There is a question you should ask before buying digital cards for your company, and almost nobody asks it: what happens to the data of the people who tap the card?
On most platforms in this category, the answer is uncomfortable. A stranger’s tap becomes a CRM record, the IP gets stored, the page loads third-party analytics, and “lead capture” happens behind the back of the person who tapped. It works — until the day your DPO asks about the legal basis, or a client asks why their company shows up in a CRM it never signed up for.
GDPR doesn’t ban leads. It bans leads that are taken.
The distinction that matters is simple: data given vs data taken. A form the visitor fills in knowingly, with a clear purpose and explicit consent, produces a lead your marketing team can legally use the next day. A profile assembled from the tap, the IP and the device fingerprint produces a legal liability with an email attached.
That is why our position is radical but simple: zero cookies, zero trackers, IPs never stored — and statistics that count taps, not people.
The questions to ask any vendor
They apply to us and to the competition — bring them to the meeting:
- Where does the data live? “The cloud” is not an answer; EU or non-EU is. Ours lives on servers in the European Union, full stop.
- What do you store about the people who tap? The right answer fits in one sentence. Ours: an aggregate count per card per day. No IP, no identity.
- Who, on the vendor’s side, can read my contacts? Our architecture has an auditable answer: nobody — and it’s proven by reading code, not by promise.
- Does automatic enrichment use the person’s data? Enriching the company from the email domain is legitimate interest; filling in the person’s phone and LinkedIn without them knowing is the kind of feature that stalls purchases in due diligence.
Privacy as a commercial advantage
A vendor that passes legal review on the first try shortens the buying cycle — and a contact page without a cookie banner projects exactly the brand image a premium card should project. In the EU, privacy is not a compliance cost: it is positioning. Our public spec sheet exists because we can show it.