Nalloo identifies companies, not people — company-level, no personal data. IP addresses are processed hashed, inside the European Union.
Why is Nalloo GDPR-friendly?
Because it identifies companies, not natural persons. Nalloo resolves the organisation behind an IP using firmographic signals — it does not profile individuals and does not store personal data (IPs are hashed). Processing and hosting happen inside the EU.
Company-level, not person-level
Does: resolve the company behind a visit, enrich it with public firmographics, store company-level data with a confidence score.
Doesn't: track or name individuals, store visitor emails, or build personal profiles.
Your privacy policy should mention that IP addresses are processed for B2B identification on a legitimate-interest basis.
Legitimate interest
Under the GDPR, processing data needs a lawful basis. For company-level B2B identification, that basis is normally legitimate interest (Article 6(1)(f)): you process an IP address to understand which businesses engage with your site, a clearly defined commercial interest, while no personal profiles are built and no PII is stored.
Because Nalloo identifies organisations rather than individuals and stores no personal data, the basis is legitimate interest and no banner is required on Nalloo's account. You should still reference IP processing for B2B identification in your privacy policy.
Why company-level matters
The whole GDPR position rests on one distinction: Nalloo identifies the organisation behind a visit, not the natural person making it. It does not name an individual, capture an email, follow someone across sites, or build a behavioural profile of a human being. What it produces is a company record — industry, size, headquarters, founded year — drawn from public firmographic sources and stamped with a confidence score.
That distinction changes which rules bite. The GDPR governs the processing of personal data — information relating to an identified or identifiable natural person. Knowing that a company visited your pricing page is firmographic, business-level information, not a personal profile, so there is no persistent identifier tied to a person and nothing for a visitor to be tracked by. The only input with any personal dimension is the IP address, and Nalloo processes it hashed and uses it solely to resolve the organisation — it is a means to a company name, not a record kept about an individual.
For a buyer, this is also why the experience is cleaner: , no personal data changing hands, and a measurement approach built on network-level signals rather than personal data.
For your DPO
If your data protection officer or legal team asks how Nalloo fits your obligations, here is the short, accurate brief to hand them. (This is informational and does not replace legal advice — review your own obligations with qualified counsel.)
FAQ
Inside the European Union (Frankfurt + Madrid), encrypted in transit and at rest. IP addresses are processed hashed.
No. Nalloo identifies companies, not people. It never stores personally identifiable information.
Yes. Nalloo identifies companies (not natural persons), stores no personal data; IP addresses are processed hashed, inside the EU. This page is informational and not legal advice.
Typically 8–18% of B2B traffic depending on industry and market. Corporate networks resolve best; mobile and consumer ISPs less. Start free and see your own rate.
Yes — native one-click OAuth for HubSpot, Salesforce and Pipedrive.
An IP can be personal data in some contexts, which is why Nalloo processes IP addresses hashed and uses them solely to resolve the organisation behind a visit — never to identify or profile a person. The output is a company record, not a personal one, and no PII is stored. This is informational, not legal advice.
Company-level B2B identification normally rests on legitimate interest under Article 6(1)(f). Because Nalloo builds no personal profiles and stores no personal data, the lawful basis is legitimate interest rather than consent. You should still reference IP processing for B2B identification in your privacy policy. Informational, not legal advice.
In short: identification is company-level only, the basis is legitimate interest, IPs are processed hashed, and all processing and storage happen inside the EU (Frankfurt and Madrid). The one action on your side is to note IP processing for B2B identification in your privacy policy. This is informational and does not replace advice from qualified counsel.
50 free identifications. No credit card. No"talk to sales."
EU-hosted · GDPR-friendly · Cancel in one click