1. Data controller and contact
Controller for data processing
EchoCall LLC
5830 E 2nd St Ste 7000, Casper, WY 82609, USA
Email: team@echocall.de
A Data Protection Officer is not required for EchoCall LLC (a US LLC) under GDPR Art. 37.
For privacy questions, please contact: team@echocall.de
2. Privacy notice under the GDPR
This Privacy Policy explains how we process your personal data and what rights you have in this regard.
Legal basis: Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)
Applicable law: German Federal Data Protection Act (BDSG), supplemented by the GDPR
3. Processing of customer data
3.1 Purpose of processing
We process your data to:
- Register you in our system (EchoCall Hub) - Art. 6(1)(b) GDPR
- Fulfill contracts (invoicing, communication) - Art. 6(1)(b) GDPR
- Provide our SaaS platform - Art. 6(1)(b) GDPR
- Provide customer support and technical operations - Art. 6(1)(b) GDPR
- Ensure security and fraud prevention - Art. 6(1)(f) GDPR
- Meet legal compliance requirements (GDPR, tax law) - Art. 6(1)(c) GDPR
3.2 Categories of personal data
We process the following data:
- Name and contact data: first and last name, email, phone
- Billing data: billing address, VAT ID where applicable, bank details
- Agent recordings: conversation content, audio recordings, IP addresses (if enabled)
- System data: user activity, logins, technical error logs
- Uploaded customer data: PDFs, knowledge bases, texts, logos
3.3 Legal basis
- Art. 6(1)(b) GDPR: contract performance
- Art. 6(1)(c) GDPR: legal obligation
- Art. 6(1)(f) GDPR: legitimate interests (security, operations)
3.4 Retention period
- Customer account: for the duration of the contract + 3 years
- Invoices: 10 years (statutory retention obligation)
- Agent conversation content: per your configuration per agent (default for new agents: 30 days; configurable from 1 to 3650 days or unlimited)
- Uploaded content: until deletion or 90 days after contract end
4. Processing of end-customer data via agents
When your agents (voice or chat) process data, you are the controller (Art. 4(7) GDPR) and we are the processor pursuant to Art. 28 GDPR.
You are responsible for:
- The lawfulness of the data processing
- Obtaining consent (e.g. for call recording)
- Providing privacy information to your end customers
- Complying with all GDPR requirements
Important note: You can obtain consent via a notice/automatic announcement before the call begins. You configure this yourself in the agent prompt.
5. Processing by sub-processors
We engage vetted sub-processors (contracts pursuant to Art. 28(4) GDPR). The versioned sub-processor overview at https://echocall.de/security (public, by category and region) is authoritative and always current; customers receive the complete list with legal names and registered offices as confidential Annex 3 to the DPA at hub.echocall.de (Settings, Compliance). The main categories:
- Hosting, database and file storage: IONOS, data centres Germany/France (in particular Frankfurt and Karlsruhe). EchoCall has full control over this infrastructure.
- Speech processing and agent platform (EchoHubTTS-eu): text-to-speech, transcription, dialog management, AI model hosting and voice cloning as EchoCall's own software, operated on EchoCall's own IONOS infrastructure in Germany/France. Not an external sub-processor.
- LLM inference of the default profiles EchoCall-Voice/EchoCall-Smart: EchoCall's own models on EchoCall's own infrastructure in the EU, not an external sub-processor. Optional additional model profiles are operated by external model providers and are not covered by the EchoCall assurance (the customer's own responsible decision, see section 11).
- Phone number procurement and identity verification: DIDWW Ireland Limited, Dublin (EU). Optional telephony via Twilio only where selected by the customer (EU/USA, Standard Contractual Clauses).
- N8N: workflow automation, self-hosted on IONOS in Germany. Controlled by EchoCall.
- Error and availability monitoring (Sentry): EU ingest endpoint, transmission of personal data disabled.
- In-hub AI assistant ("Ask AI"): fixed, named model chain via an API router (USA, Standard Contractual Clauses); processes only logged-in user inputs, never end-customer conversation data.
- Integration OAuth broker: only for integrations connected by the customer, manages connection tokens only (USA, Standard Contractual Clauses).
- Google Analytics 4: website analytics (website ONLY, only with cookie consent). Location: USA/EU.
- PostHog: website and product analytics including session recording of website usage (website ONLY, only with cookie consent). Location: EU (eu.posthog.com).
- Stripe: payment processing (credit card, SEPA). Location: USA/EU, PCI-DSS.
- PayPal (optional): alternative payment method. Location: EU (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg).
- Partner commission settlement: for purchases via a partner link we transmit name, email address and booked plan to an automation service and a partner commission service (USA/United Kingdom, Standard Contractual Clauses), solely for commission settlement (Art. 6(1)(f) GDPR).
- PartnerNet SaaS Titan (white-label reseller): server hosting for the reseller's white-label instance. Location: chosen freely by the reseller (worldwide), instead of IONOS Germany/France.
