1. Data controller and contact
Controller for data processing
EchoCall LLC
5830 E 2nd St Ste 7000, Casper, WY 82609, USA
Email: team@echocall.de
A Data Protection Officer is not required for EchoCall LLC (a US LLC) under GDPR Art. 37.
For privacy questions, please contact: team@echocall.de
2. Privacy notice under the GDPR
This Privacy Policy explains how we process your personal data and what rights you have in this regard.
Legal basis: Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
Applicable law: German Federal Data Protection Act (BDSG), supplemented by the GDPR
3. Processing of customer data
3.1 Purpose of processing
We process your data to:
- Register you in our system (EchoCall Hub) - Art. 6(1)(b) GDPR
- Fulfill contracts (invoicing, communication) - Art. 6(1)(b) GDPR
- Provide our SaaS platform - Art. 6(1)(b) GDPR
- Provide customer support and technical operations - Art. 6(1)(b) GDPR
- Ensure security and fraud prevention - Art. 6(1)(f) GDPR
- Meet legal compliance requirements (GDPR, tax law) - Art. 6(1)(c) GDPR
3.2 Categories of personal data
We process the following data:
- Name and contact data: first and last name, email, phone
- Billing data: billing address, VAT ID where applicable, bank details
- Agent recordings: conversation content, audio recordings, IP addresses (if enabled)
- System data: user activity, logins, technical error logs
- Uploaded customer data: PDFs, knowledge bases, texts, logos
3.3 Legal basis
- Art. 6(1)(b) GDPR: contract performance
- Art. 6(1)(c) GDPR: legal obligation
- Art. 6(1)(f) GDPR: legitimate interests (security, operations)
3.4 Retention period
- Customer account: for the duration of the contract + 3 years
- Invoices: 10 years (statutory retention obligation)
- Agent recordings: per your configuration (default: 30 days)
- Uploaded content: until deletion or 90 days after contract end
4. Processing of end-customer data via agents
When your agents (voice or chat) process data, you are the controller (Art. 4(7) GDPR) and we are the processor pursuant to Art. 28 GDPR.
You are responsible for:
- The lawfulness of the data processing
- Obtaining consent (e.g. for call recording)
- Providing privacy information to your end customers
- Complying with all GDPR requirements
Important note: You can obtain consent via a notice/automatic announcement before the call begins. You configure this yourself in the agent prompt.
5. Processing by sub-processors
We use the following sub-processors (pursuant to Art. 28(4) GDPR):
- EchoHubTTS-eu: Function: text-to-speech, voice cloning, AI model hosting. Location: EU (servers). Controlled by EchoCall.
- Ionos: Function: server hosting, data storage for standard plans (Voice Agent, Chat Agent, PartnerNet Starter/Growth Partner). Location: Germany, France. EchoCall has FULL control.
- PartnerNet SaaS Titan (white-label reseller): Function: server hosting for the reseller's white-label instance. Location: chosen freely by the reseller (worldwide), instead of Ionos Germany/France.
- N8N: Function: workflow automation. Location: Germany (self-hosted on Ionos). Controlled by EchoCall.
- Google Tag Manager / Google Analytics 4: Function: website analytics (website ONLY, only with cookie consent). Location: USA/EU. Operated by Google.
- PostHog: Function: website and product analytics (website ONLY, only with cookie consent). Location: EU (eu.posthog.com).
- Stripe: Function: payment processing (credit card, SEPA). Location: USA/EU. Stripe processes payment data per the PCI-DSS standard.
- PayPal (optional): Function: alternative payment method. Location: USA/EU. PayPal processes payment data if selected by the user.
Important: for all standard plans (Voice Agent, Chat Agent, PartnerNet Starter/Growth Partner), EchoCall LLC retains FULL control over all customer data on Ionos servers (Germany/France); this data is NOT transferred to the USA. For PartnerNet SaaS Titan (white-label), the reseller chooses the server location for their instance; that chosen location then applies instead of Ionos Germany/France. Regardless of location, our global Anycast network delivers low latency and high availability worldwide.
