Does any UK data leave the United Kingdom?
Clinical storage stays in London. Ordinary processing is in the UK or EU; exceptional Australian support access is scoped, authenticated and audited.
The record stays stored in the United Kingdom. The ordinary transcription and note-drafting route runs in the United Kingdom or European Union — transcription on Deepgram’s EU regional service, note drafting on Amazon Bedrock, invoked from AWS London and served in AWS’s UK or EU regions — under the UK’s adequacy regulations for the EEA. The optional Global note fallback is currently disabled. If enabled after an in-region drafting failure, a clinician may choose to send that consult’s transcript — not its audio or other outputs — for processing that may occur outside the UK and EU, for that consult’s note and later redrafts only. The organisation and session stay UK Sovereign, with no automatic switch. Remote support access from Australia is the separate exception set out below.
UK to EU
The ordinary transcription and note-drafting route runs in the United Kingdom or European Union — transcription on Deepgram’s EU regional service (Frankfurt, Germany), note drafting on Amazon Bedrock, invoked from AWS London and served in AWS’s UK or EU regions — under the consent your organisation gives, disclosed on every note. Ordinary consent to record is a separate authority, given for each consultation. UK-to-EU processing is covered by the UK’s adequacy regulations for the EEA — it is not a restricted transfer needing its own instrument. No clinical data is stored or processed outside the UK and the EU in the ordinary automated operation of the service. The Global note fallback is currently disabled; if enabled, it may process the transcript in any AWS commercial Region, including outside the UK and EU, only after the clinician accepts an offer for that consult’s note and later redrafts. It never covers audio or other outputs and does not change the organisation or session’s UK Sovereign profile. Each provider, what it does and where, is on the UK sub-processor list.
The one exception: support from Australia
Small Mercy is an Australian company, and remote access for support and platform administration may occur from Australia. Specifically:
- it is exceptional rather than routine — a support request you raised, an incident or suspected breach, or where the law requires it;
- it is scoped to the task, not bulk access;
- it requires a platform-administrator role with passkey or second-factor authentication;
- every read and action is written to an append-only audit log;
- the data itself stays stored in the United Kingdom. What crosses a border is the viewing, not the record.
That access would be a restricted transfer under UK GDPR. The agreement template for it incorporates the ICO’s International Data Transfer Agreement with the EU Standard Contractual Clauses by reference, supported by a transfer risk assessment. That documentation is not yet executed. The service is open to United Kingdom organisations. The UK privacy notice and Data Processing Schedule state the same position.
What that means in practice
In its ordinary operation the service processes clinical data by automated means only. Small Mercy personnel do not read clinical content except in the three circumstances above, and never silently — the audit log is the record, and ordinary access can add entries, never edit them; lawful purge follows export and the required retention period.
Still stuck?
Email support@smallmercy.app — or see the contact page. Service status lives at status.smallmercy.app.