GDPR

Zgrajeno za evropsko pravo o zasebnosti, ne za njegovo obhajanje

lead.box je zasnovan tako, da lahko evropske prodajne ekipe identificirajo B2B obiskovalce brez kompromisov pri standardih, ki jih morajo zagovarjati njihove pravne, varnostne in DPO ekipe.

GDPR-firstSamo first-partyGostovanje v EU · Podatkovni centri ISO 27001Digitalna DPA

Stebri

Pripravljen odstavek za politiko zasebnosti

Prilepite ta odstavek v svojo politiko zasebnosti. Odraža to, kar lead.box na vašem spletnem mestu dejansko počne.

This website uses lead.box (operated by lead.box LLC) to identify visiting organisations on the level of the company. For that purpose the tracker sets a first-party functional identifier (e.g. a device-scoped ID stored on this website’s domain) and processes technical connection data (in particular the IP address) transiently to resolve the visiting organisation. No advertising cookies and no cross-site cookies are used, no personal profile is created and no cross-site tracking takes place. Processing is based on Art. 6(1)(f) GDPR (legitimate interest of the site operator in B2B lead identification). All processing takes place on EU infrastructure inside ISO 27001-certified European data centers. You can opt out at any time at https://lead.box/opt-out.

Vse, kar zahteva pravna ekipa ali DPO, je oddaljeno en klik.

Frequently asked questions

The compliance questions we hear most often — answered without legalese.

Yes — when it happens at company level, which is exactly how lead.box works. We resolve visits to companies, never to individual people, and all data is processed in the EU. You get a DPA you can sign digitally, and our sub-processor list is public. Person-level tracking of anonymous visitors would be a different story — that is precisely what lead.box does not do.

No, deliberately not. lead.box shows you which companies visit your website — name, industry, size and the pages they viewed. It never tells you which person was on the site. Visitors from home offices or mobile networks stay anonymous, because their connection cannot honestly be matched to a company. That limit is a feature, not a gap: it is what keeps company-level identification GDPR-friendly.

In the European Union. Your visit data is processed and stored on EU infrastructure — no analytics data is shipped to servers outside the EU. Together with the public DPA and the published sub-processor list, this makes it straightforward for your data protection officer to review lead.box before you commit to anything.

Yes. Every customer can sign our DPA digitally in a few minutes — no email back-and-forth. The full list of sub-processors is published openly and versioned, so you always know which providers are involved in processing. Both documents are available before you buy, so legal review can happen during your free trial.

You add one small snippet to your site, served first-party via your own domain. It records page visits; the company behind a visit is resolved server-side by lead.box. It is not an advertising tracker — no cross-site profiles and no person-level identifiers are created. Installation works the same way for classic websites and single-page apps.

Yes. There is a public opt-out page where any visitor can object, and companies can additionally request a company-level opt-out. Combined with company-level resolution and EU processing, this keeps the balance between your legitimate interest in B2B lead generation and the rights of your visitors transparent and fair.

Most customers rely on legitimate interest under Art. 6(1)(f) GDPR, which is a three-step test: a legitimate purpose, necessity, and a balancing of interests. Company-level identification is built to sit well in that test — the output is a legal entity, no cross-site profiles are created and processing stays in the EU. The final assessment is always yours to document.

That depends on your own assessment. lead.box does not gate itself: the snippet runs where you place it. You can load it unconditionally like any other functional script, or bind it to a consent category in your consent management platform so it only runs after that category is accepted.

The network address is used to resolve the organisation and the connection type; the visit record keeps that result, not the raw value, and raw addresses are not available in the interface, exports or API. Retention windows for visit history are set out in the DPA, which is public and signable before you buy.

Because identification stops at the organisation, there is no person-level profile to hand over or erase. Company records can be removed from your workspace, workspace-wide deletion requests run through the contact channels named in the DPA, and any visitor can object through the public opt-out page.

Gradite pipeline, ki jo vaš DPO podpiše

Začnite brezplačno ali zaprosite za predstavitev — z zgornjim odstavkom, že prilagojenim vašemu spletnemu mestu.

Preizkusite brezplačno

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links