Security and Confidentiality of Medical Data
-
audio recordings of consultations are not stored after processing;
-
the initial transcript is not accessible to the administration, management of the healthcare institution, chief physician, or other platform users;
-
the physician controls the final medical document before it is saved or transferred to the MIS;
-
patient data is not sold or transferred to third parties without a lawful basis;
-
data processing workflows are built in accordance with GDPR principles and the approaches of the international standard ISO/IEC 27001.
Tayra works with medical information; therefore, the protection of personal data of physicians and patients is one of the key principles of the platform’s operation. We pay special attention to the confidentiality, integrity, and controlled processing of information created during a medical consultation.
Tayra’s data processing workflows are built in accordance with personal data protection legislation, GDPR principles, and the approaches set out in the international standard ISO/IEC 27001.


Data Storage Minimization
The audio recording of a consultation is used exclusively for automated processing and the creation of a structured medical document. After processing is completed, the audio file is automatically deleted and is not stored on the platform.
Only the structured text of the medical document, required for the physician’s further work, remains in the system. Before saving the document or transferring it to the medical information system, the physician can review, edit, and confirm the generated document.
This approach minimizes the volume of sensitive data processed by the platform and reduces the risks associated with storing raw information.
Access Control for Audio and Transcripts
Tayra is built on the principle of restricted access to sensitive medical information. The consultation audio recording and the initial transcript are used only for the automated creation of a medical document and are not available for review by the healthcare institution’s administration, management, chief physician, or other platform users.
After processing, the audio file is automatically deleted, and the initial transcript is not stored as a separate material for later review. The physician works only with the structured text of the document, which can be reviewed, edited, and confirmed before saving.
In this way, Tayra minimizes access to raw consultation data and ensures that medical information is used exclusively within its professional purpose — to prepare high-quality medical documentation.
Confidentiality of Information
Tayra does not sell personal or medical data and does not transfer it to third parties without an appropriate lawful basis. Information processed by the platform is used only to ensure the functionality of the service and to create medical documentation.
Access to data is granted only to authorized users and only to the extent necessary for the operation of the platform. If technical providers are involved in data processing, such cooperation is carried out in accordance with contractual requirements for confidentiality, security, and personal data protection.
Transparency of Processing and Physician Control
Tayra ensures a transparent and controlled process for handling medical information. Data obtained during a consultation is used exclusively to create medical documentation and is not used for other purposes without an appropriate lawful basis or separate consent.
The final medical document always remains under the physician’s control. Before saving it or transferring it to the medical information system, the physician has the opportunity to review, edit, and confirm the generated text.
Tayra does not replace the physician’s clinical decision-making; it serves as a tool for automating routine documentation work. Responsibility for the final content of the medical record remains with the healthcare professional who reviews and approves the document.
Patient data is not used to train artificial intelligence models without a proper lawful basis or separate consent.
Technical Protection
Data transmission is carried out through secure communication channels using modern SSL/TLS encryption protocols. To reduce the risk of unauthorized access, access control mechanisms, user permission management, and other organizational and technical security measures are applied.
Tayra regularly reviews its approaches to information protection and improves internal processes in line with technological development, changes in regulatory requirements, and current cybersecurity risks.
Responsible Approach to Medical Data
Data security at Tayra is not an additional feature, but an integral part of how the platform operates. We follow the principles of data minimization, restricted access, secure information transmission, and physician control over the final medical document.
Patient confidentiality, the protection of medical information, and physicians’ trust remain the foundation of Tayra’s work.