← Return to Home

Data Processing Agreement

Last updated · 11 September 2026

Echt · England and Wales

Status of this document

This is a working draft, not an executed agreement. It accurately describes how the Service processes personal data, and it is offered so a prospective Customer can see the substance before asking for paperwork. It has not been reviewed by a solicitor, one figure in the liability clause is deliberately left to be agreed, and Echt does not hold a SOC 2 report or ISO 27001 certification. A Customer requiring an executed DPA should contact us and we will complete one, taking legal advice on the terms.

1. Parties and scope

This Agreement is between the Customer (the "Controller") and Echt (the "Processor"), and governs Echt's processing of personal data on the Controller's behalf in providing the Service. It supplements the Terms of Use and, in the event of conflict on a data protection matter, takes precedence over them.

These terms have the meanings given in the UK GDPR: controller, processor, personal data, special category data, processing, data subject, and personal data breach.

2. Roles

The Controller determines the purposes and means of processing the documents it uploads and is responsible for the lawfulness of doing so, including providing privacy information to the applicants concerned and identifying a lawful basis for any special category data.

Echt processes that data only as a processor, on the Controller's documented instructions, which are given by the Controller's use of the Service and by this Agreement. Echt is an independent controller only for account, billing and support data relating to the Controller's own authorised users.

3. Echt's obligations

  • Process personal data only on documented instructions, and notify the Controller if an instruction appears to infringe UK data protection law.
  • Not use submitted documents or their contents for any purpose of Echt's own, including training machine-learning models. The Service's checks are hand-written and deterministic and do not learn from Customer data.
  • Ensure personnel with access are bound by confidentiality and have access only where necessary.
  • Apply the technical and organisational measures set out in Annex B.
  • Assist the Controller, at the Controller's cost where the effort is more than trivial, with data subject requests, data protection impact assessments, and enquiries from the Information Commissioner's Office.
  • Make available the information necessary to demonstrate compliance with this Agreement.

4. Sub-processors

The Controller authorises the sub-processors listed in Annex C. Echt will give the Controller at least 30 days' notice by email before adding or replacing a sub-processor. If the Controller reasonably objects on data protection grounds within that period, the parties will discuss in good faith; if no resolution is reached the Controller may terminate the affected part of the Service without penalty for the unused remainder of any prepaid term.

Echt remains responsible for its sub-processors' performance and will impose data protection obligations on them no less protective than those in this Agreement.

5. International transfers

Echt is established in the United Kingdom. Submitted documents are examined and their records stored in the European Economic Area, which is covered by the UK's adequacy regulations, so no additional transfer mechanism is required for those sub-processors.

One sub-processor is outside that area. Our transactional email provider is established in the United States and receives recipient email addresses in order to deliver invitations to join an organisation. It receives no submitted document and no applicant data. That transfer relies on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as set out in the provider's own terms.

Where a sub-processor outside the UK or EEA is introduced, Echt will put in place the UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses, carry out a transfer risk assessment, and disclose it under clause 4 before any data reaches it.

6. Personal data breach

Echt will notify the Controller without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. Echt will provide further information as the investigation progresses and will not delay an initial notification in order to complete one.

Notification to the Information Commissioner's Office and to affected data subjects is the Controller's responsibility as controller; Echt will provide reasonable assistance.

7. Deletion and return

The uploaded document is deleted immediately after analysis in the ordinary course of the Service, and is not retained by Echt at any point. What is retained is the record of the check described in Annex A, held for 24 months by default and configurable for each Controller. That record is deleted automatically when the period expires, and deleting a document record deletes the findings held against it.

On termination, or earlier on written request, Echt will delete the Controller's records within 30 days and confirm deletion in writing. Deleting a user account removes that user's scan records automatically. Where a copy persists in an encrypted backup, it will be overwritten in the ordinary backup cycle and will not be accessed in the meantime. Echt will retain data beyond these periods only where required by law, and will tell the Controller if that applies.

8. Audit

On reasonable written notice and no more than once a year, unless a personal data breach or a regulator requires otherwise, Echt will respond to a security questionnaire and make available documentation about the measures in Annex B. Echt does not currently hold a SOC 2 report or ISO 27001 certification and will not represent otherwise.

9. No automated decision-making

The Service produces decision support. Each result is a set of stated, checkable facts about a file, presented to a trained reviewer employed by the Controller, who makes the decision. Echt does not accept or refuse any request, does not act on its own results, and carries out no profiling of data subjects.

The Controller must not use the Service to make a decision about a person by solely automated means within the meaning of Article 22 UK GDPR.

10. Term

This Agreement takes effect when the Controller first uses the Service and continues until the Controller's data has been deleted in accordance with clause 7.

11. Liability

11.1Nothing in this Agreement excludes or limits either party's liability where that cannot be excluded or limited under the laws of England and Wales, including liability for death or personal injury caused by negligence, for fraud, or for fraudulent misrepresentation.

11.2Nothing in this Agreement affects a data subject's rights under Article 82 UK GDPR. A processor is directly liable to data subjects for damage caused by processing that breaches obligations directed at processors, or that goes beyond the controller's lawful instructions, and that liability cannot be contracted away. The caps below govern only what the parties may recover from each other.

11.3Subject to 11.1, 11.2 and 11.4, Echt's liability under this Agreement is subject to the limitation of liability in the Terms of Use and does not sit on top of it.

