EchoEcho
Legal

Data Processing Agreement

Auftragsverarbeitungsvertrag under Article 28 GDPR

Version 1.0 · Effective 6 October 2026

This agreement is part of our Terms of Service and applies automatically to every Echo account. No separate signature is needed. Download a copy for your records.

Parties

This Data Processing Agreement (“DPA”) is entered into between:

  • The Controller— the business or practitioner that holds an Echo account and determines the purposes and means of processing personal data about its own clients (“you”); and
  • The Processor — 3CHO AGENT INC LTD, a company registered in England and Wales under number 16599467, whose registered office is at 4th Floor Office, 205 Regent Street, London, W1B 4HB, United Kingdom, trading as Echo, which processes that personal data on your behalf in order to provide the Echo platform (“Echo”, “we”, “us”).

This DPA forms part of, and is governed by, Echo's Terms of Service. Where this DPA conflicts with the Terms of Service in respect of the processing of personal data, this DPA prevails. It is incorporated into the Terms of Service and takes effect automatically when you accept them by creating or using an Echo account, without any separate signature, and remains in force for as long as we process personal data on your behalf. This electronic form satisfies the requirement in Article 28(9) GDPR that the agreement be in writing.

1. Definitions

“GDPR” means Regulation (EU) 2016/679. “Personal data”, “special categories of personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Client Personal Data” means personal data relating to your clients and contacts that Echo processes on your behalf, as described in Annex I.

2. Roles and scope

You are the controller of Client Personal Data. Echo is your processor in respect of that data. Echo is a separate and independent controller in respect of your own account and billing data — the information we need to contract with you, invoice you and support you — which is governed by our Privacy Policy rather than by this DPA.

You warrant that you have a lawful basis for the processing you instruct us to carry out, and that where you process special categories of personal data you have a condition under Article 9 GDPR for doing so.

3. Processing on documented instructions

Echo processes Client Personal Data only on your documented instructions, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law — in which case we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

Your documented instructions consist of:

  • this DPA and the Terms of Service;
  • your configuration of the platform, including the settings described in clause 8; and
  • your use of the platform's features in the ordinary course.

We will inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law.

Echo does not sell Client Personal Data, does not use it for advertising, and does not use it to train artificial intelligence models — neither our own nor those of any third party. Where AI features are used, our AI subprocessor is contractually prohibited from using submitted data for model training.

4. Confidentiality

Echo ensures that persons authorised to process Client Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those personnel who need it to provide, support or secure the platform.

5. Security

Echo implements the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. We may update those measures over time provided the level of security is not reduced.

6. Subprocessors

You give Echo general written authorisation to engage subprocessors. Our current subprocessors are listed in Annex III and maintained at echo-agent.com/legal/subprocessors.

We will give you at least 30 days' notice before a new subprocessor begins processing Client Personal Data. You may object on reasonable data protection grounds within that period; if we cannot offer a reasonable alternative, you may terminate your subscription in respect of the affected functionality without penalty.

Echo imposes on each subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to you for a subprocessor's performance.

7. International transfers

Client Personal Data is stored in the European Union. Echo's database, authentication and file storage run in AWS eu-west-1 (Ireland) and its application servers run in Dublin, Ireland.

Echo is established in the United Kingdom, which is the subject of an adequacy decision of the European Commission, and processes Client Personal Data in accordance with both the GDPR and the UK GDPR.

Where personal data is transferred to a country without an adequacy decision — to the subprocessors identified as such in Annex III, and through remote access by Echo personnel working from South Africa — that transfer is made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this DPA by reference and completed as follows: the data exporter is you; the data importer is 3CHO AGENT INC LTD; Annexes I, II and III of this DPA populate the corresponding annexes of the Clauses; the optional docking clause applies; and the governing law and forum are those stated in clause 13.

If you enable confidentiality mode (clause 8), no Client Personal Data is transferred to our AI or analytics subprocessors at all.

