Effective date - 31 August 2026
Processor - KREEDL s.r.o., Záhřebská 562/41, Vinohrady, 120 00 Praha 2, Czech Republic, ID No. 24081370 ("Kreedl")
Controller - any customer using Kreedl's services ("Customer")
Contact - [email protected]
This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service at kreedl.com/terms and of every agreement between Kreedl and a Customer. It applies automatically to every Customer from the moment Kreedl first processes personal data on the Customer's behalf. No signature is required. A countersigned copy is available on request at [email protected].
"Personal Data", "Controller", "Processor", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means Personal Data that the Customer provides to Kreedl, makes accessible to Kreedl, or that Kreedl collects on the Customer's behalf in providing the services, including communication content, recordings and transcripts. "Subprocessor" means any third party engaged by Kreedl to process Customer Personal Data. "UK GDPR" means the GDPR as retained in UK law.
The Customer is the Controller of Customer Personal Data. Kreedl is the Processor. Kreedl acts as an independent Controller only for the Customer's own account, billing, usage and marketing data, as described in the Privacy Policy at kreedl.com/privacy.
Subject matter and purpose. Operating an AI assistant that communicates with tenants, residents, facility users, applicants, vendors and other persons on the Customer's behalf across phone, WhatsApp, SMS and email, and carries out the actions the Customer has authorised.
Nature of Processing. Receiving, recording, transcribing, storing, analysing and summarising communications; reading or storing Customer records according to the operating mode chosen by the Customer (section 4); booking appointments; dispatching vendors; and, where instructed, ranking applicants or summarising publicly available information about prospective tenants.
Categories of Data Subjects. Tenants, residents, prospective tenants, store managers and facility users, vendors and technicians, Customer's employees and representatives, and any other person contacting a building served by Kreedl.
Types of Personal Data. Name, contact details, building and unit, tenancy dates and conditions, rent and payment status, lease documents, fault reports, photos, voice notes, call recordings, transcripts, message content and metadata. Where the Customer instructs identity verification, the last four digits of a Czech national identification number may be compared against Customer records and are not stored in full. Kreedl does not process door codes or other physical access credentials.
Duration. For the term of the Customer's agreement and until deletion under section 12.
4.1 The Customer selects one of three operating modes described in the Privacy Policy. Mode A - no access to Customer records. Mode B - read access to the Customer's systems without storage of records. Mode C - Customer records stored by Kreedl. In every mode Kreedl stores communication content, recordings, transcripts and contact details of the persons communicating with it.
4.2 The Customer's documented instructions consist of the mode selected, the configuration agreed at onboarding, the settings the Customer makes in the Kreedl application, the data the Customer uploads or makes accessible, and any written instruction sent to [email protected]. Uploading data, activating a subscription, creating a profile, or otherwise providing data to Kreedl constitutes the Customer's instruction to process that data for the purposes of section 3.
4.3 The Customer may change its operating mode or instructions at any time by email, through the application, or by conduct that clearly indicates the change. Kreedl implements changes within 14 days.
4.4 Kreedl may refuse any instruction that in its reasonable opinion infringes the GDPR or other law, and will inform the Customer. Kreedl may also process Customer Personal Data where required by EU or Member State law, in which case it informs the Customer unless the law prohibits it.
The Customer warrants and undertakes that -
Kreedl will -
7.1 The Customer gives Kreedl general authorisation to engage Subprocessors. The current list is set out in section 7 of the Privacy Policy at kreedl.com/privacy.
7.2 Kreedl notifies the Customer of any addition or replacement of a Subprocessor by email at least 14 days before the change takes effect.
7.3 If the Customer objects on reasonable data-protection grounds within 14 days of the notice, Kreedl may propose an alternative. If none is agreed, the Customer's sole remedy is to terminate the affected services by written notice, without penalty for the terminated part. Kreedl is not obliged to change Subprocessors.
7.4 Kreedl imposes on each Subprocessor data-protection obligations no less protective than those in this DPA and remains responsible for their performance.
Kreedl stores Customer Personal Data in the European Union. AI processing and telephony may involve providers outside the EEA or the UK. For any such transfer Kreedl relies on the EU Standard Contractual Clauses, an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or, for UK data, the UK International Data Transfer Addendum. Kreedl offers an EU-only processing configuration on written request; the Customer is responsible for requesting it. The Customer authorises Kreedl to enter into Standard Contractual Clauses with Subprocessors on its behalf. A UK Addendum is available on request.
