ANTI-SPAM AND EMAIL COMPLIANCE POLICY
Version: 1.0.0 Effective Date: September 1, 2026 Last Updated: September 2026
1. INTRODUCTION
This Anti-Spam and Email Compliance Policy ("Policy") governs the use of ClevMail ("Platform") for sending email communications. This Policy applies to all users of the Platform, including agencies and their clients ("Users").
Devi Devs Technologies S.R.L. ("DeviDevs", "we", "us") operates the Platform as an email marketing and automation service. We are committed to ensuring that all emails sent through our infrastructure comply with applicable laws and industry best practices.
By using the Platform, you agree to comply with this Policy.
2. APPLICABLE LEGISLATION
This Policy is designed to comply with the following laws and regulations:
| Legislation | Jurisdiction | Key Requirements |
|---|---|---|
| Regulation (EU) 2016/679 (GDPR) | European Union | Lawful basis for processing (Art. 6), consent requirements (Art. 7) |
| Directive 2002/58/EC (ePrivacy) | European Union | Art. 13: opt-in for electronic marketing, soft opt-in exception |
| Legea nr. 506/2004 | Romania | Art. 12: prior express consent for commercial emails; sender identification; unsubscribe mechanism |
| Legea nr. 365/2002 | Romania | Clear identification of commercial communications |
| CAN-SPAM Act (15 U.S.C. § 7701-7713) | United States | Physical address, opt-out mechanism, honest headers and subject lines |
3. FUNDAMENTAL PRINCIPLES
3.1. Consent-Based Sending. All email communications sent through the Platform must be based on verifiable consent. The recipient must have actively and knowingly agreed to receive the specific type of communication being sent.
3.2. Transparency. Every email must clearly identify the sender and provide recipients with straightforward means to understand who is contacting them and why.
3.3. Control. Recipients must have easy, free, and immediate control over the communications they receive, including the ability to unsubscribe at any time.
3.4. Accountability. Users are responsible for the consent they claim to have obtained and must be able to demonstrate valid consent upon request.
4. CONSENT REQUIREMENTS
4.1. Express Consent (Opt-In)
All email marketing sent through the Platform requires prior express consent from the recipient, in accordance with Legea 506/2004 Art. 12 alin. (1) and GDPR Art. 6(1)(a).
Valid consent must be:
- (a) Freely given — not tied to unrelated conditions or services (EDPB Guidelines 05/2020);
- (b) Specific — given for a clearly defined purpose (e.g., "weekly newsletter about IT news");
- (c) Informed — the recipient was told: who the sender is, what they will receive, and how to unsubscribe;
- (d) Unambiguous — demonstrated by a clear affirmative action (e.g., checking an unchecked checkbox, clicking a subscribe button).
Pre-ticked checkboxes, silence, or inactivity do NOT constitute valid consent (GDPR Recital 32; CJEU C-673/17 Planet49).
4.2. Soft Opt-In Exception
Under Legea 506/2004 Art. 12 alin. (2) (transposing ePrivacy Art. 13(2)), email marketing may be sent without prior express consent only when ALL of the following conditions are met simultaneously:
- (a) the email address was obtained in the context of a sale of a product or service (including free/freemium services, per CJEU C-654/23 Inteligo Media);
- (b) the communication promotes the sender's own similar products or services;
- (c) the recipient was given a clear and free opportunity to object at the time of collection and in every subsequent message;
- (d) the recipient has not objected to such use.
4.3. Double Opt-In (Recommended)
We strongly recommend implementing double opt-in (confirmation email) for all new subscribers. While not legally mandatory, double opt-in:
- provides stronger evidence of consent;
- reduces invalid email addresses and bot subscriptions;
- improves email deliverability and sender reputation;
- is recommended by ANSPDCP and most EU supervisory authorities.
4.4. Consent Records
Users must maintain verifiable records of consent for every subscriber on the Platform, including:
- the identity of the Data Subject (email address);
- the date and time consent was given;
- the method of consent (e.g., web form, API, import with documented consent);
- the information provided to the Data Subject at the time of consent;
- the version of the privacy notice/terms presented.
The Platform's consent_given_at field records the timestamp of consent. Users are responsible for maintaining additional consent documentation outside the Platform if needed.
