Effective: 11 September 2026
Last updated: 11 September 2026
This notice applies to the EchoFlo software platform (the “Platform“, app.echoflo.ai), operated by Echo Collective Pte. Ltd. (UEN 202321542W) (“EchoFlo“, “we“).
It does not cover the echoflo.io website, which has its own privacy policy.
1. Two different roles, and why the difference matters
EchoFlo handles personal data in two distinct ways, and your rights differ depending on which applies.
(a) Data we hold for a business customer. When a business uses the Platform, it decides what to put in: its own staff records, its customers’ contact details, its suppliers’ invoices, its message history. For that data the business is the organisation responsible under the Personal Data Protection Act 2012, and we act as its data intermediary, processing on its instructions.
If you are an employee or a customer of a business that uses EchoFlo, and you want your data corrected or deleted, ask that business. We will help them, but we cannot act on your data without their instruction.
(b) Data we hold for ourselves. We also decide, on our own account, what to do with the details of the businesses that buy EchoFlo: the account holder’s name and work contact details, billing records, and support conversations. For that data we are the responsible organisation, and Section 9 covers it.
2. What the Platform processes for a business customer
Depending on which parts a business uses:
- Staff and payroll: names, contact details, job details, salary, bank account details, NRIC or FIN, date of birth, residency status, CPF and statutory contributions, leave and attendance.
- Customers, suppliers and contacts: names, contact details, addresses, company details, notes and history.
- Finance: invoices, bills, payments, expenses, GST records and accounting entries, which routinely contain personal data about individuals.
- Messages: conversations from channels a business connects, including WhatsApp Business, Instagram, Facebook, TikTok, Gmail and Outlook.
- Documents: files uploaded or imported, and the data extracted from them.
- Usage records: who did what in the Platform and when, which we keep as an audit trail.
3. Why we process it
Only to provide the Platform to the business, to support them, to keep the Platform secure and working, and to meet our legal obligations. We process on the business’s instructions and for no separate purpose of our own.
4. What we do not do
- We do not sell personal data.
- We do not use one business’s data to serve another business.
- We do not use Platform personal data to train or fine-tune AI models, and our AI providers are engaged on terms that do not permit them to train on it either.
- We do not disclose personal data to anyone other than the recipients in Section 7, unless the business tells us to, or the law requires it.
5. Security
Encryption. Sensitive structured personal data, including NRIC and bank account details, is encrypted at rest using AES-256-GCM. Encryption keys are held and managed by EchoFlo at the platform level. Data in transit is encrypted using TLS.
Separation between businesses. Each business is a separate tenant, and separation is enforced in the database itself using row-level security, so one business’s queries cannot return another business’s rows.
Access. Access to production systems is limited to personnel who need it. Actions in the Platform are recorded in an audit trail.
6. Where the data is, and where it goes
Storage and hosting are in Singapore. The Platform runs on DigitalOcean’s Singapore region (SGP1), files are stored in DigitalOcean Spaces in Singapore, and the database is Supabase in ap-southeast-1, Singapore.
Some AI processing happens outside Singapore. Where a business uses AI features, the relevant content is sent to an AI provider to be processed and returned. It is not retained by us outside Singapore, and it is not used to train their models, but the processing itself may occur outside Singapore:
| AI provider | Where it processes | Typically used for |
|---|---|---|
| Anthropic (Claude) | United States | Summarising conversations, drafting replies, reasoning tasks |
| OpenAI | United States | Fallback for the same tasks |
| Google Cloud (Vertex AI) | Singapore, asia-southeast1 | Reading images and scanned documents |
A business that does not want content processed outside Singapore should not enable the AI features that rely on the providers above.
7. Who else processes the data
| Recipient | What they do | Where |
|---|---|---|
| DigitalOcean, LLC | Runs the Platform, and stores uploaded files | Singapore (SGP1) |
| Supabase | Database and sign-in | Singapore (ap-southeast-1) |
| Anthropic, PBC | AI processing | United States |
| OpenAI, L.L.C. | AI processing, fallback | United States |
| Google Cloud (Vertex AI) | AI processing of images and documents | Singapore |
| DigitalOcean, LLC | Runs our self-hosted Hatchet job engine on our own droplet, and the database holding its run history | Singapore (SGP1) |
| Resend, Inc. | Sends transactional email such as invites and alerts | United States |
| Meta Platforms | WhatsApp Business, Instagram and Facebook messaging | Per Meta’s terms |
| TikTok | TikTok messaging | Per TikTok’s terms |
| Google LLC / Microsoft Corporation | Gmail and Outlook mailbox access | Per their terms |
Channel providers, in the last three rows, are connected by the business itself and process data under their own terms with that business.
We publish this list and will update it. Business customers are told before a new recipient is added.
