Privacy Policy
Last Updated: June 25, 2026
Sirma Technology (“Company,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Kords (“Service”), including our integration with Google API Services.
1. Information We Collect
We may collect the following types of information:
1.1 Information You Provide to Us:
Account Information: When you create an account, we collect your name, email address, phone number, company name, and other relevant details.
Content and Communications: Any data you provide through forms, messages, or property listings.
Google Calendar Data: If you choose to use our Google Calendar synchronization feature, we collect and process event data (titles, times, and descriptions) from your Google Calendar.
1.2 Information Collected Automatically:
Usage Data: Information about your interactions with the Service, such as IP address, browser type, and pages viewed.
Cookies and Tracking Technologies: We use cookies to enhance your experience and gather analytics.
2. How We Use Your Information
We use the information we collect for the following purposes:
To Provide and Improve Services: To deliver, maintain, and enhance our platform features, including the synchronization of real estate appointments.
To Communicate: To send you updates and support messages.
To Ensure Security: To monitor and protect against unauthorized access.
To Comply with Legal Obligations: To adhere to applicable laws and regulations.
AI Processing: We use OpenAI’s API to process certain user-provided content (such as property details or lead notes) to generate summaries, descriptions, and insights. No personal identifiers are used to train OpenAI’s global models.
3. Sharing Your Information
We may share your information in the following circumstances:
With Service Providers: Trusted third-party vendors who assist us in operating the Service.
For Legal Purposes: If required by law or government request.
With Your Consent: When you explicitly agree to share your data.
Non-Disclosure of Google Data: Notwithstanding the above, Google user data is never shared with third-party vendors or used for advertising purposes.
4. How We Use Meta Platform Data
Kords uses Meta Platform Data only to provide features requested by authorized business users.
We use Meta Platform Data for the following purposes:
Account Connection and Authentication
We use basic Meta profile information to identify the user who connects their Meta account to Kords and to show the connected account inside the Kords dashboard.Facebook Page Selection and Connection
We use Facebook Page data to show the user the Pages they manage or have access to, so they can select which Page they want to connect to Kords.Lead Retrieval and CRM Management
We use Facebook Lead Ads data to retrieve leads submitted through connected Facebook Lead Ads forms and display them inside Kords CRM.
This allows businesses to view, organize, assign, follow up with, and manage leads inside their workspace.Page Engagement and Business Insights
We may use Facebook Page engagement data to help authorized users review Page activity, engagement, and performance-related information inside Kords.Advertising Account and Campaign Management
We use Meta ad account and campaign data to allow authorized users to manage Meta advertising workflows inside Kords.
This may include viewing, creating, updating, or managing campaigns, ad sets, ads, budgets, targeting settings, and campaign performance data.Meta Business Asset Management
We use Meta Business data to allow authorized business users to connect and manage business assets such as Pages, ad accounts and related Meta assets.Integration Maintenance and Security
We use access tokens, authorization tokens, webhook data, logs, and related metadata to maintain the Meta integration, process authorized API requests, troubleshoot issues, prevent unauthorized access, and keep the Service secure.
Kords does not use Meta Platform Data for unrelated purposes.
Kords does not sell, rent, trade, or share Meta Platform Data with third parties for advertising or marketing purposes.
Kords only accesses Meta Platform Data after the user grants permission through Meta Login, Facebook Login, Meta Business authorization, or another approved Meta authorization flow.
Users remain in control of the Meta accounts, Facebook Pages, ad accounts, lead forms, and business assets they choose to connect to Kords.
5. Meta Platform Data and Integration
Kords may allow authorized business users to connect their Meta account, Facebook Pages, Meta Business assets, ad accounts, and Facebook Lead Ads forms to the Service.
When a user connects Meta integrations to Kords, we only request permissions that are necessary to provide CRM, lead management, page management, advertising management, and business workflow features selected by the user.
