Salesflare
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Antwerp-based Belgian B2B sales CRM, founder-controlled, focused on automation and pipeline visibility for SMBs.
Salesflare offers EU hosting in Belgium, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under CRM.
Assessment notes
Antwerp-based Belgian B2B CRM with founder-controlled ownership (Jeroen Corthout, Lieven Janssen) and 10k+ customers; eu_owned ownership is the key positive. The DPA is publicly downloadable as a PDF, but it is the 2018 template and its security annex only links out to a support article rather than naming processors. The Iubenda-hosted privacy policy (last updated 26 March 2024) is the only processor disclosure and it names an almost entirely US stack: Google Cloud Storage and GitHub Pages for backend infrastructure, plus Segment, Intercom, FullContact, Mailchimp, SendGrid, Stripe, Cloudflare, Hotjar and AdRoll. Google Cloud Storage as named backend infrastructure means a US-owned hyperscaler in the data path, so CLOUD Act exposure is material on verified grounds rather than by assumption, and no hosting country is published — hosting_country_iso is null rather than Belgium.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Salesflare
Salesflare is a small, founder-controlled Belgian B2B sales CRM headquartered in Antwerp. Founded in 2014 by Jeroen Corthout and Lieven Janssen, the product targets SMB sales teams with automated CRM data input from email/calendar/social activity, visual sales pipelines, email and link tracking, lead finder credits, personalised email campaigns, and tight integrations with LinkedIn, Gmail, and Outlook. The company reports more than 10,000 paying companies and a 4.8/5 average rating across 400+ public reviews.
For an EU-sovereignty audit the picture is partial: the brand is genuinely Belgian and founder-controlled (no public PE acquisition or US-VC majority on record), the privacy policy is delivered through Iubenda (an EU-based privacy-policy-as-a-service provider), and the marketing site does not advertise any US legal entity. What is thin for procurement-grade buyers is the paperwork rather than the disclosure. The DPA is publicly downloadable, but it is the 2018 template and its security annex names no processors, linking out to a support article instead; there is no separate sub-processors annex. The infrastructure that is named sits in the Iubenda-hosted privacy policy (last updated 26 March 2024): Google Cloud Storage and GitHub Pages for backend infrastructure, plus Segment, Intercom, FullContact, Mailchimp, SendGrid, Stripe, Cloudflare and Hotjar. Google Cloud Storage as named backend infrastructure puts a US-owned hyperscaler in the data path, so CLOUD Act exposure is recorded as Material on disclosed grounds, and because the vendor publishes no data-centre region the hosting country is left unrecorded rather than assumed to be Belgium.
Pricing in EUR is straightforward and contract-friendly: the Growth plan is €29/month (save €10/mo with annual billing), Pro and Enterprise tiers above; a 30-day free trial requires no credit card, and the company commits to "no features we will suddenly charge you extra for that will not be listed on this page." Best fit: Belgian, Dutch, and broader EU SMB sales teams that want a polished pipeline CRM with founder-led ownership and don't require an enterprise-grade DPA at signup. Procurement-led buyers needing a verified EU-only hosting story should ask Salesflare directly for a current DPA with a populated security annex, a named sub-processors list, and the region its Google Cloud storage runs in before committing.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Salesflare
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €24/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
GermanyEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€24/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
— |