Futuria CRM (offered by Glofu Srl Unipersonale) works in collaboration with its technical partner HighLevel to provide the SaaS platform. In this context, Futuria CRM clients act as data controllers (they decide which personal data to collect and how to use it), while Futuria CRM – through the HighLevel infrastructure – acts as data processor and handles the data solely in accordance with the client’s instructions. Futuria CRM never uses users’ personal data for its own purposes or beyond what the client has authorised. HighLevel, as technical partner, holds the role of sub-processor, supporting Futuria CRM in carrying out these tasks. A dedicated Data Processing Agreement (DPA) sets out these roles and obligations in contract, ensuring that all parties comply with the privacy legislation in force.
Futuria CRM is committed to ensuring compliance with the main data protection laws worldwide. In particular, the platform is aligned with the GDPR (Regulation (EU) 2016/679), ensuring transparency, control and rights for European data subjects. Strict principles of minimisation and purpose limitation are applied, and all the rights provided for (access, rectification, erasure, portability, objection, restriction) are supported through dedicated procedures. In addition, we offer clients a DPA governing data processing in line with GDPR standards, including the European Commission’s Standard Contractual Clauses (SCCs) to legitimise any international transfers.
In parallel, Futuria CRM complies with the California Consumer Privacy Act (CCPA) for the protection of California residents’ data, providing transparency mechanisms on the categories of data collected and the purposes of use, as well as options to exercise the right to opt out of the sale or sharing of data and to access or delete one’s own data. We also keep up to date with other international laws (such as the LGPD in Brazil and PIPEDA in Canada) to ensure an adequate level of protection wherever we operate.
Futuria CRM builds its platform on the HighLevel infrastructure, which has obtained certification under the EU–U.S. Data Privacy Framework (DPF) programme. This means that transfers of personal data from the EU to the United States take place in accordance with the new transatlantic framework, with additional supervision by the U.S. Federal Trade Commission (FTC) over the commitments undertaken. In short, Futuria CRM client data is processed lawfully and in compliance with the legislation in force, wherever it is processed.
To guarantee maximum security, reliability and scalability, Futuria CRM uses an enterprise-grade cloud infrastructure. The platform resides in cloud data centres in the United States provided by the industry leaders: Google Cloud Platform (GCP) and Amazon Web Services (AWS). HighLevel (technical partner) relies on these certified providers, benefiting from their strict physical, environmental and infrastructure security controls, which are audited regularly. The data centres offer high service availability (an SLA above 99.5% on GCP and up to 99.95%–100% on AWS) and have verified business continuity and disaster recovery plans, as attested by SOC 2 Type II compliance reports and the ISO 27001 certification of the AWS infrastructure.
The Futuria CRM cloud architecture is designed with redundancy at every level: server resources are distributed across multiple availability zones and isolated cloud networks, so as to avoid single points of failure. The system can scale automatically according to load, ensuring consistent performance. Moreover, no production data or system is hosted in the physical offices of Futuria CRM/HighLevel; the entire infrastructure is concentrated in protected cloud data centres, eliminating the risks associated with on-premise facilities. Thanks to this solid infrastructure, operational continuity and high reliability are guaranteed for all the platform’s services.
Futuria CRM adopts multiple layers of technical and organisational protection to safeguard client data. Encryption is implemented both in transit and at rest: all data exchanged between users and the platform is encrypted with TLS 1.2/1.3 protocols using 2048-bit keys (or stronger), preventing interception during transmission. Data stored in databases and cloud storage is encrypted with the AES-256 algorithm (256-bit Advanced Encryption Standard) – a military-grade standard – ensuring that, even in the event of unauthorised access to the physical media, the information remains unreadable. Encryption keys are handled through a dedicated, secure Key Management system, with periodic key rotation according to the sensitivity of the data.
