GDPR
How Sellio meets the GDPR (European Union).
Last updated: July 2, 2026 · SellioCRM, LLC
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
This document applies to the customer relationship management software-as-a-service platform, websites, applications, APIs, software, documentation, dashboards, reports, artificial intelligence features, support, and related services made available by SellioCRM, LLC, a limited liability company.
For purposes of this document, "SellioCRM," "Company," "we," "us," and "our" mean SellioCRM, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services. If you access or use the Services on behalf of an organization, you represent and warrant that you have authority to bind that organization, and that organization is the Customer.
This document is incorporated into and forms part of the SellioCRM Terms of Service unless expressly stated otherwise.
This document explains how SellioCRM approaches the General Data Protection Regulation (GDPR) and related European data protection requirements. It is provided for transparency and does not constitute legal advice. Customers should consult their own counsel to determine how the GDPR applies to their organization and use of the Services.
1. Scope
This document applies where SellioCRM processes personal data subject to the GDPR, UK GDPR, Swiss data protection law, or similar European data protection requirements.
2. Roles Under the GDPR
Depending on the processing activity, SellioCRM may act as:
- a controller for its own business operations, such as account administration, billing, infrastructure usage metering, marketing, website analytics, security, and customer relationship management
- a processor where SellioCRM processes Customer Personal Data on behalf of a Customer through the Services
- a subprocessor where Customer is a processor for another controller
The Data Processing Addendum governs SellioCRM's processor obligations for Customer Personal Data.
3. Customer as Controller
Customer is responsible for determining the purposes and means of processing Customer Personal Data submitted to the Services, including CRM data relating to leads, contacts, prospects, customers, representatives, communications, notes, files, and activities. Customer is responsible for notices, lawful bases, consents, legitimate interest assessments where required, records of processing, data protection impact assessments, data subject requests, retention rules, and compliance with GDPR obligations applicable to Customer.
4. Legal Bases for SellioCRM Controller Processing
When SellioCRM acts as controller, it may rely on legal bases such as performance of a contract, legitimate interests, consent, compliance with legal obligations, establishment or defense of legal claims, and other lawful bases under the GDPR.
5. Data Processing Addendum
SellioCRM offers a Data Processing Addendum for Customer Personal Data. The DPA includes processor commitments regarding instructions, confidentiality, security measures, subprocessors, assistance, deletion, audits, international transfers, and incident notification.
6. International Transfers
SellioCRM is based in the United States. Where personal data subject to the GDPR is transferred internationally and a transfer mechanism is required, SellioCRM may rely on appropriate safeguards, including EU Standard Contractual Clauses, UK transfer addendum, Swiss safeguards, adequacy decisions, or other lawful transfer mechanisms.
7. Subprocessors
SellioCRM may use Subprocessors to provide hosting, compute, database, storage, traffic delivery, security, analytics, support, communications, email delivery, payment processing, AI functionality, infrastructure usage metering, and other service components. SellioCRM imposes appropriate contractual obligations on Subprocessors and provides information about Subprocessors as required by the DPA.
8. Data Subject Rights
GDPR rights may include access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making. Where SellioCRM processes Customer Personal Data as processor, Customer is generally responsible for responding to data subject requests, and SellioCRM will provide reasonable assistance as required by the DPA.
9. Security Measures
SellioCRM implements commercially reasonable technical and organizational measures designed to protect personal data. Customer is responsible for security measures under Customer's control, including access management, exports, connected accounts, communications, and CRM data hygiene.
10. Personal Data Breach Notification
SellioCRM will notify Customer of confirmed Security Incidents affecting Customer Personal Data as required by the DPA and applicable law. Customer is responsible for determining whether notification to supervisory authorities, data subjects, customers, or other parties is required.
11. Cookies and ePrivacy
SellioCRM may use cookies and similar technologies as described in the Cookie Policy. Customers using the Services for their own communications, tracking, or integrations are responsible for their own ePrivacy, consent, and notice obligations.
12. Data Protection Impact Assessments
Customer is responsible for determining whether a DPIA is required for Customer's use of the Services, including CRM profiling, AI Features, large-scale processing, communications, or enrichment activities. SellioCRM will provide reasonable assistance where required and reasonably possible.
13. Retention and Deletion
Retention and deletion are described in the Terms of Service, Privacy Policy, and DPA. Customer controls retention of many categories of Customer Content and should export data before account closure or termination.
14. Contact
GDPR-related inquiries may be sent to legal@selliocrm.com.