Our commitment to client privacy
Therapy documentation demands rigorous technical safeguards. Here is exactly how we handle, process, and protect your practice data.
Encryption Standards
- All data encrypted in transit: Transmitted securely using TLS 1.2 or higher.
- Data encrypted at rest: Stored on secure databases using AES-256 encryption.
Infrastructure & Isolation
- Enterprise cloud: Clinical data is hosted on Microsoft Azure infrastructure. Every provider that touches it is listed on our sub-processors page.
- Backups & retention: Automated geo-redundant backups with a 35-day retention policy.
Technical & compliance status
Compliance Roadmap
We build to the safeguards India’s Digital Personal Data Protection (DPDP) Act expects, and we are working toward external audits and certifications. We do not currently hold SOC 2 or ISO 27001 certification, and we do not currently sign HIPAA Business Associate Agreements (BAAs).
Security Auditing
We are actively aligning our operational controls with the SOC 2 Type II trust services criteria. We currently do not hold a SOC 2 Type II certification, but we are working to prepare our environment for future external audits.
Legal Jurisdiction
MyKaya is operated out of Mumbai, India.
How we process session audio
Encrypted Transmission
Audio is captured silently from your desktop recorder and transmitted immediately to our processing environment.
Secure Transcription & Drafting
The audio is transcribed and formatted into clinical templates (SOAP, DAP, CBT) on isolated cloud compute instances. PHI-aware logging ensures no client identifiers are leaked.
Encrypted Storage
Once notes are generated, the resulting drafts are stored in our secure database encrypted at rest (AES-256).
Where your data is processed
- India: transcription of Indian-language and code-mixed sessions.
- European Union: app hosting, the database, audio storage and audio processing (Sweden and Ireland).
- United States: transcription of English and other global-language sessions, and AI note drafting (Microsoft Azure OpenAI). Microsoft may process an individual request in another Azure region where the model runs.
The full list — each provider, what it does and what data it handles — is on our sub-processors page, which you can reference in your own client consent forms.
Incident response
Access to session and client records is logged — who, which record, when — and kept for a year. We alert on any attempt to read data across practice boundaries. If a breach affects your practice’s data, we tell you without undue delay and within 72 hours, with what we know, because you have your own clients to notify.
Report a vulnerability
Found a security issue? Email security@mykaya.app. Please don’t access or change data that isn’t yours, and give us reasonable time to fix the issue before disclosing it. We won’t take legal action against good-faith research that follows these guidelines.
Verifying compliance claims
Compliance is easy to claim and harder to verify. Running on a “HIPAA-eligible” or “GDPR-ready” cloud such as AWS or Azure covers infrastructure only — on its own, it does not make an application compliant. Genuine compliance also depends on application-level safeguards and the right contractual terms. We set the strictest bar for our own software controls. We encourage you to hold any vendor you evaluate to this same standard, including us.
Under India’s Digital Personal Data Protection (DPDP) Act, 2023, your practice is the Data Fiduciary — you decide how client data is handled and carry non-delegable responsibility for it. Any tool that processes that data on your behalf acts as your Data Processor, and the Act requires a valid contract between the two. When you evaluate any AI vendor — including us — confirm they can give you data-processing terms that cover this requirement. Ours is published: our Data Processing Agreement applies to every MyKaya account automatically.
For practices serving clients under US HIPAA rules, support for Business Associate Agreements (BAAs) is on our compliance roadmap.
