Skip to content
Sovereignty and consent

What are the sovereignty profiles?

AU Sovereign, Global and UK Sovereign differ in where records are stored and where audio and transcripts are processed. UK Sovereign is live for United Kingdom organisations.

Reviewed 4 October 2026 · Updated 4 October 2026

Every organisation runs on exactly one profile — AU Sovereign, Global or UK Sovereign — chosen when the organisation is created and applied to everyone in it. It can’t be switched in place. Clinical records are stored in Australia on AU Sovereign and Global; UK Sovereign stores them in London.

The profile decides one thing: where audio and transcripts are processed. It doesn’t change where the record is kept.

AU Sovereign

For organisations in Australia and New Zealand. On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs transcription and note drafting on vetted Australian services over private links inside its cloud — disclosed on every note, under the consent your organisation gives for that processing. Ordinary consent to record is separate for each consultation. Speaker identity, including any voice profile you record, is matched only on Small Mercy’s own infrastructure and never sent to a provider. A Small Mercy-managed processing route beyond Australia requires separate, explicit acceptance for that session and purpose. The optional Global note fallback is currently disabled; if enabled after an in-cell drafting failure, a clinician may choose to send that consult’s transcript — not its audio or other outputs — for processing that may occur outside Australia, for that consult’s note and later redrafts only. The organisation and session stay AU Sovereign, with no automatic switch. A confirmed note or letter you choose to send to connected practice software reaches your vendor account; Nookal’s Australian API service alone does not establish that account’s storage region.

  • Small Mercy-managed transcription and drafting in Australia by default, on vetted services over private links; speaker identity only ever on Small Mercy infrastructure.
  • Clinical record stored in Sydney.
  • A Small Mercy-managed route beyond that pathway only after explicit per-session acceptance; an optional practice-software send goes to your vendor account.
  • The Global note fallback is disabled; if enabled, a clinician must choose it for one consult’s note and redrafts. It sends the transcript, not audio or other outputs, and does not change the AU Sovereign profile.
  • Audio deleted by default.

Global

For organisations outside Australia and New Zealand once rest-of-world access opens; it is currently coming soon and public account creation is not available. On this profile, vetted global managed providers process audio and transcripts by default under your organisation’s consent. Small Mercy stores the clinical record in Australia. No provider uses that data to train its models.

  • Clinical record stored in Sydney, Australia.
  • Inference by vetted global providers.
  • Organisation-level provider consent.
  • Audio deleted by default.

Storage is not processing. Storage in Sydney does not make Global processing Australian. On Global, inference happens with those vetted providers; the Sydney residency applies to the stored record, not to where the audio was processed.

What’s the same either way

Both profiles keep the parts that aren’t negotiable: the audio Small Mercy holds is deleted by default, clinical data is never used to train models, and every access is written to an append-only audit log. On Global, Small Mercy does not yet collect independent deletion proof from the third-party processors — see what happens to consult audio. Small Mercy is a documentation aid, not a diagnostic device — it must never invent, suggest or infer a diagnosis, dose, management plan or other clinical fact absent from the source; required gaps stay [not stated]. Every draft needs your explicit review and confirmation, on either profile.

The profile is chosen at sign-up and applied to everyone in the organisation, not per clinician. If you’re not sure which one you’re on, ask whoever set up your organisation’s account, or get in touch.

New Zealand organisations run AU Sovereign: Small Mercy’s default audio and transcript processing takes place in Australia and its clinical record is stored in Sydney. A Small Mercy-managed offshore route needs explicit acceptance for that session; an optional practice-software send reaches the connected vendor account. NZ-resident processing is on the roadmap.

UK Sovereign

The United Kingdom has its own live region: on UK Sovereign, the clinical record is stored in the United Kingdom (London), and the ordinary transcription and note-drafting route runs in the United Kingdom or European Union — transcription on Deepgram’s EU regional service, note drafting on Amazon Bedrock, invoked from AWS London and served in AWS’s UK or EU regions — under the UK’s adequacy regulations for the EEA. The optional Global note fallback is currently disabled; if enabled after an in-region drafting failure, a clinician may choose to send that consult’s transcript — not its audio or other outputs — for processing that may occur outside the UK and EU, for that consult’s note and later redrafts only. The organisation and session stay UK Sovereign, with no automatic switch. The service is open to United Kingdom organisations — Small Mercy in the UK has the detail. A confirmed note or letter you choose to send to connected practice software reaches your vendor account; Nookal’s European API service alone does not establish that account’s storage region. The UK privacy notice, Data Processing Schedule and sub-processor list are published. Everything on this page about storage in Australia describes the AU Sovereign and Global profiles.

More detail on the split between storage and processing is in where your data is stored and processed, and the whole picture is on privacy by design.

Still stuck?

Email support@smallmercy.app — or see the contact page. Service status lives at status.smallmercy.app.