Privacy Policy
Last updated · 11 September 2026
Echt · England and Wales
1. Introduction
This Privacy Policy explains how Echt ("Echt", "we", "us", or "our") collects, uses, stores, and protects personal data when you access Echt (the "Service").
Echt provides business-to-business ("B2B") software to student accommodation providers, university housing teams, and similar operators in the United Kingdom. In the cancellation workflow, the Service examines documents submitted by students who are asking to be released from an accommodation booking. That might be a visa refusal, a university withdrawal or deferral letter, a medical letter, or an identity document. The Service reports whether the file shows signs of having been altered.
The Service examines documents, not people. It reports on how a file was made, where it came from, and whether anything in it has been changed. It does not assess an applicant, score their credibility, or make any judgement about them. We are committed to compliance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and applicable privacy laws.
2. Roles and responsibilities
In most cases, your organisation (the "Customer") is the data controller for personal data contained in documents submitted by applicants, and for the case files they relate to. Echt acts as a data processor when we examine those documents, produce a result, and store a record of the check on your instructions.
Where Echt collects account, billing, or support information directly from authorised users at a Customer organisation, Echt may act as an independent controller for that administrative data. A Data Processing Agreement is published at useecht.com/dpa and forms part of our contractual relationship where applicable.
3. Categories of data we process
Depending on how you use the Service, we may process:
- Account and contact data: names, work email addresses, job titles, authentication credentials, and audit logs relating to authorised users.
- Documents submitted by applicants: visa and immigration decision letters, university admission, withdrawal and deferral letters, medical letters, identity documents such as passports and driving licences, and occasionally financial documents. These frequently contain special category data, including data concerning health and immigration status.
- The result of the check: what the file records about how it was made and by what software, whether an earlier version of it can be recovered from inside the file, whether anything it states contradicts anything else it states, and an overall result of low risk, needs manual review, high risk, or inconclusive.
- Technical and security data: IP addresses, device identifiers, session tokens, error logs, and usage telemetry necessary to operate, secure, and improve the Service.
4. Purposes and lawful bases
We process personal data for the following purposes:
- To perform our contract with the Customer and examine the documents they submit to us (lawful basis: performance of a contract; Article 6(1)(b) UK GDPR).
- To help the Customer establish whether a document supporting a cancellation request has been altered (lawful basis: legitimate interests of the Customer in preventing fraudulent release from a booking, and, where applicable, explicit instructions under contract).
- To maintain platform security, prevent abuse, and meet legal obligations (lawful basis: legitimate interests and legal obligation).
- Where special category data appears within a submitted document, such as a medical letter or a document disclosing immigration status, processing is carried out strictly on the documented instructions of the Customer as controller, on the lawful basis the Customer has identified, or as set out in the DPA.
No decision about a person is made by software alone. The result Echt produces is decision support. Every check is a stated, checkable fact about the file: the software that produced it, the dates it records, an earlier version recovered from inside it, or a sum that does not add up. Each of those is put in front of a trained reviewer at the Customer, who decides. Echt does not accept or refuse a cancellation, does not act on its own result, and carries out no profiling. The Service is not intended to be used for a decision taken solely by automated means within the meaning of Article 22 UK GDPR, and Customers must not use it that way.
5. Processing applicants' documents on your behalf
When you upload a document, Echt examines it solely to produce the result you have asked for. We do not use the contents of submitted documents to train machine-learning models, and the analysis does not work that way: the checks are hand-written and deterministic, so the same file produces the same result and every finding can be re-derived by hand.
The document is not sent to any third-party artificial-intelligence service. It is examined on our own infrastructure and deleted immediately afterwards, as described under Retention below.
Customers are responsible for providing appropriate privacy notices to the applicants whose documents they upload, for establishing a lawful basis for the check, and for limiting uploads to what is necessary for the decision being made. In particular, a Customer should ask for the specific document that evidences the reason given, rather than a general file of everything an applicant has ever sent.
