GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page. Opt-out page.
lead.box applies all five rules by design.
支柱
用通俗语言解释合法利益
我们在企业层面处理数据,所涉及的是法律实体,而非自然人。根据《通用数据保护条例》(GDPR) 第 6(1)(f) 条,此类处理以合法利益为基础,并有书面利益平衡测试证明企业利益优先。跟踪器会在您自己的域名上使用第一方功能性标识符;§25 TDDDG 是否要求对此征得同意,应由运营方在隐私声明中作出判断,我们不会代表您作出此类主张。
GDPR 第 6(1)(f) 条——合法利益
为网站所有者自身的销售管道进行企业级 B2B 识别。利益平衡测试已存档。
TDDDG §25——第一方功能性范围
仅在您自己的域名上设置第一方功能性标识符,不使用广告 Cookie,也不使用跨站 Cookie。TDDDG §25 是否将其视为绝对必要,应由您的数据保护官判断;我们会准确说明其范围,供您用于隐私声明。
不处理访客个人数据
我们识别的是组织,而非个人。个人标识符不在本产品的处理范围内。
现成的隐私政策段落
将此段落粘贴到您自己的隐私声明中。其内容如实反映 lead.box 在您网站上的实际运作方式。
本网站使用 lead.box(由 lead.box LLC 运营)在企业层面识别访问本网站的组织。为此,跟踪器会设置第一方功能性标识符(例如,存储在本网站域名下、仅适用于特定设备的 ID),并临时处理技术连接数据(尤其是 IP 地址),以识别访问本网站的组织。本网站不使用广告 Cookie 或跨站 Cookie,不建立个人画像,也不进行跨站跟踪。数据处理以《通用数据保护条例》(GDPR) 第 6(1)(f) 条为依据(网站运营方在 B2B 线索识别方面的合法利益)。所有数据处理均在欧盟基础设施上进行,并位于通过 ISO 27001 认证的欧洲数据中心内。您可随时访问 https://lead.box/opt-out 选择退出。
相关文件
法务或数据保护官团队所需的一切文件,均可一键获取。
Frequently asked questions
The compliance questions we hear most often — answered without legalese.
It is workable under the GDPR when it stays at company level. Identification resolves the organisation behind a visit through network and IP-to-company matching; individual people are never identified, and a visit that cannot be matched to a company stays anonymous. lead.box applies all five rules by design, and publishes a DPA and a sub-processor list for review.
Legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test: a legitimate purpose, necessity, and a weighing of interests. Consent is not required where no personal identifiers are processed. The final assessment stays with you as the controller; lead.box acts as processor under a DPA.
No personal identifiers are processed, so no advertising consent category is involved: there are no names, personal e-mail addresses, device fingerprints or cross-site profiles, and raw network addresses are not available in the interface, exports or API. Whether you still place the snippet behind a consent category is your own assessment — lead.box does not gate itself.
In the European Union. Personal and visitor data concerning the EU is processed in ISO-certified data centres in the EU, and EU visitor data is not moved outside the EU for this purpose. The DPA under Art. 28 GDPR and the versioned sub-processor list are published, so a data protection review is possible before you commit.
Through the public opt-out page, at any time — and companies can additionally request a company-level opt-out. Transparency is the other half of this rule: disclose the identification in your privacy policy, for which a copy-ready paragraph is provided on this page.
No, deliberately not. lead.box shows you which companies visit your website — name, industry, size and the pages they viewed. It never tells you which person was on the site. Visitors from home offices or mobile networks stay anonymous, because their connection cannot honestly be matched to a company. That limit is a feature, not a gap: it is what keeps company-level identification GDPR-friendly.
Yes. Every customer can sign our DPA digitally in a few minutes — no email back-and-forth. The full list of sub-processors is published openly and versioned, so you always know which providers are involved in processing. Both documents are available before you buy, so legal review can happen during your free trial.
You add one small snippet to your site, served first-party via your own domain. It records page visits; the company behind a visit is resolved server-side by lead.box. It is not an advertising tracker — no cross-site profiles and no person-level identifiers are created. Installation works the same way for classic websites and single-page apps.
The network address is used to resolve the organisation and the connection type; the visit record keeps that result, not the raw value, and raw addresses are not available in the interface, exports or API. Retention windows for visit history are set out in the DPA, which is public and signable before you buy.
Because identification stops at the organisation, there is no person-level profile to hand over or erase. Company records can be removed from your workspace, workspace-wide deletion requests run through the contact channels named in the DPA, and any visitor can object through the public opt-out page.