8. Confidentiality mode and special categories

Echo provides a confidentiality mode setting intended for controllers subject to professional secrecy obligations — including healthcare providers, psychologists and psychotherapists, and in Germany those bound by § 203 StGB.

When you enable it, Echo:

  • sends no audio, note text, job description or other Client Personal Data to any AI provider: voice transcription, AI-assisted quoting and invoicing, and the WhatsApp assistant are disabled. The sole exception is content moderation of reviews and replies written for public display: their text alone, without any name, business or booking details, is screened by our AI subprocessor before publication to keep abusive content off your public page. Features that use only your own business details, such as the website builder, are unaffected;
  • removes client names, practice names and addresses from WhatsApp messages, which state only the type of event, its time and a link to the authenticated detail, and neutralises email subject lines so they carry no identifying detail; and
  • excludes your account from all analytics and session-recording tools.

Analytics and session recording are never loaded on dashboards, customer portals or booking pages for any account, whether or not confidentiality mode is enabled.

9. Assistance with data subject rights

Taking into account the nature of the processing, Echo assists you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

The platform provides self-service tools for this purpose: you can export your data in a portable format and delete or anonymise client records from your dashboard, and your clients can request deletion of their own personal data through the customer portal. If you receive a request you cannot fulfil with those tools, contact privacy@echo-agent.com and we will assist without undue delay.

If a data subject contacts Echo directly about Client Personal Data, we will not respond substantively but will refer them to you and inform you promptly.

10. Personal data breaches

Echo notifies you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — to the extent known at the time, with further information supplied as it becomes available.

Echo assists you in meeting your own obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of processing and the information available to us.

11. Deletion and return of data

On termination of your Echo account you may export your data at any time before deletion. Echo deletes or anonymises Client Personal Data within 30 days of account closure, except where storage is required by Union or Member State law — for example financial records retained for tax purposes, which are retained for the statutory period and then deleted.

Backups are retained on a rolling basis and expire within 30 days, after which deleted data is no longer recoverable.

12. Audits and information

Echo makes available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance we will respond to reasonable written questions and provide available documentation, including subprocessor compliance documentation, at no charge. Where that is insufficient, an on-site inspection may be carried out no more than once in any twelve-month period, on 30 days' written notice, during business hours, subject to confidentiality undertakings and without unreasonable disruption to our operations. A supervisory authority may inspect at any time without these limits.

13. Liability, term and governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except that nothing limits either party's liability to a data subject under Article 82 GDPR or to a supervisory authority.

This DPA takes effect as described under Parties and continues until Echo has ceased all processing of Client Personal Data and deleted it in accordance with clause 11. Clauses 4, 12 and 13 survive termination.

This DPA is governed by the laws of England and Wales, save that where the Standard Contractual Clauses apply they are governed by the law of Ireland and the courts of Ireland have jurisdiction over disputes arising from them, as those Clauses require. Nothing in this clause deprives a data subject of the right to bring proceedings in their place of habitual residence.

Echo will notify you of material changes to this DPA at least 30 days before they take effect. If you object to a change on reasonable data protection grounds and we cannot address it, you may terminate your subscription before the change takes effect.

Annex I — Details of processing

Subject matter and duration

Provision of the Echo booking, scheduling, quoting, invoicing and client-record platform, for the duration of your subscription plus the deletion period in clause 11.

Nature and purpose of processing

Storing and organising client records; scheduling and managing appointments; generating and delivering quotes and invoices; sending appointment and payment notifications; processing payments; and, unless confidentiality mode is enabled, transcribing voice recordings and generating structured text using AI.

Categories of data subjects

  • Your clients and prospective clients
  • Your team members and staff
  • Third parties whose details you record in a booking or project (for example a stakeholder approving a quote)

Types of personal data

  • Identity and contact: name, email address, telephone number, postal or service address
  • Appointment data: date, time, duration, service booked, assigned practitioner, attendance and cancellation history
  • Financial: quote and invoice amounts, payment status and payment history. Card details are collected directly by our payment subprocessors and never stored by Echo.
  • Free-text and uploaded content: job descriptions, session and job notes, intake form responses, uploaded documents and images
  • Technical: IP address, device and browser information, and timestamps of actions taken in the platform

Special categories of personal data

Where you are a healthcare or therapeutic practitioner, the fact of an appointment with you, together with a client's identity, and any clinical or session notes you record, constitute data concerning health under Article 9 GDPR. Echo processes such data only where you enter it, and clause 8 governs the additional safeguards available to you.

