Managed AI for your organisation's communications

Generic AI services are built for consumers and the mass market, which is why they often retain inputs and use generated content to train AI models. In professional communications and expert organisations, this is a security risk that must be managed actively, not brushed aside.

Lyyli is a communications workflow management system that makes data flows transparent. Our platform documents comprehensively how data moves between workspaces, AI routes, and integrations. Enterprise-grade security, audit trails, and GDPR compliance are built into the core product, not sold as a costly Enterprise upsell.

Page content reviewed and updated: 13.07.2026

What we commit to and what we document

EU-focused workspace storage

Primary application data for customer workspaces is stored in the EU region. Some subprocessors may process data outside the EU/EEA; see the vendor register.

Route-specific AI settings

Selected AI routes use Zero Data Retention settings. Retention, training, and exception policies vary by route and are documented in the AI model register.

No training use of customer content

Customer content is not used to train models under applicable agreements and route-specific settings. Exceptions depend on route and provider.

Workspace isolation and access control

Each organisation operates in its own workspace with role-based access and an audit trail for approvals and changes.

TLS and infrastructure encryption

Data is protected in transit with TLS and at rest with infrastructure provider encryption controls. This is not end-to-end encryption.

ISMS aligned with ISO 27001 framework

Information security practices are developed using the ISO 27001 framework. Lyyli is not currently ISO 27001 certified; certification is a goal.

How customer content moves through Lyyli

This describes the six-step flow from workspace to AI route and back. It does not guarantee that all processing stays in one region or that no data is stored.

1

Content into workspace

A user creates or imports content into a Lyyli workspace. Content is stored according to workspace retention settings.

2

Workspace storage

Primary application data is stored in an EU-focused environment. Backups rotate for a limited period.

3

Prepare the AI request

For an AI call, Lyyli builds a request and minimises unnecessary identifiers where applicable.

4

To a documented AI route

The request is sent to a selected, documented AI route. Processing region and retention terms depend on that route.

5

Provider processing

The AI provider processes the request under its route-specific terms. ZDR settings apply to selected routes, not all processing.

6

Response returns to workspace

The response returns to Lyyli and is stored in the workspace when the workflow requires it. You can delete data from the active system.

What is logged

  • User, action, model/route, timestamp, success/error
  • Token or cost metadata where applicable
  • Whether input or response content is stored in logs depends on configuration and log type
  • Security and audit logs follow a separate retention schedule

CISO checklist: share with your IT team

Use this list to speed up procurement evaluation. Full technical documentation is available in the registers linked below.

Zero Data Retention (route-specific)

Selected AI routes use ZDR settings documented in the AI model register. ZDR does not automatically cover Lyyli's own workspace storage, web search, image generation, meeting recordings, or abuse monitoring logs.

Training data policy

Customer content is not used to train models under applicable agreements and route-specific settings. Abuse monitoring practices may vary by provider.

GDPR and DPA

Lyyli is a Finnish company. A Data Processing Agreement (DPA) is available as a standard annex. For contract and processing questions: hello@lyyli.ai.

Data location and transfers

Primary workspace data is EU-focused. AI processing, authentication metadata, email delivery, analytics, and some subprocessors may process data outside the EU/EEA under documented transfer mechanisms.

Encryption and monitoring

TLS in transit and infrastructure provider encryption at rest. Not end-to-end encryption. The platform has access controls and security monitoring.

Processing vs. storage: why can I see my chat history?

The architecture separates AI processing from workspace storage.

AI processing (route-specific): the language model processes data and returns a response under route-specific retention terms.

Your workspace (EU-focused): chat history and drafts are stored in your workspace on Lyyli's secured infrastructure. Deletion from the active system happens without undue delay; copies may remain in backups for a limited period.