5. MANDATORY EMAIL REQUIREMENTS
Every email sent through the Platform must comply with the following requirements:
5.1. Sender Identification
| Requirement | Legal Basis | Details |
|---|---|---|
| Accurate "From" name and address | Legea 506/2004 Art. 12(3); CAN-SPAM § 7704(a)(1) | The "From" field must truthfully identify the sender. Spoofing or misleading sender information is prohibited. |
| Valid "Reply-To" address | CAN-SPAM § 7704(a)(1) | The reply address must be monitored and functional for at least 30 days after sending. |
| Physical postal address | CAN-SPAM § 7704(a)(5)(A)(iii) | Every commercial email must include a valid physical postal address of the sender. |
| Clear identification as commercial | Legea 365/2002 Art. 6; Legea 506/2004 Art. 12(3) | Commercial communications must be clearly identifiable as such. |
5.2. Subject Line
The email subject line must not be misleading or deceptive about the content of the message (CAN-SPAM § 7704(a)(2); Legea 506/2004 Art. 12(3)).
5.3. Unsubscribe Mechanism
| Requirement | Legal Basis | Details |
|---|---|---|
| Visible unsubscribe link | Legea 506/2004 Art. 12(3); CAN-SPAM § 7704(a)(3) | Every email must include a clearly visible and easily accessible unsubscribe mechanism. |
| One-click unsubscribe | RFC 8058; EDPB Guidelines 05/2020 | Unsubscribe must be as easy as subscribing. We recommend one-click unsubscribe (List-Unsubscribe header). |
| Free of charge | Legea 506/2004; CAN-SPAM | Unsubscribing must not require payment or providing additional information beyond the email address. |
| Processed promptly | CAN-SPAM § 7704(a)(4) | Unsubscribe requests must be honoured within 10 business days (CAN-SPAM). Best practice: immediately. |
| Functional for 30 days | CAN-SPAM § 7704(a)(3)(A)(ii) | The unsubscribe mechanism must remain functional for at least 30 days after sending. |
The Platform automatically includes an unsubscribe link in every email and processes unsubscribes immediately upon click.
5.4. Email Content
- (a) Email content must not contain malware, viruses, or malicious code;
- (b) Links in emails must not redirect to phishing sites, malware downloads, or deceptive destinations;
- (c) Content must not violate applicable laws, including intellectual property rights;
- (d) Health claims, financial promises, or other regulated claims must comply with applicable sector-specific regulations.
6. PROHIBITED PRACTICES
The following practices are strictly prohibited on the Platform:
6.1. List Practices
- (a) Sending to purchased, rented, borrowed, scraped, or harvested email lists
- (b) Sending to lists obtained without verifiable consent
- (c) Using email append, co-registration, or similar services without transparent consent
- (d) Sharing subscriber lists between clients without each subscriber's explicit consent
6.2. Sending Practices
- (a) Sending unsolicited commercial email (spam)
- (b) Sending after a recipient has unsubscribed
- (c) Concealing or falsifying sender identity, headers, or routing information
- (d) Using deceptive subject lines or misleading content
- (e) Sending to non-existent addresses or known spam traps
6.3. Content Practices
- (a) Phishing, social engineering, or impersonation
- (b) Distribution of malware, ransomware, or harmful software
- (c) Content promoting illegal activities
- (d) Content that is discriminatory, harassing, threatening, or incites violence
- (e) Unsolicited adult content
- (f) Fraudulent or deceptive commercial practices
6.4. Technical Practices
- (a) Bypassing or circumventing the Platform's unsubscribe mechanisms
- (b) Intentionally exceeding sending rate limits
- (c) Using the Platform to relay email for third parties not authorised under the Service Agreement
- (d) Attempting to manipulate email engagement metrics (fake opens, fake clicks)
- (e) Harvesting email addresses from emails sent through the Platform
7. TECHNICAL COMPLIANCE REQUIREMENTS
7.1. Email Authentication
Users should configure the following DNS records for their sending domains to ensure email authenticity and deliverability:
| Standard | Requirement Level | Purpose |
|---|---|---|
| SPF (Sender Policy Framework) | Strongly Recommended | Authorises which mail servers can send on behalf of your domain |
| DKIM (DomainKeys Identified Mail) | Strongly Recommended | Cryptographic signature proving the email was not altered in transit |
| DMARC (Domain-based Message Authentication) | Recommended | Policy for handling emails that fail SPF/DKIM checks. Minimum: p=quarantine |
7.2. Sending Limits
The Platform enforces sending limits to protect deliverability and comply with email provider policies. Specific limits are defined per service plan. Users must not attempt to circumvent these limits.