Echt implements technical and organisational measures designed to protect submitted documents, including encryption in transit and access controls scoped so that a Customer organisation can only ever see its own records.
6. Retention
The uploaded document is not kept. A file is written to temporary storage for the seconds the analysis takes and deleted immediately afterwards. We do not retain the document itself, the text extracted from it, or the page images rendered during analysis. Those exist for the length of the request and are never written to our database.
What the checks concluded is kept. This changed on 19 August 2026, and it changed for a reason worth stating: the Service now examines evidence and recommends a next step, and an operator asked to act on that recommendation has to be able to see what it rested on. A conclusion nobody can inspect is not decision support, it is an instruction.
So for each document checked we keep the result, the scores, the individual findings with their severity and the value each rests on, what the file records about the software and dates that produced it, what an earlier version of it said where one was recovered from inside the file, which pages were examined, whether the wording was read from the file or from a picture of it, and which checks ran. Identifiers are removed before any of it is written, as described below. This is the record of a conclusion, not a copy of the document: it is why we say a passport was inconsistent, never a picture of the passport.
What we do keep, as a record of the check rather than a copy of the document:
- The filename as you supplied it, so a reviewer can tell which document a result belongs to. Filenames frequently contain a person's name; Customers who prefer they did not should rename files before upload.
- The result and the findings behind it: the verdict, the two scores, the document type determined, each finding with its severity and the value it rests on, what the file records about its own origin, what a recovered earlier version said where there was one, which pages were examined, whether the wording was read from the file or from a picture, and which checks ran.
- The wording of anything reported, with identifiers removed. Numbers that identify a person are stripped before the record is written: National Insurance numbers, account numbers, passport and reference numbers, and email addresses. Dates and times are kept, because they describe the file rather than the person.
- Fingerprints used to recognise a repeat: a hash of the file, a similarity measure of its text, and one-way salted hashes of identifiers found in it. These allow us to tell you that the same document, or the same account number, has been submitted before. They cannot be reversed to recover the original value, and the values themselves are never stored.
- The decision recorded by your reviewer: what they did, what later happened if they told us, the verdict at the time, and when.
- Who performed the check, and for which organisation.
Records of a check are kept for 24 months by default, configurable for each Customer organisation, and deleted automatically once that period expires. Deleting a document record deletes the findings held against it. Deleting a user removes that user's records; a Customer may ask us to delete their organisation's records at any time, and we will do so. Where a Data Processing Agreement is in place, its terms govern retention and return on termination.
Account and billing data is retained while the account is open. That means the name, work email, telephone number, company name and role you provide, and payment records held by our payment provider. It is kept while the account is open and for as long afterwards as tax and accounting law requires.
7. Sharing and sub-processors
We do not sell personal data. We may share data with infrastructure providers, security vendors, and professional advisers who process data on our behalf under written agreements requiring equivalent to UK GDPR protections. Material sub-processors are listed in Annex C of the Data Processing Agreement.
We may disclose information where required by law, court order, or to protect the rights, property, or safety of Echt, our Customers, or others.
8. International transfers
Echt is established in the United Kingdom. If personal data is transferred outside the UK, we implement appropriate safeguards such as the UK International Data Transfer Agreement or other mechanisms approved under UK data protection law.
9. Security
We maintain administrative, technical, and physical safeguards appropriate to the nature of the data processed, including role-based access, monitoring, and secure development practices. No method of transmission or storage is completely secure; Customers should also implement internal controls over user access and document handling.
10. Your rights
Where Echt acts as processor, data subjects should direct requests to exercise UK GDPR rights (access, rectification, erasure, restriction, objection, and data portability, as applicable) to the Customer organisation that collected their information.
Where Echt is controller of account or support data, you may contact us using the details below. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. Contact
For privacy enquiries, Data Processing Agreements, or sub-processor information, contact:
Echt Privacy
Email: hello@useecht.com