Lead Generation
Lusha
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Lusha Systems Inc. · www.lusha.com
Compare with Apollo.io → Compare with Cognism → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Lusha is a B2B contact database — 290M+ contacts, 165M+ emails, 117M+ direct dials, 29M+ companies — and the bench's strongest score is CRM sync and export, clustering at 5-6 on native Salesforce, HubSpot, Monday and Zoho integrations, API, webhooks and MCP, and terms that let customers keep exported data after termination. Data provenance scores 4-5: sources are named, including a Community Program whose members share CRM data, email headers and calendar details, and 1,119 delete/opt-out requests were processed in 2024 with none denied. The judges split by a point on data coverage and prospecting compliance, both scored 3 to 4: higher coverage scores credit the published counts and the 12.6% annual decay study, lower ones the absence of a published per-country or DACH breakdown; on compliance, higher scores credit the suppression list and filters, lower ones the terms placing call-recording consent and removal duties on the customer. The weakest showing is the data protection officer persona: 0 on all seven criteria, citing US hosting, US and Israeli joint controllers, and no published legal basis for listed people.
Speaks for it
- Native integrations with Salesforce, HubSpot, Monday and Zoho, plus an API with webhooks and MCP into Claude and ChatGPT, and terms that let customers keep exported data after termination.
- Sources named in the privacy notice — trusted data brokers, publicly available APIs, and a Community Program sharing CRM data, email headers and calendar meeting details — with 1,119 delete/opt-out requests processed in 2024 and none denied.
- Four tiers carry public prices with credit allowances, from Free at $0 USD / month with 40 credits per month and 1 seat included to Premium at $299.95 USD / month billed yearly with 40,800 credits per year, with a stated 25% yearly discount.
- 26 buying signals refreshed weekly, with intent topics tiered from five on lower plans to twenty-five with unlimited results on Scale.
- A DPA is available, a sub-processor list is published with purpose, location and transfer method, and weekly platform availability is guaranteed at 99%.
Held against it
- Data licensed 'as is' without warranties, making inaccuracy the buyer's cost — the vendor's own study puts decay at 12.6% a year from 148,000 records.
- No public information on per-country or DACH coverage, on how contact records are verified, or on any re-verification cadence beyond the weekly refresh that attaches to buying signals.
- Contact data stored on Amazon Web Services in the United States, joint controllers Lusha Systems Inc. and Lusha Systems Ltd. of Tel Aviv, sharing to the United States, United Kingdom, Australia and Israel under Standard Contractual Clauses, and no public information on an EU hosting or contracting option.
- Call-recording consent and removal of objected-to records placed on the customer by the terms, with no public information on country-aware handling of German contacts or do-not-call register checks.
- The captured pages give different figures for credit rollover — the pricing page describes monthly credits rolling over subject to an x2 monthly cap on some plans while the terms state credits expire at term end — and no public price for the Scale tier, extra seats or credits by data type.
Best for
- You need a wide-reach B2B database — 290M+ contacts, 165M+ emails, 117M+ direct dials — flowing natively into Salesforce, HubSpot, Monday or Zoho with API, webhooks and MCP support.
- You want a low-commitment pilot: Free at $0 USD / month with 40 credits per month, 1 seat included and no credit card required.
- Your outbound motion runs on intent and lookalikes: 26 buying signals refreshed weekly and intent topics tiered from five to twenty-five across plans.
- You weigh provenance disclosure heavily: named sources, a published sub-processor list with purpose, location and transfer method, and published 2024 request statistics.
Avoid if
- You must clear a German or EU data protection review — ask the vendor: the public pages we read do not show it
- Your pipeline is DACH-weighted — ask the vendor: the public pages we read do not show it
- You need the vendor to carry accuracy risk: the platform is licensed 'as is', and the vendor's own study puts decay at 12.6% a year.