Where Kreedl receives a request from a Data Subject relating to Customer Personal Data, it forwards it to the Customer within 3 working days and does not respond on the merits unless instructed. Kreedl provides reasonable assistance so the Customer can respond within statutory deadlines. Assistance beyond five requests per month, or requiring more than reasonable effort, is charged at Kreedl's then-current hourly rate.
10.1 Kreedl notifies the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and no later than 48 hours after becoming aware of it. The initial notice contains what is known at the time. Kreedl provides the full information required by Article 33(3) GDPR within 14 days and in the meantime provides updates as facts are established.
10.2 The Customer is responsible for notifying Supervisory Authorities and Data Subjects. Kreedl assists on request.
10.3 Where the Customer must carry out a data protection impact assessment, Kreedl provides a description of the Processing, the measures in Annex 1 and reasonable further information. The Customer completes, approves and owns the assessment.
Once per calendar year, on 30 days' written notice, the Customer may request Kreedl's completed security questionnaire, a copy of Annex 1 and available documentation showing compliance with this DPA. An on-site inspection takes place only where required by a Supervisory Authority or by law, during business hours, subject to confidentiality, without access to other customers' data, and at the Customer's cost. Kreedl holds no ISO 27001 or SOC 2 certification and does not represent otherwise.
On termination of the Customer's agreement, and on written request at any time, Kreedl exports Customer Personal Data in a structured machine-readable format (JSON, and audio files for recordings) and deletes Customer Personal Data within 30 days of termination. Encrypted backups are purged within 90 days. Kreedl confirms deletion in writing on request. Kreedl may retain data where required by law and only for that purpose.
13.1 To the fullest extent permitted by law, Kreedl's total liability arising out of or in connection with this DPA, including any regulatory fine or Data Subject claim, is limited to the fees paid by the Customer in the twelve months preceding the event giving rise to the claim, and Kreedl is not liable for indirect or consequential loss, loss of profit, loss of data or damage to reputation. Nothing limits liability that cannot be limited under the GDPR or Czech law.
13.2 Kreedl has no obligation to indemnify the Customer.
13.3 The Customer indemnifies Kreedl against any claim, fine, loss or cost (including reasonable legal fees) arising from the Customer's breach of this DPA or the GDPR, from an instruction given by the Customer, from data provided without a lawful basis or without required information to Data Subjects, or from the Customer's autonomy settings.
This DPA applies for as long as Kreedl processes Customer Personal Data and survives termination of the Customer's agreement until deletion is complete. It is governed by the laws of the Czech Republic and disputes are decided by the competent courts in Prague. It is published in English and Czech; the English version prevails. Kreedl may update this DPA with 14 days' email notice to Customers; continued use after the effective date means acceptance.
Encryption. Customer Personal Data is encrypted at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher). Call recordings and files are stored in encrypted object storage.
Access control. Role-based access. Only Kreedl staff who need access to operate the service have it. Multi-factor authentication is mandatory for all Kreedl staff and for all administrative access to infrastructure. Access is reviewed on staff changes and at least quarterly.
Logging and auditability. Every action of the AI assistant and every staff access to Customer Personal Data is logged with timestamp and identity. Logs are retained for 12 months and available to the Customer for its own data.
Secrets management. Provider credentials and API keys are stored in a secrets manager, never in code or exposed to users, and rotated on staff departure or suspected compromise.
Tenant isolation. Each Customer's data is logically segregated. No Customer can access another Customer's data.
Backups. Encrypted backups at least daily, retained 90 days, restore tested at least annually.
AI model providers. Model providers are contractually prohibited from using Customer Personal Data for training. Kreedl does not train or fine-tune models on Customer Personal Data.
Personnel. All staff and contractors sign confidentiality and non-disclosure agreements before access and receive data-protection onboarding. Access is revoked on the day of departure.
Incident response. Documented incident procedure with a named owner, 48-hour Customer notification and post-incident review.
Physical security. Infrastructure is hosted by the providers listed in the Privacy Policy, operating certified data centres (ISO 27001 / SOC 2 at provider level). Kreedl does not operate its own data centres.
Deletion. Automated retention rules delete communication data after 12 months or the shorter period set by the Customer. Termination deletion within 30 days, backups within 90 days.