Updated as of July 29, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms part of the echowin Terms of Service or other written agreement between echowin, Inc., a Delaware corporation ("echowin"), and the customer that has agreed to such terms ("Customer," "you," or "your") governing Customer's access to and use of the echowin Service (the "Agreement"). This DPA applies to echowin's Processing of Customer Personal Data (as defined below) in the course of providing the echowin Service and reflects the parties' agreement with regard to such Processing. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement. Except as modified below, the terms of the Agreement remain in full force and effect. In the event of any conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA will control to the extent of the conflict; in the event of any conflict between this DPA and the Standard Contractual Clauses (where they apply), the Standard Contractual Clauses will control to the extent of the conflict.
"Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, to the extent applicable: (a) Regulation (EU) 2016/679 (the "GDPR") and the GDPR as incorporated into the laws of the United Kingdom (the "UK GDPR"); (b) the EU e-Privacy Directive 2002/58/EC as implemented in each jurisdiction; (c) the Swiss Federal Act on Data Protection ("FADP"); and (d) U.S. federal and state privacy laws, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, together with its implementing regulations (the "CCPA"), and other applicable U.S. state comprehensive privacy laws (collectively, "U.S. Privacy Laws"), in each case as amended, superseded, or replaced from time to time.
"Controller" means the entity that determines the purposes and means of the Processing of Personal Data, and includes a "business" as defined under the CCPA and equivalent terms under other Applicable Data Protection Laws.
"Customer Personal Data" means Personal Data contained in Subscriber Data that echowin Processes on Customer's behalf in the course of providing the echowin Service, as further described in Annex 1. Customer Personal Data does not include Usage Data or data that has been De-identified in accordance with this DPA.
"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates, and includes a "consumer" as defined under the CCPA.
"De-identified" means data that cannot reasonably be used to infer information about, or otherwise be linked to, a particular natural person or household, provided the recipient of such data (a) takes reasonable measures to ensure the data cannot be associated with a natural person or household, (b) publicly commits to Process such data only in de-identified form and not to attempt to re-identify it, and (c) contractually obligates any recipients of such data to comply with the foregoing.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise Processed by echowin or its Subprocessors.
"Processing" (and its cognates, including "Process") means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"Processor" means the entity that Processes Personal Data on behalf of a Controller, and includes a "service provider" as defined under the CCPA and equivalent terms under other Applicable Data Protection Laws.
"Restricted Transfer" means (a) a transfer of Customer Personal Data that is subject to the GDPR to a country outside the European Economic Area not subject to an adequacy decision of the European Commission (an "EU Restricted Transfer"); (b) an equivalent transfer of Customer Personal Data subject to the UK GDPR (a "UK Restricted Transfer"); or (c) an equivalent transfer of Customer Personal Data subject to the FADP (a "Swiss Restricted Transfer").
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, superseded, or replaced from time to time.
"Subprocessor" means any Processor engaged by echowin or its affiliates to Process Customer Personal Data on Customer's behalf in connection with the echowin Service.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under s.119A(1) of the UK Data Protection Act 2018, as amended, superseded, or replaced from time to time.
2.1 Roles of the Parties. The parties acknowledge and agree that, with regard to the Processing of Customer Personal Data under the Agreement: (a) Customer is the Controller (or, where Customer acts as a Processor on behalf of a third-party Controller, Customer is a Processor); (b) echowin is a Processor acting on Customer's behalf (or, where Customer is itself a Processor, echowin is a subprocessor); and (c) echowin will engage Subprocessors in accordance with Section 6. Where Customer is itself a Processor for a third-party Controller, Customer represents and warrants that its instructions to echowin, including its appointment of echowin as a subprocessor, are authorized by the relevant Controller.
2.2 Scope. This DPA applies only to Customer Personal Data. For clarity, and as set forth in the Agreement, the echowin Service is not designed for and must not be used to Process Sensitive Data (as defined in the Agreement), except to the extent expressly agreed in a separately executed Business Associate Agreement with respect to Protected Health Information.
2.3 Duration. This DPA is effective as of the effective date of the Agreement and will remain in force for as long as echowin Processes Customer Personal Data, notwithstanding the expiration or termination of the Agreement.
