Knowbita ("we", "us", "our") operates a multi-tenant Real Estate Sales CRM platform that helps real estate businesses ("Customers") capture, manage and follow up on sales leads. This Privacy Policy explains what data we process, why, and the choices you have. It applies to the Knowbita web application and to data we receive through the Facebook / Meta Lead Ads and Conversions integrations.
1. Who is the data controller
Knowbita acts as a data processor on behalf of each Customer (the real estate business using the platform). The Customer is the controller of the lead data stored in their isolated workspace. Knowbita is the controller for account and platform operational data (login credentials, usage logs). Each Customer's data is stored in a strictly isolated tenant scope and is never shared across tenants.
2. Data we collect
- Account data: name, work email, hashed password, role and organization membership of platform users.
- Lead & customer data: prospect name, mobile number, email, enquiry source, project interest, budget, status and the immutable activity timeline created by your sales team.
- Facebook / Meta Lead Ads data: when a Customer connects a Facebook Page, we receive lead form submissions (the answers a prospect provides on a Meta Lead Ad form, e.g. full name, phone number, email and any custom questions), the lead generation ID, the form ID and the Page ID. We access this data only via permissions the Customer explicitly grants during Facebook login (
pages_show_list,pages_read_engagement,leads_retrieval,pages_manage_ads). - Operational data: IP address, login attempts, audit logs and standard server logs used for security and reliability.
3. How we use Facebook / Meta Lead Ads data
Meta Lead Ads data is used solely to deliver the CRM functionality the Customer signed up for:
- Creating a lead record in the Customer's isolated workspace the moment a prospect submits a Meta Lead Ad form.
- De-duplicating re-enquiries by matching the mobile number to an existing lead within the same workspace.
- Routing the lead to a salesperson (round-robin assignment) and tracking follow-up SLAs.
- Optionally sending back conversion events (e.g. "lead qualified", "site visit booked") to Meta's Conversions API when the Customer configures it, so their ad reporting is accurate.
We never sell lead data, never use it for our own advertising, and never combine one Customer's leads with another's.
4. Access tokens
Facebook Page access tokens obtained during the OAuth flow are encrypted at rest using authenticated encryption and are scoped to the individual Customer organization. They are used only to fetch new leads and to subscribe the Page to lead notifications. Tokens are deleted when a Customer disconnects the Page or requests data deletion.
5. Legal basis & retention
We process data to perform the contract with our Customers and on the basis of the Customer's legitimate interest in managing their sales pipeline. Lead and Meta-sourced data is retained for as long as the Customer maintains an active workspace, or until the Customer or an end user requests deletion. Operational logs are retained for up to 12 months. On account termination, tenant data is permanently deleted within 30 days.
6. Sharing & sub-processors
We share data only with infrastructure sub-processors strictly necessary to run the service (cloud hosting and database). We do not share data with third parties for marketing. We may disclose data if required by law.
7. Your rights & data deletion
End users and Customers may request access, correction or deletion of their data. Facebook users can trigger deletion of the data we received via Meta at any time — see our Data Deletion Instructions. To exercise any right, email privacy@knowbita.com.
8. Security
We enforce tenant isolation on every database query, use bearer-token authentication, hash all passwords, encrypt third-party access tokens, validate webhook signatures, and restrict administrative actions by role.
9. Changes
We will post any changes to this policy on this page and update the effective date above.
10. Contact
Questions about this policy or your data: privacy@knowbita.com.