Beyond encryption, the platform is protected by robust network security systems. The core components of the application are isolated in separate segments for each client: the solution is multi-tenant, but every account is logically segregated through unique identifiers and authorisation rules that prevent data belonging to different tenants from mixing. Network boundaries are defended by advanced firewalls and perimeter filters: all incoming traffic is monitored and inspected, with a default “deny-all” policy (blocking any connection that is not expressly authorised). Network-level access control lists (ACLs) prevent unauthorised connections to the internal infrastructure. Firewall rules are reviewed periodically to ensure that only the necessary ports and services remain open.
Intrusion Detection/Prevention systems and continuous monitoring are in use, analysing traffic behaviour and generating alerts in the event of anomalous or malicious activity. For example, application-level protections (Web Application Firewall) are active, able to detect and block common attacks (following the OWASP Top 10 guidelines) and to mitigate Distributed Denial of Service (DDoS) attempts, guaranteeing the continuous availability of users’ sites and services. The automated monitoring system triggers immediate responses or alerts to the security team if errors, abuse or attack patterns are detected, with automatic triggers (e.g. traffic throttling, blocking of processes) when predefined thresholds are exceeded. In addition, Futuria CRM carries out periodic security testing on the application and the infrastructure (vulnerability scanning and penetration testing) in order to identify and resolve any vulnerabilities proactively. Thanks to these measures, client data is protected from unauthorised access and cyber threats, ensuring confidentiality and integrity.
Futuria CRM implements strict access control policies for both platform users and technical staff, following the principle of least privilege. Clients have tools to manage access to their own data independently: the application offers granular authorisation rules that make it possible to create users and assign roles and permissions, restricting actions according to responsibilities. Account administrators can define who may view or modify sensitive information and can make two-factor authentication (2FA) mandatory for all users of their workspace. By default, multi-factor authentication is enabled for Futuria CRM accounts: every login requires not only strong passwords (at least 8 characters with upper-case and lower-case letters, numbers and symbols) but also a second verification factor (e.g. a temporary OTP code), to ensure that only the legitimate owner gains access. This adds a further layer of protection against unwanted access even if credentials were to be compromised. In addition, the platform records in audit logs every login attempt and all relevant user activity, so that access to the system can be monitored and analysed.
Internal access to data by the Futuria CRM/HighLevel team is also strictly controlled. Only a limited number of authorised technicians (for example from the Engineering department) can access the production infrastructure, and in any case following a Role-Based Access Control (RBAC) model with the privileges strictly necessary for the role. Staff are not permitted to connect freely and directly to production servers: any maintenance access must take place through secure bastion hosts and using temporary credentials or dedicated IAM roles, with every activity tracked. Customer support staff cannot access data content without explicit authorisation: where it is necessary to assist a client inside their account, a Just-In-Time (JITA) access mechanism is used, which guarantees access that is limited in time (e.g. a maximum of 24 hours) and in scope (only the sections indispensable for support). Every support request involving JITA access is logged and monitored with automated systems that detect anomalous activity, and in any case during these temporary sessions staff are unable to perform destructive actions or export data (critical functions such as exporting contacts, changing security settings and mass deletion of records are blocked). All user and staff access, as well as significant operations on the platform, are recorded in centralised logs; these audit logs are kept in a secure system and are available for any forensic analysis or compliance requirements. In short, Futuria CRM ensures that access to data is strictly regulated and traceable, protecting information from improper use both externally and internally.
To protect data from loss or incidents, Futuria CRM has robust backup systems and disaster recovery plans. All data in the platform’s databases is saved with regular backup copies according to predefined schedules. At least 7 daily backup copies are kept for each database, ensuring that data can be restored up to a week back should the need arise. Backups are stored in redundant cloud infrastructure within the same principal geographic region (USA) and are subject to continuous monitoring: if a backup operation fails, the system generates immediate alerts so that the technical team can intervene promptly.
The restore mechanisms are tested regularly to guarantee that, when required, data can be recovered quickly and in full. All critical components (web, application, database) are implemented with point-in-time recovery capability, allowing restoration to precise moments in time in the event of errors or data corruption. In the event of serious failures or the unavailability of an entire cloud zone, the distributed architecture allows failover to alternative zones, minimising downtime.