Payment processing: Payment data (credit card, SEPA, PayPal) is processed exclusively by our certified payment providers Stripe and PayPal. EchoCall does not store complete credit card data. Processing is based on Art. 6(1)(b) GDPR (contract performance) and the Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
6. Special provisions for call recordings
6.1 Consent
Recording telephone calls is only permitted with prior consent under German law (§ 86 StGB) and EU law. You are responsible for obtaining this consent under Art. 7 GDPR. We provide the technical means (automatic announcement in the agent prompt).
6.2 Required announcement
You should configure an announcement along these lines before the call begins:
"This call is being recorded and transcribed. By participating in this call, you consent to the recording."
You are solely responsible for the choice and legal validity of the wording.
6.3 Retention and deletion
You determine the retention period in the dashboard. Recordings are automatically deleted once this period expires (Art. 5(1)(e) GDPR - storage limitation). You can manually delete recordings at any time.
7. Cookies and tracking
7.1 Magic-Link authentication
We use Magic Links instead of passwords. This is not a cookie in the classic sense. A token is generated and sent by email; the session is authenticated once you click it.
7.2 Website analytics (only with your consent)
If you accept analytics cookies via our cookie banner, we use Google Tag Manager (GTM), which loads Google Analytics 4 (GA4), and PostHog (an EU-hosted analytics service, servers in the EU) on https://echocall.de.
This data collection only starts once you give consent (Art. 6(1)(a) GDPR). Until you decide, no analytics cookies are set and Google Consent Mode defaults analytics storage to "denied". You can accept, reject, or change your choice at any time via the "Cookie settings" link in the website footer.
This includes:
- Pages visited and time on page
- Referring source and browser/device type
- General interaction behavior (e.g. clicks) via PostHog
This data is pseudonymous, is NOT linked to your EchoCall customer account or platform data, and is deleted according to each provider's standard retention period. Processing by Google Analytics 4 may involve a transfer to Google in the USA under the EU-US Data Privacy Framework or the Standard Contractual Clauses (Art. 46 GDPR). PostHog processes data exclusively on servers in the EU (eu.posthog.com).
7.3 Logging and technical data
We collect technical data such as:
- IP addresses (for security and error analysis - Art. 6(1)(f) GDPR)
- Login times and locations
- Error logs
- Platform usage (anonymized where possible)
This data is not shared with third parties except for security analysis or where legally required (Art. 6(1)(c) GDPR).
8. Your rights as a data subject
Under GDPR Chapter III (Art. 12-23), you have the following rights:
- Right of access (Art. 15 GDPR): you can find out at any time which of your data we process.
- Right to rectification (Art. 16 GDPR): you can have incorrect data corrected.
- Right to erasure (Art. 17 GDPR): you can have your data deleted, unless we are still required to retain it.
- Right to restriction of processing (Art. 18 GDPR): you can limit the processing of your data.
- Right to data portability (Art. 20 GDPR): you can receive your data in a structured format.
- Right to object (Art. 21 GDPR): you can object to processing for certain purposes.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you can complain to a data protection authority.
Contact to exercise your rights: team@echocall.de
Subject line: "GDPR access request" or "GDPR deletion request"
We will respond within 30 days (Art. 12(3) GDPR).
9. Data security
We implement extensive protective measures (Art. 32 GDPR):
- Encryption: TLS/SSL for all transmissions (HTTPS)
- Authentication: Magic-Link-based (no password storage)
- Access control: role-based access control (RBAC)
- Regular audits: penetration testing and security reviews
- Incident response: emergency plan for security breaches
- Storage location: all data on German/French servers
Google API Services
Gmail, Google Drive, Google Calendar, Google Sheets
EchoCall uses Google API Services. Access to Google user data is used exclusively for the automation features configured by the user (e.g. sending emails, saving files, creating calendar events, populating spreadsheets). Google user data is not shared with third parties or used for advertising purposes. Access can be revoked at any time via Google account settings. Use complies with the Google API Services User Data Policy, including the Limited Use restrictions.
Revoke access: https://myaccount.google.com/permissions
Policy: https://developers.google.com/terms/api-services-user-data-policy
10. Special provisions for voice cloning
10.1 Voice data
If you upload MP3 files for voice cloning, you confirm that you hold all necessary rights to that voice recording or have obtained the required consent (Art. 7 GDPR).