8. Google Workspace access (Gmail, Drive, Calendar and Chat)
A business can connect its Google account so the Platform can work with the mailbox, files and calendar it already uses. This section describes that connection specifically, because Google requires it and because it is the most sensitive access the Platform asks for.
Who grants it, and how it is withdrawn. An authorised user of the business grants access through Google’s own consent screen. Nobody at Echo Collective can grant it on their behalf. It can be withdrawn at any time from the Google Account at myaccount.google.com/permissions, or by disconnecting the integration inside EchoFlo. Withdrawal stops all further access immediately; data already brought into the Platform is handled under Section 10.
What we ask for, and why.
| Access requested | What the Platform uses it for |
|---|---|
gmail.modify, gmail.compose | Reading the connected mailbox to surface and thread customer conversations, and drafting or sending replies the user asks for |
drive, drive.readonly, drive.file | Importing documents the user selects, and attaching Platform-generated documents back to Drive |
calendar.events, calendar.readonly | Reading availability and creating or updating events the user asks for |
chat.messages, chat.spaces.readonly, chat.memberships.readonly, chat.messages.reactions | Reading and posting in Google Chat spaces the business connects |
analytics.readonly | Reading marketing performance figures for reporting |
We ask only for what a connected feature actually uses. A business that does not connect Google grants none of this.
Limited Use. EchoFlo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, and without qualification:
- We do not use Google user data for advertising, and we do not serve advertising at all.
- We do not sell Google user data, and we do not transfer it to others except as needed to provide or improve the features the user connected, to comply with law, or as part of a merger or acquisition with notice.
- We do not use Google user data to train or fine-tune AI models, our own or anyone else’s. This is the same commitment made in Section 4 and it applies to Google data without exception.
- No person at Echo Collective reads Google user data, except where the user has given explicit consent for specific messages, where it is necessary for security purposes such as investigating abuse, where the law requires it, or where the data has been aggregated and made anonymous.
Where Google data goes. It is stored in Singapore on the same infrastructure described in Section 6. Where a connected feature uses AI — summarising a thread, drafting a reply — the relevant content may be processed by the AI providers named in Section 7, two of which are in the United States. A business that does not want mailbox content leaving Singapore should not connect Gmail.
Deletion. Disconnecting the integration stops access at once. Google data already held in the Platform is deleted on the schedule in Section 10, and a business can ask for it to be deleted sooner.
9. Data we hold as the responsible organisation
For the businesses that buy EchoFlo, we hold and decide the use of:
- Account details: the name, work email, and role of the people who administer the account.
- Billing: subscription, invoices and payment records.
- Support: messages sent to us, and the correspondence that follows.
- Product usage: how the Platform is used, so we can support it and improve it. We use aggregated and anonymised usage information for that purpose.
We keep this while the account is active, and afterwards only as long as we need it for legal, tax and accounting purposes.
To ask about this data, contact our Data Protection Officer in Section 11.
10. Retention and deletion
- While a business is a customer, its data is retained so the Platform works.
- Deleted records go to a recoverable area for 30 days before permanent deletion, so an accidental deletion can be undone.
- After the agreement ends, we delete the business’s data within 30 days of its written request, or within 90 days of termination if no request is made, except where law requires us to keep something.
- Backups are deleted on their ordinary cycle.
11. Your rights, and how to reach us
Under the PDPA you may ask for access to your personal data, and for correction of it.
- If your data is on the Platform because a business put it there, ask that business. We will support them in responding.
- If it is data we hold as described in Section 9, contact us directly.
Data Protection Officer Echo Collective Pte. Ltd. 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051 dpo@echocollective.ai
We respond within 30 days.
12. Breaches
If personal data is compromised, we notify the affected business without undue delay and within 24 hours of confirming it, with what they need to meet their own obligations. Where the law requires notification to the PDPC or to individuals, we support the business in making it, and we notify the PDPC ourselves where the duty is ours.
13. Changes
We may update this notice. Material changes are notified to business customers at least 30 days before they take effect, and each version carries its date.
14. Governing law
This notice is governed by the laws of Singapore.
| # | Published notice said | Reality | Change |
|---|---|---|---|
| 1 | “AES-256-GCM with per-tenant keys“ | One platform key. Per-tenant keys are an unbuilt Phase 2 | Claim corrected; row-level separation described instead |
| 2 | Sub-processors: Meta, TikTok, Google/Microsoft, DigitalOcean | Also Supabase, Anthropic, OpenAI, Google Vertex, Hatchet, Resend | List completed |
| 3 | “we do not move Platform personal data offshore in the ordinary course“ | Claude and OpenAI process in the US, routinely | Replaced with what is true, per provider |
| 4 | “Data Processor, Not Controller“ only | EchoFlo also controls account, billing and support data | New Section 9 |
| 5 | (not stated) | An internal doc claimed 48-hour raw file deletion | Not claimed, because it is not in the code |