Company data and AI meet in a contract in five places: where the data lives, who can reach it, what it may be used for, how long it is kept, and what happens to it when the relationship ends. If your contract with an AI vendor does not answer those clearly, you are handing data over blind. Here is what to ask, and why the answers get much shorter when the AI runs on your own infrastructure.
The work nobody wants
Most companies start with AI the same way. Someone in sales opens an account, uploads the client spreadsheet, and a week later five more people are doing the same. Nobody signed anything. Nobody read the terms. When the managing director or the data protection officer finally asks, it turns out the data sits in several personal accounts, on different plans, each with its own rules.
Then comes the unpleasant round. A lawyer reads thirty pages of terms of service, hunting for storage, subprocessors and model training. Sales waits. It often ends in a compromise nobody quite believes in: AI is allowed, but not with sensitive data. Which means not with anything that matters.
“So where exactly are our contracts right now?” Silence in the meeting room.
— A board meeting, abridged
Five questions the contract has to answer
When an AI vendor processes personal data about your customers or staff, it acts as a processor, and Article 28 of the GDPR requires a written contract with specific content. Beyond that legal floor, it pays to have a clear answer to five things.
- Where the data lives. Which country, which data centre, whose infrastructure.
- Who can reach it. Subprocessors by name, and how that list is allowed to change.
- What it may be used for. Above all, whether a model may be trained on it.
- How long it is kept. Logs, backups and caches as well as the main database.
- What happens at the end. Deletion or return, confirmation, deadlines.
Large vendors give decent answers to the first four. Anthropic's commercial terms, for example, state that customer content from its commercial services is not used to train models. But every extra tool you add to the chain repeats the questions. And the fifth is usually the weakest part of the whole document.
What running on your own infrastructure changes
AI stack builds the platform to run on the customer's cloud. Claude gets only what a given question needs, and it reads data through small MCP servers: bridges between Claude and the systems the company already uses. Every bridge carries the identity and permissions of the person asking.
For the contract, that means many of the answers become architecture instead of promises. The data stays where it is today. Your existing permissions govern access. The record of who asked what sits in your audit log. And ending the relationship means switching the bridges off, not negotiating the deletion of copies you never knew existed.
Concretely: contracts in Google Drive, clients in a CRM
Take a small trading company of, say, thirty people, purely for illustration. Contracts live in Google Drive, clients in Raynet CRM, invoices in Pohoda. None of it moves. Three bridges are added, each with a narrow scope.
- The Drive bridge reads only folders the person asking can open, and returns excerpts rather than whole files.
- The CRM bridge may read contacts and deal status; any write needs a person to confirm it.
- The Pohoda bridge reads balances and due dates; payroll is out of scope.
- Every request is written to an audit log inside your own tenant.
When the company's lawyer then asks the five questions above, the answers fit on one page. Data in the country and on the cloud the company already has under contract. Access by existing roles. The model is called at Anthropic under its commercial terms. At the end, the bridges are switched off.
What this will not do, and why that is good
It will not make you a lawyer, and it will not write the contract for you. The processing agreement, the impact assessment and the decision about which data goes near AI at all still belong to a person who answers for them. This article is not legal advice. It is a list of questions to bring to your lawyer.
Nor does it remove every contractual relationship. Calling the model is still a third-party service, and its terms are worth knowing. The difference is how much rests on that side. The less data leaves your environment, the fewer clauses have to carry the weight.
What it would take
Not a year-long project. You start with one system and one team: we describe what Claude should read and with which permissions, and build the bridge on your cloud. Your IT sees every step, and your lawyer gets documentation of where data flows and where it does not.
What's left
The model is not the bottleneck. The gap between Claude and the data your company already has is the bottleneck, and in contracts that gap shows most clearly: more copies, accounts and tools mean a longer document. We close the gap so the contract can stay short.
If a conversation about AI with your lawyer or DPO is coming up, write to us. A short call: we go through your systems and the five questions, and you will know what the answers would look like for you.