- You need a fully computable invoice — ask the vendor: the public pages we read do not show it
The scores
Coverage, accuracy & freshness
panel disagrees
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
The homepage splits 290M+ contacts into 165M+ emails and 117M+ direct dials, shows weekly refresh on 26 buying signals and even a decay study, but nothing on DACH or per-country coverage, and we found no description of how contact records are verified or re-verified — so I cannot judge connect rate from these pages. The terms sell the platform "as is", so the cost of a bad record lands on my reps, and we found no bounce guarantee or credit-back terms. 1 3 4
The RevOps Manager
Headline counts are published — 290M+ contacts, 165M+ emails, 117M+ direct dials, 29M+ companies, 78 fields per record, with 26 buying signals refreshed weekly — but I found no public information on DACH or any per-country coverage, on how contact records are verified, or on a re-verification cadence for anything other than the signals. The terms deliver the platform "AS IS" with no credit-back for inaccurate data, so decay is the buyer's cost, and the vendor's own study puts that decay at 12.6% a year. 1 2 4
The Data Protection Officer
Headline counts are published (290M+ contacts, 165M+ emails, 117M+ direct dials, 29M+ companies) and a decay study of 148,000 records puts annual decay at 12.6%, but we found no public information on per-country or DACH coverage, on how contact records are verified, or on a re-verification cadence for the contact data itself. Only the buying signals carry a stated refresh, at weekly. 1
The ABM Marketer
Headline counts of 290M+ contacts, 165M+ emails and 117M+ direct dials across 78 fields per record are published, but we found no public information on coverage by country — nothing on DACH specifically — no description of how emails are verified, and no re-verification cadence for contact records; the weekly refresh claim attaches to the buying signals, not the contacts. A decay study of 148,000 records showing 12.6% annual decay is disclosed, but there is no bounce guarantee or credit-back that would make inaccuracy the vendor's cost. 1 2
The DACH Sales Director
The headline counts are everywhere — 290 million contacts, 165 million emails, 117 million direct dials, 78 fields per record — but I found no public information on coverage for Germany, Austria or Switzerland, or on any per-country breakdown at all, and for a Mittelstand pipeline that silence is the whole question. The only cadence stated is buying signals refreshed weekly; I found no re-verification cadence for the contact records themselves, no accuracy methodology and no bounce guarantee or credit-back terms. The firmographic depth is real, which keeps this just above pure headline counting. 1 2
The Skeptic
Headline counts are the whole story: 290M+ contacts, 165M+ emails, 117M+ direct dials, with no country or DACH breakdown anywhere on the captured pages. The weekly refresh attaches to buying signals, not to contact records, and the only accuracy figure published is a decay rate (12.6% a year, from 148,000 records) — a market statistic, not a verification method or a refresh cadence. We found no bounce or credit-back guarantee; the platform is licensed "as is" with no warranties. 1 2 4
Data sources & lawful basis
panel disagrees
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
Sources are named — data brokers, public APIs, and a Community Program where members share CRM, email-header and calendar data about their contacts — and the listed people get a privacy notice, a permanent suppression list, and published opt-out statistics with zero denials. But we found no public statement of the legitimate-interest basis for EU records and no description of people being notified when added, which is exactly what my prospects ask about first. 1 3
The RevOps Manager
Sources are named more concretely than most — data brokers, publicly available APIs, an Auto-Complete algorithm scanning public sources, and a Community Program whose members share CRM data, email headers and calendar meeting data about their contacts — with a suppression list honored across the database and a published 2024 request log (1,119 deletions/opt-outs, none denied). But I found no public statement of the legal basis for EU records — legitimate interest is never named — and no Art. 14 notification practice or balancing test anywhere on the pages, while the community sourcing pulls contact data from members' address books without any evidence those contacts were informed. 1 3
The Data Protection Officer
Source categories are named — trusted data brokers, publicly available APIs, and a Community Program whose members share CRM data, email headers and calendar information — with the contributory nature disclosed as such, and a suppression list that permanently removes opted-out people (1,119 deletion and opt-out requests processed in 2024, none denied). However, we found no public information on the legal basis claimed for EU records, on an Article 14 notice sent to the people added, or on a published balancing test. 3 4
The ABM Marketer
