EchoCall and the General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is a privacy regulation enacted by the European Union (EU) to strengthen the protection of individuals' data. It became enforceable on May 25, 2018, and applies to any company that handles the data of EU residents, no matter where the company is based.
This page explains how EchoCall implements GDPR principles and ensures that your data is handled transparently, securely, and respectfully.
Purpose of this document
At EchoCall, we are fully committed to respecting your privacy. This page provides a clear overview of:
- Who we are
- What types of data we collect
- Why we collect data
- How long we retain your data
- Third-party services we use
- Your rights over your data
- How you can manage, update, or delete your information
- How to contact us about your data
What is GDPR?
In simple terms, GDPR gives you greater control over your personal information. Service providers (like EchoCall) must be transparent about what data they collect, how they use it, and how they share it - and users have the right to access, rectify, or delete their data.
Although GDPR is an EU regulation, it affects any business that collects or processes the data of EU residents - including EchoCall. EchoCall is a US-registered LLC, developed and operated from Germany, hosting in the EU by default.
Zero-PII mode, explained simply
One of the most important building blocks of our data protection approach is Zero-PII mode. In plain terms: your AI voice or chat agent can handle calls and chats without permanently storing names, phone numbers, email addresses, or other identifying details in our systems. The conversation is processed to help your customer - but no lasting personal data profile is built up on EchoCall's side.
For you as a customer, this means less personal data stored, lower risk in the event of a security incident, and an easier path to meeting your own GDPR obligations toward your end customers.
How EchoCall implements GDPR
EchoCall was built with privacy by design from the ground up. Our core processes are aligned with GDPR principles. The Data Processing Agreement (DPA) is available in full at echocall.de/avv, automatically becomes part of the contract upon registration, and can be downloaded as PDF together with the TOM, the sub-processor overview and the TIA from the Trust Center at echocall.de/security.
Relevant documents:
- Terms and conditions
- Privacy policy
- Data Processing Agreement (DPA) under Art. 28 GDPR, at echocall.de/avv
- Technical and organizational measures (TOM), download at echocall.de/security
- Sub-processor overview, download at echocall.de/security
- Transfer Impact Assessment (TIA), download at echocall.de/security
Data we collect
Account information: Your name, email address, and billing address when you register with EchoHub.
Call and chat data: Conversation content that your AI voice or chat agent processes on behalf of your business. In Zero-PII mode, no personally identifiable information is permanently stored.
Usage data: Interactions with the EchoHub dashboard and technical log data used for troubleshooting.
Why we collect your data
- To create and manage your EchoHub account
- To deliver and operate the AI voice and chat agents
- To process billing and manage your subscription
- To ensure security, prevent fraud, and maintain system stability
Hosting and data residency
On standard plans, your data is hosted on IONOS Cloud infrastructure in Germany and France (in particular Frankfurt and Karlsruhe). EU data residency is the default at EchoCall, not the exception; the entire speech processing stack with the default profiles EchoCall-Voice/EchoCall-Smart runs as EchoCall's own software on its own EU infrastructure (optional external model profiles are excluded and a customer decision). The only exception: resellers on the PartnerNet SaaS Titan plan receive a dedicated whitelabel instance whose server location is agreed individually and can be anywhere in the world.
Roles: who is responsible for what?
For the calls and chats your agents handle, you as the customer are the controller within the meaning of Art. 4(7) GDPR; EchoCall processes this data exclusively as a processor under Art. 28 GDPR on the basis of the DPA.
Agencies and systems integrators using EchoCall for their own end customers are themselves processors of their end customers; EchoCall then acts as a sub-processor. The DPA expressly covers this constellation (Module 3 of the Standard Contractual Clauses).
Only for your own account, contract and billing data and for the echocall.de website is EchoCall itself the controller; details are set out in the privacy policy.
Third-country transfers, explained honestly
The platform's production data stays in the EU by default. Because EchoCall LLC is a US company and some providers have US parent companies, we agree the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Modules 2 and 3) with every customer as Annex 4 of the DPA, as a precaution. In addition, we provide a Transfer Impact Assessment (TIA) evaluating the US legal situation (CLOUD Act, FISA 702, Executive Order 14086) and our supplementary measures: download at echocall.de/security. To date, EchoCall has not received a single governmental request for the disclosure of customer data.
Your data rights
Access your personal information
Rectify your account information
Request the deletion of your data
Withdraw consent for processing personal information
Request a portable copy of your stored data
Object to certain types of processing
How to manage or delete your data
- You can update your account details anytime from the EchoHub dashboard.
- You control retention periods, zero-PII mode and recording per agent directly in the dashboard; after expiry, a daily cleanup deletes conversation content automatically. To request a complete account deletion or a data export, please email: team@echocall.de
Ready to try EchoCall?
If you have any data protection questions, feel free to reach out to our team at team@echocall.de.
