Privacy

Privacy by product.

Alto Foundry, Pyris and Archer Redact handle information in different contexts. Choose a statement below to understand the relevant data flow and responsibilities.

Last updated: 13 August 2026

Alto Foundry website

Website privacy statement

This section applies when you browse this website or contact Alto Foundry through the contact details shown here.

Information we collect

The website does not intentionally use advertising trackers, behavioural analytics, user accounts or marketing cookies. The hosting provider and network services used to deliver the site may process ordinary technical request information, such as IP address, browser type, requested page, timestamps and security events.

If you contact Alto Foundry, we receive the information you include in your message, your contact details and related correspondence.

Why we use it

  • To deliver, maintain and secure the website.
  • To respond to enquiries and continue requested business discussions.
  • To meet legal obligations and protect our legitimate business interests.

Sharing and retention

Technical information may be processed by the providers used to host and secure the website. Correspondence is processed by our communications providers and may be shared with professional advisers where reasonably necessary. We retain enquiries only for as long as reasonably required for the discussion, our business records and applicable legal obligations.

Your choices

You can browse the public site without creating an account. You may ask us to access or correct personal information held in our correspondence records, subject to applicable law.

Pyris

Pyris privacy statement

Pyris supports the documentation of patient conversations and team meetings. The clinic or organisation using Pyris determines why a session is documented and is normally responsible for notices, consent, access and retention decisions.

The core boundary

Audio is processed in memory for live transcription and is never written to storage as an audio file. Pyris stores the resulting text and documentation, not the recording.

Information Pyris processes

  • Live microphone and, where enabled, system audio while a session is active.
  • Transcript segments, structured notes, edits, review status and session context supplied by the user.
  • Limited participant consent evidence, which may include participant name, role, notice version and consent or withdrawal outcome.
  • Application settings and operational information needed to run the selected deployment.

Purpose of processing

Pyris uses this information to verify the consent step, transcribe an active conversation, prepare a draft note, support human review and let authorised users find, manage and delete documentation.

Where processing occurs

Pyris can be configured for processing and storage on the user’s computer or within the customer’s cloud environment. The selected configuration, customer policy and release documentation determine the exact storage location and service providers.

In a local configuration, transcription and note generation run on the device. A clinic-operated consent service may exchange only the consent evidence required for the session; it is not intended to receive audio, transcripts or notes. In a customer-cloud configuration, relevant text and application data are processed within services selected and controlled for that customer environment.

Consent and withdrawal

Pyris includes a consent workflow, but the clinic remains responsible for choosing a lawful basis, giving an appropriate collection notice and obtaining any consent required in its jurisdiction and professional setting. Capture should not begin until the required participant decisions have been recorded. A recorded withdrawal stops capture and may trigger deletion of the affected session transcript according to the configured workflow.

Retention, access and deletion

The clinic or organisation sets the applicable retention policy and handles patient or participant requests. Authorised users can manage session records, delete individual documentation and use the available data-reset controls. Local data remains subject to the security, backup and deletion behaviour of the device and organisation managing it.

Security

Pyris reduces risk by not creating audio files. Customers remain responsible for endpoint security, user access, operating-system encryption, backups and secure configuration. Where customer-cloud services are used, the customer’s identity, network, encryption and access policies also apply.

Archer Redact

Archer Redact privacy statement

Archer Redact helps authorised teams identify and review information that should not be shared. It is deployed into the customer’s cloud environment rather than operated as a shared Alto Foundry document repository.

The core boundary

The customer controls the cloud subscription, authorised users, private connectivity, security policy, keys and retention settings for its deployment.

Information Archer processes

  • Documents uploaded to a binder and content extracted or indexed from those documents.
  • Redaction instructions, contextual exclusions, proposed findings, highlights and review decisions.
  • Comments, mentions, document-presence and collaboration information created by authorised team members.
  • User identity and access information supplied through the customer’s identity environment.
  • Audit and export events needed to support accountable document review.

Purpose of processing

Archer uses this information to organise documents, analyse them against the team’s instruction, link findings to source context, support collaborative review and produce flattened reviewed exports and audit information.

Where processing occurs

The production customer deployment is designed to run in the customer’s cloud environment. The reference Azure architecture uses private application access, customer-tenant identity, private data services and a customer-controlled AI service. If a customer elects to configure an external AI provider or another integration, that provider’s processing and the customer’s approved data-flow terms also apply.

Roles and responsibility

The customer decides what documents are uploaded, who can access them, what redaction rules apply, how long information is retained and when it is deleted. The customer is normally the organisation to contact about a document, individual-rights request or access decision. Alto Foundry’s role is governed by the relevant deployment, support and contractual arrangements.

Retention, deletion and exports

Documents, binder records, findings, collaboration records and audit information are retained under the customer’s configured policies. Authorised users can delete documents or binders and generate reviewed exports. A flattened export is a new document artifact and must be managed under the customer’s records and disclosure policies after download.

Security

The reference customer deployment supports private ingress, customer-tenant authentication and group assignment, private storage and database access, managed identities and customer-controlled secrets. Customers remain responsible for configuring access, networks, retention, monitoring, incident response and authorised integrations.