Skip to content

English guide · lead providers

CertiLead, explained in English.

What the service proves, why lead forms in France have needed it since 11 August 2026, and how to integrate the tracker without rebuilding your funnel.

CertiLead is built for the French market. The rest of this site, the provider dashboard, the emails and every legal document are in French, and the French versions prevail. Your browser's built-in translation (right-click, then "Translate to English") works well on the dashboard; this page is the reference for anything you want to get exactly right.

Last updated: 20 September 2026 · Questions: contact@certilead.fr

In short

A proof of consent that travels with the lead.

  • What it is. CertiLead is a proof-of-consent service for lead generation in France. A small script, the tracker, is added to the form where a consumer agrees to be called. At submission, CertiLead seals what the consumer saw and did, and returns a proof token that is passed along with the lead.
  • Who can use it. The account is opened by the company that operates the forms, whether it is registered in France or abroad. The professionals who will call the consumers, named in the consent, are companies registered in France.
  • Who pays. Lead buyers check the token before calling, and pay for that check. Creating proofs is free for providers, whatever the volume.
  • What does not change. Your landing pages, routing rules and CRM stay as they are. The tracker never blocks a submission: if CertiLead does not answer within three seconds, the form goes on without a token.
  • What it is not. CertiLead does not make a form compliant by itself. It records what the form displayed and what the consumer did. The wording of the form, the list of recipients and your GDPR obligations remain your responsibility.

Mechanism

How the proof is built, sealed and anchored.

1

Challenge

When the page loads, the tracker obtains a single-use anti-bot challenge from CertiLead, bound to the visitor's context (address, browser, language).

2

Capture

While the consumer fills in the form, the tracker records the session with inputs masked, measures the interaction (mouse, keyboard, scrolling, time spent) and collects the consent evidence: the designated checkbox, its label, the moment it was ticked, and the withdrawal and proof-access texts actually displayed on the page.

3

Sealing

At submission, CertiLead assembles the consent block from your tracker's configuration (the five R. 223-1 items) and the observed evidence, hashes the whole with SHA-256, chains it to the previous proof and returns a token such as CL-26-A1B2C3D4E5F6 together with a signed receipt. The tracker injects both into the form (cert_token, cert_receipt) and lets the submission go on.

4

Anchoring

Proofs are grouped into Merkle trees (RFC 6962) whose roots are published to write-once storage (WORM, three years), signed with Ed25519 keys and time-stamped by a qualified trust service provider (eIDAS, RFC 3161), with an additional anchoring on a public blockchain through OpenTimestamps.

What a proof contains

  • The hashes and the position in the chain and in its batch.
  • The sealed consent block: the professionals authorised to call, the collector, the goods or services, the validity period, the withdrawal and proof-access texts, the state and label of the checkbox, the closed list of named recipients.
  • Pseudonymous contact identifiers obtained through VOPRF in the browser, with their scheme and key identifier. Historical proofs retain their HMAC references and remain verifiable.
  • The encrypted session recording (AES-256-GCM with envelope encryption), reserved for audit.
  • The technical context: page address, timing, anti-bot score, browser environment.

Protected during provider collection. The tracker obtains VOPRF identifiers without sending the original email address or phone number to CertiLead to create the proof. The protection is automatic for every tracker, with no fallback to sending the original values. Your form still sends the lead to your own CRM as usual.

During phase 1, buyers still send contact details to CertiLead over HTTPS for verification. CertiLead computes the identifier for the proof's scheme and checks the match. Contact identifiers remain personal data: they are pseudonymous and can still be matched, not anonymous.

After the collection

  • The buyer checks. Before calling, the lead buyer checks the token on CertiLead at one of three levels (Essential, Reinforced, Premium). The check answers three questions: does the consent cover this buyer and this purpose, is it still valid, has it been withdrawn? Buyers pay per check; providers pay nothing.
  • The consumer can withdraw. On the public portal, a consumer proves ownership of their email address with a one-time code, lists the consents recorded with it and withdraws one. The proof changes status and no longer covers future calls. Buyers you listed with a contact address are notified.
  • You can withdraw on their behalf. If a consumer asks you directly, the dashboard ("Retraits de consentement") finds their proofs by email or phone number and switches them off, with a written confirmation to the person. A withdrawal is final.
  • Your signed receipt. cert_receipt is a deposit receipt signed by CertiLead (Ed25519) and handed over immediately, before any internal processing. It carries the token, the SHA-256 fingerprint of the sealed content and the submission date. Archived with the lead, it proves independently of CertiLead that the sealed content was never altered. Anyone can verify the signature with the public keys published by the API (/api/v1/public-keys); the dashboard has a "Vérifier un reçu" page for it.

