Overview
Yes — SurroundR is built for GDPR and EU data residency.
SurroundR is operated by EKSPOSE BV in Belgium under a GDPR-first posture, with primary infrastructure and data storage in the EU, and your contact data lands in your own HubSpot portal. We are a pipe into your CRM — not a data broker.
Legal entity: EKSPOSE BV · BE 0541.832.102 · Antwerp, Belgium
GDPR
Compliant · EU-based processor
EU Data Residency
HubSpot EU1 · Belgium HQ
- Your data lives in YOUR HubSpot
- EU data residency (EU1)
- 10 named subprocessors
- Every OAuth scope explained
Opens email to support@surroundr.io with subject prefilled. Available on paid plans.
Overview
SurroundR is operated by EKSPOSE BV in Belgium under a GDPR-first posture, with primary infrastructure and data storage in the EU, and your contact data lands in your own HubSpot portal. We are a pipe into your CRM — not a data broker.
Legal entity: EKSPOSE BV · BE 0541.832.102 · Antwerp, Belgium
Data flow
What moves where — and what does not. LinkedIn context you trigger, optional enrichment, then write to your HubSpot.
1. LinkedIn (Chrome extension)
When you trigger a capture or sync, SurroundR reads LinkedIn profile and conversation context — not a background scrape of your network. Typical fields: name, headline, company, role, and LinkedIn URL from the public profile.
2. SurroundR backend
The extension sends the capture to SurroundR so enrichment can run (verified work email and/or mobile from third-party B2B data providers when requested) and HubSpot OAuth can write the record. OAuth tokens are encrypted with AES-256-GCM.
3. Your HubSpot portal
Contacts, companies, and deals are written to your HubSpot account via the OAuth scopes you approve. Captured records stay in your CRM — we do not resell, repackage, or train models on your data.
What we never do
SurroundR never sees your HubSpot password. We do not sell personal data. Captured contacts stay in your CRM — we do not resell, repackage, or train models on them.
Permissions
SurroundR touches two surfaces: your HubSpot portal and your Chrome browser. Every scope and every permission is listed here, with the reason we need it and what we never do with it.
HubSpot connection
20 OAuth scopesWhen you connect SurroundR, HubSpot lists every permission on the consent screen, including the "unverified app" wall for apps not yet in the marketplace. Here is what each permission is for.
CRM records — read & write
Contacts, companies, and deals — create and update what you capture, and see associated deals from the extension.
Sequences & workflows
Powers the Add-to-sequence button and HubSpot workflow-triggered LinkedIn actions.
Setup & account — read
Your portal's users, permissions, and property definitions — team management and field mapping.
Every permission on the consent screen (20) →
CRM records
| Permission | Access | Why we ask |
|---|---|---|
| Contacts | Read | Match against your existing contacts so captures update records instead of creating duplicates. |
| Contacts | Write | Create and update the contacts you capture from LinkedIn, including enriched emails and mobiles. |
| Companies | Read | Associate captured contacts with the right company records. |
| Companies | Write | Create or update the company when a LinkedIn profile's employer isn't in your portal yet. |
| Deals | Read | Power the Deals tab in the extension — see a contact's associated deals without leaving LinkedIn. |
| Deals | Write | Create a deal from SurroundR when a conversation turns into pipeline. |
Property settings (schemas)
| Permission | Access | Why we ask |
|---|---|---|
| Contact property settings | Read | Read your property definitions so field mapping shows your real HubSpot fields. |
| Contact property settings | Write | Create the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions. |
| Company property settings | Read | Read your property definitions so field mapping shows your real HubSpot fields. |
| Company property settings | Write | Create the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions. |
| Deal property settings | Read | Read your property definitions so field mapping shows your real HubSpot fields. |
| Deal property settings | Write | Create the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions. |
Import
| Permission | Access | Why we ask |
|---|---|---|
| CRM import (create / modify via import) | Read & write | Bulk capture writes records through HubSpot's import path for reliable high-volume syncs. |
Users & permissions
| Permission | Access | Why we ask |
|---|---|---|
| Users assigned on CRM records | Read | Team management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct. |
| User object | Read | Team management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct. |
| Account users & permissions | Read | Team management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct. |
Automation
| Permission | Access | Why we ask |
|---|---|---|
| Workflows | Read & write | Powers native LinkedIn automation from HubSpot workflows — trigger SurroundR actions (like connection requests or messages) as workflow steps. |
| Sequences | Read | Show whether a contact is already enrolled before you add them. |
| Sequence enrollments | Write | The Add-to-sequence button — enroll a captured contact directly from LinkedIn (requires Sales Hub Pro on HubSpot's side). |
Account
| Permission | Access | Why we ask |
|---|---|---|
| Basic account info (domain, user emails) | Read | Identify which portal is connected and who installed the app. |
The scopes shown match the HubSpot consent screen you will see when you connect.
