Back to Tools
Salesflare logo

Salesflare

Partially Compliant

Belgian CRM that fills itself from email and calendar data, with thin public compliance documentation.

🇧🇪Belgium

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paid
Salesflare website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryBelgium
OwnershipEuropean-owned
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
UnknownNot stated. The privacy policy names "Google Cloud Storage ... a hosting service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing" without identifying which, or naming a region; read 2026-08-24.
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Entity confirmed from the terms of service: "Salesflare BVBA, a company incorporated in Belgium having its registered office at Rijnkaai 37 box 4, 2000 Antwerp, Belgium", with exclusive jurisdiction in Antwerp. EU-owned. Compliance documentation is thin: the public privacy policy is a generic iubenda template that names no controller entity, states no hosting region, and publishes no sub-processor list, offering instead that "the updated list of these parties may be requested from the Owner at any time". Google Cloud Storage is named as the hosting service, attributed ambiguously to "Google LLC or ... Google Ireland Limited". Google is a US company, so CLOUD Act reach over the host applies regardless of region, hence US_CLOUD_ACT. dataHostingLocation is UNKNOWN because no region is published, not because the data is presumed non-EU. No DPA was located. Buyers should request a DPA, a named hosting region and a sub-processor list in writing.

About Salesflare

A CRM That Fills Its Own Fields

Salesflare's design starts from the observation that sales teams do not update CRMs. It reads email, calendar and phone activity and builds contact and company records from it, enriches them from public sources, and surfaces what needs following up rather than waiting for someone to log it.

The result is a pipeline tool aimed at small B2B teams that want the reporting without the data entry discipline that Salesforce assumes. Gmail, Outlook and LinkedIn sidebars keep it in the tools sales people already have open.

Belgian, With Documentation Gaps

The terms name "Salesflare BVBA, a company incorporated in Belgium having its registered office at Rijnkaai 37 box 4, 2000 Antwerp, Belgium", with exclusive jurisdiction in Antwerp. That is a straightforward European company.

The compliance documentation is where this listing loses marks. The public privacy policy is a generic iubenda template. It names Google Cloud Storage as a hosting service but states no region, names no legal entity as controller, and links no data processing agreement. The sub-processor position is "the updated list of these parties may be requested from the Owner at any time", which is not a published list.

Google Cloud is operated by a US company, so wherever the region is, the CLOUD Act reaches the host. Without a stated region we cannot say whether the data is even physically in Europe.

What to Ask

For a small team this may be a formality. For anyone whose processing register needs to name a hosting region and a sub-processor list, request both in writing before signing, along with a DPA. A Belgian company should have no difficulty providing them; it simply has not published them.

Other European CRMs, several with far better documentation, are listed under CRM.

Key Features

Automatic contact and company capture from email and calendar
Email tracking and sequences
Gmail, Outlook and LinkedIn sidebars
Visual pipeline with drag-and-drop stages
Automated data enrichment from public sources
Mobile apps with call and meeting logging

Pros & Cons

Belgian company with Antwerp jurisdiction
Automatic capture removes most manual CRM data entry
Sits inside Gmail, Outlook and LinkedIn rather than beside them
Privacy policy is a generic template naming no controller and no hosting region
No published sub-processor list, only available on request
No data processing agreement published
Hosted on Google Cloud, so a US provider holds the data

Categories

Salesflare on EuropeanMartech

Salesflare GDPR & data protection: common questions

Is Salesflare GDPR compliant?

Partly. Salesflare meets some of the requirements, with caveats worth reading before you commit. Salesflare is a European company headquartered in Belgium.

Where does Salesflare store data?

Salesflare states: "Not stated. The privacy policy names "Google Cloud Storage ... a hosting service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing" without identifying which, or naming a region; read 2026-08-24.". Data is hosted in a location we have not been able to verify.

Does Salesflare offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Salesflare. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover →

Is Salesflare a European company?

Yes. Salesflare is headquartered in Belgium and, as far as we can establish, European-owned.

Is Salesflare subject to the US CLOUD Act?

Indirectly. Salesflare itself is European-owned and headquartered in Belgium, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.

Schrems II compliance checklist →

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Salesflare and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.