Sources are named with real specificity — trusted data brokers, publicly available APIs, and a Community Program whose members share CRM data, email headers and calendar meeting details — alongside a suppression list, a toll-free opt-out line and published 2024 figures showing 1,119 delete/opt-out requests handled within four days. We found no public information stating the legal basis for holding EU records, no practice of notifying the people added to the database, and no published balancing test; the contributory collection is at least disclosed as such. 3 1
The DACH Sales Director
Sources are named in general terms — data brokers and publicly available APIs — and the contributory side is disclosed candidly: community members share CRM data, email headers and calendar meeting details, which for my purposes is contacts harvested from other people's inboxes and will be my first question in any DPA review. The opt-out apparatus is genuinely working (suppression list, toll-free line, over a thousand delete/opt-out requests handled with none denied), but I found no public information on a legitimate-interest assessment or on any Art. 14 practice telling people they were added to the database. 3 1
The Skeptic
The privacy notice is franker than most in this category: it names data brokers and public APIs as sources and discloses the Community Program, in which members contribute CRM data, email headers and calendar meeting details, alongside scanning of customers' connected email and calendars. Opt-out is real and demonstrably exercised — 1,119 delete/opt-out requests in 2024, none denied, completed in under four days, backed by a suppression list and a toll-free opt-out line. But we found no public statement of the legal basis for processing the people in the database — no legitimate-interest position, no balancing test, no notification practice for people when added. 3
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
Website visitor identification and intent topics appear in the feature list and in tiered form (five topics on lower plans, twenty-five with unlimited results on the top one). We found no public information on how identification works, whether it stops at company level, what the script sets, or its consent position under German tracking law — nothing here I could defend to a DPO. 1 2
The RevOps Manager
"Website Visitor Identification" is named as a capability and buying-intent topics are priced into the tiers (five topics at Starter, twenty-five at Scale, signals refreshed weekly), but I found no public information on how the identification works, whether it stays at company level for EU traffic, or any consent position under TDDDG for whatever script does the tracking. 1 2
The Data Protection Officer
Website Visitor Identification is named as a product and buying-intent topics are sold in tiers (five topics on lower plans, twenty-five on Scale), with signals refreshed weekly. We found no public information on whether identification is company-level only, on how the script works, or on its behaviour under the TDDDG consent requirement before consent is given. 1 2
The ABM Marketer
Website Visitor Identification appears in the product list and buying-intent topics are sold in tiers — five topics at entry, unlimited results across twenty-five at the top tier — with a stated weekly refresh, but we found no public information on what the identification returns, company or person, how the tracking works, whether consent is required where cookies are set, or where the intent signals originate. For my three hundred named accounts I cannot tell from these pages whether an alert reaches the account owner at all. 1 2
The DACH Sales Director
The capability is named — Website Visitor Identification in the footer, buying-intent topics tiered from five up to unlimited — but I found no public information on how identification works, whether it stays at company level for EU traffic, whether a cookieless or consent-mode option exists, or any position under the German TDDDG on consent for the script. A feature name with no mechanics and no consent story is worth less to me than a described reverse-IP offering, because I cannot take an unevidenced tracker to a client's DPO. 1 2
The Skeptic
"Website Visitor Identification" appears as a feature name and buying-intent topics are tiered from five to twenty-five, but the captured pages say nothing about how identification works, whether it is company- or person-level, or how the tracking behaves with and without consent. We found no public information on a consent position under Germany's TDDDG, a consent-mode option, or a cookieless mode. A named feature with no documented mechanics and no consent statement earns little. 1 2
Prospecting workflow & outreach rules
panel disagrees
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
Basic and advanced filters, buying signals, and a vendor-maintained suppression list plus a do-not-call certification give me a workable search-and-suppress workflow. But we found no guidance on cold-outreach rules in the main EU markets and no country-aware flagging, and the terms put call-recording consent and deletion-on-request squarely on my reps rather than the product. 2 3 4