Integration

One script, one attribute, then test before buying traffic.

One asynchronous script before </body>, one attribute on the consent checkbox, two optional attributes on the displayed texts. The tracker observes the form as it exists: no library, no rebuild, no change to your submission logic.

1

Open the provider account and verify the company

Register at providers.certilead.fr/register. The account is opened in the name of the company that operates the forms, wherever it is registered: the provider does not have to be a French company. The company check ("Vérification KYC") asks for the country of registration, a company registration extract (the Kbis for a French company, less than three months old; the local trade register extract or licence elsewhere), the identity document of the legal representative, and the registration number. For a French company, the SIREN or SIRET is checked automatically against the INSEE registry. For a company registered in another country, the local number is entered as it is and the file is reviewed manually by our team, which shows as "Revue manuelle en cours" until it is approved. Tracker creation is unlocked once the check is complete. Additional users ("Sous-comptes") can be invited with owner, admin or viewer roles, and two-factor authentication is available.

What is French by design is the other end of the chain: the professionals who will call the consumers, named in the consent and checked by the buyers, are companies registered in France, identified by their SIREN.

2

Verify your domain

In "Domaines", declare the exact host of the form (example.com or landing.example.com). CertiLead gives you a TXT record to add to the DNS zone of the root domain: name @ for the apex, or the subdomain label (landing) for a subdomain, value certilead-verify=<token>. Verification is automatic once the record has propagated. The tracker only works on verified hosts.

3

Create the tracker and configure the consent

In "Trackers", create a tracker for the form. You obtain a generator identifier, used in the script address, and you configure the R. 223-1 information that will be sealed in every proof:

Setting (French label)What to enterWhy
Professionnels autorisésThe companies allowed to call, each identified by its SIREN (the French company registration number), chosen from your buyers list ("Mes acheteurs"), 1 to 20 names.Identity of the callers (R. 223-1). Recipients are companies registered in France, so the SIREN is required; the buyer's check confirms that it is on the list.
Tiers collecteurFilled in automatically with your company name.Identity of the collector.
Biens ou servicesThe goods or services the call is about, for instance "comparaison de complémentaires santé".The purpose the consumer agrees to.
Durée de validitéIn days, 365 at most.The bounded duration. Past it, the proof reads as expired.
Texte de retraitHow the consumer can withdraw.R. 223-1, withdrawal.
Texte d'accès à la preuveHow the consumer can obtain the proof.R. 223-1, access to the proof.

These texts stay in French. They are displayed to French consumers on your form and reproduced in the proof; the regulation is aimed at them, not at your integrators. The dashboard proposes model texts. The last two may be left empty in the configuration when your page already displays them and marks them with data-certilead-mention (step 4): the text actually displayed is then sealed instead.

The same screen lets you choose what happens when the form is not compliant ("Formulaire non conforme au décret"): see the three modes further down. VOPRF applies automatically in all three modes; it is not an option to enable.

4

Add the script and the attributes

Keep referrerpolicy="no-referrer" in the full snippet: it also protects the initial script request. For an older installation, copy the updated snippet, refresh the relevant caches and reload open pages. If you use CSP, allow the provider's tracker domain and CertiLead's API domain in script-src (including the API's /vendor/voprf.min.js module), and the API in connect-src.

