Not yet reviewed by legal counsel. This addendum describes what the system actually does and commits only to measures genuinely in place, but it has not been checked by a qualified lawyer. Treat it as a working draft.

One point is still open and is marked in the text where it appears:

  • A registered postal address for the processor.

Data Processing Addendum

Where a brokerage uses Kadensio to handle its property leads, the brokerage is the controller and Kadensio is the processor. This addendum sets out that relationship. It forms part of the Terms of Service and, on any data protection question, overrides them.

Last updated 27 August 2026 Version 1.0

01Parties and roles

This addendum is between the Customer — the brokerage using the service, acting as controller — and Yassin Khalil, a sole trader trading as Kadensio, acting as processor.

Open item

A registered postal address for the processor has not yet been added. It will be filled in before this addendum is finalised.

The Customer determines the purposes and means of processing its leads' personal data. Kadensio processes that data only on the Customer's documented instructions.

This addendum covers lead data only. Where Kadensio collects personal data for its own purposes — waitlist signups and direct enquiries — it acts as controller, that is outside this addendum, and the Privacy Policy governs it.

02Definitions

Controller, processor, data subject, personal data, processing and personal data breach carry the meanings given in the GDPR, and the equivalent meanings under Egypt's Personal Data Protection Law (Law No. 151 of 2020) and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) where those apply.

Customer Personal Data means personal data that Kadensio processes on the Customer's behalf under the Terms of Service.

Data Protection Law means whichever of the above applies to a given act of processing.

03Subject matter and duration

Subject matter
Automated qualification, scoring, routing and appointment booking for property leads who contact the Customer over WhatsApp or through the Customer's own lead sources.
Duration
For as long as the Customer uses the service, and for the deletion and return period afterwards described in section 14.

04Nature and purpose

Kadensio processes Customer Personal Data to:

  • Receive and store inbound messages from leads, and send replies on the Customer's behalf.
  • Ask the qualification questions the Customer has configured, and record the answers.
  • Compute a score from a fixed set of weighted factors, recording a written reason for each.
  • Route each lead to the salesperson whose project coverage matches, per the Customer's configuration.
  • Offer appointment slots, and where the Customer has connected a Google Calendar, create the booked event.
  • Send reminders and escalations when a lead is not acknowledged in time.
  • Present the resulting queue and call preparation detail to the Customer's staff in the dashboard.
  • Maintain an append-only audit log of what the system did.

Kadensio does not use Customer Personal Data for its own purposes, does not use it to train models, does not sell it, and does not use it for advertising.

05Data subjects and data categories

Categories of data subject

  • Prospective property buyers and renters who contact the Customer, or who submit an enquiry to the Customer.
  • The Customer's own salespeople and staff who use the dashboard.

Categories of personal data

Identifiers
Phone number, WhatsApp profile name.
Communications
Full message content, inbound and outbound, and delivery status reported by Meta.
Qualification answers
Location preference, unit type, budget range, payment plan, down payment, purchase timeline, purpose of purchase, site visit interest, plus any additional questions the Customer configures.
Derived data
A score from 0 to 100 with written reasons, and routing and assignment records.
Appointments
Date and time of a booked viewing, and the calendar event created for it.
Staff data
Names, work email addresses, project coverage and dashboard activity for the Customer's own users.

No special category data. The service is not designed to process data revealing health, biometrics, racial or ethnic origin, religious or political views, or trade union membership. The Customer must not configure questions that solicit it. If such data reaches the system in free text, Kadensio processes it only incidentally as message content.

06Controller obligations

The Customer:

  • Warrants that it has a lawful basis for collecting its leads' personal data and for contacting them, and can demonstrate it.
  • Is responsible for providing data subjects with the privacy information Data Protection Law requires.
  • Warrants that its instructions to Kadensio will not cause either party to breach Data Protection Law.
  • Is responsible for the accuracy of its configuration, including question wording, coverage rules and any additional languages it supplies.
  • Is responsible for its own staff's access to and handling of the data.
  • Must not route purchased, scraped or otherwise unlawfully obtained contact data through the service.

