LeadGenesis

LeadGenesis Trust Center

Request Access

Trust is central to how we operate. LeadGenesis runs managed content syndication and display programs for B2B marketing teams, and every lead we deliver is verified as having engaged with your content first. This Trust Center gives clients, partners and their security teams direct insight into how we protect and govern data.

Compliance

  • ISO 27001:2022

    Certified Information Security Management System meeting global security standards.

  • SOC 2 Type II

    Independently assessed security controls validating data protection practices.

  • GDPR

    Adherence to EU data protection requirements and data subject rights.

  • CCPA

    Adherence to California privacy requirements, including opt-out of sale or sharing.

Resources

Certifications

  • ISO/IEC 27001:2022 Certificate
  • SOC 2 Type II Certificate

Policies

Assessments

  • Web Application Penetration Test results

Other resources

  • Data Processing Agreement
  • Standard Contractual Clauses
  • Subprocessor register

Items marked with a lock are available on request. Email info@theleadgenesis.com and our team will get back to you.

Data and privacy

  • Retention schedules established and enforced
  • Identity linked only on explicit consent
  • Data classification policy established
  • Customer data deleted on request

Product security

  • Data encrypted in transit and at rest
  • Cookieless measurement, no device fingerprinting
  • Global Privacy Control and Do Not Track honoured
  • Automated and invalid traffic filtered

Infrastructure security

  • IP addresses anonymised at point of collection
  • Access control procedures established
  • Encryption key access restricted
  • Processing performed at the edge, minimising data movement

Organizational security

  • Role-based access control enforced
  • Security awareness training delivered
  • Anti-malware technology utilised
  • Asset disposal procedures utilised

Internal security procedures

  • Business continuity and disaster recovery plans established
  • Incident response plan maintained and tested
  • Change management process established
  • Vendor and subprocessor review process established

Privacy program

  • Data protection impact assessment maintained
  • Data subject rights handling process established
  • EU data residency available
  • Subprocessor register maintained

Data processed

  • Business contact information
  • Professional and employment information
  • Content engagement and measurement data
  • Payment card information
  • Personal health information
  • Government identifiers
  • Consumer financial information

Frequently asked questions