2.4 Compliance with Laws. Each party will comply with its respective obligations under Applicable Data Protection Laws in connection with the Processing of Customer Personal Data.
3.1 Processing Details. The subject matter, duration, nature, and purpose of the Processing, the types of Customer Personal Data, and the categories of Data Subjects are described in Annex 1.
3.2 Customer Instructions. echowin will Process Customer Personal Data only on Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by law to which echowin is subject; in such a case, echowin will inform Customer of that legal requirement before Processing, unless that law prohibits such disclosure on important grounds of public interest. The parties agree that the Agreement (including this DPA), Customer's and its Authorized Users' configuration of and use of the echowin Service (including the Subscriber Configuration and any integrations enabled by Customer), and any other written instructions agreed by the parties constitute Customer's complete and final documented instructions to echowin for the Processing of Customer Personal Data. Additional or alternate instructions require the prior written agreement of both parties. echowin will promptly inform Customer if, in echowin's opinion, an instruction infringes Applicable Data Protection Laws, it being understood that echowin has no obligation to monitor Customer's instructions for compliance and that this sentence does not constitute legal advice.
3.3 Permitted Purposes. echowin will Process Customer Personal Data solely: (a) to provide, maintain, secure, and support the echowin Service in accordance with the Agreement; (b) to comply with Customer's other documented instructions under Section 3.2; and (c) as required by applicable law (collectively, the "Permitted Purposes").
3.4 De-identified and Aggregated Data. echowin may De-identify or aggregate Customer Personal Data and use such De-identified or aggregated data (including as Usage Data) for its lawful business purposes, including to develop, improve, and secure its products and services, provided that echowin: (a) Processes such data only in De-identified or aggregated form; (b) does not attempt to re-identify such data and publicly commits to maintaining it in de-identified form; and (c) contractually prohibits any recipients of such data from attempting to re-identify it. For clarity, echowin will not use Customer Personal Data in identifiable form to train Artificial Intelligence models except (i) as necessary to provide the echowin Service to Customer (such as tailoring the echowin Service to the Subscriber Configuration), or (ii) with Customer's prior written consent.
3.5 Confidentiality of Processing. echowin will ensure that all persons it authorizes to Process Customer Personal Data are subject to written or statutory obligations of confidentiality with respect to such data and Process Customer Personal Data only as necessary for the Permitted Purposes.
To the extent U.S. Privacy Laws apply to the Processing of Customer Personal Data, echowin is a "service provider" or "processor" and Customer is a "business" or "controller" (or a "service provider"/"processor" acting for a third-party business/controller), and Customer discloses Customer Personal Data to echowin solely for the Permitted Purposes. echowin will not: (a) "sell" or "share" Customer Personal Data (as those terms are defined in the CCPA); (b) retain, use, or disclose Customer Personal Data for any purpose other than the Permitted Purposes, including for any "commercial purpose" other than the Permitted Purposes, or outside of the direct business relationship between the parties, except as permitted by U.S. Privacy Laws (including with respect to De-identified data as described in Section 3.4); or (c) combine Customer Personal Data with personal data that echowin receives from or on behalf of another person, or collects from its own interactions with a Data Subject, except as permitted by U.S. Privacy Laws for the Permitted Purposes. echowin certifies that it understands and will comply with the restrictions in this Section 4. echowin will: (i) comply with all obligations applicable to it as a service provider or processor under U.S. Privacy Laws and provide the same level of privacy protection as is required of Customer with respect to Customer Personal Data; (ii) notify Customer without undue delay if it determines that it can no longer meet its obligations under U.S. Privacy Laws; and (iii) grant Customer the right, upon reasonable prior written notice, to take reasonable and appropriate steps in accordance with Section 9 (Audits) to ensure that echowin uses Customer Personal Data consistently with Customer's obligations under U.S. Privacy Laws, and, if echowin has notified Customer of unauthorized use of Customer Personal Data, to require echowin to stop and remediate such unauthorized use.
5.1 Security Measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, echowin will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Personal Data Breaches and to preserve its security and confidentiality, including, at a minimum, the measures described in Annex 2 (the "Security Measures"). echowin may update the Security Measures from time to time, provided that any update does not materially reduce the overall protection of Customer Personal Data.