11.4 Data protection super-cap.For claims arising from Echt's breach of this Agreement or of its obligations as a processor under UK data protection law, Echt's aggregate liability in any twelve-month period is limited to the greater of [AMOUNT TO BE AGREED] or the fees paid by the Controller in that period. This replaces the general cap in the Terms of Use rather than being added on top of it.

Why this number is blank, and how it should be set. The general cap in our Terms is the greater of twelve months' fees or £100. That is a reasonable position for a service fault. It is not a reasonable position for the loss of a set of applicants' passports and medical letters, and a Controller carrying out a proper supplier assessment should say so. A cap that a supplier could not actually pay protects nobody, so the honest way to set this figure is to insure first and set the cap at the cover obtained, rather than to assert a number and hope. Echt will state its current cyber liability cover on request and will not quote a super-cap that exceeds it.

11.5Echt will indemnify the Controller against fines and claims to the extent they arise from Echt's breach of this Agreement, subject to the caps above. The Controller will indemnify Echt against fines and claims to the extent they arise from the Controller uploading documents without a lawful basis, without the privacy information required of it, or outside the instructions in this Agreement.

11.6 This clause has not been reviewed by a solicitor and is offered so a prospective Controller can see the shape of the position early. It will be settled, with legal advice on both sides, in any executed agreement.

Annex A: Details of processing

Subject matter. Examination of documents submitted by applicants seeking release from an accommodation booking, to establish whether a file shows signs of alteration.

Duration.The term of the Controller's subscription, plus the deletion period in clause 7.

Nature and purpose. Automated examination of file structure, embedded metadata, recoverable earlier versions, image characteristics, and the internal consistency of any text the file contains; production of a result and a retained record of it; recognition of documents previously submitted to the same Controller.

Categories of data subject.Applicants for or holders of accommodation bookings, and the Controller's own authorised users.

Categories of personal data. Whatever the submitted document contains, which is determined by the Controller. Typically: name, date of birth, nationality, address, document and reference numbers, dates, and the substance of the letter. Identity documents additionally contain a photograph and a machine-readable zone.

Special category data.Likely, and expected. Medical letters contain data concerning health. Visa and immigration documents disclose immigration status, and may indicate racial or ethnic origin. Processing is on the Controller's instructions and lawful basis.

What is retained.Not the document, its extracted text, or the images rendered during analysis. Retained: the filename as supplied, the document type determined, the result and its two scores, the individual findings with their severity and the value each rests on, what the file records about the software and dates that produced it, what an earlier version of the file said where one was recovered from inside it, which pages were examined, whether the wording was read from the file or from a picture of it, which checks ran and which reported something, counts of observations by severity, a hash of the file and a similarity measure of its text, one-way salted hashes of identifiers found in it, the reviewer's recorded decision and any later outcome, and which user and organisation performed the check. Personal identifiers are stripped from all retained text before it is written.

Why the findings are retained. From 19 August 2026 the Service examines evidence and recommends a next step. A Controller acting on that recommendation must be able to see what it rested on, and a conclusion nobody can inspect is an instruction rather than decision support. The findings are the reasoning, never a copy of the document: why a passport was inconsistent, not a picture of the passport.

Annex B: Technical and organisational measures

  • The document is not stored. It is written to temporary storage for the seconds the analysis takes, then deleted. This is the single most effective measure applied and it is architectural rather than procedural.
  • Identifiers are stripped before storage. National Insurance numbers, account numbers, passport and reference numbers and email addresses are removed from retained text.
  • Identifiers used for duplicate detection are one-way and salted with a server-side secret. The original values are never stored and cannot be recovered from the stored form.
  • Tenant isolation is enforced in the database by row-level security scoped to organisation membership, not only in application code, so a Controller cannot read another Controller's records even in the event of an application fault.
  • Encryption in transit over TLS, and at rest for the database and backups as provided by our infrastructure providers.
  • Authenticationby email and password with a twelve-character minimum, using a managed identity provider. Access to a Controller's records requires membership of that Controller's organisation, which is granted only by invitation from an existing member.
  • Administrative accessto production systems is limited to Echt personnel who require it, and is protected by the infrastructure providers' own multi-factor authentication.
  • Rate limiting and upload limits to bound abuse and denial of service.
  • Not claimed: Echt does not hold SOC 2 or ISO 27001, does not offer customer-managed encryption keys, does not offer single sign-on, and does not operate a formal penetration testing programme. These are stated so that no Controller relies on them.

Annex C: Sub-processors

  • Supabase: database, authentication and hosting of the retained record. Ireland (eu-west-1).
  • Render: hosting of the analysis service, where documents are examined and deleted. European Union (Frankfurt).
  • Vercel: hosting and delivery of the web interface. Serves the application; submitted documents pass through it in transit only and are not stored by it.
  • Dodo Payments: subscription checkout and payment processing. Processes billing data, not submitted documents.
  • Resend: delivery of transactional email, such as invitations to join an organisation. Processes recipient email addresses only, and never a submitted document. Established in the United States; see clause 5.

No artificial-intelligence or machine-learning service is a sub-processor, and no submitted document is sent to one.

Contact

For an executed DPA, a security questionnaire, or sub-processor notifications:

Echt Data Protection
Email: hello@useecht.com