10.2 Processing by EchoHubTTS-eu
This voice data is transmitted to EchoHubTTS-eu (EU servers) and processed there for voice synthesis. EchoHubTTS-eu stores this data in accordance with its own privacy policy and under data processing agreements with EchoCall (Art. 28 GDPR).
11. AI models and proprietary model development
11.1 Proprietary EchoCall models
EchoCall LLC has spent over 2 years developing proprietary AI models based on Mistral:
EchoCall-Voice: specialized for telephony agents
- Optimized for natural voice conversation in telephony
- Trained on telephony data and best practices
- Highest quality for voice agents
EchoCall-Smart: specialized for chat agents
- Optimized for written communication
- Trained on chat data and FAQ content
- Highest quality for chat agents
These models are included as standard in all packages at no extra cost.
11.2 Model use and training data
EchoCall LLC improves its proprietary models through machine learning using anonymized conversation data:
Source: anonymous prompts and agent responses from customers
Purpose: improving response quality and agent behavior
Protection: NO customer personal data (names, addresses, emails, images, phone numbers)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest), Art. 4(1) GDPR (anonymization)
11.3 Anonymization - what this means
Anonymized data is data in which:
- All identifiers (names, emails, numbers) have been removed
- re-identification is impossible (even with significant effort)
- the GDPR no longer applies
Example:
BEFORE: "Hi, my name is Max Müller, my email is max@example.com. What does the Pro package cost?"
AFTER: "What does the Pro package cost?"
RESULT: only the question remains, with no personal reference. This is what gets used for training.
11.4 Your control in the EchoCall Hub
In the EchoCall Hub, you can configure:
- Training data ON/OFF - you decide whether anonymized data is used for training
- Zero-PII retention ON/OFF - no storage of names/emails/numbers
- Retention period: 1, 7, 30, 90, 365 days, or custom
- Call recording ON/OFF - whether calls are recorded
- Transcription ON/OFF - whether text transcripts are created
- AI model selection: standard (EchoCall-Voice/Smart) or optionally Gemini, GPT-4, GPT-5, DeepSeek
All settings are free of charge and can be changed at any time.
11.5 Optional external AI models
The customer may optionally use the following external AI models (at additional cost):
- Google Gemini
- GPT-4 and GPT-5
- DeepSeek
Use of these models is subject to the respective third-party providers' terms of use and privacy policies.
11.6 No mixing with customer data
The Provider guarantees:
- No email addresses in training
- No phone numbers in training
- No names or addresses in training
- No images or media in training
- No trade secrets in training
Sole exception: the customer explicitly enters into a separate agreement for training material.
11.7 Regular reviews
The Provider regularly reviews:
- Privacy compliance of the training process
- Effectiveness of anonymization
- Security of the infrastructure
Results are available on request: team@echocall.de
11.8 Changes to training
The Provider will inform the customer when:
- New training data sources are added
- New AI models are deployed
- Sub-processors change
Changes carrying a high privacy risk are communicated with 30 days' advance notice.
12. Support and contact
12.1 Requesting data access
To exercise your rights or obtain information about your stored data, send a request to:
Email: team@echocall.de
Subject line: "GDPR access request" or "GDPR deletion request"
We will respond within 30 days (see Art. 12(3) GDPR).
12.2 Complaint to a supervisory authority
Berlin Commissioner for Data Protection and Freedom of Information (BfDI)
Phone: +49 (0)30 13889-0
Email: info@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de
13. Changes to this Privacy Policy
We may amend this Privacy Policy at any time to reflect changes in our practices or in the law. Material changes will be communicated to you by email.
14. Specific notices for B2B customers
14.1 Data Protection Impact Assessment (DPIA - Art. 35 GDPR)
If you carry out high-risk processing, a DPIA may be required. We are happy to assist you in preparing one. Contact: team@echocall.de
14.2 Records of processing activities (Art. 30 GDPR)
On request, you will receive documentation of our processing activities (for your own records pursuant to Art. 30 GDPR).
14.3 Joint controllership (Art. 26 GDPR)
For specific use cases, a joint controllership agreement may be required. Please contact us for this purpose.
