GDPR Compliant
All processing complies with EU Regulation 2016/679 (GDPR).
EU Data Residency
Customer data is stored in the European Union by default.
EU Standard Contractual Clauses
SCCs are in place for any limited transfers outside the EU/EEA.
Encryption at Rest & in Transit
AES-256 encryption at rest and TLS 1.2+ for all connections.
First-party identifiers only
No advertising or cross-site cookies. Company-level tracking uses a first-party functional identifier only — no data sold to ad networks.
Data Minimisation
We only process the firmographic data needed to identify B2B leads.
A privacy-first lead identification platform
lead.box identifies the companies visiting your website using publicly available IP intelligence. We do not track individual people, and we do not enrich personal data without a lawful basis. Every part of our processing chain — from collection at the edge to storage in the database — is designed around GDPR principles.
Questions about security or compliance? Reach our team at
info@lead.box