7.3. Bounce and Complaint Management
| Metric | Threshold | Action |
|---|---|---|
| Bounce rate | < 5% | Exceeding triggers review and potential throttling |
| Complaint rate | < 0.1% | Exceeding triggers immediate review |
| Spam trap hits | 0 | Any hit triggers immediate investigation |
The Platform automatically processes hard bounces (permanent delivery failures) by deactivating affected subscriber addresses.
8. SHARED RESPONSIBILITY
8.1. User (Controller) Responsibilities
The User is responsible for:
- (a) obtaining and maintaining valid consent from all subscribers;
- (b) the accuracy and legality of subscriber lists uploaded to the Platform;
- (c) the content of emails sent through the Platform;
- (d) responding to subscriber complaints and data subject requests;
- (e) complying with all applicable anti-spam and data protection laws.
8.2. DeviDevs (Processor) Responsibilities
DeviDevs is responsible for:
- (a) providing a compliant email sending infrastructure;
- (b) automatically including an unsubscribe mechanism in every email;
- (c) processing unsubscribe requests immediately;
- (d) monitoring bounce rates, complaint rates, and spam trap hits;
- (e) maintaining email authentication standards (SPF, DKIM);
- (f) enforcing this Policy and taking action against violations.
9. ENFORCEMENT AND CONSEQUENCES
9.1. Monitoring
DeviDevs monitors the following indicators for all accounts:
- bounce rates, complaint rates, and spam trap activity;
- sending patterns and volume anomalies;
- content analysis for prohibited material (automated and manual);
- subscriber engagement metrics.
9.2. Escalation Procedure
| Level | Trigger | Action |
|---|---|---|
| Warning | First minor violation (e.g., bounce rate 5-8%) | Written notification with corrective actions required within 7 days |
| Throttling | Repeated minor violations or moderate violation | Sending rate reduced; corrective actions required within 48 hours |
| Suspension | Serious violation or failure to correct | Sending privileges suspended pending investigation and remediation |
| Termination | Severe violation (spam, phishing, malware) or repeated serious violations | Immediate account termination without prior notice |
9.3. Immediate Suspension
DeviDevs reserves the right to immediately suspend sending privileges without prior notice in cases of:
- (a) spam or phishing activity;
- (b) malware distribution;
- (c) complaint rate exceeding 0.3%;
- (d) spam trap hits;
- (e) law enforcement or regulatory request;
- (f) any activity that poses an immediate risk to the Platform's infrastructure, reputation, or other users.
10. REPORTING ABUSE
If you receive an unwanted email sent through the DeviDevs Platform, or if you wish to report a violation of this Policy, please contact us:
- Email: salut@clevmail.ro
- Response time: Within 24 hours on business days
All reports will be investigated promptly. We take abuse reports seriously and will take appropriate action, up to and including account termination.
11. CHANGES TO THIS POLICY
DeviDevs may update this Policy from time to time. Material changes will be communicated to Users at least thirty (30) days before they take effect. Continued use of the Platform after the effective date of changes constitutes acceptance of the updated Policy.
12. LEGAL REFERENCES
- Regulation (EU) 2016/679 (GDPR) — Art. 6, 7
- Directive 2002/58/EC (ePrivacy) — Art. 13
- Legea nr. 506/2004 (Romania) — Art. 12
- Legea nr. 365/2002 (Romania) — Art. 5, 6
- Legea nr. 190/2018 (Romania) — GDPR implementation
- CAN-SPAM Act, 15 U.S.C. § 7701-7713
- EDPB Guidelines 05/2020 on consent
- CJEU C-673/17 Planet49 (pre-ticked checkboxes)
- CJEU C-654/23 Inteligo Media (soft opt-in scope)
- ANSPDCP enforcement decisions (Legea 506/2004 Art. 12)
Document ID: ASP-v1.0.0 Classification: Public This document does NOT constitute legal advice and should be reviewed by a qualified legal professional before publication.