<!-- CertiLead Tracker v3 -->
<script src="https://providers.certilead.fr/tracker/v3/YOUR_GENERATOR_ID" async referrerpolicy="no-referrer"></script>

<form action="/lead" method="post">
    <input type="email" name="email" autocomplete="email">
    <input type="tel" name="phone" autocomplete="tel">

    <label>
        <input type="checkbox" name="phone_consent" data-certilead-consent="telephone">
        J'accepte d'être contacté(e) par téléphone par Assureur A et Assureur B
        au sujet de ma complémentaire santé, pendant 180 jours.
    </label>

    <p data-certilead-mention="retrait">Vous pouvez retirer ce consentement à tout moment …</p>
    <p data-certilead-mention="preuve">Vous pouvez obtenir gratuitement la preuve de votre consentement …</p>

    <button type="submit">Être rappelé</button>
</form>
  • data-certilead-consent="telephone" designates the phone-consent checkbox explicitly. Without it, the tracker falls back on a strict heuristic and the proof states that the box was guessed rather than designated. When the box is designated and left unticked, no proof is created at all: no call to CertiLead, no token.
  • data-certilead-mention="retrait" and "preuve" mark the withdrawal and proof-access texts as displayed. The tracker captures the text and whether it was really visible: a text present in the page but hidden proves nothing.
  • The email and phone fields are detected automatically (type, name, autocomplete, placeholder, label). The session is recorded with inputs masked.
  • Variants of the script: add ?test=true to the script address for the test mode (the whole flow runs, nothing is stored), ?debug=true or data-debug="true" for the diagnostic panel. Remove both before going live. On a live page, generate a time-limited debug link from the dashboard instead: adding ?cl_debug=<token> to the page address shows the panel to you only.

What the tracker injects

On submission, the tracker holds the form for the time needed to obtain the proof (under a second in practice, three seconds at most), injects two hidden fields and replays the submission with the button that was used, so that your own handlers and libraries run with the token present:

  • cert_token: the proof token, CL-YY-XXXXXXXXXXXX. Pass it to the buyer with the lead.
  • cert_receipt: the signed receipt, base64-encoded. Keep it in your CRM with the lead.

The tracker never blocks your form. If CertiLead does not answer within three seconds, or refuses the proof, the submission goes on without the two fields. A lead without cert_token is the signal to watch in your CRM: the contact is there, but it has no proof and must not be sold as consent-proven.

Three modes when the form is not compliant

A form can work perfectly and still produce incomplete proofs: a missing text, no configuration, a recipient without SIREN. You choose, per tracker, what happens in that case.

Mode (French label)BehaviourWhen to use it
Ne rien faireThe proof is created as it is. No alert.By default, while the integration is not stable yet.
SignalerThe proof is created and you are warned: banner in the dashboard, email to the account contact, webhook tracker.non_conform if you subscribe to it. At most one alert per form and per 24 hours.Recommended in production: the proof keeps existing and you know something is wrong.
RefuserCertiLead answers HTTP 422 with the list of points to fix. No proof is created and the lead reaches your CRM without a token. The form submission itself goes through normally.When a lead without proof is of no use to you. Arm it only once the integration is validated, preferably after a period in "Signaler".

Technologies

  • Classic HTML form. Nothing to change in your markup: the tracker intercepts the submission, obtains the proof, then replays the original submission.
  • jQuery, AJAX, JavaScript-driven submissions. The interception runs before handlers listening at document level, so a library that serialises the form right after cannot leave without the token.
  • React, Vue, dynamic funnels. Forms mounted after page load are detected as they appear. A funnel step displayed later is followed like the others; CertiLead.scan() forces a rescan if needed.
  • WordPress. The script works as is, but WPForms, Gravity Forms and Contact Form 7 only save the fields declared in their editor, so the injected token is lost when the entry is stored. The CertiLead WordPress extension keeps the token and the receipt with each entry, designates the checkbox (which the editors cannot do) and shows an integration status screen. Supported: WPForms (free and paid) and Gravity Forms. Updates arrive through WordPress like any other extension. Its admin screens are in French.

No form, or custom validation: the JavaScript API

Many funnels never submit a form: the fields live in a div, a button triggers a request, and your code decides whether the input is acceptable. The tracker steps aside and hands control to you.

