SurroundR

Overview

Yes — SurroundR is built for GDPR and EU data residency.

SurroundR is operated by EKSPOSE BV in Belgium under a GDPR-first posture, with primary infrastructure and data storage in the EU, and your contact data lands in your own HubSpot portal. We are a pipe into your CRM — not a data broker.

Legal entity: EKSPOSE BV · BE 0541.832.102 · Antwerp, Belgium

GDPR

Compliant · EU-based processor

EU Data Residency

HubSpot EU1 · Belgium HQ

  • Your data lives in YOUR HubSpot
  • EU data residency (EU1)
  • 10 named subprocessors
  • Every OAuth scope explained
Request DPA

Opens email to support@surroundr.io with subject prefilled. Available on paid plans.

Overview

SurroundR is operated by EKSPOSE BV in Belgium under a GDPR-first posture, with primary infrastructure and data storage in the EU, and your contact data lands in your own HubSpot portal. We are a pipe into your CRM — not a data broker.

Legal entity: EKSPOSE BV · BE 0541.832.102 · Antwerp, Belgium

Data flow

What moves where — and what does not. LinkedIn context you trigger, optional enrichment, then write to your HubSpot.

  1. 1. LinkedIn (Chrome extension)

    When you trigger a capture or sync, SurroundR reads LinkedIn profile and conversation context — not a background scrape of your network. Typical fields: name, headline, company, role, and LinkedIn URL from the public profile.

  2. 2. SurroundR backend

    The extension sends the capture to SurroundR so enrichment can run (verified work email and/or mobile from third-party B2B data providers when requested) and HubSpot OAuth can write the record. OAuth tokens are encrypted with AES-256-GCM.

  3. 3. Your HubSpot portal

    Contacts, companies, and deals are written to your HubSpot account via the OAuth scopes you approve. Captured records stay in your CRM — we do not resell, repackage, or train models on your data.

  4. What we never do

    SurroundR never sees your HubSpot password. We do not sell personal data. Captured contacts stay in your CRM — we do not resell, repackage, or train models on them.

Permissions

SurroundR touches two surfaces: your HubSpot portal and your Chrome browser. Every scope and every permission is listed here, with the reason we need it and what we never do with it.

HubSpot connection

20 OAuth scopes

When you connect SurroundR, HubSpot lists every permission on the consent screen, including the "unverified app" wall for apps not yet in the marketplace. Here is what each permission is for.

CRM records — read & write

Contacts, companies, and deals — create and update what you capture, and see associated deals from the extension.

Sequences & workflows

Powers the Add-to-sequence button and HubSpot workflow-triggered LinkedIn actions.

Setup & account — read

Your portal's users, permissions, and property definitions — team management and field mapping.

Every permission on the consent screen (20) →

CRM records

PermissionAccessWhy we ask
ContactsReadMatch against your existing contacts so captures update records instead of creating duplicates.
ContactsWriteCreate and update the contacts you capture from LinkedIn, including enriched emails and mobiles.
CompaniesReadAssociate captured contacts with the right company records.
CompaniesWriteCreate or update the company when a LinkedIn profile's employer isn't in your portal yet.
DealsReadPower the Deals tab in the extension — see a contact's associated deals without leaving LinkedIn.
DealsWriteCreate a deal from SurroundR when a conversation turns into pipeline.

Property settings (schemas)

PermissionAccessWhy we ask
Contact property settingsReadRead your property definitions so field mapping shows your real HubSpot fields.
Contact property settingsWriteCreate the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions.
Company property settingsReadRead your property definitions so field mapping shows your real HubSpot fields.
Company property settingsWriteCreate the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions.
Deal property settingsReadRead your property definitions so field mapping shows your real HubSpot fields.
Deal property settingsWriteCreate the SurroundR properties your field mapping needs when they don't exist yet (e.g. LinkedIn URL) — we never delete or overwrite your own property definitions.

Import

PermissionAccessWhy we ask
CRM import (create / modify via import)Read & writeBulk capture writes records through HubSpot's import path for reliable high-volume syncs.

Users & permissions

PermissionAccessWhy we ask
Users assigned on CRM recordsReadTeam management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct.
User objectReadTeam management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct.
Account users & permissionsReadTeam management — sync your portal's users into SurroundR so you can assign seats and keep record ownership correct.

Automation

PermissionAccessWhy we ask
WorkflowsRead & writePowers native LinkedIn automation from HubSpot workflows — trigger SurroundR actions (like connection requests or messages) as workflow steps.
SequencesReadShow whether a contact is already enrolled before you add them.
Sequence enrollmentsWriteThe Add-to-sequence button — enroll a captured contact directly from LinkedIn (requires Sales Hub Pro on HubSpot's side).

