Skip to content

Legal

Data Processing Agreement

Effective 29 June 2026

This DPA sets out how Echo processes personal data on behalf of its customers, aligned with UK GDPR and EU GDPR Article 28. It supplements, and is incorporated into, the Echo Terms of Service.

01Roles of the parties

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and ALLIN1.APP LTD, trading as Echo ("Processor"), for the use of the Echo service.

For Customer Data processed through Echo, the Controller determines the purposes and means of processing and the Processor processes it only on the Controller’s documented instructions, which include the use of the service as configured by the Controller.

02Subject matter, nature and duration

Subject matter and nature: the processing necessary to provide the Echo service, namely receiving instructions, planning and executing tasks, calling the tools the Controller has authorised, and storing the results against the Controller’s workspace.

Duration: processing continues for the life of the workspace and ends on deletion of the workspace, subject to the retention terms below.

03Categories of data and data subjects

Categories of data: account data (names, email addresses, workspace identifiers, authentication tokens), the content of messages and files the Controller sends to Echo, the outputs Echo produces, tool-call records, and operational logs.

Derived data: to provide the service, Echo generates and stores memory derived from the above, including facts and preferences about the workspace, a knowledge graph of the people, organisations, and projects referenced, embeddings (numerical representations of text) used for search, and transcriptions of any audio the Controller sends. Derived data is isolated to the Controller’s workspace, is processed only to operate the service, and is not used to train any model.

Data subjects: the Controller’s authorised users, and any individuals whose personal data the Controller chooses to include in the content it sends to Echo.

04Processor obligations

The Processor will: process Customer Data only on the Controller’s documented instructions; ensure persons authorised to process the data are bound by confidentiality; implement appropriate technical and organisational measures (described below); and assist the Controller, taking into account the nature of processing, in meeting its own obligations.

The Processor will not sell Customer Data and will not use it to train any machine-learning model.

05Security measures

Customer Data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Tool credentials are stored encrypted and are never exposed to the browser. Access is restricted on a least-privilege basis and every tool call is logged with the workspace, the user, the input, and the result.

A current summary of the Processor’s controls and subprocessors is published at /security.

06Sub-processors

The Controller authorises the Processor to engage the sub-processors listed at /security to provide the service. The Processor imposes data protection obligations on each sub-processor that are no less protective than those in this DPA.

The Processor will notify Controllers before adding or replacing a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.

07Data subject requests

Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under applicable data protection law.

Most access, export, correction, and deletion actions are available to the Controller directly in the Echo dashboard. For anything that is not, the Controller may contact [email protected].

08Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to assist the Controller in meeting its breach-notification obligations.

09Return and deletion

On termination of the service or deletion of the workspace, the Processor will delete Customer Data from active systems within 30 days and from backups within 90 days, except where retention is required by law.

10International transfers

Customer Data is hosted in the United States (AWS, us-east-1). Where Customer Data originating in the UK or EEA is transferred to a country without an adequacy decision, such transfers are made under the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses, together with supplementary measures as appropriate.

11Audits

The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and scheduling arrangements.

12How to sign

This DPA applies to your use of Echo. If your organisation requires a counter-signed copy, write to [email protected] with your workspace name and we will arrange execution.