Privacy Policy

Last updated: July 11, 2026

1. Introduction

We value transparency, trust, and responsible data handling.

This Privacy Policy explains how personal data is collected, used, stored, and protected when you access or use our website, browser extension, applications, and related services (together, the "Services").

Personal data is processed in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.

By using the Services, you acknowledge that you have read and understood this Privacy Policy.

2. Who is responsible for your data?

EKSPOSE BV ("SurroundR", "we", "us") is the legal entity responsible for processing described in this policy:

EKSPOSE BV
Company number: BE 0541.832.102
Registered in Belgium
Registered office: Wapenhaghestraat 32, 2600 Antwerpen, Belgium

When we act as data controller

We determine the purposes and means of processing for personal data relating to:

  • Visitors to our website and marketing properties
  • Account holders and authorised users of the Services
  • Billing, subscription, and payment administration
  • Product marketing and commercial communications
  • Customer support and privacy enquiries directed to us

When we act as data processor

When customers use the Services to capture, enrich, and sync prospect or contact data — for example from professional profiles into their CRM — we process that data on the customer's instructions. In those cases the customer is the data controller and EKSPOSE BV acts as data processor. The customer decides why and how that data is used in their organisation.

Processor activities are governed by our Data Processing Agreement (DPA).

Privacy-related requests about data for which we act as controller may be submitted through the mechanisms in section 16. Requests about prospect data held on behalf of a customer should usually be directed to that customer first; we will assist them as processor where required by law.

3. What data we collect

Only data necessary to operate, improve, and secure the Services is collected.

a) Data you provide directly

This may include:

  • First and last name
  • Professional email address
  • Company name and role
  • Contact information
  • Account credentials
  • Billing and subscription information
  • Messages or requests submitted through forms

b) Data collected automatically

When using the Services, certain technical data may be collected, including:

  • IP address
  • Browser type and device information
  • Usage logs and interaction data
  • Timestamps and access activity
  • Technical identifiers

c) Business contact data

The Services may process professional contact information such as name, job title, company affiliation, and public professional contact details. Where that information relates to prospects or contacts captured by our customers from third-party sources, section 4 applies in addition.

d) Information voluntarily shared

Any information you choose to provide through forms, support requests, or product feedback.

4. Data obtained from third-party sources

SurroundR helps business users capture and enrich prospect data — personal data about individuals who have not provided that data to us directly. This section describes that processing where EKSPOSE BV or our customers rely on such sources (GDPR Article 14).

Categories of data

Professional contact data only, such as:

  • Name and job title
  • Company name and business affiliation
  • Business email address
  • Business phone number
  • Public professional profile URL

We do not knowingly process sensitive or special-category personal data. Processing is limited to a professional, B2B context.

Sources

Data may originate from publicly accessible professional profiles (for example LinkedIn) and from licensed B2B data providers used in our enrichment workflow. We do not publish a fixed list of providers here; the set may change as our product evolves.

Why and on what basis

This data is used to let customers identify and reach business contacts, keep CRM records accurate, and reduce manual data entry. Where EKSPOSE BV determines the purpose and means, we rely on legitimate interests (Article 6(1)(f) GDPR) in a B2B context, balanced against your rights. We conduct a balancing test and limit processing to what is reasonably necessary for professional outreach and CRM hygiene.

Right to object: You may object at any time to processing of your personal data based on legitimate interests, including profiling related to that processing (Article 21 GDPR). To object or request erasure, use our Delete my data page or email privacy@surroundr.io. We will review and respond without undue delay.

5. Why we process your data

Personal data is processed for the following purposes:

  • Providing and operating the Services
  • Creating and managing user accounts
  • Delivering browser extension and platform functionality
  • Managing subscriptions and billing
  • Responding to support or privacy requests
  • Improving product performance and usability
  • Ensuring platform security and fraud prevention
  • Meeting legal and regulatory obligations
  • Analyzing usage trends and product adoption

Personal data is not used for purposes incompatible with those listed above.

6. Legal grounds for processing

Depending on the context, processing is based on:

  • Performance of a contract (Article 6(1)(b) GDPR)
  • Legitimate interests (Article 6(1)(f) GDPR), such as product improvement and business operations
  • Legal obligations (Article 6(1)(c) GDPR)
  • Consent, where required (Article 6(1)(a) GDPR)

When relying on legitimate interest, a balancing test is conducted to ensure your rights and freedoms are not overridden.