Important: for all standard plans (Voice Agent, Chat Agent, PartnerNet Pay as you go/Growth Partner), EchoCall LLC retains full control over all customer data on IONOS servers (Germany/France); production and conversation data is not transferred to the USA. Transfers to payment providers and the optional services listed above are safeguarded by EU Standard Contractual Clauses or the EU-US Data Privacy Framework; our Transfer Impact Assessment evaluates the details (download at https://echocall.de/security). For PartnerNet SaaS Titan (white-label), the reseller chooses the server location for their instance; that chosen location then applies instead of IONOS Germany/France.
Payment processing: Payment data (credit card, SEPA, PayPal) is processed exclusively by our certified payment providers Stripe and PayPal. EchoCall does not store complete credit card data. Processing is based on Art. 6(1)(b) GDPR (contract performance) and the Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
6. Special provisions for call recordings
6.1 Consent
Recording telephone calls is only permitted with the prior consent of all call participants under German law (in particular § 201 StGB - violation of the confidentiality of the spoken word) and EU law. As the deployer of your agents, you are responsible for obtaining this consent, usually via an announcement at the start of the call. Legal basis: Art. 7 GDPR.
6.2 Announcement at the start of the call
EchoCall provides ready-made notice and announcement building blocks in 74 languages for this purpose, along these lines:
"Please note: you are speaking with a virtual AI assistant. This call is being recorded and transcribed. By continuing, you consent to the recording."
You activate the announcement in your conversation design; the platform documentation guides you through this. The chat widget shows an AI notice by default. If you enable call recording without setting up a corresponding announcement, you are in breach of your obligations as controller.
6.3 Retention and deletion
You determine the retention period per agent in the dashboard (1, 7, 30, 90, 365 days, custom or unlimited; default for new agents: 30 days). After expiry, conversation content is deleted automatically across all stores of the platform through a daily cleanup (Art. 5(1)(e) GDPR - storage limitation). You can manually delete recordings at any time and disable recording per agent entirely.
7. Cookies and tracking
7.1 Magic-Link authentication
We use Magic Links instead of passwords. This is not a cookie in the classic sense. A token is generated and sent by email; the session is authenticated once you click it.
7.2 Website analytics (only with your consent)
If you accept analytics cookies via our cookie banner, we use Google Analytics 4 (GA4) and PostHog (an EU-hosted analytics service, servers in the EU) on https://echocall.de.
This data collection only starts once you give consent (Art. 6(1)(a) GDPR): the analytics scripts are only loaded after you agree in the cookie banner; until then, no analytics cookies are set. You can accept, reject, or change your choice at any time via the "Cookie settings" link in the website footer.
This includes:
- Pages visited and time on page
- Referring source and browser/device type
- General interaction behavior (e.g. clicks) via PostHog
- Session recordings of website usage via PostHog (replay of mouse and scroll movements on echocall.de; input fields are masked, and recording covers the website only, never the customer dashboard or conversation data)
This data is pseudonymous, is NOT linked to your EchoCall customer account or platform data, and is deleted according to each provider's standard retention period. Processing by Google Analytics 4 may involve a transfer to Google in the USA under the EU-US Data Privacy Framework or the Standard Contractual Clauses (Art. 46 GDPR). PostHog processes data exclusively on servers in the EU (eu.posthog.com).
7.3 Logging and technical data
We collect technical data such as:
- IP addresses (for security and error analysis - Art. 6(1)(f) GDPR)
- Login times and locations
- Error logs
- Platform usage (anonymized where possible)
This data is not shared with third parties except for security analysis or where legally required (Art. 6(1)(c) GDPR).
8. Your rights as a data subject
Under GDPR Chapter III (Art. 12-23), you have the following rights:
- Right of access (Art. 15 GDPR): you can find out at any time which of your data we process.
- Right to rectification (Art. 16 GDPR): you can have incorrect data corrected.
- Right to erasure (Art. 17 GDPR): you can have your data deleted, unless we are still required to retain it.
- Right to restriction of processing (Art. 18 GDPR): you can limit the processing of your data.
- Right to data portability (Art. 20 GDPR): you can receive your data in a structured format.
- Right to object (Art. 21 GDPR): you can object to processing for certain purposes.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you can complain to a data protection authority.
Contact to exercise your rights: team@echocall.de
Subject line: "GDPR access request" or "GDPR deletion request"
We will respond within 30 days (Art. 12(3) GDPR).
9. Data security
We implement extensive protective measures (Art. 32 GDPR):
- Encryption: TLS 1.3 for all transmissions (HTTPS), encryption of data at rest at storage level, encrypted storage of credentials and 2FA secrets
- Authentication: Magic-Link-based, optional two-factor authentication (TOTP)
- Access control: role-based access control (RBAC) and granular workspace permissions, strict tenant separation
- Regular security reviews and code audits
- Incident response: documented process, notification of affected customers within 48 hours
- Storage location: ISO 27001-certified data centres in Germany/France
The complete technical and organizational measures (TOM, Annex 2 to the DPA) are available for download at https://echocall.de/security.
Google API Services
Gmail, Google Drive, Google Calendar, Google Sheets
EchoCall uses Google API Services. Access to Google user data is used exclusively for the automation features configured by the user (e.g. sending emails, saving files, creating calendar events, populating spreadsheets). Google user data is not shared with third parties or used for advertising purposes. Access can be revoked at any time via Google account settings. Use complies with the Google API Services User Data Policy, including the Limited Use restrictions.
