Marketing wants the tool. The CFO — or general counsel, or the data-protection officer, depending on the company — wants to be sure it will not create a Monday-morning headline. This piece exists so that your internal champion can walk into that meeting with the ten questions and ten answers already lined up. It is written specifically for company-level visitor identification (what lead.box does). This is non-legal-advice; run the wording past your own counsel.
Non-legal-advice
The wording below is drawn from what we have seen close procurement conversations, not from a legal opinion. Every organisation has to make its own assessment — this piece is a starting point, not a substitute for advice from your DPO or counsel.
Q1. "Is this personal data?"
Answer: Company identifiers (name, domain, industry) are typically not personal data. What we write to a visitor's browser is a first-party identifier that lets us count the same anonymous visit sequence on your own site — no cross-site advertising, no fingerprinting. Handled correctly, the personal-data surface is minimal. See /gdpr for the full breakdown.
Q2. "What is the lawful basis?"
Answer: Legitimate interest under Art. 6(1)(f) GDPR, documented via a Legitimate Interests Assessment. The three-step test — purpose, necessity, balancing — is walked through in our LIA article (linked below). This is the same basis used, defensibly, for standard B2B account intelligence in the EU today.
Q3. "Where is the data processed?"
Answer: In the EU. Our infrastructure is hosted in ISO-certified European data centres and processing stays within the EU. No routine transfers to third countries. See /subprocessors for the current list.
Q4. "Do you sign a DPA?"
Answer: Yes. A standard Data Processing Agreement is available at /dpa. Redlines are possible for larger customers. It maps to the EU-Commission standard clauses where relevant.
Q5. "How long is data retained?"
Answer: Identified-visit records are retained for the duration configured by you at workspace level (default is documented on /gdpr). Aggregate, non-personal analytics may be retained longer. Customer-controlled retention is available on eligible plans.
Q6. "How do people opt out?"
Answer: Two mechanisms. First, a self-serve opt-out at /opt-out that any visitor can trigger. Second, standard browser controls (clearing site data) remove the first-party identifier. There is no cross-site profile to opt out of.
Q7. "Who else touches the data?" (sub-processors)
Answer: A short, published list at /subprocessors. Any change is announced with lead time so customers can object. We do not use advertising networks and do not sell data.
Q8. "What about ePrivacy / TDDDG § 25?"
Answer: § 25 (and ePrivacy more broadly) governs storage of/access to information on the user's device. First-party identifiers strictly necessary for the requested service are subject to the "strictly necessary" exemption; anything beyond that is presented via your existing CMP. Our GDPR page walks through the specifics.
Q9. "What is the breach process?"
Answer: Documented incident-response with customer notification timelines in the DPA. Named security contacts. Sub-processor incidents are treated as our incidents for the purpose of notification.
Q10. "Can we cancel and get our data out?"
Answer: Yes. Standard export formats, no artificial lock-in, deletion on termination as per DPA. The commercial answer matters here as much as the legal one: monthly cancellation, no multi-year lock.
Summary sheet for your champion
| Question | Short answer | Where to point |
|---|---|---|
| Personal data? | Minimal — company data + first-party id | /gdpr |
| Lawful basis? | Art. 6(1)(f) with LIA | LIA post |
| Where processed? | EU-only | /subprocessors |
| DPA? | Yes, standard | /dpa |
| Retention? | Configurable | /gdpr |
| Opt-out? | Self-serve + browser controls | /opt-out |
| Sub-processors? | Short published list | /subprocessors |
| ePrivacy / § 25? | Strictly-necessary first-party only | /gdpr |
| Breach? | Incident response in DPA | /dpa |
| Exit? | Export + delete, monthly cancel | /dpa |
Print this table. Hand it to your CFO before the meeting. Most of the questions never get asked once the answers are already visible.
- Related: [Is website visitor identification GDPR-compliant?](/blog/is-website-visitor-identification-gdpr-compliant)
- Related: [Legitimate interest — Art. 6(1)(f) for B2B marketers](/blog/legitimate-interest-art-6-1-f-gdpr-b2b-marketers)
- Related: [Data minimalism](/blog/data-minimalism-why-collecting-less-makes-b2b-marketing-stronger)
Published by
lead.box Team
More articles
See lead.box on your own traffic
Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.
