Echo is built on enterprise-grade infrastructure. This page explains how we protect your data, what standards our infrastructure meets, and how we handle your rights as a data subject.
bigECOs does not yet hold independent ISO 27001 certification — we are transparent about this. Our infrastructure providers hold certifications trusted by the world's largest organisations, and your data is stored and processed entirely within that certified environment.
Security is designed into every layer of Echo, from how you authenticate to how your customers' data is stored and accessed.
Exactly what data Echo processes, where it travels, and what controls you have.
How bigECOs meets its obligations under UK data protection law and other applicable regulations.
All sub-processors are contractually bound to data protection standards equivalent to those in our DPA. We will provide 30 days' prior notice of any changes.
| Provider | Location | Transfer basis | Processing activity |
|---|---|---|---|
| Google LLC Firebase / Cloud Firestore | USA Data stored: europe-west2, London | UK-US Data Privacy Framework | Database hosting; user authentication; session management; customer data storage |
| Vercel Inc. | USA Compute: nearest region | UK IDTA / SCCs | Application hosting; serverless API execution; CDN delivery |
| Anthropic PBC | USA | UK IDTA / SCCs | AI processing of prospect URLs and anonymised customer reference data to generate match scores and talking points. API terms confirm no model training on submitted data. 30-day data retention. |
| Voyage AI Inc. | USA | UK IDTA / SCCs | Semantic embedding of prospect page text and anonymised customer company descriptions to rank reference relevance. No personal data transmitted. Embeddings are ephemeral and not retained. |
| Resend Inc. | USA | UK IDTA / SCCs | Transactional email: login codes, welcome emails, team invitations |
| Stripe Inc. | USA | UK IDTA / SCCs | Payment processing for Pro and Enterprise subscriptions. Stripe does not receive customer reference or prospect data. |
| Public Company Registers UK, US, EU & Australian authorities | UK / US / EU / AU | Domestic registers — no personal data transfer | Official public company register lookups for Deep Connections (UK, US, EU, AU). Only company names queried. No personal data transmitted. |
We will provide at least 30 days' prior written notice of any changes to this list. Enterprise customers may object within 14 days of notification.
If you have a security concern, a procurement question or would like to request our DPA, contact us directly. We aim to respond to all security enquiries within one business day.