Claims register
Version: v1.1
Last updated: 17.08.2026
Next review: 01.10.2026
This document is Lyyli's official claims register. It defines the scope of security, privacy, and architecture-related claims and their possible technical exceptions. The register gives IT teams and legal reviewers a transparent, detailed view of the product's current state and contractual boundaries.
Primary application data for Lyyli customer workspaces is stored and processed in the EU region.
Scope: Workspace storage, Supabase database, and primary application database.
Exceptions: User authentication metadata, email delivery, system analytics, and certain subprocessors may process data outside the EU/EEA. AI processing region is model-specific: Claude and Gemini inference is locked to the EU; GPT processing cannot currently be limited to the EU only. See the AI model register, vendor register, and DPA.
Language models used by Lyyli process requests under Zero Data Retention: the model provider does not retain the prompt or response after the request.
Scope: All language-model routes via Vercel AI Gateway (Anthropic Claude, Google Vertex AI Gemini, OpenAI GPT).
Exceptions: ZDR does not cover Lyyli's own conversation history storage, image generation, web search, meeting recordings, or abuse-monitoring logs. There are no ZDR exceptions in the current language-model lineup. Row-level detail: AI model register.
Customer content is not used to train AI models.
Scope: AI integrations and AI processing routes.
Exceptions: Statutory exceptions and abuse monitoring may apply to model providers. The Gemini route uses Vertex AI; Google Cloud Service Specific Terms and the Cloud Data Processing Addendum prohibit using Customer Data to train or fine-tune AI/ML models without the customer's prior permission or instruction. There are no ZDR exceptions in the current language-model lineup.
Language-model processing region varies by model: Claude and Gemini inference is locked to the EU, while processing for all GPT models cannot currently be limited to the EU only. Processing region is auditable in logs.
Scope: Language-model inference via Vercel AI Gateway. Claude and Gemini: EU. GPT: Global.
Exceptions: Image generation, meeting routes, authentication, email, and analytics are documented separately and are not covered by this language-model region claim. There is no absolute “all of Lyyli is EU-compliant” label.
Data is protected in transit and at rest in line with industry standards.
Scope: Application layer and infrastructure layer.
Exceptions: The system does not use end-to-end encryption. The Lyyli application and infrastructure services we use process plaintext data to deliver the service and enable workflows.
Customer content deleted from the active system is removed without undue delay.
Scope: Lifecycle of customer-produced content and manual deletion.
Exceptions: Security logs, audit trails, and legal exceptions are retained on a separate, protected schedule. Copies of deleted data may remain in automated backups for a limited period before being overwritten.
Information security practices (ISMS) are developed in line with the ISO 27001 framework.
Scope: Organisational security governance and controls.
Exceptions: Lyyli does not currently hold formal ISO 27001 certification. Certification under the standard is a future development goal and does not describe the system's current state.
Our claims register describes openly and precisely what our security commitments mean in practice, their technical scope, and their identified exceptions.