// Fields in a container, a button triggers your own request: follow the container.
CertiLead.observe(document.querySelector('#quote-block'), { trigger: '#send' });

// Custom validation: declare the manual mode, then create the proof yourself.
// <form data-certilead-mode="manual"> … </form>
const proof = await CertiLead.certify(form, { timeoutMs: 3000 });
if (proof.status === 'skipped') {
    // contact_not_found | consent_not_found | consent_not_given
}
// proof.token and proof.receipt_b64 go with your lead
CertiLead.reset(form); // before a new attempt
  • certify() never submits the form. timeoutMs is capped at three seconds: your funnel can never hang on the creation of the proof.
  • In manual mode, at least one usable email address or phone number and a ticked consent box are required; otherwise the method answers contact_not_found, consent_not_found or consent_not_given without any network call.
  • Do not combine the automatic listener and the manual call on the same form. reset() clears the stored result before a new attempt.

Test before buying traffic

  • Playground. In the dashboard ("Intégration", then "Playground"), sample forms with a compliant checkbox let you see the whole flow, consent block included, without touching your site.
  • Test mode (?test=true). Your real page, the complete flow, no proof stored.
  • Diagnostic panel (?debug=true or the debug link). Initialisation status, detected forms, live metrics, bot detection, network requests, every error explained with its fix, and a compliance assistant that compares the displayed texts with the tracker's configuration. The report can be copied as JSON for your team or for support.
  • Go live. Production script, mode "Signaler", and a watch on leads without cert_token in your CRM.

Webhooks and follow-up

In "Webhooks", subscribe an HTTPS endpoint to proof.created (a proof was written), proof.claimed (a buyer checked it), proof.withdrawn (the consumer, or you on their behalf, withdrew the consent) and proof.revoked (fraud established), plus tracker.non_conform in "Signaler" mode. Failed deliveries are retried with an increasing delay. "Attestations" lists every proof with its status, "Batches" the anchoring batches they belong to.

Dashboard

Dashboard glossary, French to English.

The provider dashboard is in French. Browser translation handles the day-to-day; this table gives the exact meaning of each entry of the menu.

Menu entryMeaning
DashboardOverview: volumes, tracker health, latest proofs.
AttestationsHistory of your proofs, with status and filters.
BatchesThe anchoring batches (Merkle trees) your proofs belong to.
Vérifier un reçuCheck a signed receipt (cert_receipt) independently.
Retraits de consentementWithdraw a consent on behalf of a consumer who asked you.
DomainesDeclare and verify the hosts of your forms (DNS TXT record).
TrackersCreate trackers, configure the R. 223-1 information, choose the non-compliance mode, get the script.
Mes acheteursYour lead buyers (company, SIREN, contact email), named in the consent texts and notified on withdrawal.
WebhooksHTTPS endpoints receiving the events listed above.
GuideThe integration documentation (French, more detailed than this page).
PlaygroundSample forms to test the tracker.
Vérification KYCCompany verification: country of registration, registration extract, identity document of the legal representative, registration number.
Sous-comptesAdditional users and their roles (owner, admin, viewer).
ProfilYour account, password, two-factor authentication ("Authentification 2FA").
JournalActivity log of the account.
SupportSupport tickets.

Statuses and terms you will meet

FrenchEnglish
ActifActive: the proof covers calls within its validity period.
RévoquéRevoked by CertiLead after fraud was established.
Retiré (consommateur)Withdrawn by the consumer, or by you on their behalf. Final.
Non consenti (case décochée)The consent box was not ticked: no valid consent.
ExpiréExpired: the validity period announced at collection is over.
Preuve · jeton · reçuProof · token · receipt.
Recueil · mentions · destinatairesCollection of consent · the mandatory information items · recipients.
Retrait · révocation · lotWithdrawal · revocation · batch.
Ne rien faire · Signaler · RefuserThe three non-compliance modes: do nothing · warn · refuse.
Domaine vérifié · tracker silencieuxVerified domain · silent tracker (no proof received for an unusual time).
Vérifié automatiquement · Revue manuelle en cours · Vérifié · RejetéCompany check statuses: verified automatically (French company, INSEE) · manual review in progress (company registered abroad, or a doubt to clear) · verified · rejected.

For your legal and data-protection teams

Data protection and hosting.

