NEW FEATURE: Finally See Which AI Engines Drive Your Leads & RevenueLearn more
LeadJourney Logo
Features

Tracking & Data

Server-Side Tracking

95%+ accuracy, cookieless & GDPR-safe — fully built-in, zero code.

Offline Conversion TrackingPopular

Connect calls, meetings & offline events to ad campaigns.

UTM & Click ID Tracking

Full coverage for Meta, Google, LinkedIn & Bing Ads.

Custom Traffic Channels

Track any channel — newsletters, podcasts, affiliates & more.

Unique feature

AI Search Engine Tracking

See exactly which AI search engines drive leads & revenue

Learn More

Reports & Analytics

Traffic Channel Report

Understand which channels drive the most valuable leads & sales.

Ad Campaign Report

Track performance of individual marketing campaigns in one ad manager.

Lead Overview Report

Get a comprehensive view of all your leads & sources in one place.

Landingpage Report

See conversion rates per page — segmented by channel, device & country.

Unique feature

Custom Report Builder

Build any report from raw data — 100% flexible, your way

Learn More

Data Management

Transparent Logs

Access detailed logs of all tracking events (Clicks, Conversions, API Postbacks).

AI Marketing AnalystASK AI

Ask anything about your campaigns, Atlas analyzes your data instantly.

Multi-Touch Attribution Popular

See every touchpoint that influenced a conversion, not just the last click.

CRM Integration

Connects with any CRM via webhook, sync leads & revenue automatically.

Unique feature

AI Agents - Automated Reports

Get daily, weekly & monthly reports delivered to email, Slack or WhatsApp.

Learn More
Solution for

Advertisers

Coaches & Consultants

Track high-ticket leads from first click to booked call

B2B & Service Businesses

Connect CRM pipeline to actual ad spend

Trade & Local Businesses

Offline conversions, calls & form leads — unified

Financial & Legal Advisors

GDPR-safe tracking for regulated industries

iGaming

Player attribution from first click to first deposit

Marketing Agencies

Performance Marketing Agencies

Prove ROI across Meta, Google & LinkedIn for every client

SEO Agencies

Track organic leads alongside paid in one view

Full-Service Agencies

One attribution source across all channels & clients

Lead Gen Agencies

White-label reporting & shared client workspaces

Marketing Freelancers

Tracking Specialists

Deploy server-side tracking fast for any client stack

Paid Media Freelancers

Attribution & reporting without building dashboards from scratch

Marketing Consultants

Show clients exactly what drives qualified leads & revenue

TestimonialsPricing
Company
About Us

Learn about LeadJourney, our mission and team.

Security

How we protect your data and keep it safe.

Jobs

Join our team — view open positions.

Press

Media resources, press releases and brand assets.

Contact

Get in touch with our team.

Resources
Integrations

Connect LeadJourney to your CRM, ad platforms and favorite tools.

Comparison

Compare LeadJourney to other Tracking Tools.

Blog

Stay ahead with marketing tracking tips, strategies & product updates

Glossary

Every performance marketing term explained — clear, simple, no fluff

Help Center

Step-by-step guides & tutorials to get the most out of LeadJourney

Customer Support

Got a question? Our team is here to help — fast responses, real answers

Book a demoLogin
Data Protection

Technical and Organisational Measures (TOMs)

The security measures we implement pursuant to Art. 32 GDPR.

Version 1.0 · Last updated: 30 June 2026

This document describes the technical and organisational measures ("TOMs") implemented by LeadJourney Ltd. ("Processor") to ensure a level of security appropriate to the risk of processing personal data pursuant to Art. 32 GDPR. These measures apply to all personal data processed by LeadJourney on behalf of its customers ("Controllers") under the Data Processing Agreement ("DPA").

LeadJourney regularly reviews and updates these measures to reflect changes in technology, threats, and applicable law.

