Coldoutreach

Compliance, by default

GDPR cold email, done by the book

GDPR-compliant cold email requires a lawful basis (usually legitimate interest in a relevant B2B context), honest sender identification, an easy opt-out honored promptly, and respect for prior objections. Coldoutreach enforces every one of these on every send, automatically.

We built compliance into the product because deliverable outreach and lawful outreach are the same thing: mailbox providers punish exactly the behavior regulators prohibit. Here is the full posture, in plain language.

Requirement → enforcement

What the law asks, what the software does

Legal requirement Law How Coldoutreach enforces it
Lawful basis for processing business contacts GDPR Art. 6(1)(f) Import flow requires confirming a legitimate-interest basis; relevance fields (role, industry) are part of every prospect record so the interest is documentable.
Honest identification of the sender CAN-SPAM §5(a)(1), GDPR Art. 14 Sender name, company and a working reply address are mandatory sequence fields; forged headers and misleading subjects are blocked at review.
Working unsubscribe in every message CAN-SPAM §5(a)(3), PECR The unsubscribe link is injected into every email and cannot be removed, hidden or styled away. One-click list-unsubscribe headers included for Gmail and Yahoo.
Opt-outs honored promptly and permanently CAN-SPAM §5(a)(4), GDPR Art. 21 Opt-outs suppress the address workspace-wide within seconds, across all current and future sequences. Suppression entries cannot be deleted or re-imported.
No purchased or harvested lists GDPR Art. 14, CAN-SPAM §5(b) Purchased-list imports are against our terms and blocked when detected: list patterns, bounce profiles and complaint spikes all trigger review.
Physical address / imprint in commercial email CAN-SPAM §5(a)(5) Sequence templates include a footer block with your company address; sending is blocked while it is empty.

The deal

What we enforce, what you bring

Built into every send

  • Unsubscribe link + one-click list-unsubscribe headers
  • Global suppression, enforced in seconds, forever
  • Warmup, throttles and authentication checks on by default
  • Complaint and bounce monitoring with automatic pausing
  • Encrypted prospect data, never sold, never used to train models

Your side of the contract

  • Contact only relevant business prospects you can lawfully process
  • No purchased, rented or scraped lists, ever
  • Identify yourself and your company honestly
  • Offers must be real; subjects must match bodies
  • When in doubt about a jurisdiction, ask a lawyer, not a vendor

Accounts that break the list rules are suspended. That protects the shared reputation every customer's email deliverability depends on, and it keeps Coldoutreach a tool mailbox providers have no reason to distrust.

Security posture

Data protection for revenue teams

Encryption

TLS 1.2+ in transit, AES-256 at rest, for prospect data, sequences and email content alike.

Data processing agreement

A standard DPA with SCCs for EU transfers is available on Scale and Enterprise plans, countersigned within two business days.

Access controls

Staff access to workspace data is support-triggered only and fully logged. Enterprise adds SSO/SAML, roles and an audit log.

Running a security review? The sales engagement platform for enterprise page covers SSO, SLAs and the review process, or ask us anything on the contact page. The legality questions every new sender asks are answered on the cold email FAQ.

Outreach that would survive an audit

Draft a compliant sequence in 30 seconds: unsubscribe included, suppression respected, warmup on.

No credit card to start · Cancel anytime · Unsubscribe honored on every send