07Processor obligations

Kadensio:

  1. Processes only on documented instructions. The Terms of Service, this addendum, and the Customer's configuration are the documented instructions. Kadensio will tell the Customer if, in its opinion, an instruction breaches Data Protection Law.
  2. Keeps it confidential. Anyone with access is bound by a duty of confidentiality. Access to production is limited to the operator of the service.
  3. Applies the security measures in section 10.
  4. Uses sub-processors only as set out in section 8.
  5. Assists with data subject requests as set out in section 12.
  6. Assists with security, breach notification and impact assessments, taking into account the nature of the processing and the information available.
  7. Deletes or returns the data on termination, as set out in section 14.
  8. Makes available the information needed to demonstrate compliance with these obligations, and allows for audits as set out in section 15.

Kadensio does not process Customer Personal Data for any purpose of its own. Aggregated operational statistics — volumes, latencies, error rates — are anonymised, contain no personal data, and cannot be traced to a Customer or a data subject.

08Sub-processors

The Customer gives general authorisation for Kadensio to engage the sub-processors below. There are no others.

Meta Platforms
Delivery of WhatsApp messages through the official WhatsApp Business Platform. Processes message content, phone numbers and delivery status because delivering a message requires it. Ireland and the United States. Privacy policy.
Google
Calendar events for booked viewings, via the Google Calendar API. Engaged only where the Customer connects a calendar; if the Customer does not, Google processes nothing. United States and global infrastructure. Privacy policy.
Hostinger
Virtual private server hosting for the application, the PostgreSQL database and backups. Data at rest sits in Frankfurt, Germany. Privacy policy.

Kadensio remains fully liable to the Customer for a sub-processor's performance of its data protection obligations.

How changes are notified

  • Kadensio gives the Customer at least 30 days' written notice by email before adding or replacing a sub-processor.
  • The Customer may object on reasonable data protection grounds within those 30 days, in writing.
  • If the objection cannot be resolved, the Customer may terminate the affected part of the service without penalty, and Kadensio will refund any prepaid fees covering the unused period.
  • Where a change is urgent — a sub-processor failing, or a security need — Kadensio may make it sooner and will notify the Customer without undue delay, with the same objection right applying afterwards.

09International transfers

Customer Personal Data is stored in Frankfurt, Germany. For an EU or EEA controller, the primary copy does not leave the European Union.

Two sub-processors process data outside the EU:

  • Meta Platforms, as part of message delivery.
  • Google, where a calendar is connected.

Both operate their own transfer mechanisms for this, including the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Kadensio relies on those mechanisms and does not operate its own. Where the Customer requires Standard Contractual Clauses to be executed directly with Kadensio, contact us and we will arrange it.

10Security measures

These are the measures actually in place. Nothing here is aspirational.

Technical measures

  • TLS encryption for all traffic to the website and the API.
  • Tenant isolation enforced in SQL on every query, not left to application convention, so one Customer's data cannot be returned to another by an application mistake.
  • Parameterised queries throughout; data is never concatenated into SQL.
  • Input validated against a strict schema at every public entry point, with unknown fields rejected rather than ignored.
  • Encrypted, checksummed backups with verified restore — restores are tested, not assumed.
  • Credentials, tokens and signatures redacted from logs. Message bodies are never written to application logs.
  • Passwords stored using a memory-hard hashing function.
  • Rate limiting on public endpoints, enforced in the database so it survives restarts.
  • An append-only audit log of system events, so activity can be reconstructed after the fact.

Organisational measures

  • Access to production limited to the operator of the service.
  • Confidentiality obligations for anyone with access.
  • Data minimisation: only three request headers are stored with a form submission, and only the qualification answers the Customer configured are collected.
  • Separation of the outbound side effects from the database transaction, so a failure cannot leave the record and the message in disagreement.

What is not in place

Stated plainly so it is not assumed: Kadensio holds no security certification — no ISO 27001, no SOC 2 — has not been independently audited, and carries no cyber or professional indemnity insurance at this stage. There is no dedicated security team; the service is operated by one person.

A Customer whose procurement requires any of the above should treat that as a gap to weigh, not something to be talked around.

11Personal data breach

If Kadensio becomes aware of a personal data breach affecting Customer Personal Data, it will:

  1. Notify the Customer without undue delay, and in any case within 48 hours of becoming aware.
  2. Describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
  3. Provide further information as the investigation develops, where it was not all available at first.
  4. Take reasonable steps to contain the breach and mitigate its effects.
  5. Assist the Customer in meeting its own obligations to notify a supervisory authority or affected data subjects.

