Privacy

Privacy is at the core of our platform's design. Protecting personal information is essential to the trusted human network we aim to build, so we are transparent about what we collect, why, and how it is used.

Best practices we hold ourselves to

We adhere to globally recognized data privacy standards, including frameworks such as the GDPR, so that all information is managed responsibly, securely, and in full compliance with applicable regulations.

  • Data minimization — we collect only the minimum information necessary to fulfill our described purposes, reducing exposure and risk.
  • Security by design — industry-standard measures, including Advanced Encryption Standard (AES) encryption for data both at rest and in transit, protect your information from unauthorized access.
  • Minimal third-party sharing — data is shared with third parties only where needed for core operations (for example AWS and Zoom).
  • User empowerment — you control your data, with clear rights to access, correct, or delete your personal information at any time.
  • Accountability — a dedicated Data Protection Officer (DPO) oversees compliance with privacy laws and policies. Reach our DPO at privacy@iecho.org.
  • Consent management — we collect only essential information during registration, and you may withdraw consent by deleting your account at any time. Once withdrawn, we stop processing your personal data, except for pre-existing program records such as attendance logs.
  • Cookie management — we use only essential cookies required for core platform functionality, and you can opt out of non-essential cookies at any time.

No patient data, by design

iECHO is not a medical record. The ECHO model's case discussions are de-identified by design, and the platform never requires protected health information.

Privacy features on the platform

  • Role-based access control — users only see and access data relevant to their role (Hub Admin, Hub Member, Participant, Subject Matter Expert).
  • Data anonymization in reports — personally identifiable information is masked or excluded where not necessary, so sensitive data is not exposed.
  • Secure authentication — each account is protected by a unique password known only to the account holder. All passwords are encrypted and never visible to the iECHO team.
  • Profile visibility settings — you manage your profile information and decide whether your profile is visible to others.
  • Program-level visibility — hubs configure whether their programs and participants are public or private.

For more information, read our Privacy Policy.

Reach our Data Protection Officer

For any privacy questions or concerns, or to exercise your data rights, write to our DPO at privacy@iecho.org.