A form on the website is not one step, but a chain of four systems
Client submissions rarely come directly to you. They usually pass through a chain:
- 01form
- →02automation
- →03CRM
- →04notification
Each link is a separate server, often with a different provider and in a different country.
The form collects data and sends it to an automation tool, such as n8n or Make. This tool passes it on to a CRM, where the salesperson or receptionist sees the submission together with the client's history. At the end, the system sends a notification – by email, via Messenger or WhatsApp – so someone in the company can respond the same day.
Each of these four steps is separate processing of personal data under GDPR. The company owner is responsible for what happens to client data at each stage, not the tool provider. That's why before connecting another system to the form, it's worth knowing whose hands the submission actually passes through.
n8n, Make and Zapier: who really decides where client data is stored
Not every automation tool stores data in the same place. n8n can be deployed on your own server. Then you decide in which country the client data is stored.
- Form on page
- CRM
- Team inbox
- SMS gateway
- Backup
Make and Zapier work differently – they are ready-made cloud services, so the provider decides the server location, not you. Therefore, the jurisdiction of each tool needs to be checked separately, in its terms and privacy policy, instead of assuming they all work the same way. The same applies to integrations with Google Calendar, Google Business Profile or SMSAPI. Each of these systems has its own data retention policy.
Google Calendar and Google Business Profile are a separate case. Some Google services allow you to choose the data storage region, but this has to be set deliberately, not assumed to happen by default. A consultant connecting the booking calendar to automation should check this together with the administrator before the system starts saving client data in it.
An administrator or consultant implementing automation should have a list of all connected tools and a verified data processing agreement with each of them, in accordance with UODO principles. Without this list, no one in the company can answer the client's question about where their data physically resides. You can find more about linking systems at integrations.
How much does it cost to organize automation for GDPR
Checking where data ends up is not expensive – neglecting this step is what can be costly. Email integration and Telegram or WhatsApp integration are two different pieces of work — the scope of each is settled after a conversation about what the business needs. This allows you to close the submission channel in one controlled place instead of spreading data across several separate inboxes.
If automation is also supposed to save submissions in CRM and track who handled them and when, another stretch of the same road is added — its scope is settled in conversation. The admin panel, where the owner or manager sees all submissions and their handling history in one place, closes that chain: under GDPR what counts is not only where the data sits, but whether you can show who touched it. There are no amounts to add up here – the scope is matched to what actually happens to data in the particular company.
If query automation already works in the company but no one has checked where the data goes, it's worth starting with an audit of connections instead of building more. We price connecting a form to CRM and notifications, i.e., query automation, after a conversation about exactly what needs to happen. This is a one-time setup cost, not a monthly subscription, because we're talking about configuration, not ongoing maintenance.
When automating submissions is a bad idea
A company that handles submissions independently and has no problem responding on time doesn't need a chain of systems. Each additional tool is another place where client data can get stuck or be stored longer than necessary. Sometimes a simple email inbox and one person reading it is safer than five connected applications.
Automation can also be risky when no one in the company is responsible for maintaining it. An integration can stop working after an update to one of the tools. The submission then goes nowhere and the client waits for a response. When such a failure occurs, someone needs to notice and fix it – usually a technician or administrator who knows the entire chain of connections, not just one element.
We don't promise that automation itself will resolve GDPR compliance issues. Those are resolved only by a decision on who administers the data and where it's stored. We only guarantee that after implementation, it's clear who is responsible for which stage. This is not something you can buy once and forget about.
Frequently asked questions about client data and integrations
Do I need a processing agreement with every automation tool?
Yes, if the tool processes clients' personal data on your behalf, you need a data processing agreement in accordance with GDPR requirements. This applies both to n8n or Make and to the CRM where the salesperson saves the contact history. The agreement is made with the tool provider, not the end client.
Can client data end up outside the European Union?
It can, if you use a cloud tool whose provider has servers outside the European Economic Area. In such a situation, a legal basis for transfer is needed, usually the provider's standard contractual clauses. You can check this in the tool's privacy policy, preferably before integrating with it, not after the fact.
Who in the company is responsible for automation compliance with GDPR?
Formally, always the company owner as the data administrator, regardless of who technically implemented the integration. In practice, day to day, this responsibility is taken over by the person designated to maintain the system – an administrator or consultant who knows the entire chain of tools.
Does a smaller company also need to check this?
Yes, obligations arising from GDPR don't depend on the company's size, only on whether you process personal data. One integration of a form with CRM already falls under the same rules as in a large company. The scale affects how many points you have to check, not whether you need to do it at all.
Do WhatsApp and Messenger also fall under GDPR?
Yes. If a client writes to you via WhatsApp or Messenger and leaves data, such as their name, phone number, or the content of their question, this is also personal data processing. The messaging app provider has its own message storage policy, independent of your CRM. When automation copies these messages to CRM, the same obligation to check the processing agreement applies to this channel.
Let's talk about where client data physically ends up in your company and how to organize it in one system.