Data Processing Addendum
Last updated: 18 September 2026
This Addendum governs the processing of personal data that Kobem carries out on behalf of its customers and gives effect to Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms & Conditions and is accepted when the service is contracted. If you need a signed copy for your records, write to us and we will send one.
1. Parties and roles
Controller: the customer, that is, the real estate company that contracts Kobem. It decides why and how the data of the people who call it is processed.
Processor: KOBEM TECHNOLOGIES - FZCO, a free zone company with limited liability (FZCO) incorporated in Dubai Silicon Oasis under Dubai Law No. 16 of 2021 and the DIEZA Implementing Regulations 2023, registration No. 85517 and trade licence No. 92297, issued by the Dubai Integrated Economic Zones Authority (DIEZA), IFZA Properties, Premises DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates. It processes that data solely on behalf of the controller and never for purposes of its own.
Were Kobem to determine the purposes or means of processing on its own, it would be liable as a controller for that particular processing (Article 28(10) GDPR). That is not what we do and not what we plan to do.
2. Subject matter, duration, nature and purpose
- Subject matter: the provision of the service of answering, qualifying and recording the controller's inbound calls.
- Duration: for as long as the subscription is in force, plus the return and deletion period in clause 9.
- Nature and purpose: receiving and recording calls, transcription, analysis of the conversation, qualification of the contact, scheduling of viewings, and making all of it available to the controller in its dashboard and in the integrations it connects.
- Types of data: identification and contact data (name, phone, email), the content of the conversation (audio and transcript) and the data derived from it (reason for the call, area, budget, timing, preferences).
- Categories of data subjects: the people who call the controller — buyers, tenants, owners — and the dashboard users the controller itself creates.
The service is not designed to process special categories of data under Article 9 GDPR. The controller undertakes not to configure questions aimed at obtaining them. The dashboard warns when a question may touch a protected category, and records that warning.
3. The controller's instructions
Kobem processes personal data solely on documented instructions from the controller. Documented instructions are: these Terms, this Addendum and the configuration the controller sets in its dashboard — the greeting, the questions, the integrations it enables and the notices.
If Kobem believes an instruction infringes data protection law, it will inform the controller without delay and may suspend execution until the matter is clarified.
Kobem does not use the content of conversations to train its own or third-party models, nor for any purpose other than providing the service to the controller.
4. Confidentiality
Kobem ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access is limited to those who need it to operate and support the service, and access by our staff to a customer account is logged.
5. Security measures
Kobem implements the appropriate technical and organisational measures required by Article 32 GDPR. They are described, including what exists and what does not, on the Security and data protection page, which forms part of this Addendum for the purpose of evidencing those measures.
Measures may evolve with the state of the art. Kobem will not reduce the level of security contracted during the term of the agreement.
6. Sub-processors
The controller grants general authorisation for Kobem to engage the sub-processors necessary to provide the service. The current list is as follows:
- Supabase — Database and storage of call recordings (EU)
- Vercel — Hosting of the web application (EU / USA)
- LiveKit Cloud — Audio transport and execution of the voice agent (EU)
- Google (Gemini) — Voice model that answers and holds the conversation (USA)
- Deepgram — Speech-to-text transcription (USA)
- OpenAI — Fallback for the voice pipeline (USA)
- Anthropic — Call analysis and summary, and dashboard assistant (USA)
- Telnyx — Telephony: numbering and call transit (EU / USA)
- Resend — Delivery of service emails (USA)
- Telegram — Notifications, only if the customer links their account (—)
- HubSpot — Lead sync, only if the customer connects it (USA)
- Google Workspace — Calendar and Sheets, only if the customer connects them (USA)
- Cal.com — Scheduling, only if the customer connects it (USA)
Sub-processors for optional integrations only come into play if the controller connects that integration from its dashboard.
Kobem imposes on each sub-processor, by contract, data protection obligations equivalent to those in this Addendum, and remains liable to the controller for their performance.
Kobem will inform the controller of the addition or replacement of a sub-processor at least thirty days in advance. Within that period the controller may object on reasonable data protection grounds; if the objection cannot be resolved, the controller may terminate the affected part of the service without penalty.
7. Data subject rights
Kobem assists the controller, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling requests for access, rectification, erasure, objection, restriction and portability.
