GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page. Opt-out page.
lead.box applies all five rules by design.
Piliers
L'intérêt légitime, en termes simples
Nous traitons les données au niveau de l'entreprise — une personne morale, jamais une personne physique. Au sens de l'art. 6(1)(f) du RGPD, ce traitement repose sur l'intérêt légitime, avec un test de mise en balance documenté en faveur de l'activité économique. Le traceur utilise un identifiant fonctionnel first-party sur votre propre domaine ; la question de savoir si le §25 du TDDDG impose un consentement relève de la décision de l'opérateur dans sa politique de confidentialité, et non d'une affirmation de notre part.
Art. 6(1)(f) RGPD — intérêt légitime
Identification B2B au niveau de l'entreprise pour le pipeline commercial du propriétaire du site. Test de mise en balance documenté.
TDDDG §25 — périmètre fonctionnel first-party
Seul un identifiant fonctionnel first-party est déposé sur votre propre domaine — aucun cookie publicitaire, aucun cookie cross-site. La question de savoir si le §25 du TDDDG le considère comme strictement nécessaire relève de votre DPO ; nous décrivons le périmètre exact pour votre politique de confidentialité.
Aucune donnée personnelle du visiteur
Nous identifions des organisations, pas des individus. Les identifiants personnels sont hors du périmètre du produit.
Paragraphe de politique de confidentialité prêt à l'emploi
Intégrez ce texte dans votre propre politique de confidentialité. Il reflète exactement ce que lead.box fait sur votre site.
This website uses lead.box (operated by lead.box LLC) to identify visiting organisations on the level of the company. For that purpose the tracker sets a first-party functional identifier (e.g. a device-scoped ID stored on this website’s domain) and processes technical connection data (in particular the IP address) transiently to resolve the visiting organisation. No advertising cookies and no cross-site cookies are used, no personal profile is created and no cross-site tracking takes place. Processing is based on Art. 6(1)(f) GDPR (legitimate interest of the site operator in B2B lead identification). All processing takes place on EU infrastructure inside ISO 27001-certified European data centers. You can opt out at any time at https://lead.box/opt-out.
Documents associés
Tout ce que votre équipe juridique ou votre DPO peut demander est à portée d'un clic.
Frequently asked questions
The compliance questions we hear most often — answered without legalese.
It is workable under the GDPR when it stays at company level. Identification resolves the organisation behind a visit through network and IP-to-company matching; individual people are never identified, and a visit that cannot be matched to a company stays anonymous. lead.box applies all five rules by design, and publishes a DPA and a sub-processor list for review.
Legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test: a legitimate purpose, necessity, and a weighing of interests. Consent is not required where no personal identifiers are processed. The final assessment stays with you as the controller; lead.box acts as processor under a DPA.
No personal identifiers are processed, so no advertising consent category is involved: there are no names, personal e-mail addresses, device fingerprints or cross-site profiles, and raw network addresses are not available in the interface, exports or API. Whether you still place the snippet behind a consent category is your own assessment — lead.box does not gate itself.
In the European Union. Personal and visitor data concerning the EU is processed in ISO-certified data centres in the EU, and EU visitor data is not moved outside the EU for this purpose. The DPA under Art. 28 GDPR and the versioned sub-processor list are published, so a data protection review is possible before you commit.
Through the public opt-out page, at any time — and companies can additionally request a company-level opt-out. Transparency is the other half of this rule: disclose the identification in your privacy policy, for which a copy-ready paragraph is provided on this page.
No, deliberately not. lead.box shows you which companies visit your website — name, industry, size and the pages they viewed. It never tells you which person was on the site. Visitors from home offices or mobile networks stay anonymous, because their connection cannot honestly be matched to a company. That limit is a feature, not a gap: it is what keeps company-level identification GDPR-friendly.
Yes. Every customer can sign our DPA digitally in a few minutes — no email back-and-forth. The full list of sub-processors is published openly and versioned, so you always know which providers are involved in processing. Both documents are available before you buy, so legal review can happen during your free trial.
You add one small snippet to your site, served first-party via your own domain. It records page visits; the company behind a visit is resolved server-side by lead.box. It is not an advertising tracker — no cross-site profiles and no person-level identifiers are created. Installation works the same way for classic websites and single-page apps.
The network address is used to resolve the organisation and the connection type; the visit record keeps that result, not the raw value, and raw addresses are not available in the interface, exports or API. Retention windows for visit history are set out in the DPA, which is public and signable before you buy.
Because identification stops at the organisation, there is no person-level profile to hand over or erase. Company records can be removed from your workspace, workspace-wide deletion requests run through the contact channels named in the DPA, and any visitor can object through the public opt-out page.
Générez un pipeline validé par votre DPO
Démarrez gratuitement, ou demandez une présentation avec le paragraphe ci-dessus déjà adapté à votre site.