The RevOps Manager
Basic and advanced filters, buying signals as triggers and a vendor-side suppression list honored across the whole database exist, the terms bind use to a defined B2B Purpose with B2C solicitation prohibited, and a do-not-call list appears among the pricing page's compliance items without stated terms. But outreach risk lands squarely on the customer — call-recording consent is "Customer's sole responsibility" — and I found no public information on cold-outreach guidance for German or other EU markets, on phone numbers being checked against national do-not-call registers, or on opt-outs syncing back from outreach into exports. 2 3 4
The Data Protection Officer
The terms restrict use to defined B2B purposes, prohibit B2C use, and oblige the customer to remove records from its possession without undue delay, while call-recording consent and validation of AI output are placed solely on the customer. We found no public information on a buyer-side suppression or do-not-contact list, on country-aware flagging of German contacts, or on guidance for cold outreach rules in the main EU markets. 4 2
The ABM Marketer
Basic and advanced filters across 78 fields, signals and automated email sequences are in the paid tiers, and the vendor honours its own suppression list so opted-out people stop appearing in the database. We found no public information on country-aware handling, guidance on cold outreach rules in the main EU markets, or checks of phone numbers against national do-not-call registers — the terms place call-recording consent solely on the customer — and a do-not-call-list badge appears without any described mechanism. 2 3 4
The DACH Sales Director
Filters, bulk reveal and sequence automation are present, and the terms are explicit that recording consent and data-subject removal obligations sit with the customer — the legal risk is contractually mine, not theirs. A 'Do not call list' badge and an unexplained 'advanced compliance' line on the top tier are the only nods, and I found no public information on country-aware flagging of German contacts, on guidance for cold outreach under UWG §7, or on a do-not-contact list living in the buyer's own workflow. For a tool sold into DACH, silence on German outreach law is the headline fact. 2 4
The Skeptic
Filters, sequences and signals exist, but the terms push the legal risk to the buyer: call-recording consent is the customer's sole responsibility and AI output is reviewed and relied upon at the customer's sole risk. The suppression list is Lusha's own mechanism for people who opted out of Lusha's database, not a do-not-contact tool for the buyer's outreach, and we found no public information on country-aware handling of German contacts, do-not-call register checks, or opt-outs syncing back from outreach. A "Do not call list" badge on the pricing page and an unnamed "Advanced compliance" tier are the entire compliance substance on show. 2 3 4
CRM sync, enrichment & export
panel disagrees
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Salesforce, HubSpot, Monday and Zoho with direct export, CRM and CSV enrichment, webhooks and MCP, and records kept current without re-running an export — plus a plainly stated right to keep exported data after termination, which I respect. We found no public information on field mapping or deduplication, and API limits are only described as strict, with no numbers and no published credit cost per call. 1 2 4
The RevOps Manager
Native integrations with Salesforce, HubSpot, Monday and Zoho, enrichment of existing records ("fill in missing emails, phone numbers, and company details in your CRM"), CSV enrichment, webhooks and an API meant to "keep them current without anyone re-running an export" — and, rare in this category, the terms state plainly that the customer may continue to use the data after termination. What I cannot find is field mapping, deduplication, bidirectional sync, published credit costs per API call, or any automatic propagation of objections and corrections into synced records; when someone objects, the terms make removal the customer's manual job, "without undue delay". 1 2 4
The Data Protection Officer
Native connections to Salesforce, HubSpot, Monday and Zoho, enrichment of CRM and CSV records, and an API with webhooks and MCP are documented, and the terms state plainly that the customer may continue using the data after termination in most cases. We found no public information on propagation of objections into synced records, on per-call credit costs, or on field-level change history. 1 2 4
The ABM Marketer
Native integrations with Salesforce, HubSpot, Monday and Zoho, enrichment of existing CRM records through the extension, CSV or API, webhooks and MCP support, and a plainly stated right to keep using exported data after termination give me a workable route into the systems where my account owners sit. We found no public information on field mapping, deduplication, propagation of deletions when a person objects, or the credit cost of an API call. 1 2 4
The DACH Sales Director