Account

PermissionAccessWhy we ask
Basic account info (domain, user emails)ReadIdentify which portal is connected and who installed the app.

The scopes shown match the HubSpot consent screen you will see when you connect.

Chrome extension

9 permissions

These are the exact permissions declared in our Manifest V3 extension, the same names a reviewer sees in the Chrome Web Store. Plain language first, Chrome's install wording where it matters.

  • No remote code. All scripts ship inside the package.
  • Manifest V3, side panel architecture.
  • sidePanel

    Show the SurroundR panel next to LinkedIn

    The side panel is the extension's main interface. View and edit contact details, manage outreach, and work with SurroundR without leaving the LinkedIn page. Only activates on LinkedIn tabs.

  • tabs

    Know when you are on LinkedIn

    Detects when you open or navigate to a LinkedIn page so the panel activates on the right tab. Not used to monitor browsing anywhere else.

  • scripting

    Load the extension into LinkedIn tabs you already had open

    When you install or update SurroundR, Chrome only injects extensions into newly opened tabs. This permission lets us load the same bundled scripts into LinkedIn tabs that were already open, so nothing looks broken until you refresh. No dynamic or external code is ever executed.

  • storage

    Keep you logged in

    Stores your session and preferences locally in your browser so you stay signed in across restarts. Session identifiers and UI settings only, no personal contact data.

  • alarms

    Keep network sync running on schedule

    Chrome suspends extension background workers aggressively. Alarms wake ours on a fixed schedule so LinkedIn network sync (new connections, sent invitations) keeps running. Never used for ads or tracking.

  • cookies

    Single sign-on with the SurroundR web app

    Reads the login cookies set by SurroundR's own backend so the web app and the extension share one session. Scoped to SurroundR domains only, never third-party sites.

  • tabCapture + desktopCapture

    Record Chirps

    Chirp is our Loom-style video DM. You start a recording, pick a screen or tab in Chrome's native picker, and we capture that source for your video. Recording happens locally, only while you record, never in the background.

  • offscreen

    Match your light or dark mode

    Detects your system color scheme so the toolbar icon shows the right variant. That is the whole job: no page access, no user data, no network calls.

  • host: linkedin.com + all sites

    Work on LinkedIn, and record the tab you choose

    LinkedIn access powers the overlay and the authenticated calls to the SurroundR API. The broad all-sites grant exists for one reason: when you record a Chirp, we inject a small recorder overlay (timer, stop button, camera bubble) into whichever tab you picked, and Chrome requires host access to that tab's URL to do it. We never read or modify content on other websites. The overlay only appears during a recording you started.

What the Chrome extension never does

  • Background reading of LinkedIn messages, connections list, or feed
  • Tracking browsing outside linkedin.com
  • Auto-scraping profiles: every capture is a deliberate click
  • Recording your screen without you starting a Chirp
  • Loading or executing code from outside the extension package
  • Reads only the profile page you are actively viewing, when you click capture

Subprocessors

Who may process data on our behalf. Ten named vendors plus a vendor-agnostic enrichment category.

10 named subprocessors + vendor-agnostic enrichment — full register with the DPA

Full subprocessor table →
Vendor / categoryPurposeRegion notes
HubSpotCRM sync destination — your contacts land in your own portal.Follows your HubSpot data residency (EU1 for EU customers).
Amazon Web ServicesVideo message (Chirp) and file storage.EU
Fly.ioApplication and processing infrastructure.Primarily EU (Amsterdam/Frankfurt).
VercelWeb application hosting.Global edge
StripeBilling and payments.US/Global — with appropriate safeguards (see privacy policy).
PostHogProduct analytics.EU
SentryError monitoring.EU
ScalewayTransactional email (invites, notifications).EU (Paris)
FeaturebaseIn-app support chat and feedback.See vendor DPA
GoogleTag management on the marketing site.Global
B2B data providers (enrichment)Optional verified email/mobile enrichment when you request it.Vendor-agnostic waterfall; named register available with the DPA on paid plans.

All third parties are contractually bound by confidentiality and data protection obligations. We do not sell personal data. Full privacy policy for legal detail. Privacy policy

DPA

DPA available on request for paid plans. When EKSPOSE BV acts as processor for customer-controlled prospect data, a DPA (GDPR Art. 28) covers Mono and Stereo — not Free.

Request DPA

Email support@surroundr.io. We will send the agreement for signature. A public /legal/dpa page is not published yet.

Controller vs processor in the privacy policy

Security controls

How we protect the product — grouped for reviewers. Only claims we can stand behind from public product and privacy copy.