Revoke access: https://myaccount.google.com/permissions
Policy: https://developers.google.com/terms/api-services-user-data-policy
10. Special provisions for voice cloning
10.1 Voice data
If you upload MP3 files for voice cloning, you confirm that you hold all necessary rights to that voice recording or have obtained the required consent (Art. 7 GDPR).
A person's voice can qualify as a biometric characteristic and therefore fall under the special categories of personal data under Art. 9 GDPR. In that case, the legal basis for processing is the explicit consent of the recorded individual (Art. 9(2)(a) GDPR), in addition to the general consent under Art. 7 GDPR. As the customer, you are responsible for obtaining and being able to demonstrate this explicit consent before uploading.
10.2 Processing by EchoHubTTS-eu
This voice data is processed and stored for voice synthesis exclusively on EchoCall's own infrastructure in the EU (EchoHubTTS-eu); no transfer to external providers takes place for this purpose.
11. AI models and model profiles
11.1 EchoCall model profiles
EchoCall LLC has spent over 2 years developing its own proprietarily tuned model profiles for use in telephony and chat:
EchoCall-Voice: specialized for telephony agents
- Optimized for natural voice conversation in telephony
- Tuned for telephony flows and best practices
- Highest quality for voice agents
EchoCall-Smart: specialized for chat agents
- Optimized for written communication
- Tuned for chat flows and FAQ scenarios
- Highest quality for chat agents
These model profiles are included as standard in all packages at no extra cost. The default profiles EchoCall-Voice and EchoCall-Smart are EchoCall’s own models, operated exclusively on EchoCall’s own infrastructure in the EU; only they are covered by the DPA, TOM and TIA. Optional additional model profiles (e.g. of the GPT, Gemini, GLM and Qwen families) are operated by external model providers. Selecting them in the dashboard is the Customer’s own responsible decision: EchoCall gives no assurance of GDPR compliance for these profiles, does not guarantee processing in the EU and concludes no Standard Contractual Clauses with those providers; the Customer assesses the legal permissibility itself. Only the default profiles are to be used for privacy-sensitive applications.
11.2 No use of your data for model training
Conversation content and customer data are not used to train AI models. To improve the platform, we use only aggregated, non-personal usage statistics (e.g. response times, success rates). Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
11.3 Your control in the EchoCall Hub
In the EchoCall Hub, you can configure per agent:
- Zero-PII retention ON/OFF - no permanent storage of names/emails/numbers
- Retention period: 1, 7, 30, 90, 365 days, custom (up to 3650 days) or unlimited; default for new agents: 30 days
- Call recording ON/OFF - whether call audio is stored
- Save conversations ON/OFF - whether chat histories are archived
- Model profile selection: EchoCall-Voice/EchoCall-Smart as standard (GDPR-compliant, EU infrastructure); additional model profiles optional and without GDPR assurance by EchoCall (own responsibility)
All settings are free of charge and can be changed at any time.
11.4 No mixing with customer data
The Provider guarantees:
- No email addresses in model training
- No phone numbers in model training
- No names or addresses in model training
- No images or media in model training
- No trade secrets in model training
Sole exception: the customer explicitly enters into a separate agreement on the provision of training material.
11.5 Regular reviews and changes
The Provider regularly reviews the privacy compliance of the processing, the effectiveness of the deletion processes and the security of the infrastructure; results are available on request at team@echocall.de. We give at least 30 days advance notice of new model profiles or changes to sub-processors (see the DPA).
11.6 Automated decision-making (Art. 22 GDPR)
The platform itself does not make automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR (e.g. no automated credit granting, contract rejection, or benefit approval). The agents support communication with end users; substantive decisions are made either by a human or by the customer's underlying system.
If the customer nevertheless configures an agent to make automated decisions with legal effect, the customer is responsible for this as the data controller, including the information obligations and rights to object under Art. 22 GDPR towards the data subjects concerned.
12. Support and contact
12.1 Requesting data access
To exercise your rights or obtain information about your stored data, send a request to:
Email: team@echocall.de
Subject line: "GDPR access request" or "GDPR deletion request"
We will respond within 30 days (see Art. 12(3) GDPR).
12.2 Complaint to a supervisory authority
You may contact any data protection supervisory authority, for example:
Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI)
Phone: +49 (0)30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de
13. Changes to this Privacy Policy
We may amend this Privacy Policy at any time to reflect changes in our practices or in the law. Material changes will be communicated to you by email.
14. Specific notices for B2B customers
14.1 Data Protection Impact Assessment (DPIA - Art. 35 GDPR)
If you carry out high-risk processing, a DPIA may be required. We are happy to assist you in preparing one. Contact: team@echocall.de
14.2 Records of processing activities (Art. 30 GDPR)
On request, you will receive documentation of our processing activities (for your own records pursuant to Art. 30 GDPR).
14.3 Joint controllership (Art. 26 GDPR)
For specific use cases, a joint controllership agreement may be required. Please contact us for this purpose.
