Skip to content

Privacy Policy

Last updated:

How Sales Surge handles personal data as a controller when you use Surge Revenue Desk, pay for it, contact us or visit these pages.

Draft for legal review
This document has 2 open points, highlighted below. They will be resolved before the document takes effect.

Sales-Surge B.V. ("Sales Surge", "we", "us") builds and operates Surge Revenue Desk, a helpdesk and customer success app for Pipedrive. This policy explains which personal data we process as a controller, why, on which legal basis, how long we keep it and which rights you have under the General Data Protection Regulation (GDPR).

1.Who we are

Controller
Sales-Surge B.V.
Address
Professor W.H. Keesomlaan 12, 1183 DJ Amstelveen, the Netherlands
Chamber of Commerce (KVK)
99261758
Privacy questions
info@sales-surge.nl

2.Controller or processor

This policy covers personal data we decide about ourselves: the people at our customers who use the app, billing contacts, people who contact us, and visitors of these pages.

Our customers also use the app to handle their own customer conversations. The tickets, messages, attachments and CRM contacts they process in the app belong to them. For that data the customer is the controller and we are its processor, bound by our Data Processing Agreement.

Did you email the support team of a company that uses Surge Revenue Desk? Then that company decides about your data. Please contact them directly. If you send your request to us, we pass it on to them.

3.What we process and why

Whose dataPersonal dataPurposeLegal basis
Users of the app (people at our customers)Name, email address, Pipedrive user and company ID, profile picture link, role, language, last activity time, and the actions recorded in the audit log.Giving you access with the right role, showing who did what, and keeping an audit trail for security.Legitimate interest (article 6(1)(f) GDPR) in delivering the service your employer subscribed to and keeping it secure.
Users of the appPipedrive access and refresh tokens (stored encrypted) and the session cookie.Signing you in and acting in Pipedrive on your behalf, only within the permissions you granted.Legitimate interest (article 6(1)(f) GDPR), as above.
Billing contactsName, email address, company name and address, VAT number, Stripe customer reference, plan and payment status. Stripe handles full card and bank details; we never see them.Charging the subscription, invoicing, collecting payments and keeping records.Performance of the contract (article 6(1)(b)) and our legal obligations under tax law (article 6(1)(c)).
People who contact usName, email address, the content of your message and our replies.Answering your question, giving support and improving the service.Legitimate interest (article 6(1)(f)), or performance of the contract when you are a customer.
Admins of customer accountsName and email address.Sending service messages, such as incident reports, price changes and changes to our terms or sub-processors.Performance of the contract (article 6(1)(b)).
Visitors of these pages and the appIP address, browser type, requested page and time.Security, preventing abuse, rate limiting and fixing errors.Legitimate interest (article 6(1)(f)) in a secure and working service.

Where we rely on legitimate interest, we have weighed that interest against your privacy. You can object at any time, see Your rights.

4.What we do not do

  • We do not sell personal data and do not share it for advertising.
  • We do not use analytics or tracking cookies in the app or on these pages. See our Cookie Policy.
  • We do not use your data or our customers' data to train AI models.
  • We do not take decisions about you based solely on automated processing that have legal or similarly significant effects (article 22 GDPR). Health and revenue scores are about companies and support our customers' own decisions.

5.Where the data comes from

Most data comes from you. When you install the app or sign in, Pipedrive shares your name, email address, profile picture link and user and company IDs with us, based on the permissions you approve. Payment status comes from Stripe.

6.Who receives the data

  • Service providers that process data for us, such as hosting, email and payments. They are listed with their location on our Sub-processors page.
  • Pipedrive, where the app writes records to your company's Pipedrive account on your instruction.
  • Our accountant and advisers, where needed and bound by confidentiality.
  • Authorities, only where the law obliges us.

7.Transfers outside the European Economic Area

We store our core data in the European Economic Area Open point: [confirm hosting and database regions]. Some providers are based in the United States, for example for email delivery, payments, network services and, only when a customer switches them on, AI features. For those transfers we rely on the European Commission's standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.

8.How long we keep data

DataRetention
User accounts and audit logAs long as the customer's installation is active, plus 30 days after it uninstalls the app or its subscription ends. Then deleted.
Pipedrive access and refresh tokensDeleted immediately when the app is uninstalled.
Invoices and billing records7 years, as Dutch tax law requires.
Support correspondence2 years after the last contact.
Technical and security logsOpen point: [log retention period, to confirm with the hosting set-up]

9.Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interest. Where we ask for consent, you can withdraw it at any time.

Send your request to info@sales-surge.nl. We may ask you to confirm your identity. We respond within one month; if a request is complex, we may extend this by two months and tell you why.

If you are not satisfied with how we handle your data, you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the authority in the EU country where you live or work.

10.Security

We protect personal data with appropriate technical and organisational measures, such as strict tenant isolation, encryption of access tokens, least-privilege access to Pipedrive and role-based access in the app. Read more on our Security page.

11.Changes to this policy

We update this policy when our processing changes. The date at the top shows the latest version. We inform the admins of customer accounts by email about material changes.