§01Subject & duration
Subject is the processing of personal data by lead.box LLC on behalf of the Customer under the main agreement. Duration follows the main agreement.
§02Nature & purpose of processing
Provision of the lead.box software, specifically company-level identification of website visitors on the Customer's sites, storage of visit data, analysis inside the Customer workspace, delivery of notifications.
§03Data-subject & data categories
Data subjects: Employees of visiting companies; end-users of the Customer's websites (only to the extent required for company resolution).
Data categories: IP addresses (short-term), user-agent, requested URLs, referrer, company-resolution result, technical session metadata.
§04Customer's instructions
Processing is carried out solely on the Customer's documented instructions. The main agreement and the configuration set inside the product (retention, recipients, enabled integrations) constitute the complete instructions.
§05Technical & organisational measures
Summary of TOMs (detailed annex available on request):
- Hosting in ISO 27001-certified EU data centres
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access control, MFA for administrators
- Row-Level-Security tenant isolation at the database layer
- Regular backups with restore tests
- Central audit log for security-relevant events
- Vendor review and GDPR-compliant contracts
§06Sub-processors (annex)
We use the following sub-processors. Specific providers are named to customers on request (confidential). Further supply-chain details are available to customers on request under a confidentiality undertaking.
| Purpose | Location | Data categories | Provider |
|---|---|---|---|
| Hosting & database | EU | Account, configuration, visit data | named to customers on request (confidential) |
| Email delivery | EU | Contact emails, auth emails | named to customers on request (confidential) |
| Company data enrichment / IP-to-company resolution | EU | IP addresses (short-term), company metadata | named to customers on request (confidential) |
§07Liability
Liability is governed by the main agreement; otherwise the statutory rules of Art. 82 GDPR apply.
§08Deletion on termination
Upon termination, personal data is, at the Customer's option, returned or deleted, no later than 30 days after termination, unless a statutory retention obligation applies.
In your account
Sign the DPA digitally
No PDF ping-pong. Conclude the DPA in one click from your workspace settings.
Open workspace