
noCRM.io
GDPR CompliantFrench lead management tool with a fully published compliance set: DPA, sub-processor list, technical measures and legal notices.
Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.
Paid
GDPR Compliance Data
Not independently verified| GDPR Status | GDPR Compliant |
| HQ Country | France |
| Ownership | European-owned , owned by Groupe Positive (France) |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | European UnionSub-processor list dated 30/04/2026: "Amazon Web Services EMEA SARL, 31 Place des Corolles, Tour Carpe Diem, 92400 Courbevoie, France / Application & data hosting and sending of transactional emails / Paris, France / Ireland / Standard Contractual Clauses". Source: assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf (read 2026-08-24). |
| EU Servers Available | |
| Data Processing Agreement | View DPA |
| Sub-processor List | View sub-processors |
| Schrems II Risk | Medium Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
Publisher named in the legal notices as SAS Positive Group Sales Solutions, 3 avenue Antoine Pinay, 59510 Hem, France, registered with the Lille Métropole Trade and Companies Register under 504 497 215, VAT FR75504497215. Parent is Groupe Positive, same address, listed in the sub-processor table as providing central services from Hem, France. EU-owned throughout. Application and data hosting is AWS EMEA SARL processing in Paris and Ireland under SCCs. The dated sub-processor list also names Sentry (Functional Software, Inc., United States) for error tracking, Nylas, Inc. (US company, processing in Ireland) for mailbox integration, Elastic N.V. (Ireland), Gleap GmbH (Austria), Bouncer sp. z o.o. (Frankfurt, Germany) and Covve Visual Network Ltd. (Cyprus, processing in Ireland). Exposure is US_CLOUD_ACT because AWS, Sentry and Nylas are US-owned and can be compelled regardless of processing location. Schrems II risk MEDIUM rather than LOW for the same reason. COMPLIANT on the strength of a published DPA, a dated sub-processor list with locations and safeguards, a technical and organisational measures document and full legal notices, which is more than almost any tool in this category publishes. Note the marketing site itself is hosted by Webflow, Inc. in San Francisco; the application is not.
About noCRM.io
Leads, Not a Database
noCRM.io deliberately refuses to be a full CRM. Every lead has a next action with a date, and the interface will not let a lead sit without one. That single rule is the product: it is aimed at small sales teams whose real problem is leads going quiet, not a lack of custom object modelling.
Leads can be created from email, a business card scan, a web form or a spreadsheet, and a prospecting list feature handles cold outreach separately from the pipeline so the two do not contaminate each other's reporting.
The Documentation Other Vendors Should Copy
This is the strongest compliance package in our CRM category, and it is worth being specific about why.
The legal notices name "SAS Positive Group Sales Solutions", a simplified joint-stock company at 3 avenue Antoine Pinay, 59510 Hem, France, registered with the Lille Métropole Trade and Companies Register under number 504 497 215, with an EU VAT number. Not a marketing claim about being European: a registration number you can look up.
The sub-processor list is dated, names every processor with its full registered address, describes what each one does and states the processing location and safeguard. Application and data hosting is Amazon Web Services EMEA SARL, the Luxembourg entity, processing in Paris and Ireland under standard contractual clauses. Sentry in the United States handles error tracking. Nylas, a US company, processes in Ireland. Elastic, Gleap in Austria, Bouncer in Frankfurt and Covve are each listed with locations.
A DPA and a technical and organisational measures document are published as PDFs alongside it.
The Honest Caveat
Two American companies sit in that chain, Sentry and Nylas, and AWS is a US-owned provider even when contracting through its Luxembourg entity. Under the CLOUD Act, US authorities can reach data those companies hold, including in Paris. noCRM cannot change that, and it does not pretend otherwise. What it does is tell you exactly who touches the data and where, which is what lets a buyer make the decision themselves.
More options in CRM.
Key Features
Pros & Cons
Categories
noCRM.io GDPR & data protection: common questions
Is noCRM.io GDPR compliant?
Yes. On the evidence we checked, noCRM.io meets the requirements European businesses usually need. noCRM.io is a European company headquartered in France, data is hosted within the European Union, and a Data Processing Agreement is published.
Where does noCRM.io store data?
noCRM.io states: "Sub-processor list dated 30/04/2026: "Amazon Web Services EMEA SARL, 31 Place des Corolles, Tour Carpe Diem, 92400 Courbevoie, France / Application & data hosting and sending of transactional emails / Paris, France / Ireland / Standard Contractual Clauses". Source: assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf (read 2026-08-24).". Data is hosted within the European Union.
Does noCRM.io offer a Data Processing Agreement (DPA)?
Yes. noCRM.io publishes a DPA at https://assets.positivegroup-cdn.com/legal/nocrm/EN_DPA.pdf. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.
What a DPA has to cover →Is noCRM.io a European company?
Yes. noCRM.io is headquartered in France and, as far as we can establish, European-owned.
Is noCRM.io subject to the US CLOUD Act?
Indirectly. noCRM.io itself is European-owned and headquartered in France, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is. Standard Contractual Clauses are in place for transfers, which is the required safeguard but does not override a lawful US order.
Schrems II compliance checklist →Who are noCRM.io's sub-processors?
noCRM.io publishes its sub-processor list at https://assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.
Related Tools

Brevo
All-in-one marketing platform with email, SMS, CRM, and automation. French company, EU data hosting.

Teamleader
Belgian CRM combining sales, project management, and invoicing. EU-hosted.

Pipedrive
Sales-focused CRM from Estonia with EU data hosting option.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at noCRM.io and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.