Security and compliance at EchoCall
Customer trust comes first
ISO 27001 data centres · SOC 2 (in progress) · GDPR
Customer trust comes first
At EchoCall, protecting your data is more than a promise - it's a foundation. Every product decision starts with one question: is this secure for our customers? We take your privacy, integrity, and business data protection seriously.
Built for enterprise-grade security
Our infrastructure runs on IONOS data centres in Frankfurt and Karlsruhe with end-to-end encryption (TLS 1.3 and AES-256) and multi-layer defense systems. All data stays in the EU by default.
Zero-PII mode: our key differentiator
EchoCall can process calls and chats without permanently storing personally identifiable information. In Zero-PII mode, conversation content is used for AI processing without persisting names, phone numbers, or other identifying details in our systems - significantly reducing your data protection risk and simplifying GDPR compliance.
Our commitment to security
We continuously improve our systems through:
Regular security reviews and code audits with documented findings.
Encryption of all data in transit (TLS 1.3) and encryption of data at rest at the storage level (AES-256).
Operation exclusively in ISO 27001-certified data centres (IONOS); SOC 2 Type II is currently in progress, targeted for completion in 2026.
Requirements of regulated industries (e.g. healthcare) are discussed individually, including zero-PII mode and short retention periods.
Our infrastructure and operations are aligned with the following industry standards and frameworks:
Transparency & trust
We believe in full transparency. On request, customers can receive information about our security measures and incident response process - so you always know how your data is protected.
Uptime and operations
We guarantee 99.9% uptime (99.95% for enterprise plans, with service credits for shortfalls). Our team continuously monitors operations and system integrity so EchoCall runs reliably, no matter the scale or complexity of your business.
Our sub-processors
We use a small, vetted set of sub-processors, each bound contractually under GDPR Art. 28:
Ionos: server hosting and data storage in Germany and France for standard plans (Voice Agent, Chat Agent, PartnerNet Pay as you go/Growth Partner) - EchoCall retains full control. PartnerNet SaaS Titan resellers can use a different, self-chosen location.
EchoHubTTS-eu: EchoCall's own speech processing (text-to-speech, transcription, AI model hosting), operated as EchoCall's own software on EchoCall infrastructure at IONOS in the EU. Not an external provider.
N8N: workflow automation, self-hosted on Ionos in Germany.
Stripe and PayPal: payment processing per the PCI-DSS standard, EchoCall never stores complete card data.
Google Analytics 4 and PostHog: website analytics, only after you grant cookie consent.
The full overview by category and region is available for download in the Trust Center below; customers receive the complete list with legal names and registered offices as confidential Annex 3 to the DPA in the customer area (hub.echocall.de, Settings, Compliance).
Retention and deletion
We don't keep data longer than necessary:
Customer account: contract duration plus 3 years.
Invoices: 10 years (statutory retention requirement).
Conversation content (transcripts, recordings): retention period configurable per agent (1, 7, 30, 90, 365 days, custom or unlimited), default 30 days for new agents. After expiry, a daily automated cleanup removes the content from the EchoCall database as well; manual deletion any time, recording can be disabled per agent.
Uploaded content: until deletion or 90 days after contract end.
BYO carrier and data sovereignty
You can connect your own telephony provider (e.g. Twilio, Telnyx, Vonage, Sinch) via SIP trunking instead of using EchoCall's own numbers, giving you additional control over your call infrastructure and existing carrier relationships.
Made in Germany, available worldwide
EchoCall is built and operated in Germany, but not limited to the EU: our global Anycast network delivers calls and chats worldwide with low latency, regardless of where your customers are. We manage the entire hosting stack for you - there is no server, scaling, or infrastructure to worry about. PartnerNet SaaS Titan resellers can additionally choose their own server location anywhere in the world.
Trust Center: documents for download
Everything you need for your data protection records, no request and no waiting. German is the governing version; effective 25 Aug 2026, document set 2026-08_v1.
- Data Processing Agreement (DPA) under Art. 28 GDPRWeb pagePDF (DE)PDF (EN)
- Technical and organizational measures (TOM, Annex 2)PDF (DE)PDF (EN)
- Sub-processor overview (public, by category)PDF (DE)PDF (EN)
- Transfer Impact Assessment (TIA, Art. 44 ff. GDPR)PDF (DE)PDF (EN)
Customers find the complete sub-processor list with legal names and registered offices (Annex 3 to the DPA, confidential) at hub.echocall.de in Settings, Compliance section. Prospects without an account receive it upon request to team@echocall.de against a confidentiality undertaking. The DPA automatically becomes part of the contract upon registration; a counter-signed copy is available on request.
