Visitor ID Vendor DPAs Compared: Controller or Processor?

A dated read of eight visitor-identification vendors' own DPAs, subprocessor pages and security pages. It compares controller or processor stance, subprocessor lists and change notice, hosting, transfer mechanism and attestations, and says what each difference means for a privacy review. Every quote comes from a page read on 2026-09-26. No vendor is judged compliant or non-compliant.

We read eight vendors' own DPAs, subprocessor pages and security pages on 2026-09-26. Three differences change what a privacy reviewer does next.

1. Role. Each vendor that states a role says it is a processor (or "Service Provider") for the customer's data. Snitcher's role is not stated on its public pages. Five also name a controller role for some data. RB2B is "a Third Party and an independent Controller" for cookie data. ZoomInfo and the customer are "independent Controllers" of personal data ZoomInfo gives the customer access to. HubSpot and the customer "act as Controllers" when enrichment products or Tracking Code intent sharing are on. Albacross and Leadinfo are controllers for their own database.

2. Subprocessor lists. Six vendors publish a list. ZoomInfo lists 36 (29 third parties and 7 affiliates). HubSpot lists 32 (17 third parties and 15 affiliates). RB2B lists 17, Snitcher 9, Albacross 8 and Leadfeeder 6. Lead Forensics and Leadinfo keep the current list in the contract or send it on request. RB2B's DPA links to a list address that returned "not found". A list at a similar address does load.

3. Hosting and transfers. Claims run from EU-only to U.S.-only. Leadinfo, Snitcher and Leadfeeder name EU hosting. ZoomInfo and RB2B name U.S. hosting. RB2B's DPA covers U.S. data only. Some EU-hosted vendors still list U.S. subprocessors under Standard Contractual Clauses (SCCs).

None of this says whether a deployment is lawful. That question belongs to the GDPR and CCPA review map. Your legal or privacy owner decides.

The vendor DPA comparison matrix

Each cell is what the vendor's own pages said on 2026-09-26. "Not stated" means the pages we read do not answer the point. "Not found" means we could not find or load a page that does.