Four CRMs named with direct export, CRM and CSV enrichment, an API with webhooks and even MCP into Claude and ChatGPT — the plumbing is modern, and the terms state plainly that exported data may be kept after termination. I found no public information on field mapping, deduplication, or propagation of objections and deletions into synced records, and the API's 'strict rate limits' appear without numbers or credit costs. Good bones, an unproven middle. 1 2 4
The Skeptic
Native integrations with Salesforce, HubSpot, Monday and Zoho, CSV and bulk enrichment, an API with webhooks and MCP, and automation partners give the data somewhere to land, and the terms state plainly that the customer may continue using the data after termination unless Lusha terminated for cause. We found no public information on field mapping, deduplication, propagation of objections or corrections into synced records, or per-call API credit costs; the rate limits are described only as "strict". 1 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
Both contracting entities are US and Israeli joint controllers, contact data sits on AWS in the United States, and the terms authorize processing in any country where Lusha or its subprocessors maintain facilities, with SCCs and a published subprocessor list as the stated safeguards. We found no EU hosting option and no EU representative named — for a database full of EU professionals this is the part a DACH buyer cannot sign off on. 3 4
The RevOps Manager
The control setup is non-EU end to end: Lusha Systems Inc. (Boston) and Lusha Systems Ltd. (Tel Aviv) are joint controllers, data is "stored on Amazon Web Services in the United States of America", the terms authorize storage "in the United States or any other country", and data is shared with recipients in the United States, United Kingdom, Australia and Israel. Standard Contractual Clauses are named as the transfer safeguard and a full sub-processor list is published, which is worth something, but there is no EU contracting entity, no EU hosting, and support hours follow Israeli time. 3 4
The Data Protection Officer
Two non-EU joint controllers (a Delaware-incorporated company and an Israeli affiliate) host the database on Amazon Web Services in the United States, with transfers to the United States, United Kingdom, Australia and Israel covered by Standard Contractual Clauses and a published sub-processor list naming purpose, location and transfer method. We found no public information on an EU contracting entity, EU hosting, or an Article 27 representative, so EU residents' contact data is processed outside the EU by default. 3 4
The ABM Marketer
The contracting entities are Lusha Systems Inc. of Boston and Lusha Systems Ltd. of Tel Aviv acting as joint controllers, and the contact data is stored on Amazon Web Services in the United States, with recipients in the United States, United Kingdom, Australia and Israel covered by Standard Contractual Clauses. A full sub-processor list with purpose, location and transfer method is published and a DPA is available, but we found no public information on EU hosting or an EU contracting entity — for a database populated with European professionals, this is a US-hosted chain. 3 4
The DACH Sales Director
Everything that matters sits outside the EU: a Delaware-incorporated vendor with an Israeli affiliate as joint controller, data stored on Amazon Web Services in the United States, and terms authorising storage in any country where Lusha or its subprocessors maintain facilities. Standard Contractual Clauses for the transfers and a published subprocessor list are the honest minimum and keep this off the floor, but I found no public information on an EU contracting entity, an EU hosting option or an Art. 27 representative. For a database of people who never chose Lusha, this is not a profile I can defend to a German buyer's Datenschutzbeauftragter. 3 4 1
The Skeptic
A Delaware company and a Tel Aviv affiliate are joint controllers, the data is stored on Amazon Web Services in the United States, and the terms authorise storage in the United States or any country where Lusha or its subprocessors maintain facilities, with sharing to the United States, United Kingdom, Australia and Israel under Standard Contractual Clauses. The subprocessor list is published with purpose, location and transfer method — real disclosure — but every disclosed location sits outside the EU, and we found no public information on any EU hosting or contracting option. Good paperwork, no sovereignty. 3 4
Pricing transparency
panel disagrees
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Four tiers carry public prices with credit allowances and a stated yearly discount, and the terms say credits expire at term end while the pricing page shows a monthly rollover cap on some plans — the captured pages give different figures for rollover. We found no public price for what a credit buys per data type, for extra seats, for the top tier, or for VAT treatment, so I still cannot compute the annual invoice for a team of eight. 2 4
The RevOps Manager
