Privacy Policy
Kadensio answers property leads on WhatsApp for real estate brokerages. That means handling two very different kinds of personal data, under two different legal roles. This policy explains both, and what you can do about either.
01Who we are, and our two roles
Kadensio is operated by Yassin Khalil, a sole trader trading as Kadensio. Contact: [email protected].
Open item
A registered postal address has not yet been added. Data protection law generally expects a controller to publish one alongside an email address, and this will be filled in before the policy is finalised.
Which rules apply to your data depends on why we hold it, so it is worth being precise about this up front.
When a brokerage uses Kadensio to handle its leads, we are a processor
If you messaged a real estate brokerage on WhatsApp and Kadensio answered, the brokerage decides why your data is collected and what happens to it. They are the controller. We are the processor, acting only on their documented instructions. We do not decide what to do with your data, we do not use it for our own purposes, and we do not contact you on our own behalf.
If you want your data corrected or deleted in that situation, the brokerage is the right place to ask. We will help them do it — see Your rights.
When you contact us directly, we are the controller
If you fill in our waitlist form or email us, we decide what happens to that data. For it, we are the controller, and you can bring requests straight to us.
02Data we handle for brokerages
When a person messages a brokerage that uses Kadensio, the system collects and stores the following on that brokerage's behalf:
- Phone number and WhatsApp profile name, as provided by WhatsApp.
- Message content, both what the lead sends and what the system replies.
- Qualification answers: location preference, unit type, budget range, payment plan, down payment, purchase timeline, purpose of purchase, and whether they want a site visit.
- A computed score from 0 to 100, together with the written reasons that produced it.
- Appointment date and time, if a viewing is booked.
- Message delivery status reported back by Meta — sent, delivered, read, failed.
The score is produced by a fixed set of weighted factors, and each factor records a written reason. It is used to order the brokerage's own follow-up queue. It does not make any decision about you by itself, and a person at the brokerage decides what to do next.
03Data we collect for ourselves
The waitlist form on our home page posts to /api/waitlist and stores:
- Email address — required, because it is how we reply.
- Company name, market and a free-text message — all optional, and only stored if you fill them in.
- Your IP address, used to rate limit the form so it cannot be abused. It is held in a separate counter table keyed by address, not attached to your signup record.
- Three request headers: user agent, content type and accept-language.
That is the whole list. There is no marketing automation, no mailing list provider, and no newsletter. If you join the waitlist, the only thing that happens is that a person reads it and may email you back.
05Lawful basis
Under the GDPR and the equivalent provisions of the other frameworks named below, we rely on the following:
06WhatsApp and Meta
Messages are sent and received through the official WhatsApp Business Platform operated by Meta Platforms. We do not use unofficial libraries, scraped sessions or automation that drives WhatsApp Web.
Why a business is allowed to message you
One of two things is true whenever Kadensio messages someone:
- You messaged the business first. This is the main path — you saw a number on a listing or a board and started the conversation.
- You submitted an enquiry through a website form or a lead ad, and the business follows up using a message template that Meta has reviewed and approved in advance.
The 24-hour window
Meta allows a business to reply freely for 24 hours after your most recent message. Each time you reply, the window restarts. Once 24 hours pass with no message from you, the business can no longer send free-form messages and may only send one of Meta's pre-approved templates until you write again.
In practice this means the conversation is led by you. If you stop replying, the messages stop being conversational and become limited, or stop entirely.
How to stop the messages
Reply STOP at any time. When you do:
- Your contact record is marked as opted out immediately.
- No further automated messages are sent to your number by the system.
- Any scheduled follow-ups for you are cancelled.
- The opt-out is recorded in the audit log, so it can be shown to have happened.
Opting out stops messages. It does not by itself delete the conversation history the brokerage already holds — for that, ask the brokerage to erase your data, or see Your rights. You can also block the number in WhatsApp, which stops delivery regardless of anything we do.
What Meta does with the messages
Meta processes message content as part of delivering it, in the same way any messaging provider does. Meta is an independent controller for its own purposes and its handling of your data is governed by its own terms. See the WhatsApp Privacy Policy and the Meta Privacy Policy.
