This statement describes how Surge Adopt, a product of Sales-Surge B.V. ("Sales Surge", "we", "us"), handles personal data. It supplements the full Sales Surge Privacy Policy (https://www.sales-surge.io/privacy/), which prevails in case of conflict.
1. Controller
Sales-Surge B.V., Professor W.H. Keesomlaan 12, 1183 DJ Amstelveen, The Netherlands. KvK: 99261758. Contact: info@sales-surge.nl.
2. What Surge Adopt processes
Surge Adopt is a tool for driving Pipedrive adoption from within Pipedrive. It processes: (a) account data of authorised users (name, email, authentication identifiers); (b) the API tokens / OAuth connections you provide to link CRM environments; (c) the CRM records and product-usage/telemetry data processed for this purpose, which may include contact names, email addresses, phone numbers, organisation data and related notes/activities. Surge Adopt does not intentionally process special categories of data (Art. 9 GDPR).
3. Legal basis
Performance of a contract and our legitimate interest in operating our services (Art. 6(1)(b) and (f) GDPR). Where Surge Adopt processes CRM data on behalf of a client, Sales Surge acts as processor and the client as controller (see the Data Processing Agreement).
4. Hosting and sub-processors
Surge Adopt runs on Lovable Cloud (powered by Supabase), with data hosted in the EU where available. CRM data is exchanged with the Pipedrive API. All sub-processors are bound by Article 28 GDPR Data Processing Agreements; a current list is available via info@sales-surge.nl.
5. International transfers
We prefer EEA processing. Where transfers outside the EEA occur, we rely on adequacy decisions (incl. the EU-US Data Privacy Framework) and the EU Standard Contractual Clauses (2021/914) with additional safeguards.
6. Retention
Account and connection data is kept for the lifetime of the account; API tokens are deleted when a connection is removed; CRM and telemetry records processed for this purpose are kept only as long as needed and then deleted or anonymised, subject to statutory retention obligations.
7. Security
TLS in transit and encryption at rest, role-based access control and row-level security, MFA on administrative access, logging and incident response (Art. 32 GDPR).
8. Your rights
Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), and the right to complain to the Autoriteit Persoonsgegevens. Contact info@sales-surge.nl.