In practice, the dashboard lets the controller view, export and delete any call, recording, transcript and contact by itself, so it can handle most requests without us. If we receive a request directly from a data subject, we will not answer it ourselves: we will pass it to the controller without delay.
8. Personal data breaches and assistance
Kobem will notify the controller of any personal data breach without undue delay and in any event within 72 hours of becoming aware of it, with the information available at that time: the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
Kobem also assists the controller in complying with Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to it.
9. Return and deletion on termination
On termination of the agreement, and at the controller's choice, Kobem will return or delete the personal data processed on its behalf.
Unless instructed otherwise, the controller has thirty days from termination to export its data from the dashboard. After that period Kobem deletes it, including recordings and transcripts, except for what it must keep under a legal obligation and for as long as that obligation requires, keeping it blocked.
10. Audit and information
Kobem makes available to the controller the information necessary to demonstrate compliance with this Addendum and Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates.
Audits are agreed with reasonable notice, no more than once a year save for a security incident or a supervisory authority's requirement, are limited to what is necessary, and respect the confidentiality of other customers' and our providers' information.
11. International transfers
Data is stored in the European Union. Some sub-processors, marked in the list above, process data outside the European Economic Area — in particular the voice and transcription providers, while the call is in progress.
Those transfers rely on the standard contractual clauses approved by the European Commission or another valid mechanism under Chapter V GDPR. The controller authorises those transfers by accepting this Addendum.
12. Term and governing law
This Addendum takes effect when the service is contracted and remains in force for as long as Kobem processes personal data on behalf of the controller. In the event of conflict between this Addendum and the Terms & Conditions on data protection matters, this Addendum prevails.
Where the processing is subject to the GDPR, this Addendum is construed in accordance with it, without prejudice to the governing law and jurisdiction clause of the Terms: These Terms are governed by the laws of the United Arab Emirates and the parties submit to the courts of Dubai. If you contract as a consumer or reside in the European Union, this clause does not deprive you of the protection afforded by the mandatory rules of your country of residence, nor of your right to bring proceedings before the courts of that country.
For any question about this Addendum, or to request a signed copy, write to contact@kobem.ai.
Schedule 1 · Details of processing
This Schedule corresponds to Annex I.B of the Standard Contractual Clauses. It describes the categories of data processed on behalf of the controller, the purpose, the retention period and the categories of data subjects.
| Category of data | Purpose | Retention | Data subjects |
|---|---|---|---|
| Call content | Answer the inbound call, hold the conversation and transcribe it. | For the term of the subscription and until the customer deletes it. Deletable at any time from the dashboard. | People who call the customer: buyers, tenants and property owners. |
| Contact and qualification data | Identify the caller and record what they need: reason, area, budget, timing and preferences. | For the term of the subscription and until the customer deletes it. | People who call the customer. |
| Customer account data | Create and administer the account, provide support and bill. | While the account is active, plus the accounting retention periods required by law. | Customer personnel authorised to use the dashboard. |
| Usage data and technical logs | Maintain the service, diagnose incidents, prevent fraud and measure consumption. | As long as necessary for those purposes and, for telephony records, as required by carrier obligations. | Customer personnel and callers. |
Frequency of transfer: continuous, for the term of the agreement. Nature of the processing: as described in clause 2.
Special categories of data: the service is not designed to process them and the controller undertakes not to configure questions aimed at obtaining them. If a data subject nonetheless mentions them spontaneously during a call, they will remain in the recording and the transcript, and the controller can delete them from the dashboard.
Schedule 2 · Technical and organisational measures
This Schedule corresponds to Annex II of the Standard Contractual Clauses and describes the measures Kobem applies under Article 32 GDPR. They are verifiable measures in force, not objectives.
