Kreedl – Data Processing Agreement (DPA)

Effective Date: June 7, 2026

Legal Entity: KREEDL s.r.o.

Registered Address: Záhřebská 562/41, Vinohrady (Praha 2), 120 00 Praha, Czech Republic

Contact: [email protected]

This Data Processing Agreement (the "DPA") is entered into by and between (i) the Kreedl customer identified in the applicable ordering document or separate contract ("Customer") and (ii) KREEDL s.r.o., with its registered address at Záhřebská 562/41, Vinohrady (Praha 2), 120 00 Prague, Czech Republic ("Kreedl"). This DPA governs the processing of personal data that Customer uploads, submits, or otherwise provides to Kreedl in connection with the services provided by Kreedl ("Services").

1. Definitions

For the purposes of this DPA:

"Customer Personal Data" means Personal Data (i) that Customer uploads, submits, or otherwise provides to Kreedl in connection with its use of the Services, including documents, links, emails, call recordings and related metadata; or (ii) for which Customer is otherwise a data controller and which is processed by Kreedl on Customer's behalf.

"Data Controller" or "Controller" means Customer, in respect of Customer Personal Data.

"Data Processor" or "Processor" means Kreedl, in respect of Customer Personal Data.

"Data Protection Requirements" means the GDPR and any other applicable laws and regulations relating to the protection of Personal Data, including local implementing legislation.

"EU Personal Data" means Personal Data the processing of which is subject to the GDPR.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

"Personal Data" means any information relating to an identified or identifiable natural person, as defined in the GDPR or other applicable Privacy Laws.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.

"Privacy Laws" means GDPR and all other applicable laws and regulations relating to privacy, data protection and the processing of Personal Data.

"Process", "Processing" and their cognates mean any operation or set of operations performed on Personal Data, whether or not by automated means, as defined in the GDPR.

"Subprocessor" means any third party engaged by Kreedl that processes Personal Data on behalf of Kreedl in connection with the Services.

"Supervisory Authority" means any competent public authority responsible for monitoring the application of Privacy Laws under Article 51 GDPR or equivalent provisions.

2. Subject matter and duration

2.1 Subject matter

The Controller authorises the Processor to process Customer Personal Data for the purpose of providing, maintaining and improving the Services under the main agreement between the parties ("Main Agreement") and this DPA.

2.2 Nature and purpose of processing

Processing activities include, in particular:

  • storage and hosting of Customer Personal Data;
  • ingestion, parsing and enrichment of materials uploaded or submitted by users (e.g. listing details, applicant documents, PDFs, links);
  • processing of contact details (e.g. email address, phone number);
  • processing of email and voice communication data (including call recordings, transcripts and summaries);
  • analytics and AI-based enrichment for matching and qualification between applicants and property operators;
  • where instructed by Customer, sourcing and analysis of publicly available information about prospective tenants for due diligence purposes.

2.3 Categories of data subjects

Data subjects may include, in particular: tenant applicants, employees and representatives of property operators or letting agents, employees or representatives of Customer, and other individuals whose data are included in the materials provided to Kreedl.

2.4 Types of Personal Data

Customer Personal Data may include, in particular: names, contact details (email, phone), company details, listing and applicant information, communication content (emails, call audio, transcripts, notes), uploaded documents and links, and related technical metadata. Where Customer provides a Czech national identification number ("rodné číslo") as part of Customer Personal Data, Customer is solely responsible for ensuring compliance with Section 13c(1) of Act No. 133/2000 Coll., on the Records of Population, as amended, and Kreedl will process such identification number solely for the purposes set out in this DPA.

2.5 Duration

Customer Personal Data will be processed by the Processor for the term of the Main Agreement and as long as necessary to fulfil the purposes set out in this DPA, unless otherwise required by applicable law.

