Privacy Policy

How we collect, use, and protect your data.

Last updated: August 2026

1. Introduction

Echo ("we", "us", "the Service"), operated by Frank Business Insights, is committed to protecting your privacy. This Privacy Policy explains how we collect, process, and protect your personal data in accordance with the Swiss Federal Act on Data Protection (nFADP / revDSG).

2. Data We Collect

We collect data necessary to provide the Service, categorized as follows:

  • Account Data: Name, email address, password hash, and account type (individual or organization).
  • Communication Data: The content of your letters and the recipient's physical address.
  • Financial Data: Billing information and transaction history.
  • Waitlist Data: Email address, language preference, and signup timestamp.
  • Usage Data: We may track basic usage patterns internally to improve the Service (e.g., login frequency, feature usage). We do not use third-party advertising or behavioral analytics tools.
  • Technical and Diagnostic Data: When the Service encounters errors or security events (e.g., Content Security Policy violations), we may collect technical information such as browser type, operating system, page URL, timestamps, and approximate connection metadata (which may include IP address). We configure our monitoring so that letter content and recipient addresses are not intentionally transmitted.
  • Release by someone you trust (Echo-5): If you use optional release by someone you trust, we also process a hashed release code for your account, timestamps and status of release attempts and cancellations, and metadata for letters waiting for release (for example dispatch options you selected).

3. Data Processing & Encryption

  • Encryption at Rest: Your letter content and recipient addresses are stored using AES-256 server-side encryption.
  • "Sealed" letters and letters ready for release: Once a letter is finalized (scheduled send) or held ready for release, its content is encrypted. Decryption occurs automatically and only for the duration required to generate the print file for our printing partner.
  • Access: We do not proactively monitor or read the content of your letters.

4. Third-Party Data Processors

To provide our Service, we work with specialized service providers (sub-processors). They process data solely on our behalf and in accordance with our instructions.

Our sub-processors:

ProviderFunctionLocation
Infomaniak Network SAHosting & infrastructureSwitzerland
Pingen GmbHPrinting & mailingSwitzerland
Swiss PostPhysical deliverySwitzerland
Payrexx AGPayment processingSwitzerland
Functional Software, Inc. (Sentry)Error monitoringEU

Detailed information on the data processed and the safeguards in place is available on our sub-processors page: startecho.ch/en/legal/sub-processors

We ensure that all sub-processors provide sufficient guarantees of data security. For transfers to third countries (e.g. the USA), we rely on the Swiss-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).

5. Data Retention & Deletion

  • Letter Content: The digital content of your letter and the recipient’s address are permanently deleted from our active database 30 days after the letter has been handed over to Swiss Post.
  • Letters ready for release: Until release and dispatch (or removal under the Terms), content and addresses of letters waiting for release are retained for the planning window applicable to that letter. After handover to Swiss Post, the 30-day deletion rule above applies.
  • Financial Records: Transaction data and invoices are retained for 10 years to comply with Swiss accounting law (Art. 958f CO).
  • Account Data: Retained as long as your account is active.
  • Waitlist Data: Retained until the Service launches or you request deletion.
  • Diagnostic Data: Retained by Sentry according to our project settings (typically up to 90 days), then deleted or anonymized.

6. Data Security

We employ technical and organizational measures to protect your data against unauthorized access, loss, or destruction. This includes the use of SSL/TLS encryption for all data transmission and AES-256 for storage. Our infrastructure is located in Switzerland (Infomaniak).

7. Your Rights

Under the revDSG, you have the following rights regarding your personal data:

  • Right to Information: To know what data we store about you.
  • Right to Rectification: To correct inaccurate data.
  • Right to Deletion: To request the deletion of your data (subject to statutory retention periods).
  • Right to Data Portability: To receive your data in a structured, commonly used format.

To exercise these rights, please contact us at hello@startecho.ch. To protect your privacy, we may require you to provide proof of your identity before processing your request.

8. Cookies

We use only essential cookies necessary for the technical operation of the platform (e.g., for authentication and session management). We do not use tracking or advertising cookies.

9. Data Breach

In the event of a data breach that poses a high risk to your personality or fundamental rights, we will notify you and the Federal Data Protection and Information Commissioner (FDPIC) as required by law.

10. Changes to this Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date.

11. Special provisions for organization accounts (B2B)

The following provisions apply exclusively when Echo is used by an organization (for example a seller, employer, or coach) as a benefit for third parties (for example customers, employees, or clients). In that case, specific data-protection roles and processing purposes arise that differ from purely private use.

11.1 Categories of data processed

In addition to the general data described above, we process the following data in the context of organization accounts:

  • Organization data: Company name, UID/VAT number, billing address, name and email address of the administrative contact, selected package (Free, Premium, Pro), letter quotas, and voucher codes.
  • Recipient data entered by the organization admin: Name of the beneficiary, desired delivery date, and optionally the content of a cover letter (Pro package only). The recipient’s postal address is not collected by the organization.
  • Data entered by the recipient: The postal delivery address and the private letter content. These data are entered exclusively by the recipient and are not visible to the organization.

11.2 Data minimization and organization visibility

We process data strictly according to the principle of data minimization. Through its dashboard, the organization can see only:

  • The recipient’s name
  • The letter status (for example “voucher not redeemed”, “scheduled”, “delivered”)
  • The delivery date chosen by the organization

The private letter content and the recipient’s postal address are never visible to the organization. The private letter content is stored encrypted and decrypted only for the duration of the printing process. The organization has no access to recipient addresses stored with third parties (printing partner, postal service).

11.3 Cover letter (Pro package)

If the organization writes a cover letter, it is stored as separate organization content and enclosed with the physical envelope at printing. The cover letter is not private communication by the recipient; it is a message from the organization.

11.4 Data processing on behalf and organization responsibility

Where an organization uses Echo as a benefit for third parties, Echo processes organization and recipient metadata as a processor under Art. 9 nFADP on behalf of the organization. The organization remains the controller responsible for the lawfulness of collecting and disclosing that data.

  • Data Processing Agreement (AVV): With every organization that uses a package, we conclude a Data Processing Agreement (AVV). It covers technical and organizational measures (TOMs), the rights of data subjects, and how data is handled at the end of the contract.

11.5 Retention and deletion for organization accounts

  • Statutory retention: Financial data, invoices, and contractual documents of the organization are retained for 10 years in accordance with statutory retention periods (Art. 958f CO).
  • Deletion on request: Operational organization data (such as dashboard credentials, configurations, recipient metadata, and unredeemed vouchers) is not deleted automatically after termination or cancellation of the subscription. That data remains in the system and can be fully deleted at the organization’s express request, provided no statutory retention obligations or legitimate business interests (for example defending legal claims) require otherwise.
  • Cover letter content: Cover letters written by the organization are deleted from the active system 30 days after the envelope is handed over to Swiss Post.

11.6 Rights of recipients in the context of organization accounts

If you received an Echo letter through an organization and have questions about how that organization processes your metadata (name, status), please contact the organization first as the controller. For questions about technical processing by Echo (for example deletion of your address or letter content), contact us directly at hello@startecho.ch. You have the right to request deletion of your data; in that case, the scheduled Echo letter can no longer be delivered.

Echo. The time capsule by letter.

Ready to start?

Create your account and send your first letter to the future.