Last Updated: 12th February 2026
Sellframe Ltd. (trading as "Add to CRM") ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (https://addtocrm.com), use our Chrome extensions, or otherwise interact with our services (collectively, the "Services").
We process personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation 2016/679 ("GDPR"), and the California Consumer Privacy Act of 2018 ("CCPA"), as amended by the California Privacy Rights Act of 2020 ("CPRA"). We also strive to comply with other relevant privacy laws, such as Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA").
Please read this Privacy Policy carefully. By using our Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with any terms herein, you should not access or use the Services.
Legal Entity Name: Sellframe Ltd. (trading as "Add to CRM")
Registered Office Address: 14 Avonside Grove, Hamilton, UK, ML3 7DL
Jurisdiction: Scotland (UK)
Contact Email: [email protected]
We do not currently have a Data Protection Officer (DPO) or EU/EEA Representative appointed.
We process your personal data for the following purposes:
Under the UK GDPR/GDPR, we process personal data based on the following legal grounds:
We do not sell or rent your personal data. However, we may share information in the following circumstances:
These providers process data on our behalf under contractual obligations consistent with this Privacy Policy.
Compliance & Protection: If required by law or in response to valid requests by public authorities (e.g., court orders), or to protect our rights, users, or the public.
Business Transfers: If we are involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice if your data becomes subject to a different Privacy Policy.
We currently store and process data on servers located in the United States (New York) via DigitalOcean. For users located in the UK, EEA, or other regions with data transfer restrictions, this may constitute a cross-border transfer. We rely on Standard Contractual Clauses (SCCs) with our US-based service providers to ensure adequate protection for international data transfers. For providers certified under the EU-US Data Privacy Framework, we rely on that framework as an additional safeguard.
If you would prefer we store your data in the EU or the UK, please contact us to discuss available options. If necessary and feasible, we may migrate our hosting to an EU-based server to further ensure GDPR compliance.
Authentication Cookies: We place cookies to keep you logged in as you navigate our website or Services.
Analytics Cookies/Tools:
Fathom: Typically does not use cookies; it collects aggregated data in a privacy-friendly manner.
We currently do not respond to "Do Not Track" (DNT) signals. You can still control cookies and trackers via your browser settings or third-party extensions.
We retain user account data for as long as the account is active, plus six (6) months. After that period, we will securely delete or anonymize personal data, unless a longer retention is required by law (e.g., for tax or regulatory purposes). Usage logs and backups may persist in our archives for a limited period.
Enrichment data (contact information retrieved from data providers) is cached for up to 30 days to improve performance and reduce redundant lookups. Data provider API response caches are retained for up to 30 days. Operation logs are retained for up to 12 months for debugging and service improvement purposes.
CRM connection credentials are retained for as long as your account is active and your CRM connection is configured. Credentials are permanently deleted when you disconnect your CRM or delete your account.
We do not hold any formal certifications such as ISO 27001 or SOC 2. However, we take reasonable technical and organizational measures to protect your data, including:
While we strive to protect your personal data, no method of electronic storage or transmission is 100% secure. If you suspect any unauthorized access or data breach, please contact us immediately at [email protected].
In the event of a data breach that impacts personal data, we will notify the relevant supervisory authority (e.g., the UK Information Commissioner's Office) within 72 hours of becoming aware, where required by applicable law. We will also notify affected individuals if there is a high risk to their rights and freedoms.
Our Services are not directed at children under 16. You must be at least 18 years of age to use our Services (see our Terms and Conditions). We do not knowingly collect personal information from anyone under 16. If you believe we have unintentionally processed a minor's data, please contact us so we can delete it.
Rights under the GDPR/UK GDPR:
You have the right to request access to, rectification of, or erasure of your personal data. You may also have the right to restrict or object to certain processing, as well as the right to data portability.
To exercise these rights, email [email protected]. We will respond within one month (or as required by law).
Complaint: If you have concerns about our data practices, please contact us first. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or another relevant supervisory authority.
No Sale of Personal Information: We do not sell or share personal information for monetary or other valuable consideration.
Your Rights:
To exercise any of these rights, please email [email protected]. If you believe we are "selling" your data despite our statement, contact us so we can address your concerns.
We strive to comply with the principles of PIPEDA. Canadian users have the right to:
Our Chrome extensions provide functionality that operates on third-party platforms including LinkedIn®, Gmail, and Outlook. We are not affiliated with, endorsed by, or sponsored by any of these platforms. Your use of our extensions on these platforms is at your own discretion and risk. You are responsible for understanding and complying with the terms of service of any platform you use in conjunction with our Services. We do not assume liability for any account restrictions, suspensions, or other actions taken by these platforms as a result of your use of our Services.
We may update this Privacy Policy from time to time by posting a new version on our website. Unless otherwise stated, any modifications take effect as soon as they are posted. We encourage you to review this page periodically to stay informed about how we protect your information.
If you have questions or comments about this Privacy Policy, or wish to exercise any data subject rights, please reach out to:
Sellframe Ltd. (trading as "Add to CRM")
14 Avonside Grove, Hamilton, UK, ML3 7DL
Email: [email protected]