| Measure | How it is met |
|---|---|
| Pseudonymisation and encryption of personal data | All traffic is encrypted in transit with TLS 1.2 or above, and real-time audio with DTLS-SRTP under the WebRTC standard. Data at rest is encrypted with AES-256 in the database and in the recording store. Customer integration credentials are further encrypted with AES-256-GCM before storage, using a key that does not reside in the database. |
| Confidentiality, integrity, availability and resilience of processing systems | The infrastructure runs on providers with redundancy and automatic recovery (AWS via Supabase, and Vercel). The database replicates automatically and object storage is redundant by the provider's design. |
| Ability to restore availability and access to data after an incident | Automatic daily database backups, retained by the provider, with point-in-time recovery. Restoration is performed manually following the provider's procedure. |
| User identification and authorisation | Each user signs in with their own account, managed by Supabase Auth. Kobem staff access to a customer account is granted on a support-need basis and is written to an audit log with the actor and the time. Administrative access to infrastructure providers requires two-factor authentication. |
| Isolation of data between customers | Every table holding customer data has PostgreSQL row-level security (RLS) enabled, and in addition every server query filters by account identifier in code. These are two independent controls: isolation between two customers requires both to fail. |
| Protection of data during transmission | No data travels in the clear. Service security headers include HSTS, a strict referrer policy, protection against framing by third parties and blocking of content-type sniffing. On routes where a session identifier travels in the URL, no referrer is sent at all. |
| Protection of data during storage | Recordings are held in a private store whose address is never published: each playback generates a signed link that expires after sixty seconds. The database stores the file path, never a permanent address. |
| Physical security of processing locations | Kobem operates no data centres of its own. Physical processing is carried out by the infrastructure providers identified in the sub-processor list, in their certified facilities. |
| Event logging | Administrative access to a customer account is written to an audit log. The platform also retains execution logs for the service and for the handling of each call. |
| System configuration and secret management | No credential is written into the source: all are injected as environment variables by the hosting provider, and files that could contain them are excluded from version control. Elevated-privilege keys are used on the server only and are never exposed to the browser. |
| Data minimisation | Only the data necessary to provide the service is processed, as described in Schedule 1. The dashboard warns the customer when a question they configure may touch a special category of data under Article 9 GDPR, and records that warning. |
| Limited data retention | Retention periods are those in Schedule 1. The customer can delete any call, with its recording and transcript, at any time and without our involvement. No artificial-intelligence provider retains conversation content or uses it to train models. |
| Portability and erasure | The customer can view, export and delete data from their dashboard without Kobem's involvement. Requests they cannot resolve themselves are handled by writing to contact@kobem.ai. |
| Technical and organisational measures of sub-processors | Kobem engages each sub-processor under a data processing agreement with protection obligations equivalent to those in this Addendum, and remains liable to the customer for the performance of all of them. |
Measures may evolve with the state of the art. Kobem will not reduce the level of security during the term of the agreement. Kobem does not currently hold SOC 2 or ISO 27001 certification, and states so expressly rather than implying otherwise.
Schedule 3 · Cross-border transfer mechanisms
Kobem is established in the United Arab Emirates, outside the European Economic Area, and some sub-processors process data in the United States. Where the processing is subject to the GDPR, those transfers rely on the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, which are deemed incorporated into this Addendum by reference and entered into by both parties on acceptance of the agreement.
Module Two (controller to processor) applies where the customer is a controller, and Module Three (processor to processor) where the customer acts as a processor on behalf of a third party. In clause 7 the docking clause does not apply; in clause 9, Option 2 applies, with the thirty-day notice period in clause 6 of this Addendum; in clause 11 the optional language does not apply; in clause 17 Irish law governs and in clause 18(b) the courts of Ireland have jurisdiction.
For the purposes of Annex I.A of the Clauses: the exporter is the customer, at the contact details designated in their account; the importer is Kobem, at the data protection contact given in this document. Annex I.B is Schedule 1 of this document, Annex II is Schedule 2, and the list of sub-processors is published on the Sub-processors page. The competent supervisory authority is the Irish Data Protection Commission.
For transfers from the United Kingdom, the ICO International Data Transfer Addendum (version B1.0) applies; for transfers from Switzerland, the Clauses are read with the adaptations of the Swiss FADP, the competent authority being the Federal Data Protection and Information Commissioner.
Schedule 4 · Jurisdiction-specific terms
European Union and European Economic Area. Regulation (EU) 2016/679 applies. This Addendum gives effect to its Article 28(3). The customer may lodge a complaint with the supervisory authority of their Member State.
United Kingdom. The UK GDPR and the Data Protection Act 2018 apply, and references to the GDPR are read as references to that legislation. The competent authority is the Information Commissioner’s Office.
United Arab Emirates. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) applies. Kobem expressly discloses that data is stored in the European Union and that its processing therefore involves a transfer outside the Emirates; the customer authorises that transfer by accepting this Addendum. Call recording requires the prior notice that the service includes by default.
Spain. Alongside the GDPR, Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights applies. The competent authority is the Spanish Data Protection Agency.