Run your CRM under GDPR without guessing who is responsible
GDPR is a law you comply with, not a certificate you hold. No CRM can be GDPR certified, and any vendor claiming otherwise is worth a second look. What a CRM vendor can do is act as a competent processor: handle personal data only on your instructions, secure it properly, disclose its subprocessors, and help you answer the requests your own customers and prospects send you. This page explains the controller and processor split, what Article 28 requires in a contract, how transfers work, and what HelloGrowthCRM does as a processor. It also sets out plainly which duties stay with you as controller.
Controller and processor: who is responsible for what
GDPR splits responsibility between two roles. The controller determines the purposes and means of processing. The processor processes personal data on the controller's behalf and on its documented instructions. When you use a sales CRM, you are almost always the controller and the vendor is the processor. You decided to collect prospect names and business email addresses, you chose why, and you decided how long to keep them. The vendor supplies the system that stores them. This is not a technicality. It determines who a regulator writes to, who must respond to an access request, and who must be able to justify the processing at all.
Being the controller means several duties are yours and cannot be outsourced by contract. You choose and record a lawful basis. You provide the privacy notice at the point of collection. You decide retention and delete records when the purpose ends. You handle data subject requests, decide whether exemptions apply and respond within the deadline. You run a data protection impact assessment where the processing is high risk. A vendor can give you tools that make each of these easier, and a good vendor will, but the accountability sits with you under Article 5(2) and cannot be transferred to a supplier by agreement.
The processor has its own direct obligations, and they are enforceable against the processor. It must act only on your documented instructions, secure the data under Article 32, keep staff under confidentiality obligations, manage subprocessors properly, assist you with data subject requests and breach handling, and delete or return data at the end of the service. One point deserves attention during vendor evaluation. If a vendor uses your CRM data for its own purposes, such as building its own products or marketing lists, it may be acting as a controller for that activity. Ask the question directly, and check that the contract answers it.
Choosing a lawful basis for CRM data
Every processing activity needs a lawful basis under Article 6, and there are six: consent, contract, legal obligation, vital interests, public task and legitimate interests. In a B2B sales CRM, three come up repeatedly. Contract covers processing needed to deliver something the person has asked for or to take pre-contract steps at their request. Legitimate interests often covers business development and account management, provided the balancing test genuinely holds. Consent covers activities where the law or your own risk appetite requires an unambiguous opt-in, and it must be freely given, specific, informed and as easy to withdraw as it was to give.
Legitimate interests is the basis most sales teams rely on, and it is the one most often applied loosely. It requires a documented three part test: identify the interest, show the processing is necessary for it, and balance it against the rights and reasonable expectations of the individual. Write that assessment down before you start, not after a complaint arrives. Remember also that electronic marketing is governed separately by the ePrivacy rules as implemented in each member state, so a valid Article 6 basis for storing a contact record does not by itself authorise sending that contact a marketing email today.
Two practical habits reduce risk considerably. First, keep special category data out of the CRM. Article 9 sets a much higher bar for data revealing health, religion, trade union membership, political opinions and similar categories, and free-text notes fields are where this data usually enters a CRM by accident. Train your team on what not to type. Second, set retention rules per record type and then actually enforce them. Holding a cold prospect record indefinitely because nobody deleted it is a storage limitation problem under Article 5, and it is entirely within your control to fix without vendor help.
Article 28 and what your DPA must contain
Article 28 requires a written contract between controller and processor, usually called a data processing agreement. It must set out the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subject, and the controller's rights and obligations. It must then bind the processor to a specific list of commitments: process only on documented instructions including for transfers, ensure personnel are under confidentiality obligations, implement Article 32 security measures, respect the rules on engaging subprocessors, assist with data subject requests, assist with obligations under Articles 32 to 36, delete or return data at the end, and make information available for audits.
When reviewing any vendor DPA, read for the parts that are commonly weakened. Check that subprocessor changes come with advance notice and a real opportunity to object, rather than a clause saying the list may change at any time. Check the audit clause: many vendors satisfy it by providing an independent report such as SOC 2 rather than admitting on-site auditors, which is normal and workable, but the mechanism should be stated. Check the end of service terms, including how deletion is confirmed and how long backups persist. Check that assistance with data subject requests is an obligation, not a chargeable professional services engagement.
