Security and compliance at EchoCall
Customer trust comes first
ISO 27001 · SOC 2 (in progress) · GDPR
Customer trust comes first
At EchoCall, protecting your data is more than a promise - it's a foundation. Every product decision starts with one question: is this secure for our customers? We take your privacy, integrity, and business data protection seriously.
Built for enterprise-grade security
Our infrastructure runs on IONOS data centres in Frankfurt and Karlsruhe with end-to-end encryption (TLS 1.3 and AES-256) and multi-layer defense systems. All data stays in the EU by default.
Zero-PII mode: our key differentiator
EchoCall can process calls and chats without permanently storing personally identifiable information. In Zero-PII mode, conversation content is used for AI processing without persisting names, phone numbers, or other identifying details in our systems - significantly reducing your data protection risk and simplifying GDPR compliance.
Our commitment to security
We continuously improve our systems through:
Regular external penetration tests, conducted twice a year.
Encryption of all data in transit (TLS 1.3) and at rest (AES-256).
ISO 27001-certified data centres; SOC 2 Type II is currently in progress, targeted for completion in 2026.
A HIPAA-ready configuration available for healthcare customers, on request.
Our infrastructure and operations are aligned with the following industry standards and frameworks:
Transparency & trust
We believe in full transparency. On request, customers can receive information about our security measures and incident response process - so you always know how your data is protected.
Uptime and operations
We guarantee 99.9% uptime (99.95% for enterprise plans, with service credits for shortfalls). Our team continuously monitors operations and system integrity so EchoCall runs reliably, no matter the scale or complexity of your business.
Our sub-processors
We use a small, vetted set of sub-processors, each bound contractually under GDPR Art. 28:
Ionos: server hosting and data storage in Germany and France for standard plans (Voice Agent, Chat Agent, PartnerNet Starter/Growth Partner) - EchoCall retains full control. PartnerNet SaaS Titan resellers can use a different, self-chosen location.
EchoHubTTS-eu: text-to-speech and AI model hosting, servers in the EU.
N8N: workflow automation, self-hosted on Ionos in Germany.
Stripe and PayPal: payment processing per the PCI-DSS standard, EchoCall never stores complete card data.
Google Tag Manager, Google Analytics 4, and PostHog: website analytics, only after you grant cookie consent.
The full list with locations and functions is published in our privacy policy.
Retention and deletion
We don't keep data longer than necessary:
Customer account: contract duration plus 3 years.
Invoices: 10 years (statutory retention requirement).
Call recordings: per your configuration, 30-day default, deletable manually at any time.
Uploaded content: until deletion or 90 days after contract end.
BYO carrier and data sovereignty
You can connect your own telephony provider (e.g. Twilio, Telnyx, Vonage, Sinch) via SIP trunking instead of using EchoCall's own numbers, giving you additional control over your call infrastructure and existing carrier relationships.
Made in Germany, available worldwide
EchoCall is built and operated in Germany, but not limited to the EU: our global Anycast network delivers calls and chats worldwide with low latency, regardless of where your customers are. We manage the entire hosting stack for you - there is no server, scaling, or infrastructure to worry about. PartnerNet SaaS Titan resellers can additionally choose their own server location anywhere in the world.
