Skip to main content
Cavefish
Governance

EchoDepth Governance Framework

Responsible deployment of Emotional AI requires governance architecture as rigorous as the measurement itself.

Emotional AI that operates without governance is not just a regulatory risk — it is an ethical failure. Cavefish builds governance into every EchoDepth deployment: consent architecture, purpose limitation, data minimisation and audit trails as standard.

Purpose Limitation

Every EchoDepth deployment is scoped to a defined analytical purpose. Data is processed only for that purpose — not retained, repurposed or shared.

Consent Architecture

Explicit, informed consent is required from all data subjects before any analysis. Consent frameworks are deployment-specific, documented and auditable.

Data Subject Rights

EchoDepth deployments include documented mechanisms for data subjects to exercise their rights under UK GDPR — access, rectification, erasure and portability.

Third-Party Audit

Enterprise deployments can include third-party audit provisions. Cavefish supports full transparency in governance documentation and process review.

Equality Act Alignment

EchoDepth outputs are designed to augment human judgement — not replace it — particularly in sensitive HR, recruitment and assessment contexts.

Request Governance Documentation →

Common questions

What is EchoDepth's governance framework?

EchoDepth's governance framework is built on five principles: purpose limitation (data processed only for the agreed analytical scope), consent-first architecture (explicit informed consent from all data subjects), data subject rights (GDPR access, rectification, erasure), third-party audit support, and Equality Act alignment (outputs augment human judgement, not replace it).

Does EchoDepth comply with the Equality Act 2010?

Yes. EchoDepth is designed to augment human judgement — not replace it — particularly in HR, recruitment and assessment contexts. All outputs are presented as evidence to support qualified decision-makers, never as automated determinations. This aligns with Equality Act 2010 requirements in regulated deployment contexts.

Can EchoDepth be used in regulated financial services?

Yes. EchoDepth has been tested within the FCA Regulatory Sandbox. It includes governance documentation specifically designed for FCA Consumer Duty compliance, with timestamped vulnerability assessment evidence records and explicit consent architecture for customer interaction analysis.

Common questions

What is EchoDepth's governance framework?

EchoDepth's governance framework is built on five principles: purpose limitation, consent-first architecture, data subject rights (UK GDPR), third-party audit support, and Equality Act alignment. Outputs augment human judgement — they never replace it.

Does EchoDepth comply with the Equality Act 2010?

Yes. EchoDepth is designed to augment human judgement, not replace it, particularly in HR, recruitment and assessment contexts. All outputs are presented as evidence to support qualified decision-makers, not as automated determinations.

Can EchoDepth be used in FCA-regulated financial services?

Yes. EchoDepth has been tested within the FCA Regulatory Sandbox and includes governance documentation for FCA Consumer Duty compliance, with timestamped vulnerability assessment evidence records and explicit consent architecture.

RelatedSecurity & CompliancePrivacy PolicyAPI & DevelopersEchoDepth OverviewWorking With CavefishHow It WorksCompare EchoDepthGDPR & AI Analysis

How EchoDepth Governance Works in Practice

Every EchoDepth enterprise deployment operates under a documented governance framework. This is not a policy document — it is an architecture requirement. The governance framework is enforced at the DPA level, not the preference level.

Before deployment
Data Processing Agreement signed — covers purpose limitation, retention, sub-processor obligations, data subject rights
DPIA completed or in progress — Cavefish provides structured DPIA support inputs for all enterprise deployments
Consent architecture documented — explicit informed consent required from all data subjects before any analysis
Deployment scope defined in writing — purpose limitation is enforced, not assumed
During deployment
Raw biometric data is not retained after the analysis window closes — architectural, not policy
Outputs are structured evidence for human review — EchoDepth does not make automated decisions about individuals
Data subject rights mechanisms documented and accessible — access, rectification, erasure, portability
UK data residency by default — all processing within UK data centres. EU available on request. On-premise for air-gap environments

What EchoDepth Does Not Do — Equally Important

Make automated decisions about individuals — human review is a deployment condition, not a feature
Retain raw biometric data after the analysis window closes
Profile, score or psychologically assess individual data subjects without explicit consent
Operate outside the defined purpose in the Data Processing Agreement
Share outputs with parties not specified in the DPA

What is EchoDepth Governance Framework?