Who operates this service
Sense CMS Social is operated by QUANT Software House Limited for the Sense CMS product website. Privacy enquiries can be sent to info@SenseCMS.com. This policy covers the Meta connection broker hosted at www.sensecms.com and the Facebook Publisher extension installed in a licensed Sense CMS website.
Information we process
When an authorised administrator connects Facebook, Meta may provide an app-scoped account identifier, the identifiers and names of Pages they can manage, Page permissions and a Page access token. The customer installation also processes the reviewed post text, selected media, delivery time, provider response identifier and delivery status needed to publish and audit the requested post. We do not request a Facebook password.
How the connection works
The central Sense CMS broker validates the calling CMS licence, completes Meta authorization and transfers the selected Page credential through a short-lived, single-use encrypted claim. Pending broker records are encrypted, expire after ten minutes and are removed after a successful claim. The Page token is then stored encrypted in that customer’s own Sense CMS installation; it is not kept as a reusable credential by the central broker.
Purposes and legal bases
Information is used to connect the Page selected by its administrator, publish content the administrator has reviewed, prevent replay and duplicate delivery, diagnose failed delivery, protect the service and comply with legal obligations. Processing is based on performing the requested service, the customer’s instructions and our legitimate interests in security, reliability and abuse prevention.
Sharing and international transfers
Publishing sends the chosen content and Page token to Meta Platforms through the Graph API. Meta processes that information under its own terms and privacy policy. Infrastructure and security providers may process limited technical data on our behalf under appropriate safeguards. We do not sell Facebook account or Page information.
Retention and security
Central authorization state is short-lived. The customer installation retains its encrypted Page credential until an authorised user disconnects Facebook. Delivery history may be retained for audit and retry safety without retaining the removed credential. Server logs are limited and must not contain access tokens. Access is restricted, transport uses HTTPS and sensitive state is encrypted at rest.
Your choices and rights
An authorised Sense CMS user can disconnect Facebook in Social Publishing, which removes the stored credential and disables further delivery. A Facebook user can also remove the app from Facebook settings. Depending on applicable law, individuals may request access, correction, deletion, restriction or objection by contacting info@SenseCMS.com. Identity and authority may need to be verified before acting on a request.
Changes
We may update this policy when the integration, law or security requirements change. The current version is published at this address. Last updated: 16 September 2026.