Back to Tools
noCRM.io logo

noCRM.io

GDPR Compliant

French lead management tool with a fully published compliance set: DPA, sub-processor list, technical measures and legal notices.

🇫🇷France🇪🇺EU Hosted🇪🇺 European

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paid
noCRM.io website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryFrance
OwnershipEuropean-owned , owned by Groupe Positive (France)
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
European UnionSub-processor list dated 30/04/2026: "Amazon Web Services EMEA SARL, 31 Place des Corolles, Tour Carpe Diem, 92400 Courbevoie, France / Application & data hosting and sending of transactional emails / Paris, France / Ireland / Standard Contractual Clauses". Source: assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf (read 2026-08-24).
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListView sub-processors
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Publisher named in the legal notices as SAS Positive Group Sales Solutions, 3 avenue Antoine Pinay, 59510 Hem, France, registered with the Lille Métropole Trade and Companies Register under 504 497 215, VAT FR75504497215. Parent is Groupe Positive, same address, listed in the sub-processor table as providing central services from Hem, France. EU-owned throughout. Application and data hosting is AWS EMEA SARL processing in Paris and Ireland under SCCs. The dated sub-processor list also names Sentry (Functional Software, Inc., United States) for error tracking, Nylas, Inc. (US company, processing in Ireland) for mailbox integration, Elastic N.V. (Ireland), Gleap GmbH (Austria), Bouncer sp. z o.o. (Frankfurt, Germany) and Covve Visual Network Ltd. (Cyprus, processing in Ireland). Exposure is US_CLOUD_ACT because AWS, Sentry and Nylas are US-owned and can be compelled regardless of processing location. Schrems II risk MEDIUM rather than LOW for the same reason. COMPLIANT on the strength of a published DPA, a dated sub-processor list with locations and safeguards, a technical and organisational measures document and full legal notices, which is more than almost any tool in this category publishes. Note the marketing site itself is hosted by Webflow, Inc. in San Francisco; the application is not.

About noCRM.io

Leads, Not a Database

noCRM.io deliberately refuses to be a full CRM. Every lead has a next action with a date, and the interface will not let a lead sit without one. That single rule is the product: it is aimed at small sales teams whose real problem is leads going quiet, not a lack of custom object modelling.

Leads can be created from email, a business card scan, a web form or a spreadsheet, and a prospecting list feature handles cold outreach separately from the pipeline so the two do not contaminate each other's reporting.

The Documentation Other Vendors Should Copy

This is the strongest compliance package in our CRM category, and it is worth being specific about why.

The legal notices name "SAS Positive Group Sales Solutions", a simplified joint-stock company at 3 avenue Antoine Pinay, 59510 Hem, France, registered with the Lille Métropole Trade and Companies Register under number 504 497 215, with an EU VAT number. Not a marketing claim about being European: a registration number you can look up.

The sub-processor list is dated, names every processor with its full registered address, describes what each one does and states the processing location and safeguard. Application and data hosting is Amazon Web Services EMEA SARL, the Luxembourg entity, processing in Paris and Ireland under standard contractual clauses. Sentry in the United States handles error tracking. Nylas, a US company, processes in Ireland. Elastic, Gleap in Austria, Bouncer in Frankfurt and Covve are each listed with locations.

A DPA and a technical and organisational measures document are published as PDFs alongside it.

The Honest Caveat

Two American companies sit in that chain, Sentry and Nylas, and AWS is a US-owned provider even when contracting through its Luxembourg entity. Under the CLOUD Act, US authorities can reach data those companies hold, including in Paris. noCRM cannot change that, and it does not pretend otherwise. What it does is tell you exactly who touches the data and where, which is what lets a buyer make the decision themselves.

More options in CRM.

Key Features

Lead-centric pipeline where every lead needs a dated next action
Prospecting lists separated from the active pipeline
Lead creation from email, web forms, spreadsheets and business card scan
Email integration with mailbox sync
Sales scripts and qualification forms
Published DPA, sub-processor list and technical measures documentation

Pros & Cons

French company with a lookup-able registration number, not just a flag
Dated sub-processor list naming every processor, location and safeguard
Application data hosted in Paris and Ireland under standard contractual clauses
The next-action rule genuinely stops leads going quiet
AWS, Sentry and Nylas are US-owned, so CLOUD Act reach applies to the host
Deliberately not a full CRM, so no deep contact or account modelling
Marketing site is hosted by Webflow in San Francisco

Categories

noCRM.io GDPR & data protection: common questions

Is noCRM.io GDPR compliant?

Yes. On the evidence we checked, noCRM.io meets the requirements European businesses usually need. noCRM.io is a European company headquartered in France, data is hosted within the European Union, and a Data Processing Agreement is published.

Where does noCRM.io store data?

noCRM.io states: "Sub-processor list dated 30/04/2026: "Amazon Web Services EMEA SARL, 31 Place des Corolles, Tour Carpe Diem, 92400 Courbevoie, France / Application & data hosting and sending of transactional emails / Paris, France / Ireland / Standard Contractual Clauses". Source: assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf (read 2026-08-24).". Data is hosted within the European Union.

Does noCRM.io offer a Data Processing Agreement (DPA)?

Yes. noCRM.io publishes a DPA at https://assets.positivegroup-cdn.com/legal/nocrm/EN_DPA.pdf. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover →

Is noCRM.io a European company?

Yes. noCRM.io is headquartered in France and, as far as we can establish, European-owned.

Is noCRM.io subject to the US CLOUD Act?

Indirectly. noCRM.io itself is European-owned and headquartered in France, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is. Standard Contractual Clauses are in place for transfers, which is the required safeguard but does not override a lawful US order.

Schrems II compliance checklist →

Who are noCRM.io's sub-processors?

noCRM.io publishes its sub-processor list at https://assets.positivegroup-cdn.com/legal/nocrm/EN_Subprocessors.pdf. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at noCRM.io and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.