HelloGrowthCRM makes a DPA available, and you should request and read it from sales@hellogrowthcrm.com before you load EU or UK personal data into a workspace. Alongside it, ask for the SOC 2 Type II report, which Soor LLC completed for the February to June 2025 observation window and shares under NDA. Together those two documents answer most of what Article 28 asks you to verify: the contractual commitments in the DPA, and independent evidence of the security measures in the report. Reviewing them at the same time is faster than treating security and privacy as two separate procurement exercises.
Transfers, subprocessors and hosting
Chapter V of the GDPR restricts transfers of personal data outside the EEA unless a safeguard applies. The common routes are an adequacy decision covering the destination country, or the European Commission's 2021 Standard Contractual Clauses, which come in modules for different controller and processor combinations. For UK data, the UK GDPR uses the ICO's International Data Transfer Agreement or the Addendum to the EU clauses. Since the Schrems II judgment, using the clauses is not enough on its own. You are expected to run a transfer impact assessment considering the destination country's laws and any supplementary technical measures, such as encryption, that reduce the risk.
Subprocessors are the vendors your vendor uses, and they matter because your data reaches them. Article 28 requires prior authorisation, either specific or general, and where authorisation is general the processor must notify you of intended changes and give you the chance to object. In practice most vendors operate a published list plus a notice mechanism. HelloGrowthCRM publishes its subprocessor list at /subprocessors. Review it before signing, and check it again at renewal. A vendor that will not tell you which providers touch your data cannot support you in a transfer assessment, because you cannot assess a destination you are not permitted to know about.
For HelloGrowthCRM, customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer. Data is encrypted in transit with TLS and encrypted at rest, which are exactly the kind of supplementary technical measures a transfer assessment looks for. The specific hosting region for your workspace is confirmed during onboarding, so raise data residency early if your own customer contracts or sector rules constrain where data may sit. Getting that answer in writing before implementation is far easier than discovering a constraint after your team has already migrated its pipeline into the system.
Data subject rights, security and breach notification
GDPR gives individuals rights of access, rectification, erasure, restriction, portability and objection, plus rights concerning solely automated decision making. Controllers generally must respond within one month, extendable by two further months for complex or numerous requests, with the individual informed of the extension. As controller you decide whether a request is valid, whether an exemption applies and what to disclose. Your processor's job is to make the underlying data reachable. Practically, that means you need to be able to search across records, export what you find, correct inaccuracies and delete a person from the system without leaving orphaned fragments behind anywhere.
HelloGrowthCRM supports this operationally. Workspace admins can export contacts, deals and activity data at any time, which serves both access and portability requests and gives you a route out of the product if you ever want one. Account deletion is honoured. Role-based access control inside each workspace lets you limit who can view or change records while a request is being handled. How data rights requests are handled is documented at /legal/data-rights. Data-handling practices align with India's DPDPA, and EU, UK and California customers have equivalent access, correction and erasure rights, so the same operational routes serve several regimes at once.
Article 32 requires security appropriate to the risk, and Articles 33 and 34 govern breaches. A controller must notify its supervisory authority without undue delay and where feasible within 72 hours of becoming aware, and must tell affected individuals where the risk to their rights is high. A processor must notify the controller without undue delay, which is why the vendor's incident process directly affects whether you can meet your own deadline. HelloGrowthCRM operates a documented incident-response workflow covering detect, contain, assess, remediate and notify, and runs automated backups with point-in-time recovery to support the restoration expectations in Article 32.
Controls and capabilities at a glance
- HelloGrowthCRM acts as your processor and processes workspace data on your documented instructions, while you remain the controller for the data you collect.
- A DPA is available from sales@hellogrowthcrm.com; review its Article 28 terms before loading EU or UK personal data into a workspace.
- The subprocessor list is published at /subprocessors so you can review every third party involved before signing and again at renewal.
- Customer records live in Supabase-managed Postgres on AWS, with row-level security enforcing tenant isolation at the database layer rather than in application code alone.
- Data is encrypted in transit with TLS and encrypted at rest, providing the supplementary technical measures a transfer impact assessment looks for.
- Workspace admins can export contacts, deals and activity data at any time, which serves both access requests and portability requests under Article 20.
- Account deletion is honoured, and how data rights requests are handled is documented at /legal/data-rights for your privacy team to review.
