What happens to the address
Every web request carries the address of the network it came from — that is how the internet delivers a response, with or without any analytics on the page. lead.box uses that value for one job: resolving which organisation the connection belongs to, and whether it is a business connection at all.
Once that lookup is done the raw value has served its purpose. What is kept on the visit record is the result — organisation, business-or-consumer classification, coarse location and, where relevant, the internet provider name — not the address itself. Raw address values are not exposed in the interface, in exports or in the API.
What is stored on a visit
A stored visit is a company-level record. It holds the resolved organisation and its profile fields, the pages viewed with timestamps, session duration, the referrer and campaign parameters, and a functional session identifier scoped to your own domain that groups pageviews of the same browser session.
There is no cross-site identifier, no advertising identifier, no device fingerprint and no person-level profile. This matters for retention questions: the record describes an organisation's interaction with your website, not an individual's browsing history.
How long data is kept
Visit history is kept while it is useful to you and while your workspace is active, so that returning accounts can be recognised across a normal B2B sales cycle rather than only within a single session. Concrete retention windows, including what happens after a workspace is closed, are set out in the data processing agreement, which is public and can be signed digitally.
We would rather point you at the contract than quote a number here that could drift out of date. If your privacy assessment needs a specific period in writing, the DPA is the document to cite — and it is available before you buy, during the free trial.
Deletion and control
You keep control of what sits in your workspace: individual company records can be removed from the interface, and a deletion request for your workspace data can be raised through the contact channels named in the DPA. Visitors who object can use the public opt-out page, and companies can additionally request a company-level opt-out.
One more property worth naming: processing runs in the EU, and every processor involved is listed on the public sub-processor page, which is versioned so you can see what changed and when.
Related questions
Read the DPA first
The data processing agreement and the sub-processor list are public, so your privacy review can happen during the free 14-day trial — no credit card required.