1. Infrastructure & hosting

All personal data processed under the DPA is hosted exclusively within the European Economic Area (EEA):

  • Cloud infrastructure: DigitalOcean, LLC in Frankfurt, Germany (FRA1 region)
  • All production data remains within the EU at all times, with no default transfers to third countries
  • Infrastructure is provisioned and managed via infrastructure-as-code (IaC) to ensure consistent, auditable configuration
  • DigitalOcean maintains SOC 2 Type II attestation and ISO 27001 certification for its Frankfurt data centres
  • Physical access to data centre facilities is controlled by DigitalOcean under industry-standard physical security protocols including biometric access, 24/7 CCTV monitoring, and on-site security personnel

2. Encryption of personal data

LeadJourney applies encryption at all stages of data processing:

  • At rest: All personal data stored in LeadJourney databases and file storage is encrypted using AES-256 bit encryption.
  • In transit: All data transmitted between clients and LeadJourney servers, and between internal services, is protected using Transport Layer Security (TLS 1.2 or higher). Unencrypted connections are rejected.
  • Webhook payloads: Outbound webhook events are signed using HMAC (Hash-based Message Authentication Code) to ensure authenticity and integrity. Recipients can verify that payloads originate from LeadJourney and have not been tampered with.
  • Backup encryption: Database backups are encrypted at rest using AES-256 and stored within the EEA.

3. Access control & authentication

Access to personal data is strictly controlled on the basis of the least-privilege and need-to-know principles:

  • Role-based access control (RBAC) is implemented across all systems; each employee and service account is granted only the minimum permissions necessary for their role
  • Two-factor authentication (2FA) is mandatory for all staff accessing production systems and the LeadJourney application
  • Customer data is logically separated at the database level; no customer can access another customer’s data
  • Access to production databases and infrastructure requires authentication through a secure, audited access mechanism; direct database access is prohibited for standard operations
  • All access attempts, successful and unsuccessful, are logged and retained for audit purposes
  • Access rights are reviewed regularly and revoked immediately upon termination of employment or change of role
  • Shared or generic accounts are not permitted; each individual has a unique, identifiable account

4. Pseudonymisation & data minimisation

  • LeadJourney’s server-side tracking architecture is designed to minimise the collection of personal data at the point of ingestion; only data explicitly configured by the Controller is collected
  • Visitor identifiers (click IDs, session tokens) are hashed and pseudonymised where technically feasible, reducing re-identification risk
  • IP addresses are processed server-side and are not stored in plain text in analytics reports
  • Personal data is not collected or retained beyond what is necessary for the purposes configured by the Controller

5. Availability, resilience & recovery

LeadJourney maintains measures to ensure the ongoing availability and resilience of its processing systems:

  • Infrastructure is deployed across multiple DigitalOcean availability zones within the Frankfurt region to ensure redundancy
  • Automated database backups are performed on a regular schedule and retained within the EEA; backup integrity is tested periodically
  • Monitoring and alerting systems operate 24/7; automated alerts are triggered for infrastructure anomalies, error spikes, or availability issues
  • Application error monitoring and log management is provided by Better Stack s.r.o. (Czech Republic, EU), which captures real-time error events without storing full personal data payloads
  • Recovery procedures are documented and tested to ensure the ability to restore availability and access to personal data in a timely manner following a physical or technical incident
  • Business continuity plans are maintained and reviewed annually

6. System integrity, logging & monitoring

  • All significant system events, including data access, modifications, deletions, authentication attempts, and administrative actions, are recorded in immutable audit logs
  • Logs are retained for a minimum of 90 days and are accessible for security review and incident investigation
  • System configurations are managed through version-controlled infrastructure-as-code; deviations from specified configurations are detected automatically
  • Automated monitoring scans for anomalous activity, unauthorised access attempts, and service degradation continuously
  • Separation of production and test environments is enforced; no real personal data is used in test or development environments without explicit anonymisation

7. Organisational measures & governance

  • All employees with access to personal data receive data protection training at onboarding and at regular intervals thereafter
  • All employees are bound by contractual confidentiality obligations that survive the termination of their employment
  • A documented information security policy is in place; adherence is mandatory and subject to a formal disciplinary procedure
  • A designated Data Protection Officer (Jonas Strambach, [email protected]) is responsible for overseeing compliance with data protection obligations
  • Internal data processing activities are documented in a Record of Processing Activities (RoPA) maintained pursuant to Art. 30 GDPR
  • Vendor assessments are conducted before engaging new sub-processors; sub-processors are required to maintain equivalent security standards

