice.

On this page