There is a question you should ask before buying digital cards for your company, and almost nobody asks it: what happens to the data of the people who tap the card?

On most platforms in this category, the answer is uncomfortable. A stranger’s tap becomes a CRM record, the IP gets stored, the page loads third-party analytics, and “lead capture” happens behind the back of the person who tapped. It works — until the day your DPO asks about the legal basis, or a client asks why their company shows up in a CRM it never signed up for.

GDPR doesn’t ban leads. It bans leads that are taken.

The distinction that matters is simple: data given vs data taken. A form the visitor fills in knowingly, with a clear purpose and explicit consent, produces a lead your marketing team can legally use the next day. A profile assembled from the tap, the IP and the device fingerprint produces a legal liability with an email attached.

That is why our position is radical but simple: zero cookies, zero trackers, IPs never stored — and statistics that count taps, not people.

The questions to ask any vendor

They apply to us and to the competition — bring them to the meeting:

  • Where does the data live? “The cloud” is not an answer; EU or non-EU is. Ours lives on servers in the European Union, full stop.
  • What do you store about the people who tap? The right answer fits in one sentence. Ours: an aggregate count per card per day. No IP, no identity.
  • Who, on the vendor’s side, can read my contacts? Our architecture has an auditable answer: nobody — and it’s proven by reading code, not by promise.
  • Does automatic enrichment use the person’s data? Enriching the company from the email domain is legitimate interest; filling in the person’s phone and LinkedIn without them knowing is the kind of feature that stalls purchases in due diligence.

Privacy as a commercial advantage

A vendor that passes legal review on the first try shortens the buying cycle — and a contact page without a cookie banner projects exactly the brand image a premium card should project. In the EU, privacy is not a compliance cost: it is positioning. Our public spec sheet exists because we can show it.