Kavvl

Data processing agreement

How we process personal data you store in Kavvl as a business customer.

Why this agreement

If you use Kavvl for business, you store personal data of third parties: names, phone numbers and email addresses of agents, call notes, and details of owners who submit a property. For that data you are the controller and CYOS Group B.V. is the processor. This data processing agreement forms part of the terms of service and applies as soon as you take a paid plan; separate signing is not required, but on request we send a signed copy via support@kavvl.com.

Subject matter and instructions

We process the personal data solely to deliver the service as described in the terms and according to your instructions: storing and displaying your call notes, agent contact details, LOIs and submitted properties. We do not use this data for our own purposes and do not sell it.

Categories of data subjects and data

Data subjects: agents and their brokerages, owners who submit a property, and your own team members. Data: name, phone number, email address, brokerage name, call notes, offers and correspondence status. We do not process special categories of personal data, so do not enter any.

Sub-processors

We engage: Stripe (payments and invoicing), Resend (email delivery), MongoDB Atlas (database), RentCast and Realtor via RapidAPI (property data), Google Maps (maps) and OpenAI, Anthropic and Google Gemini (AI analysis and assistant). Processing terms are in place with each. New sub-processors are announced by email at least 30 days in advance; if you object, you may cancel immediately with a refund of the remaining period.

Transfers outside the EEA

Some sub-processors process data in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Security measures

Encryption in transit (TLS 1.2 or higher), passwords stored hashed only, access to production data limited to administrators with two-factor authentication, separate test and production environments, daily backups retained for 30 days, logging of administrative actions and periodic dependency reviews.

Data breaches

If we become aware of a security breach affecting your data, we notify you without undue delay and in any case within 48 hours, describing what we know about the nature, the data involved, the likely consequences and the measures we take. Notifying the supervisory authority is your responsibility as controller; we provide all information you need. Reports go through support@kavvl.com.

Data subject rights

If we receive a request from a data subject, we refer them to you and assist you within 5 business days with access, rectification, erasure or portability of the relevant data. You can also export your data yourself in the app.

Retention and return

On termination of the subscription we delete the personal data within 30 days, except where we must retain it by law (invoices for 7 years). On request we provide an export before deletion.

Audits and liability

Once a year you may carry out a written review of our compliance; we respond within 20 business days with documentation. The limitation of liability in the terms of service also applies to this agreement. Questions: support@kavvl.com. Last updated: June 2026.

CYOS Group B.V. · Glenn Millerweg 39, 1311 RP Almere, Nederland
Chamber of Commerce 42098698 · VAT NL869714284B01 · support@kavvl.com