- Role-based access control lets you restrict who inside your workspace can view or change contact records, supporting data minimisation in daily practice.
- A documented incident-response workflow covering detect, contain, assess, remediate and notify supports your own Article 33 notification deadline as controller.
- Production access is least-privilege, MFA-gated, logged and periodically reviewed, and those measures sit within the SOC 2 Type II covering February to June 2025.
Questions reviewers ask
- Is HelloGrowthCRM GDPR certified?
- No, and neither is any other CRM. GDPR is a regulation you comply with, not a certification scheme with certificates issued to products. Article 42 does allow for approved certification mechanisms, but these are limited in scope and rarely what vendors mean when they use the phrase. What HelloGrowthCRM can do is act as a processor that meets Article 28 obligations, provide a DPA, publish its subprocessor list at /subprocessors, secure data appropriately and support your handling of data subject requests. Treat any claim of GDPR certification as a prompt for more questions.
- Are we the controller or the processor?
- If you decide what prospect and customer data to put into the CRM and why, you are the controller. HelloGrowthCRM is the processor, acting on your documented instructions. This matters because controller duties cannot be contracted away. You choose the lawful basis, publish the privacy notice, set retention periods, decide how to answer data subject requests and remain accountable to your supervisory authority. The processor secures the data, discloses its subprocessors, assists you with requests and breaches, and returns or deletes data when the service ends.
- What lawful basis should we use for CRM contacts?
- That is your decision as controller, and it depends on the activity rather than the tool. In B2B sales, legitimate interests commonly covers business development and account management, provided you document the three part test balancing your interest against the individual's rights and reasonable expectations. Contract covers processing needed to deliver something the person requested. Consent is required where you rely on it or where local ePrivacy rules demand it for electronic marketing. Record the basis for each activity before you start, and review it when the activity changes.
- Where is our data stored, and are there transfers?
- Customer records live in Supabase-managed Postgres on AWS. The specific hosting region for your workspace is confirmed during onboarding, so raise residency requirements early if your own contracts or sector rules constrain where data may sit. Review the published subprocessor list at /subprocessors to see which providers are involved in delivering the service, and request the DPA to review the transfer terms that apply to your agreement. Those two documents plus the encryption measures in place are the inputs your transfer impact assessment needs.
- How do we handle a data subject access request?
- You handle it as controller, and you generally have one month to respond, extendable by two further months for complex or numerous requests if you inform the individual. Operationally, you need to find every record relating to the person, decide what to disclose, and produce it. Workspace admins can export contacts, deals and activity data at any time, which covers both access and portability. Corrections and deletion can be made directly in the workspace. How requests are handled on our side is documented at /legal/data-rights.
- What happens to our data if we leave?
- Export first, then delete. Workspace admins can export contacts, deals and activity data at any time, so take a full export before you close the account rather than after. Account deletion is honoured. Read the deletion and return provisions in the DPA before signing, since Article 28 requires the processor to delete or return personal data at the end of the service, and you should understand the mechanism and how deletion propagates through backups. Ask for written confirmation once the deletion is complete.
- Do we need a DPIA to use a CRM?
- Usually not for ordinary B2B contact management, but the decision is yours as controller. Article 35 requires a data protection impact assessment where processing is likely to result in high risk, particularly for large scale processing, systematic monitoring or special category data. Standard sales pipeline data about business contacts rarely meets that bar on its own. It can if you combine the CRM with enrichment, behavioural tracking, profiling or automated decisions affecting individuals. Assess your actual configuration rather than the product category, and document the conclusion either way.
- How will we hear about a breach?
- As processor, HelloGrowthCRM must notify you without undue delay after becoming aware of a personal data breach, so that you can meet your own obligation to notify your supervisory authority without undue delay and where feasible within 72 hours. A documented incident-response workflow covers detect, contain, assess, remediate and notify. Make sure your DPA records the notification route and that we hold current contact details for your privacy team, because a notification sent to a dormant inbox helps nobody meet a deadline.
Get the DPA and subprocessor list
Email sales@hellogrowthcrm.com to request the data processing agreement and the SOC 2 Type II report under NDA. The subprocessor list is already published at /subprocessors, and data rights handling is documented at /legal/data-rights, so your privacy team can start its review today.