Vendor Controller or processor stance Public subprocessor list Change notice Hosting stated Transfer mechanism named Attestations claimed Sources
RB2B "Service Provider" for Customer Data (example given: "email addresses received from Customer, for use in email marketing"). "A Third Party and an independent Controller" for Cookie Data, used "to generate cross-contextual or cross-channel behavioral advertising." Each party "an independent Controller" of Output Data. The DPA names GetEmails, LLC (d.b.a Retention.com) as "Vendor". 17 entries, all USA, no date. The DPA links rb2b.com/sub-proccesors-list, which returned HTTP 404. The list loads at rb2b.com/sub-processors-list, linked from the compliance page. Updated list at least 15 days before a new subprocessor processes Customer Data, plus an email "on the same day". Objection within 10 days of the update. AWS, USA (subprocessor list). Compliance page: "we use IP ringfencing to only resolve US traffic." None named. DPA §11, "U.S. Data Only": for EU or UK data, "additional data processing addendums may be required." "RB2B is SOC2 Type 2 Certified and CCPA Compliant." DPA, list, compliance, security
ZoomInfo Customer DPA §2.1: "Customer is the Controller and Supplier is a Processor." §5.1: each party acts as an independent Controller of personal data ZoomInfo gives the customer access to. The DPA does not name WebSights. 36 (29 third parties, 7 affiliates). Page dated "Last Updated: July 17, 2026." DPA §8.1: a "method for Customer to receive notice and an opportunity to object"; no objection within 30 days means acceptance. The list page says "bookmark and periodically review this page." "Our services are hosted on the three major cloud providers with hosting data centers in the U.S." 28 of 36 list entries are in the USA. SCCs (Decision 2021/914), Module 2, plus UK Addendum and Swiss terms (DPA §8.4 to §8.6). "ZoomInfo is ISO 27001, ISO 27701, TRUSTe, and SOC 2 Type II certified." customer DPA, list, security overview
Leadfeeder (Dealfront) "We act as a data processor and you act as a data controller" for data shared through the script or a CRM connection. Separately: "Dealfront processes personal data in our systems based on legitimate interest." The page names no role for that. 6. Page dated "Last updated: 14 November 2025." The DPA points to a different list address on dealfront.notion.site. List page: "We will update this list regularly as changes occur." DPA Sect. 10(3): advance notice to customers who register at leadfeeder.com/privacy/. No day count. "Hosted and processed on Amazon Web Services in the EU, specifically in Ireland." 3 of 6 list rows (Google Cloud, OpenAI Ireland, Perplexity) say "USA (covered by Standard Contractual Clauses Controller to Processor)." SCCs, for the U.S. entity and on the list. ISO 27001 and ISO 27701. GDPR page, DPA, list, security
Lead Forensics "When Lead Forensics processes customer personal data through the SaaS platform, we act as a data processor." Contact-data suppliers "act as independent data controllers." Not public: "available in the Data Processing Agreement between the parties." "Where required by contract," notice of material changes. Opt-in updates at leadforensics.com/dpa-update-notification/. No day count found. Not stated. Data may be processed "in countries where its systems, or approved sub-processors, operate." "Adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum or other approved transfer mechanisms." Certified to ISO/IEC 27001; "not currently SOC 2 certified." customer FAQ
Albacross Processor for the customer. Schedule 1: IP address, URL with query string, form-input domain and contact employer "may be stored to improve the database. This processing is carried out by Albacross as the controller." 8 (Schedule 3), no date. Section 8: notice of intended changes; no objection within "ten (10) days" of receipt counts as no objection. AWS Ireland. Others in Denmark, the EEA and the Netherlands. OpenAI Ireland: "Global." Bright Data: user-chosen location. Waterfall Data (US) and Cognism (UK): data "only transferred" from those countries "into the EU/EEA." "May include entering into model clauses for data transfer outside of the European Economic Area." Not found. DPA
Leadinfo Processor "on the Controller's instructions." "For the purpose of maintaining and enriching this database, the Processor is the controller." Annex 2 names 1 subprocessor at signing: AWS EMEA SARL, Luxembourg. "A current list of Subprocessors can be requested via privacy@leadinfo.com." Clause 5.1: will "inform the Controller of any intended changes." No day count. One month's notice for DPA amendments (12.4). "The server is located in Ireland, ensuring that the data processed by Leadinfo does not leave the European legal jurisdiction." DPA Clause 3.1: transfers outside the EEA "are allowed, provided that the conditions set out in Chapter V of the GDPR are met." "Leadinfo is ISO 27001 certified." The linked ISO/IEC 27001:2022 certificate is issued to team.blue nl B.V. and its scope includes "lead generation software from LeadInfo" (valid to 24 May 2029). DPA, GDPR page
Snitcher Not stated on public pages. The trust center says Snitcher "offers a Data Processing Agreement to customers." The DPA file is behind a "Request access" form. 9, on the trust center, no date. Not stated. AWS "Frankfurt, Germany (eu-central-1)," so "your visitor data never leaves the EU." Trust center: "No customer data is stored at rest outside the EU." Support tools (Google Workspace, GitHub, Intercom) "may process data outside the EU." For those support tools: SCCs, "and where applicable" the EU-U.S. Data Privacy Framework (DPF). "ISO 27001: In progress." Trust center FAQ: Stage 1 audit completed 9 September 2026; Stage 2 "scheduled for 23 September 2026." trust center, help center
HubSpot (enrichment and Tracking Code) Processor for Customer Personal Data (Section 3). Section 10 applies "to the extent that the parties Process Controller Personal Data in connection with Customer's uses of our enrichment products and the HubSpot Tracking Code when Intent data sharing is enabled." Then both "act as Controllers." 35 rows in three tables (4 infrastructure, 16 feature, 15 affiliate). That is 32 organizations, as AWS and Google each appear more than once. Three rows are marked "Effective October 16, 2026." Opt-in email: "we will notify you at least 30 days prior to any such change." Objection within 30 days of notice (Section 5). Per infrastructure subprocessor: United States, Germany, Australia and Canada data centers. DPF self-certification, then SCCs: Module 2 or 3 for Customer Personal Data, Module 1 for Controller Personal Data, UK Addendum, Swiss terms (Section 11). Public SOC 3 report. Confidential SOC 2 Type 2 report to download "if you are a customer or prospect." DPA, list, security

We also looked at Warmly. Its DPA and subprocessor list are Google Drive files we could not open, so it is not in the matrix.

What does each difference mean for your review?

What changes when a vendor names a controller role?

GDPR Article 4(7) defines a controller as the body "which, alone or jointly with others, determines the purposes and means of the processing of personal data." Article 4(8) defines a processor as one that "processes personal data on behalf of the controller." Article 26(1) adds: "Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers."

The vendors use different labels. RB2B says "independent Controller" and ZoomInfo "independent Controllers." HubSpot says both parties "act as Controllers." Albacross and Leadinfo say "the controller" for their own database. Which label fits your setup is not settled by the vendor's wording.

