Managed AI for your organisation's communications
Generic AI services are built for consumers and the mass market, which is why they often retain inputs and use generated content to train AI models. In professional communications and expert organisations, this is a security risk that must be managed actively, not brushed aside.
Lyyli is a communications workflow management system that makes data flows transparent. Our platform documents comprehensively how data moves between workspaces, AI routes, and integrations. Enterprise-grade security, audit trails, and GDPR compliance are built into the core product, not sold as a costly Enterprise upsell.
Page content reviewed and updated: 13.07.2026
What we commit to and what we document
EU-focused workspace storage
Primary application data for customer workspaces is stored in the EU region. Some subprocessors may process data outside the EU/EEA; see the vendor register.
Route-specific AI settings
Selected AI routes use Zero Data Retention settings. Retention, training, and exception policies vary by route and are documented in the AI model register.
No training use of customer content
Customer content is not used to train models under applicable agreements and route-specific settings. Exceptions depend on route and provider.
Workspace isolation and access control
Each organisation operates in its own workspace with role-based access and an audit trail for approvals and changes.
TLS and infrastructure encryption
Data is protected in transit with TLS and at rest with infrastructure provider encryption controls. This is not end-to-end encryption.
ISMS aligned with ISO 27001 framework
Information security practices are developed using the ISO 27001 framework. Lyyli is not currently ISO 27001 certified; certification is a goal.
How customer content moves through Lyyli
This describes the six-step flow from workspace to AI route and back. It does not guarantee that all processing stays in one region or that no data is stored.
Content into workspace
A user creates or imports content into a Lyyli workspace. Content is stored according to workspace retention settings.
Workspace storage
Primary application data is stored in an EU-focused environment. Backups rotate for a limited period.
Prepare the AI request
For an AI call, Lyyli builds a request and minimises unnecessary identifiers where applicable.
To a documented AI route
The request is sent to a selected, documented AI route. Processing region and retention terms depend on that route.
Provider processing
The AI provider processes the request under its route-specific terms. ZDR settings apply to selected routes, not all processing.
Response returns to workspace
The response returns to Lyyli and is stored in the workspace when the workflow requires it. You can delete data from the active system.
What is logged
- User, action, model/route, timestamp, success/error
- Token or cost metadata where applicable
- Whether input or response content is stored in logs depends on configuration and log type
- Security and audit logs follow a separate retention schedule
CISO checklist: share with your IT team
Use this list to speed up procurement evaluation. Full technical documentation is available in the registers linked below.
Zero Data Retention (route-specific)
Selected AI routes use ZDR settings documented in the AI model register. ZDR does not automatically cover Lyyli's own workspace storage, web search, image generation, meeting recordings, or abuse monitoring logs.
Training data policy
Customer content is not used to train models under applicable agreements and route-specific settings. Abuse monitoring practices may vary by provider.
GDPR and DPA
Lyyli is a Finnish company. A Data Processing Agreement (DPA) is available as a standard annex. For contract and processing questions: hello@lyyli.ai.
Data location and transfers
Primary workspace data is EU-focused. AI processing, authentication metadata, email delivery, analytics, and some subprocessors may process data outside the EU/EEA under documented transfer mechanisms.
Encryption and monitoring
TLS in transit and infrastructure provider encryption at rest. Not end-to-end encryption. The platform has access controls and security monitoring.
Processing vs. storage: why can I see my chat history?
The architecture separates AI processing from workspace storage.
AI processing (route-specific): the language model processes data and returns a response under route-specific retention terms.
Your workspace (EU-focused): chat history and drafts are stored in your workspace on Lyyli's secured infrastructure. Deletion from the active system happens without undue delay; copies may remain in backups for a limited period.
Does your IT team need deeper documentation?
Or contact us directly: hello@lyyli.ai