On the application side, the platform also provides self-service tools for clients: for example a recycle bin, through which deleted items (contacts, opportunities, notes, and so on) can be recovered within 30 days, and a versioning feature to restore earlier versions of web pages or emails built in the editor. In addition, through Futuria CRM’s public APIs, clients can periodically export and synchronise their data to external systems, effectively creating additional safety copies. These options offer further peace of mind, but in parallel Futuria CRM ensures that its entire cloud infrastructure is resilient and ready to face emergencies: the disaster recovery plans provide documented procedures for restoring services quickly, with clearly defined roles and responsibilities within the technical team. Thanks to constant backups and a proven disaster recovery strategy, our users’ data remains safe even in the most adverse scenarios.
Futuria CRM takes a proactive approach to managing security incidents, with the primary objective of preventing breaches and, should they occur, of immediately mitigating their effects. A detailed Incident Response plan is in place, defining the phases of identification, containment, eradication, recovery and post-incident analysis. Thanks to the round-the-clock monitoring systems mentioned above, any anomaly or intrusion is detected promptly; this allows our security team to act quickly and in a coordinated way. Periodic testing of the response plans (for example data breach simulations) is carried out to sharpen the readiness of staff and the effectiveness of the procedures.
In the event of a personal data breach, Futuria CRM (working with HighLevel) undertakes to inform the affected clients promptly, providing all known information about what happened, in line with the requirements of the GDPR (notification within 72 hours of detection, where applicable). The notifications would include the nature of the breach, the data involved, the possible consequences and the corrective measures adopted. At the same time, we activate containment actions to block improper access and protect the systems (for example by isolating compromised components) and we proceed with the secure restoration of services. A forensic analysis is then carried out to identify the root causes of the incident, and improvements are implemented to prevent similar events from recurring in future.
Futuria CRM regards its clients’ trust as a fundamental asset: this is why transparency and speed underpin our approach to incidents. Beyond the notifications due, we make dedicated channels available to support clients in dealing with the event (e.g. providing guidance on how to notify the authorities or the data subjects, if necessary). It is worth stressing that, thanks to the solid security measures in place, incidents are extremely rare, but we are prepared to handle them effectively should they occur.
To deliver its services, Futuria CRM relies on a number of carefully selected sub-processors (third-party providers), which process personal data on behalf of Futuria CRM in specific areas. All these providers are bound by contractual agreements that govern their access to data and impose security and confidentiality standards equivalent to those we adopt. Below is a summary table of the main sub-processors and their respective roles:
| Sub-processor | Service/purpose | Location |
|---|---|---|
| HighLevel (LeadConnector LLC) | Core CRM SaaS platform and cloud infrastructure (principal technical partner) | USA |
| HighLevel India Pvt. Ltd | HighLevel affiliate for infrastructure support and development | India |
| Google Cloud Platform | Cloud hosting and data storage | USA (data centres) |
| Amazon Web Services (AWS) | Cloud hosting and data storage | USA (data centres) |
| Twilio | SMS/telephony communication services | USA |
| Mailgun | Transactional email sending service | USA |
| Stripe | Online payment gateway (PCI-DSS compliant) | USA |
| Authorize.net | Online payment gateway | USA |
| Zoom | Integrated videoconferencing platform | USA |
| Yext | Management of local listings and reviews (reputation) | USA |
| Zapier | Automated integration with third-party services (automations) | USA |
| Freshworks (Freshdesk) | Helpdesk and customer support platform | EU / USA |
| OpenAi | Provider of artificial intelligence features (“AI Provider”) | USA |
| ChartMogul | Revenue/subscription metrics analytics | EU (Germany) |
| FirstPromoter | Affiliate programme management | EU (Germany) |
(Note: the complete, up-to-date list of sub-processors is available in our DPA and can be provided on request. Futuria CRM/HighLevel notifies clients of any additions or significant changes.)