3. Compliance with laws

Each party shall comply with its respective obligations under all applicable Privacy Laws. Customer is responsible for ensuring that it has a valid legal basis for all Customer Personal Data provided to Kreedl for Processing.

4. Customer obligations

Customer agrees to:

4.1 Provide written or documented instructions to Kreedl and determine the purposes and means of Kreedl's Processing of Customer Personal Data in accordance with this DPA.

4.2 Ensure that Customer's instructions comply with applicable Privacy Laws.

4.3 Ensure that it has provided adequate notice and (where required) obtained all necessary consents from data subjects for Kreedl's Processing of Customer Personal Data.

4.4 Where Customer instructs Kreedl to source or analyze publicly available information about prospective tenants (e.g. from social media or other public sources), Customer is solely responsible for providing the data subject with the information required under Article 14 GDPR, including the source of the data, no later than at the time of first contact with the data subject.

4.5 Where Customer uses the Services to communicate with data subjects via AI-based voice, chat, or messaging agents, Customer is responsible for ensuring that data subjects are informed that they are interacting with an AI system, in accordance with Article 50(1) of Regulation (EU) 2024/1689 (the "AI Act"), unless this is otherwise apparent from the circumstances.

5. Processor obligations

Kreedl agrees to:

5.1 Process Customer Personal Data only on documented instructions from Customer, unless required by applicable law.

5.2 Ensure that persons authorised to process Customer Personal Data are under appropriate confidentiality obligations.

5.3 Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks presented by Processing, including protection against unauthorized or unlawful Processing and against accidental loss, destruction or damage.

5.4 Assist Customer in responding to requests from data subjects exercising their rights under the GDPR (e.g. access, rectification, erasure).

5.5 Assist Customer in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments and prior consultations, to the extent required by law.

5.6 At Customer's choice, delete or return all Customer Personal Data upon termination of the Services, unless retention is required by applicable law.

5.7 Provide Customer with information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or its designated auditor, subject to reasonable notice and confidentiality obligations.

5.8 Where the Services involve automated scoring, ranking, or profiling of prospective tenants, Kreedl will provide Customer with reasonable assistance necessary for Customer to carry out a data protection impact assessment under Article 35 GDPR where required. Any such scoring, ranking, or profiling is provided as decision support only; Customer retains full responsibility for the final decision affecting the data subject.

6. Subprocessors

6.1 Customer grants Kreedl general authorization to engage Subprocessors for the Processing of Customer Personal Data.

6.2 Kreedl will impose data protection obligations on any Subprocessor that are substantially similar to those in this DPA.

6.3 Kreedl will notify Customer of any intended changes concerning the addition or replacement of Subprocessors. Customer may object within 14 days of notification if the objection is based on legitimate data protection concerns.

7. Data transfers

7.1 Kreedl may transfer Customer Personal Data outside the European Economic Area only where appropriate safeguards are in place, such as the EU Standard Contractual Clauses or an adequacy decision.

7.2 Customer authorises Kreedl to enter into Standard Contractual Clauses on Customer's behalf with Subprocessors located outside the EEA.

8. Personal Data Breach

8.1 Kreedl will notify Customer without undue delay (and, where feasible, within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 Such notification will include, to the extent available: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects and records concerned; (c) likely consequences; and (d) measures taken or proposed to address the breach.

9. Liability and indemnification

Each party's liability under this DPA shall be subject to the limitations and exclusions set out in the Main Agreement, except where prohibited by law.

10. Term and termination

This DPA shall remain in effect as long as Kreedl Processes Customer Personal Data. Upon termination, Kreedl will delete or return Customer Personal Data in accordance with section 5.6.

11. Governing law

This DPA shall be governed by and construed in accordance with Czech law, unless otherwise required by applicable Privacy Laws.

12. Contact

For questions or concerns about this DPA, contact:

KREEDL s.r.o.

Záhřebská 562/41, Vinohrady (Praha 2), 120 00 Praha, Czech Republic

Email: [email protected]