In practice, a controller carve-out raises three questions for that data:

  • Whose privacy notice discloses the vendor's use?
  • Whose lawful basis covers it?
  • Who answers an access or deletion request?

HubSpot's DPA answers the first in part: "Customer is responsible for providing all necessary notices, consents, and opt-out mechanisms for the use of the HubSpot Tracking Code." Its Annex also says Controller Personal Data may be used to "improve, and develop HubSpot's commercial dataset." Read the carve-out, not only the headline role. Your legal or privacy owner decides whether the split fits your notice.

What does a subprocessor notice window buy you?

Article 28(2) says: "The processor shall not engage another processor without prior specific or general written authorisation of the controller." Each DPA above meets that point with its own process. The differences are practical:

  • Fixed window, pushed to you. RB2B (15 days' notice, 10 days to object), Albacross (10 days to object) and HubSpot (30 days, opt-in email). Someone must read the notice and be able to object in time.
  • Notice with no day count. Leadfeeder, Leadinfo and Lead Forensics say they inform you in advance or where the contract requires. Ask for the period in writing.
  • Watch the page yourself. ZoomInfo's list page says "bookmark and periodically review this page." Its DPA adds a 30-day objection term. Find out how the notice reaches you.

HubSpot's three rows marked "Effective October 16, 2026" show the mechanism at work. They were visible on 2026-09-26, 20 days before they take effect.

Also check that the list your DPA names is the list you read. RB2B's DPA link returned 404. Leadfeeder's DPA points to a different address from the page we counted. ZoomInfo's DPA Annex III points to its public list page.

What do hosting and transfer claims settle, and what do they leave open?

A hosting claim tells you where the main systems run. It does not cover every subprocessor. Leadfeeder hosts in Ireland but lists three U.S. rows under SCCs. Snitcher keeps customer data at rest in the EU but says its support tools "may process data outside the EU."

A named transfer mechanism answers a different question. SCCs are contract terms for a given transfer. The DPF is an adequacy decision. The European Commission says that "personal data can flow freely from the EU to companies in the United States that participate in the Data Privacy Framework." Ask which mechanism covers the subprocessor that does the work you care about.

RB2B's position is a scope limit, not a transfer mechanism. Its DPA covers U.S. data only and says EU or UK data may need "additional data processing addendums."

SOC 2 Type II or ISO 27001: what should you ask for?

A SOC 2 Type II report is an auditor's opinion on whether a company's controls worked over a set period. A SOC 3 report is a short public summary. An ISO/IEC 27001 certificate says a certification body found an information security management system conforms to the standard, for a stated scope and period.

Neither one is a promise about visitor matching or subprocessor handling. What the eight vendors claim on 2026-09-26:

  • SOC 2 Type 2: RB2B, ZoomInfo, HubSpot (report on request).
  • ISO 27001: ZoomInfo, Leadfeeder, Lead Forensics, Leadinfo.
  • In progress: Snitcher (ISO 27001).
  • Not found: Albacross.

Ask for the report or certificate, not the badge. Then check three things: the named entity, the scope and the dates. Leadinfo's certificate is a useful example. It is issued to the parent group, and the scope names Leadinfo's product. Lead Forensics states what it does not hold: "not currently SOC 2 certified."

Fillable review map

Use this for the one vendor you are evaluating. Leave the last column blank until your reviewer fills it in.

Question What the vendor's documents say (with link) What your deployment needs Owner Your decision
Controller or processor for the identification data itself?
Is there a public, dated, counted subprocessor list, and how are changes notified?
Where is the data hosted, and does that cover every subprocessor you care about?
Which transfer mechanism is named for the transfers you actually have (SCCs, DPF, adequacy, other)?
Which attestations are claimed, and have you seen the actual report, not just the badge?
Does the vendor take a controller role over any of your data for its own purposes (database enrichment, cross-channel advertising, model training)?

Worked example (hypothetical): an EU team comparing two vendors

This example is hypothetical. An EU-based B2B marketing team is choosing between Leadinfo and Albacross for company-level visitor identification. The matrix does not say which is "compliant." It changes which questions the team sends before signing.

Leadinfo. Annex 2 lists one subprocessor at signing. The current list comes by email from privacy@leadinfo.com. The team asks for that list in writing and asks whether any AI, analytics or support subprocessors were added. It also asks Leadinfo to square two statements. The GDPR page says data "does not leave the European legal jurisdiction." DPA Clause 3.1 allows transfers outside the EEA under Chapter V. Last, the team checks the ISO certificate. It is issued to team.blue nl B.V., so the team confirms the scope line that names Leadinfo's product.

