EchoCall and the General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is a privacy regulation enacted by the European Union (EU) to strengthen the protection of individuals' data. It became enforceable on May 25, 2018, and applies to any company that handles the data of EU residents, no matter where the company is based.
This page explains how EchoCall implements GDPR principles and ensures that your data is handled transparently, securely, and respectfully.
Purpose of this document
At EchoCall, we are fully committed to respecting your privacy. This page provides a clear overview of:
- Who we are
- What types of data we collect
- Why we collect data
- How long we retain your data
- Third-party services we use
- Your rights over your data
- How you can manage, update, or delete your information
- How to contact us about your data
What is GDPR?
In simple terms, GDPR gives you greater control over your personal information. Service providers (like EchoCall) must be transparent about what data they collect, how they use it, and how they share it - and users have the right to access, rectify, or delete their data.
Although GDPR is an EU regulation, it affects any business that collects or processes the data of EU residents - including EchoCall, which is headquartered in Germany.
Zero-PII mode, explained simply
One of the most important building blocks of our data protection approach is Zero-PII mode. In plain terms: your AI voice or chat agent can handle calls and chats without permanently storing names, phone numbers, email addresses, or other identifying details in our systems. The conversation is processed to help your customer - but no lasting personal data profile is built up on EchoCall's side.
For you as a customer, this means less personal data stored, lower risk in the event of a security incident, and an easier path to meeting your own GDPR obligations toward your end customers.
How EchoCall implements GDPR
EchoCall was built with privacy by design from the ground up. Our core processes are aligned with GDPR principles, and we provide a Data Processing Agreement (DPA) on request.
Relevant documents:
- Terms and conditions
- Privacy policy
Data we collect
Account information: Your name, email address, and billing address when you register with EchoHub.
Call and chat data: Conversation content that your AI voice or chat agent processes on behalf of your business. In Zero-PII mode, no personally identifiable information is permanently stored.
Usage data: Interactions with the EchoHub dashboard and technical log data used for troubleshooting.
Why we collect your data
- To create and manage your EchoHub account
- To deliver and operate the AI voice and chat agents
- To process billing and manage your subscription
- To ensure security, prevent fraud, and maintain system stability
Hosting and data residency
Your data is hosted on IONOS Cloud infrastructure in Frankfurt and Karlsruhe (Germany). EU data residency is the default at EchoCall, not the exception.
Your data rights
Access your personal information
Rectify your account information
Request the deletion of your data
Withdraw consent for processing personal information
Request a portable copy of your stored data
Object to certain types of processing
How to manage or delete your data
- You can update your account details anytime from the EchoHub dashboard.
- To request a complete data deletion or data export, or to request a Data Processing Agreement (DPA), please email: team@echocall.de
Ready to try EchoCall?
If you have any data protection questions, feel free to reach out to our team at team@echocall.de.