Product security
  • OAuth 2.0 for HubSpot — scopes listed on the consent screen (revocable by the customer). No HubSpot password storage.
  • Encryption in transit (HTTPS / TLS) for extension ↔ SurroundR ↔ HubSpot traffic.
  • OAuth tokens encrypted at rest with AES-256-GCM.
  • Chrome extension published via the Chrome Web Store (reviewed listing).
  • Stereo-tier workspace controls to audit captures across seats.
Infrastructure security
  • Primary infrastructure and data storage in the EU; application compute can scale outside the EU where needed. Contact data lands in your HubSpot portal; video (Chirp) storage is EU (AWS).
  • Secure infrastructure providers with monitoring and logging.
  • Access control and authentication mechanisms with restricted internal access policies.
Organizational security
  • Access control and authentication mechanisms for systems that process personal data.
  • Restricted internal access policies for personal data.
  • Monitoring and logging as part of ongoing security operations.
Data & privacy
  • GDPR-first processing; Data Processing Agreement (Art. 28) available on paid plans.
  • Data deletion on request via Delete my data (individuals) or support@surroundr.io (customers).
  • LinkedIn reads happen on deliberate capture clicks only — not background scraping. HubSpot access is limited to the OAuth scopes you approve on the consent screen (full table on this page).
  • Public named subprocessor register on this page; named enrichment register available with the DPA on paid plans.

We do not claim SOC 2, ISO 27001, or other certifications on this page. Continuous efforts are made to minimize risk; no system can guarantee absolute security.

FAQ

Short answers for security reviewers and RevOps buyers evaluating SurroundR.

Is SurroundR GDPR-compliant?

SurroundR is built and operated in Belgium by EKSPOSE BV under EU GDPR. We take a GDPR-first posture: legitimate-interest processing in a B2B context where applicable, primary infrastructure and data storage in the EU, contact data landing in your HubSpot portal, and a DPA available on paid plans when we act as processor.

How do I request deletion of personal data?

Individuals whose public LinkedIn profile may have been captured can use the Delete my data page. We confirm within 24 hours and complete deletion within 7 days. SurroundR customers deleting their own account or exports should email support@surroundr.io.

Where is data hosted, and what about HubSpot EU1?

Primary infrastructure and data storage are in the EU; application compute can scale outside the EU where needed. Captured contacts are written to your HubSpot account. SurroundR operates with HubSpot EU1; your CRM data residency follows your HubSpot portal configuration. Video message (Chirp) storage is in the EU (AWS).

What HubSpot OAuth scopes does SurroundR request?

SurroundR requests HubSpot OAuth scopes covering: Contacts, Companies, Deals, Contact property settings, Company property settings, Deal property settings, CRM import (create / modify via import), Users assigned on CRM records, User object, Account users & permissions, Workflows, Sequences, Sequence enrollments, Basic account info (domain, user emails). Access levels are listed in the consent-screen table on this page — including deals and property-schema permissions, not contacts and companies alone. You approve the exact list on HubSpot's consent screen. Authentication uses OAuth 2.0 — SurroundR never sees your HubSpot password. OAuth tokens are encrypted with AES-256-GCM.

What does the Chrome extension read on LinkedIn?

SurroundR reads only the LinkedIn profile you are actively viewing when you click to capture — not your messages, connections list, or feed, and not browsing outside linkedin.com. Every capture is a deliberate click; there is no background auto-scrape. Captured contacts go to your HubSpot portal; we do not sell, share, or reuse them for anyone else.

Can we get a Data Processing Agreement?

Yes on paid plans (Mono and Stereo). Request a DPA by emailing support@surroundr.io. The Free tier does not include a DPA, matching the pricing comparison table.

Who are your sub-processors?

The public register on this page lists 10 named subprocessors (including HubSpot, AWS, Fly.io, Vercel, Stripe, PostHog, Sentry, Scaleway, Featurebase, and Google) plus a vendor-agnostic enrichment category. The named enrichment register is available with the DPA on paid plans.

How is data encrypted?

Connections use HTTPS/TLS. HubSpot OAuth tokens are encrypted with AES-256-GCM. See the Security controls section for product, infrastructure, organizational, and data & privacy controls.

Do you store our CRM contacts as a database?

Captured contacts are written to your HubSpot account — we are a pipe, not a data broker. We do not resell, repackage, or train models on your contacts. Operational processing (for example enrichment and deletion requests) is described in the privacy policy and Delete my data page.

Does SurroundR send my data to AI models?

No. A full audit of our codebase confirms no customer or prospect data is sent to any AI/LLM provider. If that ever changes, it will appear on this page and in our subprocessor register first.

Report a concern

If you believe you have found a security vulnerability in SurroundR, email us with details. We take responsible disclosure seriously and will follow up on reports sent to support@surroundr.io.

Procurement

Need the DPA or a security questionnaire?

Email support@surroundr.io — we help security reviewers and RevOps buyers self-serve. Primary action: request the DPA on a paid plan.