Skip to main content

What processes does Lyrebird use to protect data?

How Lyrebird Health protects patient data - data sovereignty, encryption, retention, and compliance. Aligned with our Trust Centre.

Lyrebird Health takes a privacy-first approach to safeguarding patient information, aligned with the data protection requirements of the regions we operate in. For the most current and complete detail on our security posture, compliance certifications, and sub-processors, see our Trust Centre - this is our source of truth for all privacy and security information.


Data Sovereignty & Regional Hosting

Lyrebird Health hosts and processes data within the same region it is collected in. For example, UK data is stored in the UK, and Australian data is stored in Australia. This ensures information never leaves the jurisdiction it originates from.

  • No audio storage: Audio from consultations is transcribed in real time and discarded immediately once it is no longer needed 0 it is never stored.

  • In-region processing: Both transcription and AI/LLM processing take place within the same region as the deployment, on secure cloud infrastructure hosted on Amazon Web Services (AWS).


Encryption & Data Handling

  • Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

  • Access control: Access to sensitive information is restricted on a least-privilege, need-to-know basis, with multi-factor authentication enforced for all privileged access. All access is logged, monitored, and reviewed.


Data Retention

  • Transcripts and draft notes are retained for a default period of 7 days, configurable by the customer, and then securely and permanently deleted.

  • If your account remains inactive for over 12 months, all associated personal data is destroyed.


AI & Data Use

  • Customer and patient data is never used to train or fine-tune the underlying AI model.

  • Every AI-generated note or letter is reviewed and approved by a clinician before it becomes part of any official record. The AI is an assistive tool only and never makes clinical decisions.

  • AI processing happens entirely within our own secure cloud environment - no external AI provider has access to, or visibility into, customer data.


Legal & Regulatory Compliance

Our practices are designed to align with applicable data protection legislation depending on the region in which Lyrebird is used, including:

  • UK GDPR

  • HIPAA (US)

  • The Australian Privacy Act 1988

Lyrebird Health is ISO 27001 certified for Information Security Management.


Sub-Processors & Third Parties

Lyrebird Health maintains a formal sub-processor list identifying every third party that may process data on our behalf, what they do, and where they are located. This is available in the Sub-Processors section of our Trust Centre. Data is never sold and never used for marketing.


Questions or Concerns?

If you'd like to learn more about our privacy and security practices, or report a potential security issue, contact our privacy/security officer at [email protected].

Did this answer your question?