Lime CRM
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swedish public-listed Nordic + DACH CRM (Lime Technologies, since 1990), 1M+ users, vertical-tailored, agnostic to single-vendor lock-in.
Lime CRM offers EU hosting in Sweden, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under CRM.
Assessment notes
Lime Technologies Sweden AB (Org. nr 556397-0465) is a publicly-listed Swedish enterprise software company operating Lime CRM, Lime Go, Lime Connect, and Lime Intenz with 1M+ users across 6 European markets (SE, DK, DE, FI, NL, NO). Ownership is the strong signal and is unchanged: Nasdaq Stockholm listed, no controlling US shareholder, EU-operated. The processor chain is the weak one, and it is now published. Lime's sub-processor page names Amazon Web Services (EU) for cloud storage and backup of Lime CRM, Lime Forms and Lime Portal, alongside Nylas Inc. (US and Ireland, calendar integration for Lime Go) and Flatfile Inc. (US entity, processing in Germany, contact import for Lime Go). A US-owned hyperscaler holding customer data at rest is material CLOUD Act exposure under the rubric regardless of the EU region, so the earlier minor flag no longer holds and the score drops from 4 to 3. The Trust Center does confirm ISO/IEC 27001 certification with a published Statement of Applicability, but it describes hosting only as a 'Major Cloud Provider' and publishes no data-centre country, so hosting_country_iso is null rather than Sweden.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Lime CRM
Lime CRM is the flagship product of Lime Technologies Sweden AB (Org. nr 556397-0465), a publicly-listed Swedish enterprise software company that traces back to 1990 (originally as a Lund University spin-off) and now operates across Sweden, Denmark, Germany, Finland, Netherlands, and Norway with more than 1 million users. The product portfolio is unusually broad for a Nordic CRM vendor: Lime CRM (enterprise CRM tailored by vertical), Lime Go (plug-and-play B2B sales CRM), Lime Connect (customer messaging + AI), and Lime Intenz (change-management services). Industry verticals include real estate, manufacturing, energy, retail / wholesale, NGO, services, and consultancy.
For an EU-sovereignty audit the key positive signals are strong: the operating entity is publicly listed on Nasdaq Stockholm (per the investor-relations page at investors.lime-technologies.com), Swedish-incorporated, and no controlling US shareholder is on record; the cap table is a Swedish public free-float with institutional investors and founder/insider holdings. Operations are confined to Nordic and DACH/Benelux markets with explicit EU jurisdiction. Two gaps recorded in May have since closed, and not in the vendor's favour. The Trust Center now publishes an ISO/IEC 27001 certification with a Statement of Applicability, and the sub-processor list names Amazon Web Services (EU) for cloud storage and backup of Lime CRM, Lime Forms and Lime Portal, alongside Nylas Inc. (US and Ireland) and Flatfile Inc. (a US entity processing in Germany) for Lime Go. A US-owned hyperscaler holding customer data at rest puts CLOUD Act exposure at Material regardless of the EU region, and the Trust Center still describes hosting only as a "Major Cloud Provider" without naming a data-centre country.
Pricing is enterprise / volume-negotiated; trial signups offered for both Lime CRM and Lime Go. Best fit: Nordic and DACH SMBs and mid-market companies in real estate, manufacturing, energy, retail, NGO, or consulting verticals that want a publicly-listed Swedish vendor with deep industry templates and multi-product breadth across CRM + customer messaging + change management. Procurement-grade EU-only buyers should ask which AWS region holds their data, since the vendor publishes only "EU", and read the DPA, which is public but served as a scanned PDF without a text layer.
Sub-processor map · not disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Lime CRM
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €24/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
GermanyEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€24/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
— |