Four tiers are priced publicly with credit allowances — Free $0 with 40 credits per month, Starter $37.45 USD / month billed yearly with 4,800 credits per year, Pro $52.45, Premium $299.95 with 40,800 — and the terms state that unused credits expire at term end, while the pricing page also describes a monthly rollover capped at x2 on some plans. But the real invoice is still not computable: credits are not broken out by data type (email versus phone versus mobile), extra seats are billed at an unstated "prevailing rate", ad hoc credits carry an unstated "additional fee", Scale pricing is a sales conversation, and I found no public information on VAT treatment, per-API-call credit costs, or any refund rule for inaccurate data. 2 4
The Data Protection Officer
Four tiers are priced with credit allowances, from Free at $0 with 40 credits per month to Premium at $299.95 USD per month billed yearly with 40,800 credits per year, and the captured pages give different figures for rollover: the pricing page describes rolling over monthly credits subject to a x2 monthly cap while the terms state credits expire at term end and do not roll over. We found no public information on what a credit buys per data type, per-seat costs beyond included seats, ad hoc credit pricing, overage rates, or VAT treatment. 2 4
The ABM Marketer
Four tiers are priced publicly with credit allowances — Starter at $37.45 USD / month billed yearly with 4,800 credits per year, Premium at $299.95 USD / month billed yearly with 40,800 credits per year — but the top tier carries no price, additional seats are charged at an unstated prevailing rate, and no page defines what a credit buys per data type or states VAT treatment. The captured pages give different figures for credit rollover: the pricing page describes rolling over monthly credits up to a cap on some plans, while the terms state unused credits expire at the end of the term. 2 4
The DACH Sales Director
Four of five tiers carry public monthly prices with credit allowances and a stated 25 percent yearly discount, and the terms are blunt that unused credits expire at the end of the term — though the pricing page separately describes monthly credits rolling over up to a cap on some plans, so the captured pages give different figures for rollover. I found no public information on what a credit buys per data type, the extra-seat rate beyond 'prevailing rate', the price of ad hoc credits, VAT treatment or API costs, and the Scale tier is unpriced entirely. The invoice is computable for a small team; anything Scale-shaped is a sales call. 2 4
The Skeptic
Four tiers are priced with credit allowances and credit expiry is stated, though the captured pages give different figures for rollover — the pricing page shows monthly credits rolling over to a 2x cap on some plans while the terms say purchased credits expire at term end and do not roll over. The invoice still cannot be computed: no credit cost per data type (email versus direct dial versus mobile), no per-seat price beyond the included free seats, no price for the Scale tier, no per-call API cost, and VAT treatment unstated. There is no refund rule for inaccurate data — the data is licensed "as is". 2 4
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in US ⚠ unverified | 0/3 pts | 3 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | US by default ⚠ unverified | 0/3 pts | 3 Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The same privacy notice names an Israeli affiliate, Lusha Systems Ltd. (Tel Aviv), which is joint controller for Contacts and Visitors, so the Lusha entity involved may vary.
- Weak sourcing — Data residency. The same sentence notes that many data processing activities are carried out in other countries, and no EU hosting option is offered anywhere in the excerpts.
- Weak sourcing — Subprocessors. The privacy notice also names Stripe Inc. as payment processor and says data may go to recipients in the United States, the United Kingdom, Australia and Israel, but the full sub-processor list is only linked, not shown.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 11 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 support fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (12)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.lusha.com Checked 22 Sep 2026 Details →
- 2 Pricing page www.lusha.com Checked 22 Sep 2026 Details →
- 3 Privacy policy www.lusha.com Checked 22 Sep 2026 Details →
- 4 Terms of service www.lusha.com Checked 22 Sep 2026 Details →
- 5 Coverage, accuracy & freshness — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
- 6 Data sources & lawful basis — found from sitemap www.lusha.com Checked 1 Oct 2026 Details →
- 7 Visitor identification & intent signals — found from sitemap www.lusha.com Checked 1 Oct 2026 Details →
- 8 Visitor identification & intent signals — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
- 9 Prospecting workflow & outreach rules — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
- 10 Prospecting workflow & outreach rules — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
- 11 CRM sync, enrichment & export — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
- 12 CRM sync, enrichment & export — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →