Document Version History
VersionDateChangesAuthor
3.1 May 2026 SCC transfer basis corrected to Module 3 (Processor to Processor). INSTRAT Technology ApS location clarified (legal entity: Denmark, EU; remote developers: Bangladesh). Echory GmbH
3.2 12 June 2026 Updated Deepgram API architecture to the EU endpoint. Speech-to-text processing localised within the EU/EEA. DPO / Engineering Team
3.3 July 2026 Corrected §1 summary table: SCC transfer basis for OpenAI unified to Module 3, consistent with §9 and version history. DPO / Legal
4.0 August 2026 Document reduced to the security measures required under Art. 32 GDPR. Service levels, processing details and customer obligations are no longer restated here; they are governed by the Service Level Addendum (Annex 4) and the Data Processing Addendum (Annex 2). Sub-processor register moved to a dedicated, continuously maintained page. Former §§1–10 consolidated into §§1–9. Tenancy model clarified (logical separation by tenant identifier, reinforced by per-tenant envelope encryption) and application-level two-factor authentication added to §2. Echory GmbH
Annex III · Exhibit D · Data Processing Addendum

Technical and Organisational
Security Measures (TOMs)

Echory GmbH · echoryflow.com Version 4.0 Effective: August 2026 Art. 32 GDPR & Art. 28 GDPR
These Technical and Organisational Measures describe the security controls implemented by Echory GmbH ("echory") as data processor in accordance with Art. 32 GDPR. They are incorporated by reference into the Data Processing Addendum (DPA) and are binding on echory and its sub-processors.

This document is deliberately limited to those measures. Service levels, which cover availability, error classification, response and recovery times and maintenance windows, are governed exclusively by Annex 4 (Service Level Addendum). The categories of personal data, data subjects, purposes and duration of processing are set out in Annex II of Exhibit D to the DPA. Customer obligations follow from the Master Services Agreement and the DPA. Nothing in this document restates, extends or replaces those terms.
§1

Scope, Role and Data Residency

echory acts as processor on behalf of its customers, or as sub-processor where the customer itself acts as a processor. These measures apply to all personal data processed via the echory real-time AI decision support platform.

  • All processing infrastructure is hosted on AWS eu-central-1 (Frankfurt, Germany)
  • Personal data does not leave the European Economic Area except as disclosed in the sub-processor register, where transfers are covered by Standard Contractual Clauses
  • echory maintains no physical server infrastructure of its own; physical security is delegated to Amazon Web Services EMEA SARL (ISO 27001, SOC 1/2/3, ISO 27017/27018)
§2

Access Control

  • AWS IAM enforced for all cloud resource access; no shared root credentials in use
  • TOTP-based multi-factor authentication required for all AWS IAM accounts
  • Unique credentials per team member; no shared service accounts
  • Access to personal data restricted on a strict need-to-know basis; production access requires a documented operational requirement
  • Production, staging and development environments are separated, with no cross-environment data flows
  • Access rights reviewed and revoked within one business day of role change or departure
  • Application users can enable two-factor authentication using a one-time code delivered by e-mail
  • Rate limiting applied to authentication and sensitive endpoints
Development sub-processor access. INSTRAT Technology ApS operates under a scoped access model for production environments. Access is granted per documented task, is logged, and is subject to echory's oversight.
§3

Encryption and Separation

Encryption

  • In transit: TLS 1.3 enforced for all HTTPS and WebSocket Secure (WSS) connections, including audio transmission and API calls to sub-processors
  • At rest: AES-256 at the AWS storage layer for the database, object storage and compute volumes. Above the storage layer, transcripts and sensitive meeting content are additionally protected by application-layer envelope encryption, using a dedicated data-encryption key per tenant with key versioning
  • Application credentials, API keys and service tokens are held in managed secret storage; access is restricted on a need-to-know basis

