Privacy Policy

What personal information we hold, why, and what you can ask us to do with it.

In effect from 16 Sept 2026 · Last updated 16 Sept 2026


This policy explains what personal information [Your registered company name] ("we", "us") collects through the Realto Xperts service, why we hold it, and what you can ask us to do with it.

Two different roles

This matters, because it decides who is answerable to whom.

  • Your account data — the names, emails and phone numbers of the people at your business who sign in, plus your billing details. We decide how that is used, so for it we are the data fiduciary (controller).
  • The data you put into the CRM — your leads, customers, site visits, bookings and payments. You decide what to collect and why; we only store and process it so the Service works. For that we are a data processor acting on your instructions, and you are answerable to those individuals. Making sure you have a lawful basis to collect and use their information is your responsibility.

What we collect

From you, when you use the Service

  • Account details: name, work email, mobile number, role, and the organisation you belong to.
  • Billing details: company name, address, GSTIN or PAN where required for invoicing, and payment references. We do not store full card numbers.
  • Sign-in and security records: timestamps, IP address, browser and device, two-step verification status.
  • Usage records: which pages and features were used, and an audit log of changes made to records — who changed what and when. The audit log cannot be edited or deleted, by anyone, including us.
  • Anything you send us in a support request.

Data you upload

Whatever you choose to put in: lead and customer names, phone numbers, email addresses, budgets and requirements, notes your team writes, visit and booking records, payment schedules, and identity or bank details where you record them.

Why we hold it

  • To provide the Service and keep your account working.
  • To keep it secure — detecting and investigating unauthorised access, abuse and fraud.
  • To bill you and keep the accounting and tax records we are required to keep.
  • To support you when you ask, and to tell you about material changes to the Service.
  • To improve the Service, using aggregate usage patterns. We do not read the contents of your CRM records to do this.

What we do not do

  • We do not sell personal information, and we never have.
  • We do not share your CRM data with our other customers, or use one customer's data to benefit another.
  • We do not use your CRM data to train models.
  • We do not send marketing to the leads and customers in your CRM. Any message to them is one you sent.

How it is protected

  • Every account is a separate tenant. Queries are scoped to the account, and permissions and data scopes limit what each user sees inside it — down to only their own records where you set it that way.
  • Sensitive fields, including PAN, Aadhaar and bank account numbers, are encrypted before they are stored.
  • Traffic between your browser and the Service is encrypted in transit.
  • Phone numbers and email addresses are masked for roles that do not need to see them, and exports by those roles are masked too.
  • Every export of personal data is recorded in the audit log before the file is produced.
  • Access to production systems is limited to staff who need it for support or operations.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant authority as the law requires.

Who else sees it

We use service providers to run the Service — cloud hosting, database hosting, email and SMS delivery, and error monitoring. They act on our instructions and only to the extent needed to provide their part. In addition:

  • Integrations you switch on send data to those providers using credentials you supply. You control which are connected.
  • We may disclose information where the law requires it, or to establish or defend a legal claim.
  • If our business is acquired or merged, information may transfer as part of it; you will be told before that happens.

Where it is stored

The Service runs on cloud infrastructure. State the region your deployment actually uses before publishing this page — do not describe a location you have not configured.

How long we keep it

  • CRM data stays while your account is open, and you can delete records yourself at any time.
  • After an account closes we keep it for a limited period so you can ask for a copy, then delete it.
  • Invoices and accounting records are kept for as long as tax law requires.
  • Audit and security logs are kept for a limited period, because they are append-only and exist to show what happened.

Fill in the actual periods above before publishing.

Your rights

Depending on where you are, you may ask us to give you a copy of your personal information, correct it, delete it, or restrict how we use it, and you may withdraw consent where we relied on it. Write to [email protected] and we will respond within the period the law allows.

If you are a lead or customer whose details are in a CRM account here, the business that collected them is responsible for them, not us. Contact that business. If you contact us we will pass your request to them and help them act on it.

Cookies

We use cookies only to keep you signed in, protect forms against cross-site request forgery, and remember interface preferences. No advertising or cross-site tracking cookies are set. Blocking the sign-in cookie stops the Service from working.

Grievance officer

Indian law requires a named grievance officer with contact details. Add the name, designation, address and email here before publishing.

Changes

We will update this page when our practices change, and note the date at the top. If a change materially affects you we will tell you in the product or by email.

Contact

[email protected]


Questions? [email protected]