07Google Calendar
A brokerage can connect a Google Calendar so that booked property viewings appear in it automatically. This is optional and off unless the brokerage turns it on.
The scope we request
We request exactly one Google OAuth scope:
https://www.googleapis.com/auth/calendar
Exactly what we do with it
Two things, and nothing else:
- Read free/busy availability on the connected calendar, so the system can offer a lead time slots that are genuinely free.
- Create calendar events for property viewings that a lead books, so the appointment lands in the brokerage's calendar with the details attached.
We do not read the content of unrelated calendar events, we do not modify or delete events the system did not create, and we do not access any other Google service, product or data.
Limited Use
Kadensio's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through the Google Calendar API is:
- Never used for advertising of any kind.
- Never sold to anyone, in any form.
- Never transferred to others, except as strictly necessary to provide the booking feature to the brokerage whose calendar it is, to comply with applicable law, or as part of a merger or acquisition where the receiving party is bound by this policy.
- Never used to train models, including generalised or artificial intelligence models.
- Never read by a human, except where the brokerage explicitly asks us to help with a specific problem, where it is necessary for security purposes such as investigating abuse, or where the law requires it.
How a brokerage revokes access
Two ways, either of which is sufficient:
- Disconnect the calendar from inside Kadensio, which discards the stored refresh token, or ask us at [email protected] to do it.
- Revoke it directly with Google at myaccount.google.com/permissions, which takes effect immediately regardless of anything on our side.
Once revoked, the system can no longer read availability or create events. Events already created stay in the calendar and belong to the brokerage; delete them in Google Calendar if they are no longer wanted.
09Where data is stored
The application and its PostgreSQL database run on a Hostinger virtual private server in Frankfurt, Germany. Backups are stored in the same region. For anyone in the EU or EEA, this means the primary copy of the data does not leave the European Union.
Two of our sub-processors are outside the EU:
- Meta Platforms processes message content internationally as part of delivery.
- Google processes calendar data internationally.
Both companies operate their own transfer mechanisms for this, including the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. We rely on those mechanisms; we do not operate our own.
10How long we keep things
11Security
What is actually in place, stated without embellishment:
- Traffic to the site and the API is encrypted with TLS.
- Backups are encrypted, checksummed, and restore-tested rather than assumed to work.
- Separation between brokerages is enforced in SQL on every query, not left to application convention.
- Database queries are parameterised throughout, so data is never concatenated into SQL.
- Logs redact credentials, tokens and signatures. Message bodies are not written to application logs.
- An append-only audit log records system events, so activity can be reconstructed after the fact.
- Access to production is limited to the operator of the service.
We hold no security certification — no ISO 27001, no SOC 2 — and have not been independently audited. We are not going to imply otherwise. No system is perfectly secure, and we cannot guarantee absolute security.
12Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict how it is processed, to receive it in a portable form, and to object to processing. Where processing rests on consent, you can withdraw that consent at any time.
Which door to knock on
We aim to respond within 30 days. There is no charge. We may need to ask a question to confirm you are who you say you are, so that we do not hand someone's data to the wrong person.
Frameworks
We aim to handle personal data consistently with:
- The EU General Data Protection Regulation (Regulation 2016/679).
- Egypt's Personal Data Protection Law, Law No. 151 of 2020.
- The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.
Naming these is a statement of what we aim at, not a claim of certification, registration or audit under any of them. We hold no such certification, and we are not registered with any data protection authority.
If you are in the EU or EEA and are unhappy with how we have handled something, you can complain to your national supervisory authority. We would rather you told us first so we can fix it.
13Children
Kadensio is a business tool for real estate brokerages and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached the system, tell us and we will remove it.
14Changes to this policy
When this policy changes, the date at the top changes with it. For a change that materially affects how personal data is handled, we will notify brokerages using the service by email at least 30 days before it takes effect.
15Contact
Questions about this policy, or a request about your data, go to [email protected]. A person reads it.
See also the Terms of Service and the Data Processing Addendum.