
Data Processing Agreement
Kalynto Ltd
Version 1.0 · Effective 20 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Kalynto Ltd and the customer identified in the applicable order form or subscription (the "Agreement") for the provision of the Kalynto property search service (the "Service").
This DPA reflects the parties' obligations under the UK GDPR and the Data Protection Act 2018.
1. Parties and roles
Kalynto Ltd, company number 17151969, registered in England and Wales at 4 Waterwheel Court, Merriott, England, TA16 5AF ("Kalynto", "we", "us"), and
the Customer, being the estate agency or other business that subscribes to the Service ("Customer", "you").
For personal data processed through the Service, you are the controller and Kalynto is the processor. You determine the purposes and means of processing. We process personal data only on your documented instructions.
Kalynto acts as a controller in its own right only for data relating to the administration of your account, including your staff contact details, billing records and support correspondence. That processing is governed by our Privacy Policy and falls outside this DPA.
Where a conflict arises between this DPA and the Agreement, this DPA prevails in respect of the processing of personal data.
2. Subject matter, duration, nature and purpose
Subject matter. Provision of an AI property search interface on your website, which interprets buyer search queries in natural language, scores your property listings against those queries, and captures each search as a lead.
Duration. For the term of the Agreement, plus the deletion period set out in section 11.
Nature and purpose. Collection, structuring, storage, analysis and transmission of buyer search data for the purpose of returning property matches and delivering enquiry records to you.
Full details are set out in Annex 1.
3. Processing on documented instructions
3.1 We process personal data only on your documented instructions, including in relation to international transfers, unless required to do otherwise by law. Where we are required by law to process otherwise, we will inform you before processing unless the law prohibits that notification.
3.2 The Agreement, this DPA and your configuration of the Service constitute your complete documented instructions.
3.3 We will inform you if, in our opinion, an instruction infringes the UK GDPR or other data protection law. We may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
3.4 We will not sell personal data, and will not use personal data processed under this DPA for our own marketing, product development or profiling purposes.
4. Confidentiality
4.1 We ensure that persons authorised to process personal data are subject to an appropriate contractual or statutory duty of confidentiality.
4.2 Access is limited to personnel who require it to deliver, support or secure the Service.
5. Security
5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to individuals, we implement appropriate technical and organisational measures under Article 32 UK GDPR.
5.2 Those measures are described in Annex 2. We may update them provided the level of security is not reduced.
6. Sub-processors
6.1 You give general written authorisation for our engagement of sub-processors.
6.2 Our current sub-processors are listed in Annex 3.
6.3 We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your registered account contact. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the Service without penalty and receive a pro rata refund of prepaid fees.
6.4 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. AI processing
7.1 The Service uses a large language model provided by a third party sub-processor to interpret buyer search queries and generate match explanations.
7.2 Buyer query data submitted to that provider is not used to train its models. Anthropic, our model provider, states: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." We do not enable any optional setting that would permit such use.
7.3 We do not use personal data processed under this DPA to train, fine tune or evaluate any model of our own.
7.4 Match scores and their accompanying explanations are generated automatically. They are informational and are not intended to produce legal effects concerning any individual or similarly significantly affect them, and so are not a decision within the meaning of Article 22 UK GDPR. You remain responsible for how you act on the results.
8. Assistance with data subject rights
8.1 Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III UK GDPR.
8.2 If we receive a request directly from a data subject, we will not respond substantively. We will notify you without undue delay and refer the individual to you.
8.3 The Service provides functionality allowing you to access, export, correct and delete individual records. Assistance beyond that functionality is provided at no additional charge where the request volume is reasonable.
9. Personal data breach
9.1 We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.
9.2 The notification will describe, so far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full detail is not available at once, we will provide it in phases without undue delay.
9.3 We do not notify the Information Commissioner or affected individuals on your behalf unless you instruct us in writing to do so. As controller, that obligation is yours.
10. Data protection impact assessments
We provide reasonable assistance with your data protection impact assessments and any prior consultation with the Information Commissioner, in each case relating to the Service and taking into account the information available to us.
11. Deletion and return
11.1 On termination or expiry of the Agreement, we will, at your election, delete or return all personal data processed under this DPA.
11.2 Unless you request return in writing within 30 days of termination, we will delete the data within 90 days of termination, including from backups in accordance with our backup rotation schedule.
11.3 We may retain personal data to the extent required by law, in which case we will continue to protect it under this DPA and will process it only for the purpose requiring its retention.
11.4 On request we will certify deletion in writing.
12. Audit and information
12.1 We make available to you the information necessary to demonstrate compliance with Article 28 UK GDPR.
12.2 We allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once in any twelve month period unless a personal data breach has occurred or the Information Commissioner requires otherwise, must be on at least 30 days' notice, during business hours, and must not unreasonably disrupt our operations.