Frequency of processing

Continuous, for the duration of the agreement.

Annex II — Technical and organisational measures

Data location

  • Database, authentication and file storage: Supabase on AWS eu-west-1 (Ireland)
  • Application servers: Vercel, Dublin, Ireland (dub1)
  • No replication of the primary data store outside the EEA

Encryption

  • All data encrypted in transit using TLS 1.2 or higher
  • All data encrypted at rest at the storage layer
  • Third-party calendar access tokens held in an encrypted vault with a separately managed encryption key

Access control and tenant isolation

  • Row-level security enforced at the database layer, so a query executed on behalf of one business cannot return another business's rows
  • Role-based access control within each account (owner, admin, technician, viewer), with team members scoped to the records assigned to them
  • Passwords hashed with bcrypt; customer authentication by one-time passcode; session tokens issued and validated server-side
  • Administrative access to the platform requires separate authentication and is limited to named personnel
  • Payment card data never reaches Echo's servers; it is collected directly by PCI DSS Level 1 certified processors

Resilience and recovery

  • Managed database with automated point-in-time backup, retained on a rolling 30-day basis
  • Infrastructure operated by providers maintaining SOC 2 Type II attestation

Organisational measures

  • Personnel bound by written confidentiality obligations, with access granted on a need-to-know basis and revoked on departure
  • Changes to production systems made through version-controlled deployments with an auditable history
  • Secrets held in managed secret storage, never in source code
  • Documented breach notification process meeting the 48-hour commitment in clause 10

Data minimisation by configuration

  • Confidentiality mode prevents personal data reaching AI and analytics subprocessors entirely (clause 8)
  • Raw audio is not retained after transcription completes; only the resulting text is stored
  • Analytics and session-recording tools are never loaded on dashboards, customer portals or booking pages
  • Notification delivery logs are retained for 90 days

Annex III — Subprocessors

The following subprocessors are authorised as at 6 October 2026. The current list, with full detail of what each receives, is maintained at echo-agent.com/legal/subprocessors.

SubprocessorPurposeLocationTransfer
SupabaseDatabase, authentication and file storageAWS eu-west-1 (Ireland)Within EEA
VercelApplication hosting and serverless compute; cookieless page-view counting on public marketing pagesDublin, Ireland (dub1)Within EEA
TwilioWhatsApp and SMS delivery, one-time passcodesUnited StatesSCCs
Meta (WhatsApp)Delivery of WhatsApp messages sent via TwilioIreland / United StatesSCCs
Twilio SendGridTransactional email deliveryUnited StatesSCCs
OpenAIVoice transcription, note structuring, quote generation, content moderationUnited StatesSCCs
StripeCard payments, payouts and subscription billingUnited States / IrelandSCCs
PaystackCard payments and payouts in supported African marketsSouth Africa / NigeriaSCCs
GoogleAddress autocomplete and travel distance; Google Calendar sync where the provider connects itEuropean Union / United StatesSCCs
MicrosoftOutlook Calendar sync where the provider connects itEuropean Union / United StatesSCCs
Google Analyticsreceives no client data in confidentiality modeAggregate usage analytics on Echo's public marketing pagesEuropean Union / United StatesSCCs
Microsoft Clarityreceives no client data in confidentiality modeAggregate usage analytics on Echo's public marketing pagesEuropean Union / United StatesSCCs

How this agreement applies

This DPA applies automatically to every Echo account as part of the Terms of Service. You do not need to sign or return anything. The version and effective date are shown at the top of this page.

Questions about this agreement: privacy@echo-agent.com.