Skip to main content
Project Affinity logo

Project Affinity

GDPR evidence

affinity.coCRMLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Project Affinity and GDPR

CertReports found no public GDPR evidence for Project Affinity as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
3 Nov 2023
Expires or valid through
29 Oct 2026
Scope
Affinity collects personal data such as name, email, phone number, and other information about individuals or such information provided by customers for the purpose of providing its services (such as relationship intelligence and customer relationship management software) and related purposes, as well as complying with applicable regulatory requirements. Affinity uses a limited number of third-party service providers to assist us in providing our services to customers. These third party providers assist with the transmission of data, provide data storage services, and support technical operations. These third parties may access, process, or store personal data while providing their services - each of which is subject to agreements with Affinity which restricts their access, use, and processing of applicable data.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Project Affinity, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 aabff80ce4
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
13 May 2019
Scope
We process Personal Data to operate, improve, understand and personalize our Services. We collect Personal Data about you when you provide such information directly to us, when third parties such as our business partners or service providers provide us with Personal Data about you, or when Personal Data about you is automatically collected in connection with your use of our Services. Information we collect directly from you: We receive Personal Data directly from you when you provide us with such Personal Data, including without limitation the following: • First and last name • Email address • Telephone number • Employer Information we receive from third-party sources: Some third parties such as Crunchbase and Clearbit provide us with Personal Data about you, such as the following: • Account information for third-party services: If you interact with a third party service when using our Services, such as if you use a third-party service to log-in to our Services (e.g., Facebook Connect or Twitter OAuth), or if you share content from our Services through a third party social media service, the third party service will send us information about you, such as information from your public profile, if the third party service and your account settings allow such sharing. The information we receive will depend on the policies and your account settings with the third party service. • Information from our advertising partners: We receive information about you from some of our service providers who assist us with marketing or promotional services related to how you interact with our websites, applications, products, services, advertisements or communications. Publicly accessible sources: We use third-party providers to supplement data that you provide to us, using publicly accessible sources. For example, when you provide us with the name of your contact, we may use Clearbit to find your contact’s job title and a corresponding photo from publicly accessible sources (e.g. your contact’s company page). Information we automatically collect when you use our Services: Some Personal Data is automatically collected when you use our Services, such as the following: • Device identifiers • Web browser information • Usage information • Location information • Log data (e.g. access times, hardware and software information) We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below. We share Personal Data with vendors, third party service providers and agents who work on our behalf and provide us with services related to the purposes described in this Privacy Policy or our Terms of Service. These parties include: • Payment processors • Fraud prevention service providers • Ad networks • Analytics service providers • Staff augmentation and contract personnel • Hosting service providers • Co-location service providers • Telecommunications service providers We also share Personal Data when necessary to complete a transaction initiated or authorized by you or provide you with a product or service you have requested. In addition to those set forth above, these parties also include: • Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services) • Social media services (if you interact with them through your use of the Services) • Third party business partners who you access through the Services • Other parties authorized by you We also share information with third parties when you have given us consent to do so (as indicated at the point such information is collected). We also share Personal Data when we believe it is necessary to: • Comply with applicable law or respond to valid legal process, including from law enforcement
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Affinity: Inactive
Live pagesha256 813020d7fc
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Project Affinity GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the CRM category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No CRM vendor has GDPR evidence in the index yet.