Privacy Policy
To Echo ApS Last updated: 6 September 20261. General
1.1 This Privacy Policy applies to the personal data that To Echo ApS collects and processes when you use the Ekko app, available at ekkoapp.app, and related services. “Personal Data” means any information relating to an identified or identifiable natural person. 1.2 This Privacy Policy describes processing activities for which To Echo ApS acts as data controller. Where we process personal data on behalf of an organisation that uses Ekko app, such organisation may be the data controller, and our processing will be governed by our agreement with that organisation. 1.3 This Privacy Policy is intended to provide information to users of the Ekko app and related services, including where required in connection with the publication and operation of the app through app stores.2. Identity of the Data Controller
2.1 If there are any questions regarding this Privacy Policy, you may contact us using the information below.To Echo ApS2.2 We process your personal data in accordance with the General Data Protection Regulation (GDPR) and any national regulations applicable to us.
Reg. no.: 37697796
C/O Ekko App
Mileparken 22
2740 Skovlunde
Denmark
support@toecho.dk
+45 71 72 74 10
3. Purpose of Processing
3.1 We collect the following non-sensitive personal data about you when you create an account, use our app or related services, contact us, or participate in customer satisfaction surveys:- First and last name
- Date of birth
- Address (street, postal code and city)
- Phone number
- Country
- Usage and device data (e.g. IP address, device identifiers, in-app activity and diagnostics)
- Customer satisfaction (CSAT) survey responses
- Account and profile information
- Technical information, including app version, device type, operating system, crash logs and diagnostic information
- Support and communication information if you contact us
- (i) Creating and managing user accounts: Article 6(1)(b) GDPR, where processing is necessary to provide the app or related services requested by you, or Article 6(1)(f) GDPR, where you use the app through an organisation and our legitimate interest is to provide and administer the app and related services.
- (ii) Providing, operating, maintaining and improving the app and related services: Article 6(1)(f) GDPR, based on our legitimate interest in operating, maintaining, developing and improving our app and related services.
- (iii) Customer support and responding to requests: Article 6(1)(b) GDPR where the request relates to services provided to you, or Article 6(1)(f) GDPR based on our legitimate interest in responding to enquiries and providing support.
- (iv) Service communications, including updates, security notices and relevant push notifications: Article 6(1)(b) GDPR or Article 6(1)(f) GDPR, depending on the nature of the communication.
- (v) Usage analytics, diagnostics, troubleshooting and security: Article 6(1)(f) GDPR, based on our legitimate interest in understanding how the app is used, identifying and fixing errors, maintaining security and improving the app. Where required by applicable law, we will obtain your consent before using non-essential analytics, software development kits or similar technologies.
- (vi) Customer satisfaction (CSAT) surveys: Article 6(1)(a) GDPR, where you have consented to participate in the survey. Where we process limited feedback or support-related information without consent, we rely on Article 6(1)(f) GDPR based on our legitimate interest in receiving feedback and improving our services.
- (vii) Compliance with legal obligations: Article 6(1)(c) GDPR.
4. Transfer of Personal Data
4.1 We may share or transfer your personal data to a country or territory outside the EU/EEA. 4.2 If we transfer personal data outside the EU/EEA, we will ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, the European Commission’s standard contractual clauses or another lawful transfer basis, together with any supplementary measures required under applicable data protection law. 4.3 We may share personal data with third parties where necessary for the purposes described in this Privacy Policy, where required by law, or where we otherwise have a lawful basis for doing so. 4.4 We may share personal data with service providers and data processors that assist us with hosting, infrastructure, analytics, crash reporting, customer support, surveys, push notifications and similar services. Such service providers may only process personal data on our behalf and in accordance with our instructions, unless otherwise required by law.5. Profiling and Automated Decision Making
5.1 Our processing activities do not include profiling or automated decision-making that produces legal effects concerning you or similarly significantly affects you.6. Business Transfers
6.1 In connection with an actual or contemplated merger, acquisition, financing, reorganisation, sale of assets, bankruptcy or similar transaction, we may disclose personal data to relevant parties and their advisers for due diligence and transaction purposes. Such disclosure will be subject to appropriate confidentiality and data protection safeguards.7. Use of Personal Data
7.1 We only process your personal data as stated in this Privacy Policy and we do not use your personal data for any other purpose than explicitly described above or communicated directly to you elsewhere. 7.2 We process your personal data in a lawful, fair and transparent manner. The data we collect is solely used for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. 7.3 All use of your personal data is relevant and limited to what is necessary in relation to the purposes for which they are processed.8. Security