Purpose and legal basis (summary)

PurposeTypical legal basis
Providing and operating the ServicesContract (Art. 6(1)(b))
Creating and managing user accountsContract (Art. 6(1)(b))
Delivering browser extension and platform functionalityContract (Art. 6(1)(b))
Managing subscriptions and billingContract (Art. 6(1)(b)); legal obligation where applicable
Responding to support or privacy requestsContract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Improving product performance and usabilityLegitimate interest (Art. 6(1)(f))
Ensuring platform security and fraud preventionLegitimate interest (Art. 6(1)(f)); legal obligation where applicable
Meeting legal and regulatory obligationsLegal obligation (Art. 6(1)(c))
Analyzing usage trends and product adoptionLegitimate interest (Art. 6(1)(f)); consent for non-essential cookies where required
Prospect capture and enrichment (section 4)Legitimate interest (Art. 6(1)(f)) in B2B context; customer as controller when using the Services

7. Data retention

Personal data is retained only as long as necessary:

  • Account data: for the duration of the active account
  • Customer data: for the duration of the contractual relationship
  • Prospect data: up to 3 years after last interaction
  • Billing and accounting records: up to 10 years (legal obligation)
  • Support and privacy requests: until resolution, then archived
  • Security logs: limited retention for protection purposes

After expiration of retention periods, data is securely deleted or anonymized.

8. Who may access your data

Access to personal data is strictly limited.

Data may be accessed by:

  • Authorized internal team members
  • Service providers acting on our instructions, including categories such as:
    • Hosting and infrastructure
    • CRM platform integration
    • Payment processing
    • Product analytics
    • Email and communications
    • B2B data providers (enrichment)
  • Public authorities where legally required

All third parties are contractually bound by confidentiality and data protection obligations. We do not sell personal data.

9. International data transfers

The Services are primarily hosted within the European Economic Area (EEA).

Some service providers — including providers established in the United States and other countries outside the EEA — may process personal data on our behalf or on behalf of our customers. Where personal data is transferred outside the EEA, appropriate safeguards are applied, including:

  • European Commission adequacy decisions, including the EU–US Data Privacy Framework where applicable to certified recipients
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical and organizational safeguards where appropriate

10. Data security

Appropriate technical and organizational measures are implemented, including:

  • Access control and authentication mechanisms
  • Encrypted connections (HTTPS)
  • Secure infrastructure providers
  • Monitoring and logging
  • Restricted internal access policies

While no system can guarantee absolute security, continuous efforts are made to minimize risk.

11. Cookies and tracking technologies

Cookies and similar technologies may be used to:

  • Enable essential functionality
  • Improve user experience
  • Analyze website and product usage

Where required by law, cookies are used only after consent is obtained.

Cookie preferences can be managed or withdrawn at any time through our dialog (Cookiebot), or via your browser settings.

The full, current list of cookies we use is maintained below and updates automatically:

12. Your rights under GDPR

You have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Request deletion ("right to be forgotten")
  • Restrict processing
  • Object to processing
  • Withdraw consent at any time
  • Request data portability
  • Lodge a complaint with a supervisory authority

Requests may be submitted through our Delete my data page (for erasure and related privacy requests) or by emailing privacy@surroundr.io. SurroundR account holders may also contact support@surroundr.io.

Identity verification may be required before fulfilling certain requests.

Supervisory authority

You have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) at gegevensbeschermingsautoriteit.be, or with the supervisory authority in your country of habitual residence or place of work.

Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

Is providing data required?

Account, billing, and payment information is required to create and maintain a paid subscription and deliver the Services under our contract with you. Other information — such as optional profile fields, marketing preferences, or enrichment of contacts you choose to capture — is voluntary. If you do not provide required data, we may be unable to provide some or all of the Services.

13. Third-party websites and integrations

The Services may include integrations or links to third-party tools.

The Company is not responsible for the privacy practices of such third parties.

Users are encouraged to review third-party privacy policies independently.

14. Children

The Services are intended exclusively for professional users.

The Company does not knowingly collect personal data from individuals under the age of 16.

15. Updates to this Privacy Policy

This Privacy Policy may be updated to reflect legal, technical, or operational changes.

The most recent version will always be available through the Services or the Company's website, including the latest revision date.

Continued use of the Services after changes constitutes acceptance of the updated policy.

16. Contact

For privacy-related questions or requests, use our Delete my data page or email privacy@surroundr.io. For account and product support, email support@surroundr.io.