Effective date - 31 August 2026
Controller / processor - KREEDL s.r.o., Záhřebská 562/41, Vinohrady, 120 00 Praha 2, Czech Republic, ID No. 24081370
Contact - [email protected]
This policy explains how Kreedl handles personal data when you visit kreedl.com, when you are a customer using our services, or when you speak or message with a Kreedl AI assistant as a tenant, resident, facility user, vendor or other person. It covers the EU GDPR and the UK GDPR.
Kreedl is an AI building manager for residential and facility management. On behalf of property managers, facility teams, building operators and developers ("Customers"), it answers phone calls, WhatsApp, SMS and email from tenants, residents, store managers, facility users and vendors, and arranges repairs, viewings and other requests. Kreedl is operated by KREEDL s.r.o.
If you are a Customer or a Customer's employee - Kreedl is the data controller for your account, contact, billing, usage and marketing data. This policy governs that data.
If you are a tenant, resident, facility user, applicant, vendor or any other person contacting a building that Kreedl serves - the Customer (your building operator) is the data controller. Kreedl is the data processor and acts only on the Customer's documented instructions, under the Data Processing Agreement at kreedl.com/dpa. To exercise your rights, contact your building operator, or write to [email protected] and we will forward your request and assist.
If you visit kreedl.com - Kreedl is the controller for website, cookie and analytics data (section 11).
Each Customer chooses one of three operating modes. The mode determines what Kreedl stores.
Mode A - No personal records. Kreedl answers general questions (house rules, opening hours, how to report a fault) and does not have access to any tenant or facility-user records. Kreedl still stores the communication itself - call recordings, transcripts, messages and the phone number or email address of the person contacting it.
Mode B - Access without storage. Kreedl reads data in the Customer's own system (property management software, ticketing tool, CRM) at the moment of a request, for example to confirm which unit a caller lives in or which vendor covers a site. Kreedl does not copy those records into its own database. Kreedl stores the communication itself - recordings, transcripts, messages, the contact number or email, and whatever the person says or writes during the conversation, which may include details about their tenancy.
Mode C - Kreedl stores records. The Customer uploads or syncs tenant, unit, contract and vendor records to Kreedl so the assistant can act on them. Kreedl stores those records for the duration of the contract, plus all communication data as in modes A and B.
Which mode applies to your building is set by your building operator. Ask them if you are not sure.
Depending on the mode chosen by the Customer, this may include -
Czech national identification number (rodné číslo). Kreedl does not require it. In rare cases, and only when the Customer instructs us to verify a caller's identity, Kreedl may compare the four digits after the slash of the national identification number provided by the caller against the Customer's records. Kreedl does not store the full number. The Customer is responsible for compliance with Section 13c of Act No. 133/2000 Coll. where it provides this number.
Where a Customer instructs us, Kreedl may collect and summarise publicly available information about a prospective tenant, such as public social-media profiles, public registers and other openly accessible websites, to support the Customer's decision on a tenancy application. In that case -
Kreedl uses AI models to understand requests, answer, triage, book appointments, dispatch vendors within limits the Customer sets, and where instructed, rank applicants or summarise public-source information.
Every conversation with Kreedl starts with a disclosure -
Disclosure is not conditional on local law. We do it everywhere.
We share data only as needed to run the service. We never sell personal data.
Your building operator (the Customer). All communication and request data is available to the Customer whose building you contacted.
Vendors and technicians. To arrange a repair, Kreedl passes the vendor the details needed to do the job - building, unit, description of the fault, photos, and a contact number if access must be arranged.
Subprocessors. We use these providers under data-processing agreements -
Legal requirements. We disclose data where required by law or a competent authority.
Kreedl can run entirely on EU infrastructure or with AI processing in the United States. The Customer chooses. Where any provider processes data outside the EEA or the UK, we rely on EU Standard Contractual Clauses, the UK International Data Transfer Addendum or an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified). Ask your building operator which configuration applies to your building.
| Data | Retention |
|---|---|
| Call recordings, transcripts and summaries | 12 months, or shorter if the Customer's policy requires |
| WhatsApp, SMS and email content | 12 months, or shorter if the Customer's policy requires |
| Photos, voice notes and attachments | 12 months, or shorter if the Customer's policy requires |
| Tenant, unit, contract and vendor records (mode C) | For the term of the Customer contract |
| Public-source summaries (section 4.4) | Until the tenancy decision is made, max 6 months |
| Customer account, contact and configuration data | 3 years after the contract ends |
| Invoices and accounting records | 10 years (statutory) |
| Website analytics and session data | 12 months |
| Support and sales correspondence | 3 years |
When a Customer contract ends, we delete or return all tenant, resident and facility-user data within 30 days. Encrypted backups are purged within 90 days. Where a person asks for deletion earlier, we delete sooner unless a legal obligation prevents it.
Access is role-based and limited to staff who need it to run the service, and every access and every assistant action is logged. Provider credentials and API tokens are stored in a secrets manager and never exposed to users. We test and review our controls regularly. In the event of a personal data breach we notify affected Customers without undue delay, and where feasible within 72 hours, and notify supervisory authorities where the law requires.
kreedl.com uses Cookiebot to manage consent. On your first visit you can accept or reject non-essential cookies, and you can change your choice at any time at kreedl.com/cookies.
The full list of cookies, updated automatically by Cookiebot, is at kreedl.com/cookies.
Under the EU and UK GDPR you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest, withdraw consent at any time, and request human review of any automated recommendation about you.
Write to [email protected]. We answer within one month. If your data is controlled by a building operator, we will forward your request to them and help them respond. You can complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz) or, in the UK, to the Information Commissioner's Office (ico.org.uk).
Our services are aimed at adults. Where a minor contacts a building, the data is handled under the Customer's instructions and deleted on request from a parent or guardian at [email protected].
We may update this policy. Material changes will be announced to Customers by email at least 14 days in advance and reflected by a new effective date.
KREEDL s.r.o., Záhřebská 562/41, Vinohrady, 120 00 Praha 2, Czech Republic