All the sub-processors listed have been assessed to ensure their compliance with the applicable privacy legislation. We make sure that each provider adopts adequate security measures and processes data solely for the purposes established and instructed by Futuria CRM. For example, data is hosted on secure Google/AWS infrastructure, communications take place through reliable providers such as Twilio/Mailgun, and payments are handled by PCI-DSS certified processors such as Stripe and Authorize.net. We maintain data processor appointment agreements with all these parties and, as part of our ongoing commitment, we review their security and privacy standards periodically. This ecosystem of sub-processors allows us to offer advanced features while ensuring that the data processing chain remains under control and compliant with the law.
To improve operational efficiency in client management and in supporting the Service, authorised Futuria Marketing staff use assistants based on generative artificial intelligence. These tools are used to support the work of operators and do not replace human judgement: all actions that affect client data are validated by an operator.
It is important to distinguish these tools from the Service sub-processors listed above: whereas the latter are an integral part of the CRM infrastructure and operate continuously, the AI assistants listed in this section are accessory operational tools used by staff, under full human control and on an occasional basis.
| Provider | Tool | Registered office | No-training | Retention | Transfer outside the EEA |
|---|---|---|---|---|---|
| Anthropic, PBC | Claude (including Claude Code) | San Francisco, CA, USA | Configured (opt-out active) | 30 days (abuse monitoring) | SCCs + DPF where applicable |
| OpenAI, L.L.C. (EU: OpenAI Ireland Ltd.) | ChatGPT | San Francisco, USA / Dublin, IRL | Configured (“Improve the model for everyone” toggle OFF) | 30 days (abuse monitoring) | SCCs + DPF where applicable |
(Last updated: 13 May 2026)
Separately from the role of data processor performed for the data uploaded by clients to the Platform, Glofu S.r.l. Unipersonale / Futuria Marketing may process the data of its own professional contacts as an independent controller, for commercial, operational and relationship management purposes.
For these activities we use internal, confidential documentation and knowledge management tools. Such tools may contain notes on clients, prospective customers, partners, suppliers and professional contacts, including contextual information, interaction history, attendance at calls or meetings and operational assessments limited to managing the relationship.
Access to these notes is limited to authorised staff following the principle of least privilege. Operational notes must not contain special categories of data, diagnoses, intimate information or assessments that are not necessary to the professional relationship. Any inferences are limited to operational purposes, must be based on observed facts and do not produce automated decisions.
Futuria CRM is a service offered by an Italian company (Glofu Srl) and operates with clients both in the EU and worldwide. Personal data collected through the platform may be transferred outside the user’s country of origin (for example, it is hosted on servers in the United States, as described above). We are fully aware of the implications of such transfers and have implemented the necessary contractual and organisational safeguards to ensure that data retains an adequate level of protection abroad as well, in compliance with Chapter V of the GDPR.
As mentioned, our DPA with clients includes the Standard Contractual Clauses (SCCs) approved by the European Commission, which legitimise transfers of data from the EU to third countries such as the USA. These clauses impose on non-EU recipients (in this case HighLevel and its US sub-providers) binding data protection obligations comparable to the European ones. In addition, thanks to HighLevel’s certification under the EU-U.S. Data Privacy Framework (DPF), data transferred to the United States falls within a recognised protection regime, which offers specific redress and oversight mechanisms for European data subjects. For transfers to other countries (e.g. HighLevel India for technical purposes), adequacy assessments are carried out and, where necessary, supplementary measures (encryption, pseudonymisation, etc.) are applied in addition to the SCCs.
Futuria CRM constantly monitors legal developments concerning international transfers. Should there be changes (for example rulings or guidance from the authorities that may affect the validity of transfers), we are ready to adapt our measures and, where appropriate, to enter into additional agreements or configure suitable local data residency solutions. Our objective is to ensure that client data always travels securely and compliantly, regardless of where it is processed, thereby offering peace of mind both to us and to our users in using Futuria CRM globally.