Next Automate

Privacy Policy

Next Automate CRM · crm.nextautomate.in

Effective 13 September 2026 · Last updated 13 September 2026

Overview

Next Automate operates the Next Automate CRM (the “Service”), a business CRM at crm.nextautomate.in used by our business customers (“Clients”) to manage their sales pipeline. This policy explains what data we collect, why we collect it, how we store it, who can see it, how long we keep it, and how it can be deleted.

Two kinds of personal data pass through the Service:

1. Meta Lead Ads Data

Next Automate accesses Meta Lead Ads data through the Meta Graph API and Meta Marketing API. Where this policy says “Meta” it means Meta Platforms, Inc. and its APIs (Facebook, Facebook Lead Ads, the Graph API and the Marketing API).

1.1 How the data reaches us

A Client connects their own Facebook Page to the Service using Facebook Login, granting the permissions leads_retrieval, pages_show_list, pages_read_engagement, pages_manage_metadata and pages_manage_ads. We then subscribe the Page the Client selected to our app’s leadgen webhook. When a person submits one of that Page’s Lead Ad forms, Meta sends us a leadgen_id and we call the Graph API to retrieve the data that person voluntarily submitted, so it can appear as a lead in the Client’s CRM.

1.2 Exactly which fields we collect

DataDetail
Namefull_name, or first_name and last_name
Email addressemail
Phone numberphone_number / phone
Company and citycompany_name, city, where the form asks for them
Custom questionsAny additional question the Client added to their own Lead Ad form, stored with the lead as submitted
Lead metadataLead ID, form ID, ad ID, Page ID and submission time — used to file the lead correctly and to avoid importing the same lead twice
Page detailsThe connected Page’s name and ID, the name and Facebook user ID of the person who authorised the connection, and the Page access token

We request no more than the above. We do not collect or store Page posts, comments, follower lists, messages, ad-spend data, or any Facebook profile data beyond the identifiers needed to maintain the connection the Client authorised.

1.3 Why we collect it

Solely to deliver the leads generated by the Client’s own advertising into the Client’s own CRM so their sales team can follow up. We do not sell Meta Lead Ads data, do not use it for advertising, do not build profiles from it, do not share it with data brokers, and do not use it to train machine learning models.

1.4 Where and how it is stored

1.5 Who can see it

Only authorised users of the single Client tenant that owns the connected Page, subject to that Client’s own roles and permissions. No other Client can see it. Next Automate staff access it only where necessary for support or to investigate a fault, under access controls and audit logging.

1.6 How long we keep it

1.7 How Meta Lead Ads data is deleted

Lead records themselves belong to the Client whose ad generated them and remain in that Client’s CRM after an app deletion request unless the Client or the lead subject asks us to erase them, as described above — the same way a business keeps an enquiry it received. We honour every such erasure request.

2. Other data we collect

CRM account data

Name, work email, phone number, role and password hash for each user our Client creates, so they can sign in and be assigned work.

Business records the Client enters

Customers, leads, deals, projects, tasks, quotations, invoices, files and messages that the Client or their users create in the Service. This is the Client’s data; we process it only to provide the Service.

Technical data

IP address, browser user agent, timestamps and audit entries for security, abuse prevention and troubleshooting.

Other connected channels

Where a Client connects additional channels — such as WhatsApp Business, Instagram or email — we process the messages and contact details from those channels for the same purpose: delivering them into that Client’s CRM. The storage, access, retention and deletion terms in this policy apply to that data too.

3. Who we share data with

We do not sell personal data and we do not share it for advertising. We disclose it only to:

4. Security

5. Retention

DataRetained for
Meta Lead Ads lead recordsLife of the Client account, then deleted within 90 days of closure
Facebook Page access tokensDestroyed on disconnect, deauthorization, deletion request or token invalidation
Facebook connection audit events24 months
CRM user accountsLife of the Client account, then deleted within 90 days of closure
Security and access logs12 months

Deletion requests are honoured ahead of these periods, except where we are legally required to retain a record (for example, tax records relating to an invoice).

6. Your deletion rights and how to exercise them

You may ask us to access, correct, export or permanently erase personal data we hold about you. Email support@nextautomate.in with enough detail to locate the record — for a lead, the email address or phone number submitted, and the business you submitted it to. We verify every request, complete it within 30 days, and confirm in writing.

Where the data is a lead in a Client’s CRM, the Client is the controller: we will action the erasure and notify that Client, or direct you to them where the law requires the controller to respond. You may also contact us to withdraw consent, object to processing, or complain to your local data protection authority.

Facebook users can additionally trigger deletion directly from Facebook — see section 1.7. A full description of that flow, including the callback URLs, is on our data deletion instructions page.

7. Children, changes and contact

The Service is a business tool and is not directed at children under 16; we do not knowingly collect their data.

If we change this policy we will update the “Last updated” date above, and will notify Clients in the application where the change is material.

Contact / Grievance Officer
Next Automate
Email: support@nextautomate.in
Web: crm.nextautomate.in