Markets

See your European and US buyers, not your mainland traffic

Chinese exporters, trading houses and manufacturers already sell across Europe and North America — and their websites see research from procurement teams in Hamburg, Chicago or Rotterdam long before an inquiry form is filled in. Company-level identification turns that quiet browsing into a named account: a European distributor, a US importer, a specific buyer worth a follow-up call.

  • Framework referencedPIPL (Personal Information Protection Law, 2021) as the relevant mainland framework
  • SupervisionCyberspace Administration of China (CAC), for mainland personal information matters
  • Scope of this productCompany-level identification of European and US website visitors
  • Processing locationISO-certified EU data centres

This page is deliberately narrow in scope. It explains what lead.box does for the international side of a Chinese company's traffic, and it is equally clear about what it does not attempt inside mainland China.

At a glance

Framework referenced
PIPL (Personal Information Protection Law, 2021) as the relevant mainland framework
Supervision
Cyberspace Administration of China (CAC), for mainland personal information matters
Scope of this product
Company-level identification of European and US website visitors
Processing location
ISO-certified EU data centres

Why this page does not promise mainland coverage

Regulation at a glance

  • Framework referencedPIPL (Personal Information Protection Law, 2021) as the relevant mainland framework
  • SupervisionCyberspace Administration of China (CAC), for mainland personal information matters
  • Scope of this productCompany-level identification of European and US website visitors
  • Processing locationISO-certified EU data centres

The PIPL, in force since November 2021, is China's comprehensive personal information law, enforced under the Cyberspace Administration of China together with sector regulators. It sets its own consent standard, its own rules on cross-border data handling, and — for larger or sensitive processors — security assessments and standard contract mechanisms before personal information can leave the mainland. None of that is a formality a foreign SaaS vendor can satisfy by adding a clause to a contract.

Data export and localisation requirements under the PIPL, together with the Data Security Law and the Cybersecurity Law that surround it, are the reason lead.box does not process or store personal information relating to mainland Chinese visitors, and does not claim any PIPL certification or CAC approval. Rather than describe a compliance posture it cannot substantiate, lead.box keeps its scope to what it actually does: identify company-level visitors from Europe and the United States and process that data in ISO-certified EU data centres.

For a Chinese company selling internationally, this division of labour is usually the right one anyway. Your European and US buyers' visits are governed by GDPR-style rules that lead.box is built for; your own mainland compliance obligations under the PIPL, including any assessment of a website's own visitor logging, remain a matter for your own legal and IT teams and are not something a foreign vendor should be assumed to have solved.

What international-facing exporters expect

Export manufacturers and trading companies selling B2B into Europe and the US usually run a website that mixes product catalogues, certifications and an inquiry form — and get most of their real interest from a small number of researching companies rather than a flood of leads. What they want from a visitor identification tool is simple: which company, from which country, looking at which product line, so the sales or export team can follow up while the buyer is still comparing suppliers.

Because the buying company sits in Europe or North America, the relevant data protection question is theirs, not a mainland one — GDPR-style reasoning about legitimate interest and company-level data applies, and a European or US buyer's own procurement or legal team may ask for the same processor documentation any GDPR-facing vendor provides.

Sobriety matters here too. A tool that names a European engineering firm or a US distribution company by name, without resolving named individuals, is a workable and defensible signal. A tool that claims to identify visitors anywhere in the world, including mainland China, without addressing PIPL export rules, is not something a careful export team should rely on.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where this pays off for exporters

Export manufacturers with catalogue-driven sites, trading companies running inquiry-based sourcing pages, and businesses that convert trade-show contacts into follow-up research all see the same pattern: a European or US buyer visits the site repeatedly after a fair or an initial email before sending a real RFQ. Seeing the company name during that research window lets the sales team reach out with the right timing instead of waiting for the inquiry form.

It fits particularly well alongside trade-fair follow-up: a booth conversation at a European or US show is often followed by weeks of quiet website research from the same company before any commitment. Company-level identification turns that research into a list your export sales team can work through weekly.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

Reliable detection of visitors inside mainland China is not something lead.box offers, and we do not want to overstate this. The product is built and tuned to resolve company-level identity for organisations browsing from Europe and the United States, using network-level signals that are well mapped for those regions. Traffic originating from mainland China networks falls outside that coverage in practice, and lead.box does not process or store personal information relating to individuals located in mainland China. If your export site also draws meaningful mainland traffic and you need visibility into that segment, this product is not the tool for it, and you would need a mainland-specific solution assessed separately under the PIPL.

