Trust

Your data, handled with care.

Customer research is sensitive. Here's how we treat the data you trust us with, in plain language.

Draft for legal review. Yellow fields are placeholders. Not legal advice; have this page checked before go-live.
01

Used only for your study

Your files and research data are used to build your audiences and run your studies. Nothing else. They are never shared with other customers.

02

Never used to train AI models

Your data is not used to train, improve or fine-tune AI models: not Google's, and not Echo's own. We use commercial API terms that guarantee this.

03

Hosted in Europe

The Echo platform runs on Google Cloud and our database on Supabase, both in the EU (europe-west). AI inference runs through Google's Gemini API, protected by EU Standard Contractual Clauses.

04

GDPR by default

We sign a data processing agreement with every customer, and we work with providers that offer GDPR-compliant terms.

05

You stay in control

Ask us at any time to return or delete your data. We do it within 30 days and confirm it in writing. Pseudonymise your documents before upload, and we'll help you do it well.

06

NDA when you need one

Working on something confidential? We're happy to sign an NDA before you share anything sensitive.

Security measures

  • Encrypted connections (HTTPS) for the website and the platform
  • Per-customer data separation in the platform
  • Access limited to the people working on your project
  • Breach notification without undue delay, within 72 hours where feasible
  • [Add only measures that are actually in place: encryption at rest, backups, 2FA, logging]

Questions about data?

Email olivier@userecho.io. For the legal detail, see our Privacy policy.