Notifying the Customer is not an admission of fault. The Customer, as controller, decides whether to notify a supervisory authority or data subjects, and is responsible for doing so.

Breach reports go to [email protected]. The Customer should keep a current contact on file with us for receiving them.

12Assistance with data subject requests

Data subjects have rights of access, rectification, erasure, restriction, portability and objection.

Because Kadensio is the processor, it will not respond to such a request on its own initiative. Instead:

  • If a data subject contacts Kadensio directly, Kadensio forwards the request to the Customer without undue delay and tells the data subject it has done so.
  • Kadensio assists the Customer in responding — retrieving a lead's records, correcting them, exporting them in a portable format, restricting processing, or deleting them.
  • Assistance is provided within 10 working days of a request from the Customer, so the Customer can meet its own statutory deadline.
  • Kadensio acts on such a request only on the Customer's instruction.

An opt-out recorded by the service — a lead replying STOP — takes effect immediately and automatically, and does not wait on an instruction.

13Assistance with impact assessments

Taking into account the nature of processing and the information available, Kadensio will provide reasonable assistance with a data protection impact assessment, and with any prior consultation with a supervisory authority that follows from one.

In practice this means answering specific questions about how the system works: what data is collected, where it is stored, how scoring is computed, what the sub-processors do, and what the security measures are. Much of it is already documented here and in the Privacy Policy.

14Deletion and return

On termination, and at the Customer's choice:

  1. For 30 days, the Customer may request an export of Customer Personal Data in a structured, commonly used, machine-readable format, at no charge.
  2. At the end of that window, or sooner if the Customer asks, Kadensio deletes Customer Personal Data from the live database.
  3. Encrypted backups age out on a 35-day rolling cycle. Data in backups is not restored to live use, and a deletion propagates out of backups within 35 days.
  4. Audit log entries recording that events occurred are retained for up to 24 months. They record system activity, not message content, and are kept so that the history of what the system did remains reconstructable.

Kadensio will confirm deletion in writing on request.

Calendar events already written to the Customer's Google Calendar are held by the Customer in its own Google account and are outside Kadensio's control. The Customer deletes them in Google Calendar.

Where law requires longer retention of a specific record, Kadensio will keep only that record, only for as long as required, and will tell the Customer.

15Audit rights

The Customer may verify Kadensio's compliance with this addendum. Because Kadensio holds no third-party audit report to offer instead, the following applies:

  • Kadensio will make available the information reasonably necessary to demonstrate compliance, in writing, on request.
  • The Customer may request an audit once in any 12-month period, on at least 30 days' written notice, or more often where a supervisory authority requires it or following a personal data breach.
  • An audit is conducted during business hours, must not unreasonably disrupt the service, and is subject to confidentiality.
  • The Customer bears its own costs. Where an audit requires significant time from Kadensio, reasonable costs may be charged, agreed in advance.
  • An audit does not extend to another Customer's data, or to infrastructure operated by a sub-processor. For those, the sub-processor's own published certifications and reports apply.

16Liability and precedence

This addendum forms part of the Terms of Service. The limitation of liability in those terms applies to this addendum, except where Data Protection Law does not permit it.

Where this addendum conflicts with the Terms of Service on a data protection question, this addendum prevails. Where it conflicts with Data Protection Law, the law prevails.

This addendum is governed by the law of England and Wales, and the courts of England have exclusive jurisdiction, following the Terms of Service. That choice governs the agreement only. It does not affect which data protection regimes apply to the processing itself — the GDPR, Egypt's Law No. 151 of 2020 and the UAE's Federal Decree-Law No. 45 of 2021 apply on their own terms regardless, and the obligations in this addendum are owed under whichever of them is engaged.

If a term here is found unenforceable, the rest continues to apply.

17Changes

Kadensio may update this addendum to reflect a change in the service, in its sub-processors, or in the law. For a change that materially affects the Customer's rights, at least 30 days' written notice by email is given. Sub-processor changes follow section 8.

18Contact

Data protection questions, data subject requests, breach reports and audit requests all go to [email protected].

A Customer needing this addendum executed as a signed document, or Standard Contractual Clauses entered into directly, should contact us and we will arrange it.

See also the Privacy Policy and the Terms of Service.