UK Privacy Notice
Two kinds of data, two roles
Clinical data — session audio (transient), transcripts, drafted and confirmed clinical notes, letters, patient identifiers your practice enters, and processing-evidence records — is controlled by your practice. Akoua processes it only on the practice's instructions, as its processor under UK GDPR, on the terms in the Data Processing Schedule. Patients seeking access to or correction of their health records should contact their practice, which Akoua assists.
Account data — practitioner names, sign-in credentials and factors, billing records, and support correspondence — is controlled by Akoua, and this notice describes that processing.
Where data lives
Clinical data at rest is stored in the United Kingdom (London, eu-west-2), in a deployment isolated from every other Akoua region. Automated transcription runs on Deepgram's EU regional service (Frankfurt, Germany) and automated note drafting on Amazon Bedrock, invoked from Amazon Web Services' London region (eu-west-2) and served in Amazon Web Services' European Union regions, as the ordinary route for every consult; that UK-to-EU processing is covered by the UK's adequacy regulations for the EEA. No clinical data is stored or processed outside the UK and the EU in the ordinary operation of the service.
Remote access for support and platform administration may occur from Australia. It is exceptional rather than routine, scoped to the task, authenticated, and written to an append-only audit log; the data itself remains stored in the United Kingdom. This would be a restricted transfer. The agreement template for that transfer incorporates the ICO's International Data Transfer Agreement (IDTA) with the EU Standard Contractual Clauses by reference, supported by a transfer risk assessment. That documentation is not yet executed. The service is open to United Kingdom organisations.
Automated by design
In ordinary operation the service processes clinical data by automated means only. Akoua personnel do not access clinical data content except at your practice's request for support, to investigate an incident or suspected breach, or where required by law — and every such access is role-restricted and logged in an append-only audit record.
Deletion and retention
Consult audio is deleted by default: kept encrypted only while the clinician reviews and deleted the moment the note is confirmed; a practice can instead set immediate deletion after processing, or a short fixed retention window, and every mode sits under a hard 7-day ceiling. On account termination or on the practice's instruction, clinical data is deleted within 14 days, except processing-evidence and audit records retained for legal claims and regulatory accountability, and encrypted backups, which expire on their retention cycle of 35 days. Backups remain within the UK region.
Never used to train models
Clinical data is never used to train models — not by Akoua, and not by the providers that process it. Transcription runs on Deepgram's EU regional service under a zero-retention configuration for audio and transcripts and an opt-out from provider model-improvement programmes; note drafting runs on Amazon Bedrock, which under AWS's published commitments does not store prompts or outputs or use them to train models. Every external processing hop is recorded immutably and is disclosable to your practice in-product.
Sub-processors
The providers that process data for the UK service, what they do, and where they do it are published on the UK sub-processor list, which is incorporated into the Data Processing Schedule. Practices receive advance notice of changes and may object on reasonable data-protection grounds.
If something goes wrong
Akoua notifies affected practices of a personal data breach involving clinical data without undue delay and in any event within 72 hours of becoming aware, with the information UK GDPR requires so far as then known.
Your rights
UK GDPR gives you rights over personal data Akoua controls — access, rectification, erasure, restriction, portability and objection. Write to privacy@akoua.ai. You can also complain to the Information Commissioner's Office (ico.org.uk). For clinical data, your practice is the controller — contact the practice first, and we will assist it.
Cookies and storage on your device
This website sets no cookies. There are no tracking, advertising or third-party cookies, and no third-party scripts: fonts are self-hosted, and visitor measurement is Cloudflare Web Analytics — a cookieless, aggregate page count that stores nothing on your device and does not profile you.
The one thing the site keeps on your device is the region you are viewing, so pages show the right availability, currency and residency. If you chose that region yourself from the switch in the top bar, it is stored until you change or clear it; if it was merely derived — you arrived on a regional page, or from your connection's country — it is kept only for the visit and then discarded. It contains a two-letter region, identifies nobody, is never sent to a third party, and you can remove it at any time by clearing site data in your browser. On that basis we do not ask you to accept cookies to read this site.
The Akoua web app is separate: signing in there uses the essential cookies and tokens needed to keep your session secure.
Measuring the sign-up form. When someone begins creating an account — whether or not they finish — we record how far the attempt got: a random number the browser tab invents for that attempt, which step it reached, how long it had taken, and — if the visitor arrived from a link on this site — the single word that link carried. No name, email address, IP address or account is stored alongside it, and the table it lands in has no column that could hold one. In the United Kingdom nothing is written to your device for this. The random number exists only while the page is open, so reloading simply begins a new attempt; we would rather lose the count than store something on your device that the sign-up does not need.
EU/EEA & UK GDPR Representatives (Article 27)
If you are located in the EU or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:
Euverify Ltd (UK)
3rd Floor
86–90 Paul Street
London
EC2A 4NE
United Kingdom
Email: gdpr@euverify.com
Euverify Ltd (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road
Cork
T23 AT2P
Ireland
Email: gdpr@euverify.com
To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal at gdpr.euverify.com/verify/ffcf2699-ff35-4e70-a7c2-c1b58951c65a. This link allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to ensure timely response and compliance.
More detail
The help centre explains the same ground in plain language: what UK Sovereign is, whether any UK data leaves the UK, your rights and who controls what, how long data is kept, and what happens if there is a breach.
Who we are
Akoua Pty Ltd · ACN 700 204 388 · ABN 31 700 204 388 · South Yarra, Victoria, Australia. Our Article 27 UK and EU representatives are listed above. Questions: privacy@akoua.ai.