Kreedl - Data Processing Agreement

EN · CZ

Effective date - 31 August 2026

Processor - KREEDL s.r.o., Záhřebská 562/41, Vinohrady, 120 00 Praha 2, Czech Republic, ID No. 24081370 ("Kreedl")

Controller - any customer using Kreedl's services ("Customer")

Contact - [email protected]

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service at kreedl.com/terms and of every agreement between Kreedl and a Customer. It applies automatically to every Customer from the moment Kreedl first processes personal data on the Customer's behalf. No signature is required. A countersigned copy is available on request at [email protected].

1. Definitions

"Personal Data", "Controller", "Processor", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means Personal Data that the Customer provides to Kreedl, makes accessible to Kreedl, or that Kreedl collects on the Customer's behalf in providing the services, including communication content, recordings and transcripts. "Subprocessor" means any third party engaged by Kreedl to process Customer Personal Data. "UK GDPR" means the GDPR as retained in UK law.

2. Roles

The Customer is the Controller of Customer Personal Data. Kreedl is the Processor. Kreedl acts as an independent Controller only for the Customer's own account, billing, usage and marketing data, as described in the Privacy Policy at kreedl.com/privacy.

3. Subject matter, nature, purpose, duration

Subject matter and purpose. Operating an AI assistant that communicates with tenants, residents, facility users, applicants, vendors and other persons on the Customer's behalf across phone, WhatsApp, SMS and email, and carries out the actions the Customer has authorised.

Nature of Processing. Receiving, recording, transcribing, storing, analysing and summarising communications; reading or storing Customer records according to the operating mode chosen by the Customer (section 4); booking appointments; dispatching vendors; and, where instructed, ranking applicants or summarising publicly available information about prospective tenants.

Categories of Data Subjects. Tenants, residents, prospective tenants, store managers and facility users, vendors and technicians, Customer's employees and representatives, and any other person contacting a building served by Kreedl.

Types of Personal Data. Name, contact details, building and unit, tenancy dates and conditions, rent and payment status, lease documents, fault reports, photos, voice notes, call recordings, transcripts, message content and metadata. Where the Customer instructs identity verification, the last four digits of a Czech national identification number may be compared against Customer records and are not stored in full. Kreedl does not process door codes or other physical access credentials.

Duration. For the term of the Customer's agreement and until deletion under section 12.

4. Operating modes and documented instructions

4.1 The Customer selects one of three operating modes described in the Privacy Policy. Mode A - no access to Customer records. Mode B - read access to the Customer's systems without storage of records. Mode C - Customer records stored by Kreedl. In every mode Kreedl stores communication content, recordings, transcripts and contact details of the persons communicating with it.

4.2 The Customer's documented instructions consist of the mode selected, the configuration agreed at onboarding, the settings the Customer makes in the Kreedl application, the data the Customer uploads or makes accessible, and any written instruction sent to [email protected]. Uploading data, activating a subscription, creating a profile, or otherwise providing data to Kreedl constitutes the Customer's instruction to process that data for the purposes of section 3.

4.3 The Customer may change its operating mode or instructions at any time by email, through the application, or by conduct that clearly indicates the change. Kreedl implements changes within 14 days.

4.4 Kreedl may refuse any instruction that in its reasonable opinion infringes the GDPR or other law, and will inform the Customer. Kreedl may also process Customer Personal Data where required by EU or Member State law, in which case it informs the Customer unless the law prohibits it.

5. Customer obligations

The Customer warrants and undertakes that -

  • it has a valid legal basis for all Customer Personal Data it provides to Kreedl and for every communication it instructs Kreedl to initiate;
  • it has informed Data Subjects in accordance with Articles 13 and 14 GDPR, including by publishing the tenant notice provided by Kreedl, and it alone bears this obligation;
  • where it instructs Kreedl to collect publicly available information about prospective tenants, it will inform those persons of the source of the data no later than at first contact;
  • where it provides Czech national identification numbers, it complies with Section 13c of Act No. 133/2000 Coll.;
  • it is responsible for the autonomy limits it sets and for reviewing escalations;
  • its instructions comply with applicable law.

6. Kreedl obligations

Kreedl will -

  • process Customer Personal Data only on the Customer's documented instructions and only for the purposes of section 3;
  • ensure that persons authorised to process Customer Personal Data are bound by confidentiality and non-disclosure agreements;
  • implement the technical and organisational measures in Annex 1;
  • not use Customer Personal Data to train or fine-tune any AI model;
  • assist the Customer with Data Subject requests (section 9), security, breach notification and data protection impact assessments (section 10), taking into account the nature of Processing;
  • delete or return Customer Personal Data as set out in section 12;
  • make available the information necessary to demonstrate compliance with Article 28 GDPR and allow audits as set out in section 11.

7. Subprocessors

7.1 The Customer gives Kreedl general authorisation to engage Subprocessors. The current list is set out in section 7 of the Privacy Policy at kreedl.com/privacy.

7.2 Kreedl notifies the Customer of any addition or replacement of a Subprocessor by email at least 14 days before the change takes effect.

