whats-best.ai
Search Sign in

Lead Generation

Lusha

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 3 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Lusha Systems Inc. · www.lusha.com

Compare with Apollo.io → Compare with Cognism → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Skeptic

Weighted verdict

Has read "98% accuracy" and "GDPR-compliant data" on every homepage in the category. Reads instead for the refresh cadence, the credit-back rule for a bounced email, what a mobile number costs in credits, and the source the privacy notice admits to.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Skeptic

Coverage, accuracy & freshness

How this is scored

How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.

0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.

3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.

5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.

8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.

10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.

Report an error

The Skeptic

Headline counts are the whole story: 290M+ contacts, 165M+ emails, 117M+ direct dials, with no country or DACH breakdown anywhere on the captured pages. The weekly refresh attaches to buying signals, not to contact records, and the only accuracy figure published is a decay rate (12.6% a year, from 148,000 records) — a market statistic, not a verification method or a refresh cadence. We found no bounce or credit-back guarantee; the platform is licensed "as is" with no warranties. 1 2 4

Report an error

Data sources & lawful basis

How this is scored

Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.

0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.

3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.

5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.

8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.

10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.

Report an error

The Skeptic

The privacy notice is franker than most in this category: it names data brokers and public APIs as sources and discloses the Community Program, in which members contribute CRM data, email headers and calendar meeting details, alongside scanning of customers' connected email and calendars. Opt-out is real and demonstrably exercised — 1,119 delete/opt-out requests in 2024, none denied, completed in under four days, backed by a suppression list and a toll-free opt-out line. But we found no public statement of the legal basis for processing the people in the database — no legitimate-interest position, no balancing test, no notification practice for people when added. 3

Report an error

Visitor identification & intent signals

How this is scored

Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.

0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.

3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.

5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.

8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.

10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.

Report an error

The Skeptic

"Website Visitor Identification" appears as a feature name and buying-intent topics are tiered from five to twenty-five, but the captured pages say nothing about how identification works, whether it is company- or person-level, or how the tracking behaves with and without consent. We found no public information on a consent position under Germany's TDDDG, a consent-mode option, or a cookieless mode. A named feature with no documented mechanics and no consent statement earns little. 1 2

Report an error

Prospecting workflow & outreach rules

How this is scored

Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.

0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.

3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.

5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.

8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.

10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.

Report an error

The Skeptic

Filters, sequences and signals exist, but the terms push the legal risk to the buyer: call-recording consent is the customer's sole responsibility and AI output is reviewed and relied upon at the customer's sole risk. The suppression list is Lusha's own mechanism for people who opted out of Lusha's database, not a do-not-contact tool for the buyer's outreach, and we found no public information on country-aware handling of German contacts, do-not-call register checks, or opt-outs syncing back from outreach. A "Do not call list" badge on the pricing page and an unnamed "Advanced compliance" tier are the entire compliance substance on show. 2 3 4

Report an error

CRM sync, enrichment & export

How this is scored

Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.

0 — Manual CSV export only; no CRM integration and no API.

3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.

5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.

8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.

10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.

Report an error

The Skeptic

Native integrations with Salesforce, HubSpot, Monday and Zoho, CSV and bulk enrichment, an API with webhooks and MCP, and automation partners give the data somewhere to land, and the terms state plainly that the customer may continue using the data after termination unless Lusha terminated for cause. We found no public information on field mapping, deduplication, propagation of objections or corrections into synced records, or per-call API credit costs; the rate limits are described only as "strict". 1 2 4

Report an error

European sovereignty

How this is scored

Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.

0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.

3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.

5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.

8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.

Report an error

The Skeptic

A Delaware company and a Tel Aviv affiliate are joint controllers, the data is stored on Amazon Web Services in the United States, and the terms authorise storage in the United States or any country where Lusha or its subprocessors maintain facilities, with sharing to the United States, United Kingdom, Australia and Israel under Standard Contractual Clauses. The subprocessor list is published with purpose, location and transfer method — real disclosure — but every disclosed location sits outside the EU, and we found no public information on any EU hosting or contracting option. Good paperwork, no sovereignty. 3 4

Report an error

Pricing transparency

How this is scored

Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.

0 — No public prices at all; every tier is a sales conversation.

3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.

5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.

8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.

10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.

Report an error

The Skeptic

Four tiers are priced with credit allowances and credit expiry is stated, though the captured pages give different figures for rollover — the pricing page shows monthly credits rolling over to a 2x cap on some plans while the terms say purchased credits expire at term end and do not roll over. The invoice still cannot be computed: no credit cost per data type (email versus direct dial versus mobile), no per-seat price beyond the included free seats, no price for the Scale tier, no per-call API cost, and VAT treatment unstated. There is no refund rule for inaccurate data — the data is licensed "as is". 2 4

Report an error

European sovereignty — proven facts

3 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency US by default ⚠ unverified 0/3 pts 3 Report an error
Subprocessors US CLOUD Act reach ⚠ unverified 0/2 pts 3 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (12)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.lusha.com Checked 22 Sep 2026 Details →
  2. 2 Pricing page www.lusha.com Checked 22 Sep 2026 Details →
  3. 3 Privacy policy www.lusha.com Checked 22 Sep 2026 Details →
  4. 4 Terms of service www.lusha.com Checked 22 Sep 2026 Details →
  5. 5 Coverage, accuracy & freshness — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
  6. 6 Data sources & lawful basis — found from sitemap www.lusha.com Checked 1 Oct 2026 Details →
  7. 7 Visitor identification & intent signals — found from sitemap www.lusha.com Checked 1 Oct 2026 Details →
  8. 8 Visitor identification & intent signals — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
  9. 9 Prospecting workflow & outreach rules — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
  10. 10 Prospecting workflow & outreach rules — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
  11. 11 CRM sync, enrichment & export — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →
  12. 12 CRM sync, enrichment & export — found from sitemap docs.lusha.com Checked 1 Oct 2026 Details →