The Meta permissions we may request include:
public_profile: Used to identify the Meta user who connects their account to Kords and to display basic account information inside the dashboard.pages_show_list: Used to display the Facebook Pages that the user manages or has access to, so the user can select which Page to connect to Kords.pages_manage_metadata: Used to access and manage basic Page metadata required to maintain the connection between Facebook Pages and Kords.pages_read_engagement: Used to read engagement information from connected Facebook Pages, such as Page activity, comments, messages, or performance-related information where available and permitted.leads_retrieval: Used to retrieve leads submitted through Facebook Lead Ads forms connected to the user’s Facebook Page and display them inside Kords CRM.pages_manage_ads: Used to help authorized users manage Page-related advertising features connected to their Facebook Pages.ads_management: Used to allow authorized business users to create, read, update, and manage Meta advertising campaigns, ad sets, ads, budgets, targeting settings, and campaign performance data from within Kords.business_management: Used to allow authorized business users to connect and manage Meta Business assets, including Pages, ad accounts, business users, and related business assets.Marketing API Access Tier: Used to provide advertising and campaign management features for authorized business users through Meta’s Marketing API.
Data received from Meta may include basic profile information, Facebook Page IDs and names, Meta Business IDs, ad account IDs, lead form IDs, lead data submitted through Facebook Lead Ads forms, advertising campaign data, Page engagement data, access tokens, authorization tokens, webhook data, and integration logs.
Kords uses Meta Platform Data only to provide the features requested by the authorized user, including account connection, Page selection, CRM lead retrieval, lead management, Page engagement review, advertising management, campaign reporting, and business asset management.
Kords does not sell, rent, trade, or share Meta Platform Data with third parties for advertising or unrelated purposes.
Access to Meta Platform Data is limited to authorized users and personnel who need access to operate, support, secure, or maintain the Service.
Meta access tokens and integration credentials are stored securely and used only to communicate with Meta APIs on behalf of the authorized user.
Users may disconnect their Meta integration at any time from Kords settings, where available, or by contacting Kords support. When a Meta integration is disconnected or a deletion request is received, Kords will stop processing new Meta data for that integration and will delete stored Meta integration data where permitted, including access credentials, Facebook Page connection records, Meta Business connection records, ad account connection records, Lead Ads data, webhook records, logs, and related metadata.
Deleting Meta integration data from Kords does not necessarily delete data stored directly by Meta. Users may also need to manage or delete data directly through Meta Business Manager, Facebook Pages, Meta Ads Manager, or other Meta tools.
Kords retains Meta Platform Data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, maintain security, or enforce agreements. Where retention is required, we retain only the data necessary for the applicable purpose and limit access to it.
For questions or requests related to Meta Platform Data, including access, correction, disconnection, or deletion requests, please contact us at:
Email: support@kords.ai
6. Google API User Data Policy
Kords’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Access: We only request the minimum necessary scopes (
auth/calendar.events) to sync your real estate tasks and viewings.Usage: We use Google Calendar data solely to display your schedule within Kords and to write Kords-specific events to your Google Calendar.
Storage: Google Calendar event data is cached only to facilitate the synchronization process.
Sharing: We do not share, sell, or trade Google user data with third parties.
7. Data Security and Protection Mechanisms
We implement industry-standard security measures to protect your sensitive data, including data received via Google APIs:
Encryption in Transit: All data transmitted between your browser and our servers, or between Kords and Google APIs, is encrypted using Secure Socket Layer (SSL/TLS) technology.
Encryption at Rest: Sensitive information and Google-sourced data are stored using advanced encryption standards (e.g., AES-256) to prevent unauthorized access.
Access Controls: Access to user data is strictly limited to authorized personnel who require it to maintain the service, following the principle of least privilege.
Monitoring: We conduct regular security audits and monitoring to detect and prevent potential vulnerabilities.
8. Data Retention and Deletion
We retain your data only for as long as necessary to provide our services.
Google User Data Retention: Google Calendar data is cached only while your Google integration is active. We do not store permanent copies of your entire calendar history.
Deletion upon Disconnection: If you disconnect the Google Calendar integration from within Kords settings, all cached Google user data is immediately and permanently deleted from our servers.
Account Termination: If you delete your Kords account, all associated data, including any data derived from Google APIs, will be purged from our databases within 30 days, unless retention is required by law.
Revoking Access: You may revoke Kords’ access to your Google data at any time via your Google Account Security Settings. Upon revocation, we will no longer be able to sync data, and existing cached data will be deleted.
9. Contact Us
If you have questions or concerns about this Privacy Policy or our handling of Google data, please contact us at:
Email: support@kords.ai
Organization: Sirma Technology