7.3 If the Customer objects on reasonable data-protection grounds within 14 days of the notice, Kreedl may propose an alternative. If none is agreed, the Customer's sole remedy is to terminate the affected services by written notice, without penalty for the terminated part. Kreedl is not obliged to change Subprocessors.

7.4 Kreedl imposes on each Subprocessor data-protection obligations no less protective than those in this DPA and remains responsible for their performance.

8. International transfers

Kreedl stores Customer Personal Data in the European Union. AI processing and telephony may involve providers outside the EEA or the UK. For any such transfer Kreedl relies on the EU Standard Contractual Clauses, an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or, for UK data, the UK International Data Transfer Addendum. Kreedl offers an EU-only processing configuration on written request; the Customer is responsible for requesting it. The Customer authorises Kreedl to enter into Standard Contractual Clauses with Subprocessors on its behalf. A UK Addendum is available on request.

9. Data Subject requests

Where Kreedl receives a request from a Data Subject relating to Customer Personal Data, it forwards it to the Customer within 3 working days and does not respond on the merits unless instructed. Kreedl provides reasonable assistance so the Customer can respond within statutory deadlines. Assistance beyond five requests per month, or requiring more than reasonable effort, is charged at Kreedl's then-current hourly rate.

10. Personal Data Breach and DPIA

10.1 Kreedl notifies the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and no later than 48 hours after becoming aware of it. The initial notice contains what is known at the time. Kreedl provides the full information required by Article 33(3) GDPR within 14 days and in the meantime provides updates as facts are established.

10.2 The Customer is responsible for notifying Supervisory Authorities and Data Subjects. Kreedl assists on request.

10.3 Where the Customer must carry out a data protection impact assessment, Kreedl provides a description of the Processing, the measures in Annex 1 and reasonable further information. The Customer completes, approves and owns the assessment.

11. Audit

Once per calendar year, on 30 days' written notice, the Customer may request Kreedl's completed security questionnaire, a copy of Annex 1 and available documentation showing compliance with this DPA. An on-site inspection takes place only where required by a Supervisory Authority or by law, during business hours, subject to confidentiality, without access to other customers' data, and at the Customer's cost. Kreedl holds no ISO 27001 or SOC 2 certification and does not represent otherwise.

12. Return and deletion

On termination of the Customer's agreement, and on written request at any time, Kreedl exports Customer Personal Data in a structured machine-readable format (JSON, and audio files for recordings) and deletes Customer Personal Data within 30 days of termination. Encrypted backups are purged within 90 days. Kreedl confirms deletion in writing on request. Kreedl may retain data where required by law and only for that purpose.

13. Liability

13.1 To the fullest extent permitted by law, Kreedl's total liability arising out of or in connection with this DPA, including any regulatory fine or Data Subject claim, is limited to the fees paid by the Customer in the twelve months preceding the event giving rise to the claim, and Kreedl is not liable for indirect or consequential loss, loss of profit, loss of data or damage to reputation. Nothing limits liability that cannot be limited under the GDPR or Czech law.

13.2 Kreedl has no obligation to indemnify the Customer.

13.3 The Customer indemnifies Kreedl against any claim, fine, loss or cost (including reasonable legal fees) arising from the Customer's breach of this DPA or the GDPR, from an instruction given by the Customer, from data provided without a lawful basis or without required information to Data Subjects, or from the Customer's autonomy settings.

14. Term, governing law, language

This DPA applies for as long as Kreedl processes Customer Personal Data and survives termination of the Customer's agreement until deletion is complete. It is governed by the laws of the Czech Republic and disputes are decided by the competent courts in Prague. It is published in English and Czech; the English version prevails. Kreedl may update this DPA with 14 days' email notice to Customers; continued use after the effective date means acceptance.

Annex 1 - Technical and organisational measures

Encryption. Customer Personal Data is encrypted at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher). Call recordings and files are stored in encrypted object storage.

Access control. Role-based access. Only Kreedl staff who need access to operate the service have it. Multi-factor authentication is mandatory for all Kreedl staff and for all administrative access to infrastructure. Access is reviewed on staff changes and at least quarterly.

Logging and auditability. Every action of the AI assistant and every staff access to Customer Personal Data is logged with timestamp and identity. Logs are retained for 12 months and available to the Customer for its own data.

Secrets management. Provider credentials and API keys are stored in a secrets manager, never in code or exposed to users, and rotated on staff departure or suspected compromise.

Tenant isolation. Each Customer's data is logically segregated. No Customer can access another Customer's data.

Backups. Encrypted backups at least daily, retained 90 days, restore tested at least annually.

AI model providers. Model providers are contractually prohibited from using Customer Personal Data for training. Kreedl does not train or fine-tune models on Customer Personal Data.

Personnel. All staff and contractors sign confidentiality and non-disclosure agreements before access and receive data-protection onboarding. Access is revoked on the day of departure.

Incident response. Documented incident procedure with a named owner, 48-hour Customer notification and post-incident review.

Physical security. Infrastructure is hosted by the providers listed in the Privacy Policy, operating certified data centres (ISO 27001 / SOC 2 at provider level). Kreedl does not operate its own data centres.

Deletion. Automated retention rules delete communication data after 12 months or the shorter period set by the Customer. Termination deletion within 30 days, backups within 90 days.