Separation and Secure Development

  • AWS VPC with private subnets isolates database and internal services from the public internet
  • Security Groups configured as allowlists with default-deny for all inbound traffic; network ACLs provide additional subnet-level filtering
  • Customer data is separated logically: every record is bound to its tenant and every query is scoped by tenant identifier, so data belonging to different customers is never pooled, joined or returned across tenant boundaries
  • Separation is reinforced cryptographically: transcripts and sensitive meeting content are protected by application-layer envelope encryption with a dedicated data-encryption key per tenant, so tenant data is separated at the key level and not only by query scope
  • All code changes require a pull request with at least one approving reviewer before merge; branch protection prevents direct production deployments
  • Infrastructure changes are managed as infrastructure-as-code
§4

Availability and Resilience

Backup frequency
Daily
Automated database snapshots
Retention
7 days
Encrypted, AWS-managed storage
Recovery time objective
4 h
Critical service restoration
Recovery point objective
24 h
Maximum data loss window
  • Database backups are stored in encrypted AWS-managed storage (AES-256)
  • Infrastructure and application logs are aggregated via AWS CloudWatch; authentication events and system errors are logged
  • Alerting is configured for anomalous access patterns and service degradation
  • OS and runtime patches are applied on a regular schedule; critical patches on an expedited basis. Application dependencies are monitored for known vulnerabilities
RTO and RPO are internal recovery targets for the restoration of the service. They are not service levels. Contractually agreed availability, error classes, response times and recovery times are set out exclusively in Annex 4 (Service Level Addendum).
§5

AI Processing

No model training on customer data. For language model inference this follows from the provider’s standard API terms, in effect since 1 March 2023, under which data sent to the API is not used for training. For speech-to-text, model training is disabled at account level for echory’s account. echory may process anonymised customer data for its own AI model development under separate provisions of the Master Services Agreement; customers retain full opt-out rights at any time.

Audio lifecycle

Audio is captured in the user's browser and transmitted via an encrypted WebSocket connection (WSS) to echory's processing service hosted on AWS eu-central-1. It is forwarded to Deepgram's EU endpoint for real-time speech-to-text conversion, with all transcription processing localised within the EU/EEA. The resulting transcript is then processed by echory's AI pipeline. Audio is not persisted beyond the active session. It is deleted once transcription is complete.

Inference

  • All AI inference is triggered by the echory platform on behalf of the controller and operates solely on data provided within the session context
  • Model inference runs under the provider’s standard API terms, under which customer data is not used to train or improve models. Inputs and outputs may be held in the provider’s abuse-monitoring logs for up to 30 days and are then deleted
  • Only data strictly necessary for the specific processing task is transmitted to a sub-processor
§6

Sub-processors

echory engages sub-processors under written terms governing security and confidentiality. The current register, which names each sub-processor, its role, its processing location and the applicable transfer mechanism, is maintained at:

Changes to the register are notified to controllers in accordance with the DPA, which also governs the notice period and the customer's right to object.

§7

Personnel and Endpoints

  • All personnel and contractors with access to personal data are bound by confidentiality agreements
  • Data protection awareness training is provided to all team members with data access
  • Screen lock and auto-lock policies are enforced on all team devices
  • Malware and endpoint protection software is installed on all team devices
  • Sub-processors are contractually bound to equivalent security obligations
§8

Retention, Deletion and Return

  • Personal data is deleted within 30 days of contract termination
  • Customers may request earlier deletion in writing; echory will action such requests within 5 business days
  • Audio recordings are session-scoped and are not persisted after the transcription pipeline completes
  • Transcripts and AI outputs are retained per controller instructions or the DPA schedule
  • Secure deletion procedures are applied: data is overwritten or cryptographically erased
  • Deletion certification is available on request

Export of customer data on switching is governed by Annex 3 (Data Act Addendum) and the echory Data Register.

§9

Incident Response

  • echory notifies the controller within 24 hours of becoming aware of a confirmed or suspected personal data breach
  • The notification includes the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the mitigation measures taken or planned
  • The controller remains responsible for notifying the competent supervisory authority within the statutory 72-hour window (Art. 33 GDPR)
  • A post-incident review is conducted for all critical and high-severity incidents; findings are documented and acted upon
Incident classification, response times and recovery times are set out in Annex 4 (Service Level Addendum) and are not restated here.

Questions regarding these measures: security@echoryflow.com

© 2026 Echory GmbH. All rights reserved. Technical and Organisational Measures · v4.0