5.2 Customer Responsibilities. Customer is responsible for: (a) securing its own account credentials, Access Protocols, systems, and devices; (b) the security of Customer Personal Data while in transit to the echowin Service via systems or integrations under Customer's or its providers' control; (c) configuring and using the echowin Service (including the Subscriber Configuration, retention settings, and integrations) in a manner appropriate to the sensitivity of the Customer Personal Data; and (d) not submitting Sensitive Data to the echowin Service in violation of the Agreement.
6.1 Authorization. Customer provides echowin with general written authorization to engage Subprocessors, including echowin's affiliates and the third parties listed at the URL identified in Annex 3 (the "Subprocessor List"), to Process Customer Personal Data for the Permitted Purposes.
6.2 Notice and Objection. echowin will maintain the current Subprocessor List at the URL identified in Annex 3 and will provide Customer with a mechanism to subscribe to notifications of changes. echowin will give Customer at least thirty (30) days' prior notice (via the Subprocessor List, email, or notice in the echowin Service) before authorizing a new Subprocessor to Process Customer Personal Data. Customer may object to the new Subprocessor on reasonable, documented grounds relating to data protection by notifying echowin in writing within fifteen (15) days of such notice. Following such objection, the parties will discuss the objection in good faith, and echowin may, at its option: (a) not use the new Subprocessor for Customer's Customer Personal Data; (b) propose a commercially reasonable change to Customer's use of the echowin Service that avoids the new Subprocessor; or (c) if neither (a) nor (b) is reasonably available, permit Customer to terminate the affected subscription upon written notice, in which case echowin will refund Customer any prepaid fees for the terminated portion of the Term following the effective date of termination. This Section 6.2 states Customer's sole and exclusive remedy with respect to any new Subprocessor.
6.3 Subprocessor Obligations; Liability. echowin will enter into a written agreement with each Subprocessor imposing data protection obligations that are, in substance, no less protective of Customer Personal Data than those imposed on echowin under this DPA, to the extent applicable to the services provided by the Subprocessor. echowin remains responsible for each Subprocessor's performance of echowin's obligations under this DPA and liable for the acts and omissions of its Subprocessors to the same extent echowin would be liable if performing the services of the Subprocessor directly under this DPA.
7.1 Data Subject Requests. Taking into account the nature of the Processing, echowin will provide reasonable assistance to Customer, including by appropriate technical and organizational measures (such as the search, export, correction, and deletion functionality of the echowin Service), for the fulfilment of Customer's obligation to respond to requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, objection, and opt-out). If echowin receives a request from a Data Subject that identifies Customer or that echowin can reasonably attribute to Customer, echowin will promptly forward the request to Customer and will not respond to the request itself except to acknowledge receipt, to direct the Data Subject to Customer, or as required by applicable law. Customer is responsible for responding to Data Subject requests, and for communicating any resulting instructions (such as deletion of specific records) to echowin where Customer cannot fulfil them using the echowin Service's self-service functionality.
7.2 DPIAs and Consultations. Taking into account the nature of the Processing and the information available to echowin, echowin will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Applicable Data Protection Laws in relation to the echowin Service.
7.3 Government and Legal Requests. Unless prohibited by applicable law, echowin will promptly notify Customer of any legally binding request for disclosure of Customer Personal Data by a law enforcement, regulatory, or other governmental authority, will direct the authority to request the data from Customer where appropriate, and will disclose only the minimum Customer Personal Data necessary to comply with the request.
echowin will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach. Such notification will, to the extent then known (and may be supplemented as information becomes available): (a) describe the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) provide the name and contact details of echowin's point of contact for the incident; (c) describe the likely consequences of the Personal Data Breach; and (d) describe the measures taken or proposed by echowin to address the Personal Data Breach and mitigate its possible adverse effects. echowin will take reasonable steps to contain, investigate, and remediate the Personal Data Breach and will provide reasonable cooperation to Customer in connection with Customer's own notification obligations under Applicable Data Protection Laws. echowin's notification of or response to a Personal Data Breach will not be construed as an acknowledgement by echowin of any fault or liability. Customer is solely responsible for determining whether and how to notify Data Subjects, supervisory authorities, or other third parties of a Personal Data Breach as required by Applicable Data Protection Laws, and echowin will not make any such notification on Customer's behalf or characterize the incident to third parties as attributable to Customer, in each case unless required by applicable law or agreed by the parties.
9.1 Records and Reports. echowin will maintain records of its Processing of Customer Personal Data as required by Applicable Data Protection Laws and will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which echowin may satisfy in the first instance by providing: (a) responses to reasonable written security and privacy questionnaires (no more than once per twelve (12) month period, absent a Personal Data Breach affecting Customer or a demonstrated material non-compliance); and (b) copies of relevant summaries of third-party audit reports, certifications, or assessments held by echowin, which constitute echowin's Confidential Information.
9.2 Audits. If the information provided under Section 9.1 is not reasonably sufficient to demonstrate echowin's compliance with this DPA, or where an audit is required by a supervisory authority or Applicable Data Protection Laws, echowin will allow for and contribute to audits, including inspections, conducted by Customer or an independent third-party auditor mandated by Customer (which auditor must not be a competitor of echowin and must be bound by confidentiality obligations), subject to the following conditions: (a) at least thirty (30) days' prior written notice, unless a shorter period is mandated by a supervisory authority; (b) no more than once per twelve (12) month period, absent a Personal Data Breach affecting Customer or a demonstrated material non-compliance; (c) conduct during normal business hours, in a manner that does not unreasonably disrupt echowin's operations, and limited in scope to information and systems relevant to the Processing of Customer Personal Data (excluding data of other customers and echowin's proprietary or privileged information); and (d) Customer bears its own costs and reimburses echowin for its reasonable time and expenses, except where the audit reveals material non-compliance by echowin with this DPA. The parties will agree in advance on the scope, timing, and duration of the audit, and Customer will promptly provide echowin with a copy of any audit findings, which constitute the Confidential Information of both parties.
9.3 Notification of Non-Compliance. echowin will inform Customer without undue delay if echowin determines that it can no longer meet its obligations under this DPA, in which case Customer may take the steps described in Section 4(iii).
10.1 Processing Locations. Customer authorizes echowin and its Subprocessors to Process Customer Personal Data in the United States and in the other locations identified in the Subprocessor List, subject to this Section 10.
10.2 EU Restricted Transfers. To the extent that any transfer of Customer Personal Data from Customer to echowin is an EU Restricted Transfer, the SCCs are hereby incorporated into this DPA and apply as follows: (a) Module Two (controller-to-processor) applies where Customer is a Controller, and Module Three (processor-to-processor) applies where Customer is a Processor; (b) in Clause 7, the optional docking clause applies; (c) in Clause 9, Option 2 (general written authorisation) applies, and the time period for prior notice of Subprocessor changes is as set out in Section 6.2 of this DPA; (d) in Clause 11, the optional language does not apply; (e) in Clauses 17 and 18, the governing law and forum are those of Ireland; (f) Annexes I, II, and III to the SCCs are deemed completed with the information set out in Annexes 1, 2, and 3 to this DPA, respectively, with Customer as "data exporter" and echowin as "data importer"; and (g) audits under Clause 8.9 and 13(b) of the SCCs will be conducted in accordance with Section 9 of this DPA to the maximum extent permissible under the SCCs.
10.3 UK and Swiss Restricted Transfers. To the extent that any such transfer is a UK Restricted Transfer, the SCCs as incorporated under Section 10.2 apply as amended by the UK Addendum, which is hereby incorporated into this DPA, with Tables 1 to 3 of the UK Addendum deemed completed with the information in this DPA and its Annexes, and with neither party being able to terminate the UK Addendum under Section 19 of the UK Addendum. To the extent that any such transfer is a Swiss Restricted Transfer, the SCCs as incorporated under Section 10.2 apply with the following modifications: references to the GDPR are to be understood as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the governing law and forum are as set forth in Section 10.2(e); and the term "Member State" must not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence.
10.4 Alternative Transfer Mechanisms. If echowin adopts an alternative lawful data transfer mechanism recognized under Applicable Data Protection Laws (such as certification under an adequacy framework), such mechanism will apply in place of the SCCs to the extent it covers the relevant transfer, and Customer agrees to execute such documents and take such actions as reasonably necessary to give effect to it. If any transfer mechanism relied upon under this Section 10 is invalidated or superseded, the parties will cooperate in good faith to promptly implement a lawful replacement mechanism.
Upon termination or expiration of the Agreement, echowin will, at Customer's election made in writing within thirty (30) days after termination or expiration, delete or return to Customer all Customer Personal Data (including copies) in echowin's possession or control, and delete existing copies, unless and to the extent that applicable law requires storage of the Customer Personal Data, in which case echowin will isolate and protect such retained data from further Processing except as required by such law, and will delete it when the legal retention requirement expires. If Customer does not make an election within such thirty (30) day period, echowin may proceed to delete Customer Personal Data in accordance with its standard data retention schedules. During the Term, Customer may retrieve and delete Customer Personal Data using the self-service functionality of the echowin Service. Deletion under this Section will be carried out in accordance with echowin's deletion practices described in Annex 2, and, upon Customer's written request, echowin will confirm deletion in writing. This Section does not require deletion of De-identified or aggregated data or of backup archives, provided that backup archives are deleted or overwritten in the ordinary course pursuant to echowin's standard backup rotation schedule and are protected by the Security Measures until deleted.
Each party's and its affiliates' total, aggregate liability arising out of or relating to this DPA (including the SCCs, to the maximum extent permitted by the SCCs and Applicable Data Protection Laws), whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the Agreement, and any reference in such provisions to the liability of a party means the aggregate liability of that party and its affiliates under the Agreement and this DPA together. Nothing in this DPA or the Agreement limits any party's liability with respect to a Data Subject's data protection rights under the SCCs where the SCCs apply and prohibit such limitation, or any liability that cannot be limited under applicable law.
This DPA is governed by the governing law of the Agreement, and any Dispute arising from or relating to this DPA will be resolved in accordance with the dispute resolution provisions of the Agreement, in each case except to the extent Applicable Data Protection Laws or the SCCs require otherwise. echowin may update this DPA from time to time in accordance with the modification provisions of the Agreement, provided that no update will materially diminish the protections for Customer Personal Data under this DPA during the then-current subscription period. If any provision of this DPA is held invalid or unenforceable, the remainder of this DPA will remain in full force and effect, and the invalid or unenforceable provision will be deemed modified so that it is valid and enforceable to the maximum extent permitted by law. The obligations of this DPA survive for as long as echowin Processes Customer Personal Data.
A. List of Parties. Data exporter: Customer (contact details as provided in Customer's account); activities: use of the echowin Service to automate customer communications; role: Controller (or Processor on behalf of a third-party Controller). Data importer: echowin, Inc., 110 Sugar Beet Circle, Longmont, CO 80501, privacy contact email: privacy@echo.win; activities: provision of the echowin Service; role: Processor.
B. Categories of Data Subjects. Contacts (including Customer's customers, prospective customers, callers, and other individuals who communicate with Customer through the echowin Service); Customer's Authorized Users, employees, and other personnel whose Personal Data is contained in Subscriber Data.
C. Categories of Personal Data. Identification and contact data (e.g., name, phone number, email address); voice recordings of calls and other interactions; call metadata (e.g., caller ID, phone numbers, date, time, and duration); transcripts, chat logs, messages, and AI-generated summaries or extractions of interactions; appointment, inquiry, order, and workflow information provided by Data Subjects during interactions; account and configuration data of Authorized Users; and any other Personal Data contained in Subscriber Data submitted to the echowin Service by or on behalf of Customer or by Contacts, or imported via Customer-enabled integrations.
D. Sensitive Data. None. The echowin Service is not designed to Process Sensitive Data, and Customer is contractually prohibited from submitting Sensitive Data (see Section 2.2 of this DPA and the Agreement), except PHI to the extent expressly permitted under a separately executed Business Associate Agreement.
E. Frequency of the Transfer. Continuous, for the duration of the Agreement, as determined by Customer's and Contacts' use of the echowin Service.