  • Roles. For the personal data collected on your form, your company is the controller. CertiLead acts as its processor for the technical operation of sealing and archiving the proof. The applicable terms are the French general terms of use and service and the French privacy policy, which also lists the subprocessors and the data processing terms.
  • Hosting. The service and its data are hosted in France by OVH SAS (Roubaix). Transactional emails are sent through Mailjet.
  • Data in the proof. Integrity hashes, VOPRF contact identifiers (HMAC references for historical proofs), the sealed consent block, the technical context, and the encrypted session recording. The proof contains no readable copy of the original email address or phone number.
  • Retention. Three years from collection (article R. 223-2), on write-once storage that CertiLead itself cannot alter or delete before the term.
  • Integrity. SHA-256 hash chain, Merkle batches (RFC 6962), Ed25519 signatures, qualified electronic time stamps (eIDAS, RFC 3161), OpenTimestamps anchoring, and the signed receipt handed to you at submission.
  • Session recordings. Encrypted with AES-256-GCM under envelope encryption. Decryption is reserved for audit, requires a stated reason and is logged.
  • Consumer rights. The public portal lets any consumer list the consents recorded with their email address and withdraw them; you can also do it on their behalf from the dashboard, and the buyers you listed are notified.

Questions

What your acquisition, technical and legal teams ask first.

Do we have to rebuild our forms?

No. The tracker is added with a script and an attribute on the consent checkbox. Dynamic forms are detected automatically, and custom funnels have a JavaScript API.

Can our team abroad operate the account?

Yes, and the company itself can be registered outside France: the account is opened in the name of the company operating the forms, with its local registration documents, and the file is reviewed manually by our team. The integration itself (script, attributes, API, webhooks) is language-neutral, and the dashboard works with your browser's translation. Only the texts displayed to consumers, which are sealed in the proof, must be in French.

Can a pre-ticked box produce valid consent?

No. The decree requires a clear positive action. A box already ticked, or continued browsing, does not demonstrate an express choice by the consumer.

Can we sell the same lead to several buyers?

Yes, if the collection really covers each of the authorised professionals and the purpose of their calls. The list of recipients must be exhaustive, accessible and up to date at the time of consent.

Can the tracker block the collection of a lead?

No. After three seconds at most, or if the proof fails, the form goes on without a token. The lead is still collected, but must not be presented as proven.

How do we prove that the information was actually displayed?

The texts marked with data-certilead-mention are captured with their visibility state and linked to the proof produced at submission.

What if our form changes?

The diagnostic panel reports structural defects. The "Signaler" mode, tracker health and the "silent tracker" event help spot a broken integration or an unusual drop in proofs.

Is it compatible with WordPress?

Yes. The script works on WordPress. The CertiLead extension keeps the token and the receipt, designates the right checkbox and adds diagnostics with WPForms and Gravity Forms.

Does CertiLead keep contact details in clear in the proof?

No. The tracker uses VOPRF without sending the original contact details to CertiLead to create the proof. If that operation fails, the tracker does not create the proof or send the original values as a fallback. Buyers still send contact details over HTTPS for verification during phase 1, and historical HMAC proofs remain verifiable.

What happens after a withdrawal of consent?

The proof changes status and no longer covers future prospecting. The buyers you listed with a contact address are notified.

How long must the proof remain available?

The decree requires digital retention for at least three years from collection. During that period the consumer must be able to obtain, free of charge, an individual proof on a durable medium.

Is the proof paid for?

No. Creating the proof is free for lead providers. The buyer then pays for the level of check they want to apply to the lead they receive.

Does CertiLead make our form compliant automatically?

No. CertiLead records the collection as observed and provides a chain of proof. The lawfulness of the form, the relevance of the recipients and your GDPR obligations remain your responsibility.

Support

Talking to the team.

  • By email: contact@certilead.fr. The team answers within one working day. You may write in English.
  • From the dashboard: the "Support" section opens a ticket tied to your account, which is the fastest route for anything about a tracker, a domain or a proof.
  • Through the site: the contact form (in French).

Never include personal data from a lead in a message to us: no name, phone number or email address of a consumer. A token, a tracker identifier or the JSON report of the diagnostic panel is all we need.

Your first tracker

Test the integration before your next traffic purchase.

Open your provider account, verify your domain and use the test mode until every check is green.