Chrome extension
9 permissionsThese are the exact permissions declared in our Manifest V3 extension, the same names a reviewer sees in the Chrome Web Store. Plain language first, Chrome's install wording where it matters.
- No remote code. All scripts ship inside the package.
- Manifest V3, side panel architecture.
- sidePanel
Show the SurroundR panel next to LinkedIn
The side panel is the extension's main interface. View and edit contact details, manage outreach, and work with SurroundR without leaving the LinkedIn page. Only activates on LinkedIn tabs.
- tabs
Know when you are on LinkedIn
Detects when you open or navigate to a LinkedIn page so the panel activates on the right tab. Not used to monitor browsing anywhere else.
- scripting
Load the extension into LinkedIn tabs you already had open
When you install or update SurroundR, Chrome only injects extensions into newly opened tabs. This permission lets us load the same bundled scripts into LinkedIn tabs that were already open, so nothing looks broken until you refresh. No dynamic or external code is ever executed.
- storage
Keep you logged in
Stores your session and preferences locally in your browser so you stay signed in across restarts. Session identifiers and UI settings only, no personal contact data.
- alarms
Keep network sync running on schedule
Chrome suspends extension background workers aggressively. Alarms wake ours on a fixed schedule so LinkedIn network sync (new connections, sent invitations) keeps running. Never used for ads or tracking.
- cookies
Single sign-on with the SurroundR web app
Reads the login cookies set by SurroundR's own backend so the web app and the extension share one session. Scoped to SurroundR domains only, never third-party sites.
- tabCapture + desktopCapture
Record Chirps
Chirp is our Loom-style video DM. You start a recording, pick a screen or tab in Chrome's native picker, and we capture that source for your video. Recording happens locally, only while you record, never in the background.
- offscreen
Match your light or dark mode
Detects your system color scheme so the toolbar icon shows the right variant. That is the whole job: no page access, no user data, no network calls.
- host: linkedin.com + all sites
Work on LinkedIn, and record the tab you choose
LinkedIn access powers the overlay and the authenticated calls to the SurroundR API. The broad all-sites grant exists for one reason: when you record a Chirp, we inject a small recorder overlay (timer, stop button, camera bubble) into whichever tab you picked, and Chrome requires host access to that tab's URL to do it. We never read or modify content on other websites. The overlay only appears during a recording you started.
What the Chrome extension never does
- Background reading of LinkedIn messages, connections list, or feed
- Tracking browsing outside linkedin.com
- Auto-scraping profiles: every capture is a deliberate click
- Recording your screen without you starting a Chirp
- Loading or executing code from outside the extension package
- Reads only the profile page you are actively viewing, when you click capture
Subprocessors
Who may process data on our behalf. Ten named vendors plus a vendor-agnostic enrichment category.
10 named subprocessors + vendor-agnostic enrichment — full register with the DPA
Full subprocessor table →
| Vendor / category | Purpose | Region notes |
|---|---|---|
| HubSpot | CRM sync destination — your contacts land in your own portal. | Follows your HubSpot data residency (EU1 for EU customers). |
| Amazon Web Services | Video message (Chirp) and file storage. | EU |
| Fly.io | Application and processing infrastructure. | Primarily EU (Amsterdam/Frankfurt). |
| Vercel | Web application hosting. | Global edge |
| Stripe | Billing and payments. | US/Global — with appropriate safeguards (see privacy policy). |
| PostHog | Product analytics. | EU |
| Sentry | Error monitoring. | EU |
| Scaleway | Transactional email (invites, notifications). | EU (Paris) |
| Featurebase | In-app support chat and feedback. | See vendor DPA |
| Tag management on the marketing site. | Global | |
| B2B data providers (enrichment) | Optional verified email/mobile enrichment when you request it. | Vendor-agnostic waterfall; named register available with the DPA on paid plans. |
All third parties are contractually bound by confidentiality and data protection obligations. We do not sell personal data. Full privacy policy for legal detail. Privacy policy
DPA
DPA available on request for paid plans. When EKSPOSE BV acts as processor for customer-controlled prospect data, a DPA (GDPR Art. 28) covers Mono and Stereo — not Free.
Email support@surroundr.io. We will send the agreement for signature. A public /legal/dpa page is not published yet.
Controller vs processor in the privacy policySecurity controls
How we protect the product — grouped for reviewers. Only claims we can stand behind from public product and privacy copy.
Product security
- ✓OAuth 2.0 for HubSpot — scopes listed on the consent screen (revocable by the customer). No HubSpot password storage.
- ✓Encryption in transit (HTTPS / TLS) for extension ↔ SurroundR ↔ HubSpot traffic.