Albacross. Schedule 1 names Albacross "as the controller" when four fields are stored "to improve the database." The team asks which products and customers use that database. It asks its privacy owner whether its own notice must mention this. It notes the 10-day objection window and asks where the notice will be sent. It also asks how the Waterfall Data (US) and Cognism (UK) rows work, since the DPA says data flows only from those countries into the EU/EEA.

When this does not apply

  • You sign a negotiated agreement. Enterprise contracts often replace the public template, including lists, notice windows and liability terms. Ask which document governs yours. ZoomInfo, for example, publishes two versions of its customer DPA (dated 1/1/2023 and 5/1/2025).
  • The page changed after 2026-09-26. Vendors can edit any page here at any time. Re-read the live page before you sign or renew.
  • You need a legal answer. This guide is a dated read of public documents. It helps you ask better questions. Your legal or privacy owner decides.

Method

We read each vendor's pages on 2026-09-26 by direct request with a browser user agent. Snitcher's trust center needs JavaScript, so we read it in a browser. We quote only text we could load that day.

We counted subprocessors by table row on each vendor's own list. Where one company appears in more than one row, we also give the number of distinct organizations. Only HubSpot's list has such repeats.

What we could not read: ZoomInfo's /security, /trust and /legal index pages returned HTTP 403 from bot-protection software. We did not try to get around it. We used ZoomInfo's Security Overview, which its DPA names, instead. Snitcher's DPA sits behind a request form, so we did not read it. Warmly's documents are Google Drive files we could not open.

GDPR quotes are checked against the official text of Regulation (EU) 2016/679, published on EUR-Lex.

FAQ

Is a vendor that calls itself a processor always the lower-risk choice?

Not by itself. Five vendors here also name a controller role for some data, such as their own database or advertising use. Send the carve-out to your legal or privacy owner, who decides.

Ask the vendor in writing for the current list and for the address the contract should point to. Do not assume nothing has changed.

Is an "ISO 27001 In Progress" badge the same as a certificate?

No. It describes work under way. Snitcher's trust center showed "In progress" on 2026-09-26, with a Stage 2 audit scheduled for 23 September 2026. Ask for the certificate and check its entity, scope and dates.

Sources

All vendor pages were read on 2026-09-26. Each matrix row links its own sources.

For the full due-diligence process, see Vendor Due Diligence for Visitor ID Tools. For the legal framing, see Is Website Visitor Identification Legal? The GDPR and CCPA Review Map. For pre-launch checks, see B2B Visitor Identification Privacy Checklist.

Sources

  1. https://www.rb2b.com/data-protection-addendum-dpa
  2. https://www.rb2b.com/sub-proccesors-list
  3. https://www.rb2b.com/sub-processors-list
  4. https://www.rb2b.com/compliance
  5. https://www.rb2b.com/security
  6. https://www.zoominfo.com/cws/uploads/2025/04/DPA-ZoomInfo-C2P-SCCs-w_-UK-Addendum-April-23-25.docx.pdf
  7. https://www.zoominfo.com/legal/dpa-c2p.pdf
  8. https://www.zoominfo.com/legal/data-processing-addendum
  9. https://www.zoominfo.com/legal/subprocessors
  10. https://www.zoominfo.com/legal/security-overview
  11. https://www.leadfeeder.com/gdpr
  12. https://marketing.leadfeeder.com/inside-eea-data-processing-agreement-dealfront-en.pdf
  13. https://www.leadfeeder.com/privacy/sub-processor-list-leadfeeder/
  14. https://www.leadfeeder.com/security
  15. https://www.leadforensics.com/compliance/customer-faq/
  16. https://www.albacross.com/data-processing-agreement
  17. https://www.leadinfo.com/en/legal/dpa/
  18. https://www.leadinfo.com/en/legal/gdpr/
  19. https://www.leadinfo.com/wp-content/uploads/2026/06/ISO-IEC_27001-ENG-C846177-1-20260520.pdf
  20. https://trust.snitcher.com
  21. https://help.snitcher.com/en/articles/1745067-how-snitcher-complies-with-gdpr
  22. https://legal.hubspot.com/dpa
  23. https://legal.hubspot.com/sub-processors-page
  24. https://legal.hubspot.com/security
  25. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
  26. https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en

Reviewed

Scope: B2B visitor identification and lead-magnet operations. We update this guide as the underlying search behaviour changes.