Skip to content
Sovereignty and consent

Where is my data stored, and where is it processed?

Clinical records are stored in Sydney on AU Sovereign and Global, and in London on the UK Sovereign region; processing location depends on the profile.

Reviewed 4 October 2026 · Updated 4 October 2026

These are two separate questions with two different answers.

Stored: on the AU Sovereign and Global profiles, your clinical record is stored in Small Mercy’s Australian cloud in Sydney (ap-southeast-2), on Amazon Web Services. The UK Sovereign region stores its records in the United Kingdom instead — see below.

Processed: where audio and transcripts are processed depends on the sovereignty profile your organisation chose at sign-up.

Keep the two apart when you’re answering a patient or a medico-legal reviewer. Storage residency in Sydney does not by itself tell you where processing happened.

Storage: Sydney, on the AU Sovereign and Global profiles

Your clinical record sits on Australian infrastructure — Sydney, ap-southeast-2 — handled in line with the Australian Privacy Principles (Privacy Act 1988 Cth). Where the processing happens is a separate question, answered by your profile below. That holds on AU Sovereign and on Global alike.

Everything is encrypted: AES-256-GCM application-level at rest, covering transcripts, notes, PII and voiceprints, and TLS 1.2/1.3 in transit. Sign-in supports emailed codes or links and optional passkeys, and every access to a record is written to an append-only audit log. Small Mercy doesn’t yet hold formal certifications — they’re on the roadmap, and we’d rather say that plainly than imply otherwise.

Processing: set by your profile

On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs transcription and note drafting on vetted Australian services over private links inside its cloud — disclosed on every note, under the consent your organisation gives for that processing. Ordinary consent to record is separate for each consultation. Note drafting runs on an Australian route spanning Sydney and Melbourne, so a consult may be structured in a different state from the one you practise in; the sub-processor list names each route. Speaker identity, including any voice profile, is matched only on Small Mercy’s own infrastructure and never sent to a provider. A Small Mercy-managed processing route beyond Australia needs separate, explicit acceptance for that session and purpose. The optional Global note fallback is currently disabled; if enabled after an in-cell drafting failure, a clinician may choose to send that consult’s transcript — not its audio or other outputs — for processing that may occur outside Australia, for that consult’s note and later redrafts only. The organisation and session stay AU Sovereign, with no automatic switch. An optional send of a confirmed note or letter to practice software reaches the connected vendor account; Nookal’s Australian API service alone does not establish that account’s storage region.

New Zealand organisations run AU Sovereign too: Small Mercy’s record is in Sydney and its default transcription and drafting run in Australia, across the Tasman. The separate vendor-account destination for an optional practice-software send has the same caveat described above.

On Global, audio and transcripts are processed by vetted global providers under your organisation’s consent. Neither Small Mercy nor those providers use your data to train models. The record still lands in Sydney; the processing did not happen there.

The profiles are set out in full in the sovereignty profiles.

UK Sovereign is live for United Kingdom organisations: it stores the clinical record in the United Kingdom (London), and the ordinary transcription and note-drafting route runs in the United Kingdom or European Union — transcription on Deepgram’s EU regional service, note drafting on Amazon Bedrock, invoked from AWS London and served in AWS’s UK or EU regions — under the UK’s adequacy regulations for the EEA. The optional Global note fallback is currently disabled; if enabled after an in-region drafting failure, a clinician may choose to send that consult’s transcript — not its audio or other outputs — for processing that may occur outside the UK and EU, for that consult’s note and later redrafts only. The organisation and session stay UK Sovereign, with no automatic switch. An optional send of a confirmed note or letter to Cliniko or Nookal reaches the connected vendor account; Nookal’s European API service alone does not establish that account’s storage region. United Kingdom organisations sign up at uk.smallmercy.app — Small Mercy in the UK has the detail.

Support tickets stay in Small Mercy

When you raise a support ticket, it is handled inside Small Mercy’s own platform — there is no third-party helpdesk service holding your correspondence. On the AU Sovereign and Global profiles, tickets are stored encrypted in the same Australian cloud as the rest of your organisation’s records, scoped to your organisation, and every access to clinical content is written to the audit log.

That is also why the ticket itself should stay operational: describe what happened rather than pasting clinical content into it. Support staff who need to look at a record do so through a separate, audited path that records who looked, when, and why.

The website and billing are separate

Records from the smallmercy.app website — the updates list and the contact form — are stored using Cloudflare Workers KV, a globally replicated store, so they may be held outside Australia. Contact-form enquiries may also be delivered to our inbox through Amazon SES and may be processed outside Australia in transit. These website records are entirely separate from service data. Billing is handled by Apple, Google or Stripe on their own infrastructure.

On Free, audio is deleted when the first draft arrives. Paid plans keep it encrypted for review and delete it on confirmation by default. See what happens to consult audio, or the privacy notice for your region.

Still stuck?

Email support@smallmercy.app — or see the contact page. Service status lives at status.smallmercy.app.