8. Sub-processor security

The transfer of personal data to sub-processors is only made where a corresponding Data Processing Agreement (DPA) or equivalent contractual instrument exists, and only for specified purposes. LeadJourney requires all sub-processors to:

  • Implement technical and organisational measures equivalent to those described in this document
  • Process personal data only on LeadJourney’s documented instructions
  • Not engage further sub-processors without prior authorisation

Where personal data is transferred to sub-processors located outside the EEA (e.g. Stripe, Google, Mailtrap, Intercom, X Corp., Reddit), LeadJourney ensures adequate protection through Standard Contractual Clauses (SCCs) as adopted by the European Commission pursuant to Art. 46 GDPR, supplemented by transfer impact assessments where required.

9. Incident management & breach notification

  • A documented incident response procedure is in place covering detection, containment, investigation, remediation, and notification
  • All employees are required to report suspected security incidents immediately to the Data Protection Officer
  • Personal data breaches are assessed without undue delay; where required under Art. 33/34 GDPR, the Controller is notified within 72 hours of the Processor becoming aware of the breach
  • All personal data breaches are documented, including the facts, effects, and remedial action taken, regardless of whether notification to a supervisory authority is required

10. Data portability & erasure

  • Upon the Controller’s written request, LeadJourney can export customer data in machine-readable formats (e.g. CSV, JSON) for portability
  • Upon termination of the DPA or the Controller’s written request, all personal data is permanently deleted from active databases within 60 days
  • Deletion is cascading: records deleted from active databases are removed from backup systems as backups are rotated per the data retention policy
  • LeadJourney can provide written confirmation of deletion upon request

11. Regular testing & review

  • Technical and organisational measures are reviewed at least annually, or following any significant change to infrastructure, processing activities, or applicable law
  • Vulnerability scanning and security assessments are conducted on a regular basis
  • Third-party penetration testing is performed periodically; findings are remediated according to severity
  • The effectiveness of these measures is monitored continuously through automated tooling and periodic manual review

12. Summary of key measures

MeasureImplementation
Hosting locationDigitalOcean FRA1, Frankfurt, Germany (EEA)
Encryption at restAES-256 bit encryption
Encryption in transitTLS 1.2+ for all connections
Webhook integrityHMAC-signed payloads
Access controlRBAC + least privilege + 2FA mandatory
Customer data separationLogical separation at database level
Audit loggingAll access and administrative actions logged
AvailabilityMulti-AZ deployment, automated backups, 24/7 monitoring
Error monitoringBetter Stack s.r.o. (Czech Republic, EU)
Breach notificationWithin 72 hours of becoming aware
Data deletionWithin 60 days of contract end or request
Staff trainingOnboarding + regular data protection training
DPOJonas Strambach, [email protected]
Sub-processor transfersSCCs where outside EEA

LeadJourney Ltd. · HE485008 · Artemidos 6, 6030 Larnaca, Cyprus · [email protected] · TOMs Version 1.0

Track every lead
With Pixel-Perfect Accuracy

Stop losing data to iOS, ad blockers and CRM gaps. Server-side tracking, built for lead generation — live in 21 minutes.

98% data accuracyeven with iOS & ad blockers
Book a demo
Try for free14-day free trial, no credit card
CTA visual
CTA visual
LeadJourney Logo

Features

AI Marketing AnalystNEWTraffic Channel ReportAd Campaign ReportLead Overview ReportOffline Conversion TrackingLandingpage Report

Solutions

AdvertisersMarketing AgenciesMarketing FreelancersAgency DirectoryNEWFree ToolsHOT

Company

About usPressEnterpriseJobs2 open jobsIntegrationsAffiliate ProgramCustomer SupportContact us

Comparison

LeadJourney vs HyrosLeadJourney vs RedtrackLeadJourney vs CometlyLeadJourney vs AnytrackLeadJourney vs GA4LeadJourney vs Voluum

Legal

ImprintPrivacy policyTerms & ConditionsGDPRCookie policySitemapLLMs.txtSecurityLegal

Follow us:

2026 - LeadJourney Ltd. All rights reserved

LeadJourney