We do not claim PIPL compliance, because that claim would be inaccurate. The Personal Information Protection Law, in force since November 2021 and enforced by the Cyberspace Administration of China, sets its own consent standard, its own rules for cross-border transfer including security assessments, standard contracts and certification routes, and its own scope of personal information. lead.box has not sought PIPL certification and has not been assessed against it, because the product avoids the underlying trigger: it does not process personal information about individuals located in mainland China. What lead.box does claim, and can document, is GDPR-aligned processing of company-level data for European and US visitors, handled in EU data centres under a data processing agreement.

Because lead.box resolves the visiting organisation, not an individual, and the buyer company sits in Europe or the United States rather than mainland China, the applicable legal reasoning is GDPR-style, not PIPL-style. The usual basis is legitimate interest under Art. 6(1)(f) GDPR, supported by a documented balancing test that weighs the exporter's interest in identifying business visitors against the low intrusiveness of company-level, non-individual data. A European or US buyer's own procurement or legal team may ask a Chinese exporter for the same processor documentation any GDPR-facing vendor would provide, including a data processing agreement and sub-processor list, and lead.box supplies both so that chain of accountability is complete on request.

No. Identification runs from company-level network signals rather than cookies, local storage, device fingerprints or any advertising identifier, and it does not attempt to name or profile an individual person behind a visit. The output is a company name, not a person, which is the distinction that matters both for GDPR reasoning around European and US visitors and for keeping the product out of the personal information categories the PIPL, the Data Security Law and the Cybersecurity Law regulate for mainland China. This design choice was made deliberately to keep the product's claims narrow and defensible rather than to stretch coverage into jurisdictions or data categories it cannot properly support.

Chinese export manufacturers and trading companies typically run a small commercial team tracking a defined set of named accounts across export markets rather than a high-volume inbound funnel, often mixing WeChat-based internal coordination with email and phone follow-up toward overseas buyers. lead.box exports identified European and US companies as a CSV or Excel list, or pushes them by webhook into whichever CRM the export team already runs, so the export sales staff can see which named buyer researched a product page after a trade fair conversation or an initial quotation request. A weekly list of researching companies, timed against known trade-show and RFQ cycles, tends to fit this workflow better than a real-time alert dashboard.

A data processing agreement under Art. 28 GDPR is available, along with a published, versioned sub-processor list, and both can be reviewed before signing rather than requested mid-negotiation. Company-level data concerning European and US visitors is processed and stored in ISO-certified EU data centres, and that EU data is not routed through or stored in mainland China as part of this service. This matters for two separate reasons: it keeps the product aligned with GDPR-style expectations that a European or US buyer's own legal team may hold, and it avoids raising the cross-border transfer questions that mainland Chinese data would trigger under the Data Security Law if the product processed it, which it does not.

Rollout is a first-party JavaScript snippet added once to the site, after which identified European and US companies typically start appearing within the first days as qualifying traffic arrives, with no separate onboarding project required. Teams can add colleagues as seats, export results as CSV, Excel or JSON, and wire a webhook into an existing CRM or spreadsheet workflow without custom development. Because many export sites already run analytics or chat widgets, the snippet is designed to sit alongside those without conflicting, and it does not require changes to a site's cookie banner or consent management setup, since it does not rely on the device-level storage those tools govern.

Company-level identification resolves the organisation behind a visit from network-level signals, primarily IP address ranges associated with a known business, and accuracy depends on how cleanly a visitor's network maps to a specific company; visits from home connections, mobile networks, VPNs or shared hosting cannot be reliably resolved and are excluded rather than guessed. For internationally active buyers with recognisable corporate networks — the profile of most European and US procurement teams researching a Chinese supplier — resolution tends to be strong. Coverage for visitors on mainland Chinese networks is limited for the reasons already described, and the tool should be treated as a signal to prioritise follow-up, not as a verified, individually attributed contact record.

See which European and US buyers are already researching you

Install a first-party snippet and get named company visits from Europe and the US, without extending any claim to mainland China.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links