| Version | Date | Changes | Author |
|---|---|---|---|
| 3.1 | May 2026 | SCC transfer basis corrected to Module 3 (Processor to Processor). INSTRAT Technology ApS location clarified (legal entity: Denmark, EU; remote developers: Bangladesh). | Echory GmbH |
| 3.2 | 12 June 2026 | Updated Deepgram API architecture to the EU endpoint. Speech-to-text processing localised within the EU/EEA. | DPO / Engineering Team |
| 3.3 | July 2026 | Corrected §1 summary table: SCC transfer basis for OpenAI unified to Module 3, consistent with §9 and version history. | DPO / Legal |
| 4.0 | August 2026 | Document reduced to the security measures required under Art. 32 GDPR. Service levels, processing details and customer obligations are no longer restated here; they are governed by the Service Level Addendum (Annex 4) and the Data Processing Addendum (Annex 2). Sub-processor register moved to a dedicated, continuously maintained page. Former §§1–10 consolidated into §§1–9. Tenancy model clarified (logical separation by tenant identifier, reinforced by per-tenant envelope encryption) and application-level two-factor authentication added to §2. | Echory GmbH |
Technical and Organisational
Security Measures (TOMs)
This document is deliberately limited to those measures. Service levels, which cover availability, error classification, response and recovery times and maintenance windows, are governed exclusively by Annex 4 (Service Level Addendum). The categories of personal data, data subjects, purposes and duration of processing are set out in Annex II of Exhibit D to the DPA. Customer obligations follow from the Master Services Agreement and the DPA. Nothing in this document restates, extends or replaces those terms.
Scope, Role and Data Residency
echory acts as processor on behalf of its customers, or as sub-processor where the customer itself acts as a processor. These measures apply to all personal data processed via the echory real-time AI decision support platform.
- All processing infrastructure is hosted on AWS eu-central-1 (Frankfurt, Germany)
- Personal data does not leave the European Economic Area except as disclosed in the sub-processor register, where transfers are covered by Standard Contractual Clauses
- echory maintains no physical server infrastructure of its own; physical security is delegated to Amazon Web Services EMEA SARL (ISO 27001, SOC 1/2/3, ISO 27017/27018)
Access Control
- AWS IAM enforced for all cloud resource access; no shared root credentials in use
- TOTP-based multi-factor authentication required for all AWS IAM accounts
- Unique credentials per team member; no shared service accounts
- Access to personal data restricted on a strict need-to-know basis; production access requires a documented operational requirement
- Production, staging and development environments are separated, with no cross-environment data flows
- Access rights reviewed and revoked within one business day of role change or departure
- Application users can enable two-factor authentication using a one-time code delivered by e-mail
- Rate limiting applied to authentication and sensitive endpoints
Encryption and Separation
Encryption
- In transit: TLS 1.3 enforced for all HTTPS and WebSocket Secure (WSS) connections, including audio transmission and API calls to sub-processors
- At rest: AES-256 at the AWS storage layer for the database, object storage and compute volumes. Above the storage layer, transcripts and sensitive meeting content are additionally protected by application-layer envelope encryption, using a dedicated data-encryption key per tenant with key versioning
- Application credentials, API keys and service tokens are held in managed secret storage; access is restricted on a need-to-know basis
Separation and Secure Development
- AWS VPC with private subnets isolates database and internal services from the public internet
- Security Groups configured as allowlists with default-deny for all inbound traffic; network ACLs provide additional subnet-level filtering
- Customer data is separated logically: every record is bound to its tenant and every query is scoped by tenant identifier, so data belonging to different customers is never pooled, joined or returned across tenant boundaries
- Separation is reinforced cryptographically: transcripts and sensitive meeting content are protected by application-layer envelope encryption with a dedicated data-encryption key per tenant, so tenant data is separated at the key level and not only by query scope
- All code changes require a pull request with at least one approving reviewer before merge; branch protection prevents direct production deployments
- Infrastructure changes are managed as infrastructure-as-code
Availability and Resilience
- Database backups are stored in encrypted AWS-managed storage (AES-256)
- Infrastructure and application logs are aggregated via AWS CloudWatch; authentication events and system errors are logged
- Alerting is configured for anomalous access patterns and service degradation
- OS and runtime patches are applied on a regular schedule; critical patches on an expedited basis. Application dependencies are monitored for known vulnerabilities
AI Processing
Audio lifecycle
Audio is captured in the user's browser and transmitted via an encrypted WebSocket connection (WSS) to echory's processing service hosted on AWS eu-central-1. It is forwarded to Deepgram's EU endpoint for real-time speech-to-text conversion, with all transcription processing localised within the EU/EEA. The resulting transcript is then processed by echory's AI pipeline. Audio is not persisted beyond the active session. It is deleted once transcription is complete.
Inference
- All AI inference is triggered by the echory platform on behalf of the controller and operates solely on data provided within the session context
- Model inference runs under the provider’s standard API terms, under which customer data is not used to train or improve models. Inputs and outputs may be held in the provider’s abuse-monitoring logs for up to 30 days and are then deleted
- Only data strictly necessary for the specific processing task is transmitted to a sub-processor
Sub-processors
echory engages sub-processors under written terms governing security and confidentiality. The current register, which names each sub-processor, its role, its processing location and the applicable transfer mechanism, is maintained at:
Changes to the register are notified to controllers in accordance with the DPA, which also governs the notice period and the customer's right to object.
Personnel and Endpoints
- All personnel and contractors with access to personal data are bound by confidentiality agreements
- Data protection awareness training is provided to all team members with data access
- Screen lock and auto-lock policies are enforced on all team devices
- Malware and endpoint protection software is installed on all team devices
- Sub-processors are contractually bound to equivalent security obligations
Retention, Deletion and Return
- Personal data is deleted within 30 days of contract termination
- Customers may request earlier deletion in writing; echory will action such requests within 5 business days
- Audio recordings are session-scoped and are not persisted after the transcription pipeline completes
- Transcripts and AI outputs are retained per controller instructions or the DPA schedule
- Secure deletion procedures are applied: data is overwritten or cryptographically erased
- Deletion certification is available on request
Export of customer data on switching is governed by Annex 3 (Data Act Addendum) and the echory Data Register.
Incident Response
- echory notifies the controller within 24 hours of becoming aware of a confirmed or suspected personal data breach
- The notification includes the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the mitigation measures taken or planned
- The controller remains responsible for notifying the competent supervisory authority within the statutory 72-hour window (Art. 33 GDPR)
- A post-incident review is conducted for all critical and high-severity incidents; findings are documented and acted upon
Questions regarding these measures: security@echoryflow.com