F. Nature and Purpose of the Processing. Collection, recording, storage, transcription, analysis (including Processing by Artificial Intelligence models), organization, disclosure to Customer and Customer-designated recipients and integrations, and deletion of Customer Personal Data, in each case for the purposes of providing, maintaining, securing, and supporting the echowin Service (including AI-powered voice agents, chatbots, notifications, and workflow automation) in accordance with the Agreement and Customer's documented instructions.
G. Duration of Processing; Retention. For the duration of the Agreement and until deletion or return of Customer Personal Data in accordance with Section 11 of this DPA.
H. Transfers to Subprocessors. Subject matter, nature, and duration of Processing by Subprocessors are as described in the Subprocessor List identified in Annex 3.
I. Competent Supervisory Authority (where the SCCs apply). The supervisory authority determined in accordance with Clause 13 of the SCCs; where the data exporter is not established in the EEA, the supervisory authority of Ireland unless another authority applies under Clause 13.
echowin implements and maintains the following technical and organizational measures, which it may enhance or update from time to time in accordance with Section 5.1 of this DPA:
1. Governance and Personnel. A designated individual or team responsible for security and privacy; documented information security policies reviewed at least annually; security and privacy training for personnel at onboarding and periodically thereafter; written confidentiality obligations for all personnel with access to Customer Personal Data; background checks for relevant personnel to the extent permitted by law.
2. Access Control. Role-based access to Customer Personal Data on a least-privilege and need-to-know basis; unique user IDs; multi-factor authentication for administrative and production access; prompt revocation of access upon role change or termination; periodic access reviews; logging and monitoring of access to production systems.
3. Encryption. Encryption of Customer Personal Data in transit over public networks using TLS 1.2 or higher; encryption of Customer Personal Data at rest using industry-standard algorithms (e.g., AES-256); documented key management procedures.
4. Network, Application, and Infrastructure Security. Hosting with reputable cloud infrastructure providers maintaining recognized certifications (e.g., SOC 2, ISO/IEC 27001); network segmentation and firewalling; hardening and patch management processes; vulnerability scanning and remediation on a risk-prioritized basis; periodic penetration testing by qualified internal or external testers; secure software development practices, including code review and separation of production and non-production environments (with no Customer Personal Data used in non-production environments except as protected equivalently).
5. Resilience, Backup, and Recovery. Redundancy and availability measures appropriate to the echowin Service; routine backups of production data with encryption and access controls; documented backup rotation and deletion schedules; disaster recovery and business continuity procedures tested periodically.
6. Incident Management. A documented security incident response plan covering detection, escalation, containment, investigation, remediation, and notification (including the notification obligations in Section 8 of this DPA); post-incident reviews and corrective actions.
7. Data Lifecycle Controls. Logical separation of Customer Personal Data from other customers' data; data minimization and retention controls, including configurable retention and deletion functionality where made available in the echowin Service; secure deletion procedures for Customer Personal Data and decommissioned media.
8. Subprocessor Management. Risk-based due diligence of Subprocessors before engagement; written contracts consistent with Section 6.3 of this DPA; periodic reassessment of Subprocessors' security posture.
9. Physical Security. Physical security of data center facilities is maintained by echowin's cloud infrastructure providers and includes controlled access, surveillance, and environmental protections; echowin maintains appropriate physical and device security measures for its own offices and endpoints, including device encryption and remote-wipe capability.
10. Assistance Measures. The measures described in Sections 7 (Data Subject Requests; Assistance) and 8 (Personal Data Breach) of this DPA constitute the specific technical and organizational measures by which the data importer will provide assistance to the data exporter for purposes of Annex II of the SCCs.
echowin's current list of authorized Subprocessors, including each Subprocessor's name, location, and a description of its Processing activities, is available at: https://echo.win/subprocessors. Customer may subscribe at that page to receive notifications of changes to the Subprocessor List. As of the date of this DPA, the Subprocessor List includes, without limitation, providers in the following categories: cloud hosting, edge computing, and infrastructure; telephony and communications (voice, SMS); speech-to-text / transcription; text-to-speech / voice synthesis; large language model and other Artificial Intelligence inference services (including model routing services); email and notification delivery; internal operational alerting; product analytics and error monitoring; and customer support tooling.