- ✓OAuth tokens encrypted at rest with AES-256-GCM.
- ✓Chrome extension published via the Chrome Web Store (reviewed listing).
- ✓Stereo-tier workspace controls to audit captures across seats.
Infrastructure security
- ✓Primary infrastructure and data storage in the EU; application compute can scale outside the EU where needed. Contact data lands in your HubSpot portal; video (Chirp) storage is EU (AWS).
- ✓Secure infrastructure providers with monitoring and logging.
- ✓Access control and authentication mechanisms with restricted internal access policies.
Organizational security
- ✓Access control and authentication mechanisms for systems that process personal data.
- ✓Restricted internal access policies for personal data.
- ✓Monitoring and logging as part of ongoing security operations.
Data & privacy
- ✓GDPR-first processing; Data Processing Agreement (Art. 28) available on paid plans.
- ✓Data deletion on request via Delete my data (individuals) or support@surroundr.io (customers).
- ✓LinkedIn reads happen on deliberate capture clicks only — not background scraping. HubSpot access is limited to the OAuth scopes you approve on the consent screen (full table on this page).
- ✓Public named subprocessor register on this page; named enrichment register available with the DPA on paid plans.
We do not claim SOC 2, ISO 27001, or other certifications on this page. Continuous efforts are made to minimize risk; no system can guarantee absolute security.
FAQ
Short answers for security reviewers and RevOps buyers evaluating SurroundR.
Is SurroundR GDPR-compliant?
SurroundR is built and operated in Belgium by EKSPOSE BV under EU GDPR. We take a GDPR-first posture: legitimate-interest processing in a B2B context where applicable, primary infrastructure and data storage in the EU, contact data landing in your HubSpot portal, and a DPA available on paid plans when we act as processor.
How do I request deletion of personal data?
Individuals whose public LinkedIn profile may have been captured can use the Delete my data page. We confirm within 24 hours and complete deletion within 7 days. SurroundR customers deleting their own account or exports should email support@surroundr.io.
Where is data hosted, and what about HubSpot EU1?
Primary infrastructure and data storage are in the EU; application compute can scale outside the EU where needed. Captured contacts are written to your HubSpot account. SurroundR operates with HubSpot EU1; your CRM data residency follows your HubSpot portal configuration. Video message (Chirp) storage is in the EU (AWS).
What HubSpot OAuth scopes does SurroundR request?
SurroundR requests HubSpot OAuth scopes covering: Contacts, Companies, Deals, Contact property settings, Company property settings, Deal property settings, CRM import (create / modify via import), Users assigned on CRM records, User object, Account users & permissions, Workflows, Sequences, Sequence enrollments, Basic account info (domain, user emails). Access levels are listed in the consent-screen table on this page — including deals and property-schema permissions, not contacts and companies alone. You approve the exact list on HubSpot's consent screen. Authentication uses OAuth 2.0 — SurroundR never sees your HubSpot password. OAuth tokens are encrypted with AES-256-GCM.
What does the Chrome extension read on LinkedIn?
SurroundR reads only the LinkedIn profile you are actively viewing when you click to capture — not your messages, connections list, or feed, and not browsing outside linkedin.com. Every capture is a deliberate click; there is no background auto-scrape. Captured contacts go to your HubSpot portal; we do not sell, share, or reuse them for anyone else.
Can we get a Data Processing Agreement?
Yes on paid plans (Mono and Stereo). Request a DPA by emailing support@surroundr.io. The Free tier does not include a DPA, matching the pricing comparison table.
Who are your sub-processors?
The public register on this page lists 10 named subprocessors (including HubSpot, AWS, Fly.io, Vercel, Stripe, PostHog, Sentry, Scaleway, Featurebase, and Google) plus a vendor-agnostic enrichment category. The named enrichment register is available with the DPA on paid plans.
How is data encrypted?
Connections use HTTPS/TLS. HubSpot OAuth tokens are encrypted with AES-256-GCM. See the Security controls section for product, infrastructure, organizational, and data & privacy controls.
Do you store our CRM contacts as a database?
Captured contacts are written to your HubSpot account — we are a pipe, not a data broker. We do not resell, repackage, or train models on your contacts. Operational processing (for example enrichment and deletion requests) is described in the privacy policy and Delete my data page.
Does SurroundR send my data to AI models?
No. A full audit of our codebase confirms no customer or prospect data is sent to any AI/LLM provider. If that ever changes, it will appear on this page and in our subprocessor register first.
Report a concern
If you believe you have found a security vulnerability in SurroundR, email us with details. We take responsible disclosure seriously and will follow up on reports sent to support@surroundr.io.
Procurement
Need the DPA or a security questionnaire?
Email support@surroundr.io — we help security reviewers and RevOps buyers self-serve. Primary action: request the DPA on a paid plan.