Privacy

Sub-Processors

Last updated · April 19, 2026

Download a signed copy as PDF — same content, suitable for procurement and DPO records.

This page lists the categories of sub-processors lead.box engages to provide the Service. Infrastructure providers are named below; category-critical intelligence providers are described by function and region and are named to customers on request (confidential). This protects the integrity of our supply chain while giving you the information required by GDPR Art. 28 and related contractual data-protection obligations: category, purpose, location, data categories and the contractual safeguards in place. The full list forms Annex I of our Data Processing Agreement.

ProviderFunctionLocationData CategoriesLegal Safeguard
Stripe
Payment Processing
Processing of subscription payments and invoicingIreland (EU) / United StatesName, billing address, email, payment methodGDPR Art. 28 DPA, EU SCCs, PCI-DSS Level 1
Resend
Transactional Email
Delivery of transactional emails (account, lead alerts, billing)European Union / United States (parent)Recipient email, name, message contentGDPR Art. 28 DPA, EU data residency, EU SCCs
Heroku (Salesforce)
Application Runtime
Hosting of internal background jobs and processing pipelinesEuropean Union (eu region)Processing logs, transient job payloadsGDPR Art. 28 DPA, EU SCCs
Cloudflare
Edge Network & DDoS Protection
CDN, WAF and traffic routing for the tracking endpointGlobal edge with EU-preferred routingIP addresses, request metadataGDPR Art. 28 DPA, EU SCCs
Supabase
Database & Authentication
Managed PostgreSQL, authentication and file storageEU (Frankfurt, eu-central-1)Account, tracking and lead dataGDPR Art. 28 DPA, EU-only data residency
GDPR-Compliant IP & Company Intelligence
Resolution of public company IP ranges into firmographic informationEuropean Union / EEAAnonymised IP, company metadata (name, domain, industry, size)GDPR Art. 28 DPA, EU/EEA processing — specific provider and sub-sub-processor list named to customers on request under a confidentiality undertaking

1. Notification of changes

We notify customers of intended additions or replacements of sub-processors at least 30 days in advance, giving you a reasonable opportunity to object on data-protection grounds. Active customers receive notifications via email; this page is the canonical source.

2. Safeguards in place

  • Written sub-processor agreements meeting GDPR Art. 28 requirements
  • EU Standard Contractual Clauses for any transfers outside the EEA / UK
  • EU-preferred data residency wherever technically feasible
  • Contractual restriction to processing on documented instructions only
  • Regular review of each sub-processor's security posture and certifications

3. Customer audit

Customers with a signed DPA may request additional information about specific sub-processors, including copies of audit reports where available, by contacting info@lead.box.

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links