12.3 We may satisfy an audit request by providing a current third party audit report, security questionnaire response or certification where one adequately addresses your request.
12.4 The auditor must be bound by confidentiality and must not be a competitor of Kalynto.
13. International transfers
13.1 Personal data is processed and stored in the United Kingdom or the European Economic Area except as stated in Annex 3.
13.2 Where a sub-processor is located outside the UK, the transfer is made under one of the following, as identified for that sub-processor in Annex 3:
- UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework, where the recipient has an active status on the Data Privacy Framework list, has self certified to the UK Extension, and its certification covers the type of personal information transferred;
- the International Data Transfer Agreement issued by the Information Commissioner; or
- the International Data Transfer Addendum to the EU Standard Contractual Clauses.
13.3 Where we rely on an Article 46 safeguard rather than adequacy, we carry out a transfer risk assessment and make it available to you on request.
14. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law.
15. Term, variation and governing law
15.1 This DPA takes effect on the effective date above and continues for as long as we process personal data on your behalf.
15.2 We may update this DPA where required by a change in law, regulatory guidance or our sub-processing arrangements, on 30 days' notice, provided the update does not materially reduce your protections.
15.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1 · Details of the processing
Categories of data subject
- Prospective buyers and tenants who use the search interface on your website
- Your employees and agents who access the Kalynto dashboard
Types of personal data
- Search queries submitted in free text, which may contain location, budget, household composition, schooling and commuting preferences volunteered by the individual
- Contact details submitted with an enquiry, being name, email address and where provided telephone number
- Search history and interaction records associated with an individual or a device
- Technical data including IP address, device and browser type, and timestamps
- Account credentials and access logs for your staff users
Special category data
The Service is not designed or intended to process special category data under Article 9 UK GDPR. Free text search queries may nonetheless contain information from which such data could be inferred, for example a query mentioning accessibility requirements, a place of worship or a specific school. You must not instruct us to process special category data, and we do not use any such information to target or segment individuals.
Frequency of processing
Continuous, for the duration of the Agreement.
Processing operations
Collection, recording, organisation, structuring, storage, retrieval, analysis, transmission to your CRM at your instruction, restriction and erasure.
Retention
Search and enquiry records are retained for 24 months from the date of collection, or until you delete them, whichever is earlier.
Annex 2 · Technical and organisational measures
Access control
- Role based access to production systems, granted on the principle of least privilege
- Multi factor authentication required on all administrative and cloud provider accounts
- Access reviewed quarterly and revoked within one working day of a leaver's departure
Encryption
- Personal data encrypted in transit using TLS 1.2 or above
- Personal data encrypted at rest by our hosting provider using AES-256
Segregation
- Customer data logically separated so that one agency's stock and enquiry data is not accessible to another
- Separate development and production environments, with no live personal data in development
Resilience and recovery
- Automated daily backups, retained for 30 days
- Restoration tested at least annually
Logging and monitoring
- Administrative access to personal data is logged, and logs are retained for 90 days
Personnel
- Confidentiality obligations in all staff and contractor agreements
- Data protection awareness training on engagement and annually thereafter
Secure development
- All changes reviewed before deployment to production
- Dependencies monitored for known vulnerabilities and patched on a risk assessed basis
Vendor management
- Sub-processors assessed before engagement and reviewed annually
Certifications
Kalynto does not currently hold a formal information security certification such as ISO 27001 or SOC 2. The measures above are implemented and can be evidenced on request.
Annex 3 · Sub-processors
| Sub-processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Anthropic PBC | Interpretation of buyer search queries and generation of match explanations | United States | Safeguards in Anthropic's data processing addendum, incorporating the UK Addendum to the EU Standard Contractual Clauses or UK adequacy where applicable |
| Supabase | Application hosting and database storage | United Kingdom or European Economic Area | Not applicable, no restricted transfer |
| Cloudflare | Content delivery, routing, DNS and security | Global edge network, including the United States | Safeguards in Cloudflare's data processing addendum, incorporating the UK Addendum to the EU Standard Contractual Clauses |
Buyer search and enquiry data is stored in the United Kingdom or the European Economic Area. Query text is transmitted to Anthropic for interpretation and is not retained by Anthropic for training, as set out in section 7.
Transfer risk assessments for the transfers above are available on request. The current list is maintained at kalynto.co.uk/data-processing.
Contact
Questions about this DPA, or a request for a countersigned copy, to jack@kalynto.co.uk.
Kalynto Ltd, company number 17151969, registered in England and Wales.