8.1 When we store and process personal data that we have received from you, we take appropriate steps to store and process it securely. We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Although no method of transmission or storage is completely secure, we continuously work to protect personal data in accordance with applicable data protection law. 8.2 The following security measures are in place to keep your data safe:- Encryption
- Pseudonymization or Anonymization, where relevant
- Use of service providers holding relevant ISO certificates, where applicable
- Firewalls & anti-virus
- Internal policies & password protection
9. Access to Your Information
9.1 Right to accessGDPR Article 15: You have the right to obtain confirmation from us as to whether personal data concerning you are being processed, including information on the purposes of processing, categories of personal data, recipients or categories of recipients, and the envisaged storage period. 9.2 Right to rectification
GDPR Article 16: If you find that the data that is being processed about you is inaccurate or incomplete, you have the right to get that data rectified. We will communicate any rectification or erasure of personal data to any recipient to whom the personal data has been originally disclosed, unless it proves impossible according to Article 19. 9.3 Right to erasure and restriction of processing
GDPR Article 17: You also have the right to get your personal data erased, if the personal data is no longer necessary in relation to the purposes for which they were collected or otherwise processed. If you have created an account in the app, you may request deletion of your account and associated personal data by contacting us at support@toecho.dk, with a copy to jens@ekkoapp.dk or by using the deletion functionality made available in the app, if applicable. We may retain certain information where required or permitted by law, including for legal compliance, dispute resolution and security purposes. 9.4 Right to restriction of processing
GDPR Article 18: You have the right to restrict the processing of your personal data if it is (i) inaccurate; (ii) unlawful; (iii) we no longer need the personal data, but you require it for legal claims; or (iv) you have objected to the processing according to Article 21. 9.5 Right to data portability
GDPR Article 20: You have the right to receive the personal data concerning you which you have provided to us, in a structured, commonly used, and machine-readable format. You can also request that we transmit your data to another party. 9.6 Right to object
GDPR Article 21: You have the right to object to the processing of your personal data where the processing is based on our legitimate interests. You also have the right to object at any time to processing of your personal data for direct marketing purposes, including profiling related to such direct marketing.
10. Cookies, Software Development Kits and Similar Technologies
10.1 We and our service providers may use cookies, software development kits, analytics tools, crash reporting tools, device identifiers and similar technologies to operate the app, remember preferences, analyse usage, troubleshoot, maintain security and improve the services. Where required by law, we will obtain your consent before using non-essential cookies or similar technologies. 10.2 Our use of analytics tools and similar technologies may involve the collection of usage and device data, such as feature interactions, navigation patterns, device identifiers, IP address, app version, operating system, diagnostic data and crash logs. 10.3 We may share personal data with service providers that assist us with hosting, infrastructure, analytics, crash reporting, customer support, surveys, push notifications and similar services. Such service providers may only process personal data on our behalf and in accordance with our instructions, unless otherwise required by law. 10.4 You can change your consent preferences for non-essential analytics (including customer satisfaction (CSAT) surveys) and similar technologies under your profile page or other relevant settings in the app, where available.11. Sub-processors
11.1 We use service providers and data processors to deliver, operate, secure and improve the app and related services. These may include providers of hosting, infrastructure, analytics, crash reporting, customer support, surveys, push notifications and similar services. 11.2 Where such service providers process personal data on our behalf, they may only process personal data in accordance with our instructions, unless otherwise required by law. We enter into data processing agreements with our data processors where required by applicable data protection law. 11.3 You may contact us using the contact details in section 13 if you would like more information about the service providers and data processors involved in the processing of your personal data. 11.4 Some of our service providers and data processors may be located outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we ensure that an appropriate transfer mechanism is in place, as described in section 4 above.12. Children’s Privacy
12.1 Our app and related services are not directed at children under the age of 13, and we do not knowingly collect personal data from children under the age of 13. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will take steps to delete such information.13. Contact Information, Requests & Complaints
13.1 If you want to exercise any of your above rights, please contact:To Echo ApS13.2 If you find that your personal data has been processed in a way that does not meet the requirements of the GDPR, and if you want to file a complaint, you have a specific right to lodge a complaint with the relevant supervisory authority. The supervisory authority will guide you through the process. See contact information below:
Reg. no.: 37697796
C/O Ekko App
Mileparken 22
2740 Skovlunde
Denmark
support@toecho.dk
+45 71 72 74 10
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
dt@datatilsynet.dk
+45 33 19 32 00