Security your communications team can evaluate before procurement
Lyyli is built for secure organisational use. Customer data is protected with encryption, access controls, workspace isolation and logging. Data is processed only to deliver the service, in line with GDPR and agreed processing terms.
Lyyli is a communications operations platform that makes data flows transparent. Details on data location, AI processing, subprocessors and technical practices are in Trust Center.
Page content reviewed and updated: 13.07.2026
What we commit to and what we document
EU-focused workspace storage
Primary application data for customer workspaces is stored in the EU region. Some subprocessors may process data outside the EU/EEA; see the vendor register.
ZDR for language models · region is model-specific
Language models process requests under Zero Data Retention. Lyyli stores conversations for service functionality. Claude and Gemini: EU; GPT: Global. Details in the AI model register.
No training use of customer content
Customer content is not used to train models. The Gemini route goes through Vertex AI (Google Cloud SST + CDPA).
Workspace isolation and access control
Each organisation operates in its own workspace with role-based access and an audit trail for approvals and changes.
TLS and infrastructure encryption
Data is protected in transit with TLS and at rest with infrastructure provider encryption controls. This is not end-to-end encryption.
ISMS aligned with ISO 27001 framework
Information security practices are developed using the ISO 27001 framework. Lyyli is not currently ISO 27001 certified; certification is a goal.
How customer content moves through Lyyli
This describes the six-step flow from workspace through Vercel AI Gateway to the model provider and back. Processing region is model-specific. Lyyli stores conversations.
Content into workspace
A user creates or imports content into a Lyyli workspace. Content is stored according to workspace retention settings.
What is logged
- User, action, model/route, processing region (EU or Global), timestamp, success/error
- Token or cost metadata where applicable
- Whether input or response content is stored in logs depends on configuration and log type
- Security and audit logs follow a separate retention schedule
CISO checklist: share with your IT team
Use this list to speed up procurement evaluation. Full technical documentation is available in the registers linked below.
Zero Data Retention (language models)
Language models process requests under ZDR via Vercel AI Gateway. ZDR does not automatically cover Lyyli's own conversation history, web search, image generation, meeting recordings or abuse monitoring logs.
Training data policy
Customer content is not used to train models. Gemini: Google Cloud Service Specific Terms + Cloud Data Processing Addendum.
GDPR and DPA
Lyyli is a Finnish company. A Data Processing Agreement (DPA) is available as a standard annex. For contract and processing questions: hello@lyyli.ai.
Data location and transfers
Primary workspace data is EU-focused. Language-model processing region is model-specific. Authentication metadata, email delivery, analytics and some subprocessors may process data outside the EU/EEA under documented transfer mechanisms.
Encryption and monitoring
TLS in transit and infrastructure provider encryption at rest. Not end-to-end encryption. The platform has access controls and security monitoring.
Processing vs. storage: why can I see my chat history?
The architecture separates AI processing from workspace storage.
AI processing (ZDR, region is model-specific): the language model processes data via Vercel AI Gateway and does not retain the prompt or response after the request. Claude and Gemini: EU; GPT: Global.
Your workspace (EU-focused): chat history and drafts are stored in your workspace on Lyyli's secured infrastructure. Deletion from the active system happens without undue delay; copies may remain in backups for a limited period.
Does your IT team need deeper documentation?
Or contact us directly: hello@lyyli.ai
Requires a credit card.