Compliance built into
the architecture.

Kuulo processes everything, audio, transcripts, and AI notes, on your device. There’s no server to breach and no cloud record to request. Here’s the formal compliance picture, by framework.

UK & EU GDPRHIPAA-readyEU AI ActCCPA / CPRAAES-256 encrypted
UK GDPR mark

UK GDPR & Data Protection Act 2018

Compliant

Everything Kuulo records is processed on your device. Personal data never reaches our servers, so you, or your practice, stay the data controller throughout.

What we comply with

  • UK GDPR & Data Protection Act 2018
  • Processed on your device, nothing transmitted to Kuulo
  • AES-256 encryption at rest (Apple Data Protection)
  • DPIA completed and Records of Processing maintained
  • No Data Processing Agreement needed for standard use

Request compliance documentation

Documents are provided by email, typically acknowledged within one business day.

Data Protection Impact Assessment

Full ICO-methodology DPIA: risks assessed, no residual high risk.

Request →

Records of Processing Activities

Article 30 controller and processor records.

Request →
Questions about UK GDPR? support@kuulo.aiContact us →