# Compliance

This page describes how Flomailr behaves around unsubscribes, postal addresses, suppression, consent and erasure. It is not legal advice. The law that applies to you depends on where you and your recipients are, and meeting it is your responsibility.

## Unsubscribe

Every campaign and automation email carries a footer with **Update your preferences** and **Unsubscribe** links and your postal address. The message also carries the one-click `List-Unsubscribe` and `List-Unsubscribe-Post` headers that Gmail and Yahoo expect from bulk senders.

- The footer link opens a page that asks "Unsubscribe?" and acts only when the button is pressed. Security scanners open every link in a message, and a link that unsubscribed on open would remove people who did nothing. The mail client's one-click header acts immediately.
- An unsubscribe sets the contact to Unsubscribed, adds the address to the suppression list with the reason Unsubscribed, takes the contact off every list and sends a `CONTACT_UNSUBSCRIBED` webhook.
- The confirmation page then offers the preference centre, as a second chance and not a condition.
- Setting the contact back to Subscribed, importing the address or submitting a signup form does not lift the suppression. The person can lift it by confirming a subscription link or saving their preferences. An admin can release the address from the suppression list.

## Postal address

Set **Business mailing address** in **Settings > Workspace**, under **Email sending**. It appears in the footer of every campaign email.

Campaign sends are refused until it is set, whether you send from the dashboard, the API, a schedule or an AI agent. Automation emails are not sent until it is set either.

## Suppression list

**Settings > Suppressions** lists addresses this workspace will not mail, with the reason:

| Reason         | How it gets there                                                                 |
| -------------- | --------------------------------------------------------------------------------- |
| Hard bounce    | A permanent bounce from the mail provider, or a contact marked Bounced            |
| Spam complaint | A recipient reports a message as spam, or a complaint status in an import         |
| Unsubscribed   | The unsubscribe link or one-click, or a contact marked Unsubscribed               |
| Added by hand  | **Block address** on this page (admins only), or a suppressed status in an import |

Campaigns and automations never mail a suppressed address, even if the **Check the suppression list** guardrail is off. **Release address** (admins only) removes an entry.

A person's own consent can clear an Unsubscribed entry: confirming a subscription link, or saving the preference centre. Nothing automatic clears a bounce, a complaint or a hand-added block.

## Consent log

The **Consent log** card on a contact records when consent was given or withdrawn. Entries are written when:

- a signup form, hosted subscribe page or landing page subscribes someone without a confirmation email, such as a form with no list
- someone confirms a double opt-in email (source `double_opt_in`)
- a contact re-subscribes through the preference centre
- an integration reports an explicit opt-in or refusal
- an SMS opt-out is processed
- personal data is erased

Imports, contacts added by hand and the contacts API do not write consent entries.

The `check_compliance` tool (see [MCP tools](/docs/ai/tools)) checks email content and the share of a list with recorded consent. Pass `physicalAddress`, because the footer address is added at send time and is not part of the content it inspects.

## GDPR erasure

On a contact, **Data & privacy** has **Erase personal data (GDPR)**. It cannot be undone. It:

- replaces the email with `erased-ID@erased.invalid` and clears first name, last name, tags and custom fields
- sets the status to Unsubscribed and removes the contact from every list
- records an Erased entry in the consent log

The contact row stays so campaign history keeps its counts. Engagement history stays but can no longer be traced to a person. Other fields on the record, such as phone number, time zone or Stripe customer ID, are not part of this action. Erasure does not add the old address to the suppression list, so a later import of it creates a new contact.

## Topics and preferences

The **Update your preferences** link opens a hosted page. People choose how often they hear from you (**Every email**, **At most once a week**, **At most once a month**, or **Pause everything** for 30, 60 or 90 days or until they say otherwise) and which topics they want.

Create topics in **Settings > Topics**, then set a campaign's **Topic** in the builder. Contacts who opted out of that topic are skipped. Weekly and monthly caps look at the last time the contact was sent anything (7 and 30 days). These checks run when a campaign is sent. Automation emails do not apply them, but still skip contacts who are not subscribed or are suppressed.

## Marketing and transactional

| Rule                                       | Campaigns and automations | `POST /api/v1/send` |
| ------------------------------------------ | ------------------------- | ------------------- |
| Unsubscribe footer and header              | Added                     | Not added           |
| Postal address                             | Required                  | Not required        |
| Open and click tracking                    | Added                     | Not added           |
| Unsubscribed entries block the send        | Yes                       | No                  |
| Hard bounce, complaint, hand-added block   | Block                     | Block               |
| Topics and frequency                       | Campaigns only            | No                  |
| Quiet hours and daily cap                  | Apply                     | Do not apply        |
| Monthly limit, suspension, blocked domains | Apply                     | Apply               |

`send_email`, the AI connector's tool for one to five recipients, follows the same rules with two differences: the daily cap applies to it, and every suppression entry blocks it, Unsubscribed included. Flomailr does not inspect a message to decide which kind it is. Sending promotional mail through the transactional route skips the unsubscribe link and the address, and that is your call to make. See [Transactional Send](/docs/api/send) and [Sending Health](/docs/concepts/sending-health).
