ANTI-SPAM AND EMAIL COMPLIANCE POLICY

Version: 1.0.0 Effective Date: September 1, 2026 Last Updated: September 2026


1. INTRODUCTION

This Anti-Spam and Email Compliance Policy ("Policy") governs the use of ClevMail ("Platform") for sending email communications. This Policy applies to all users of the Platform, including agencies and their clients ("Users").

Devi Devs Technologies S.R.L. ("DeviDevs", "we", "us") operates the Platform as an email marketing and automation service. We are committed to ensuring that all emails sent through our infrastructure comply with applicable laws and industry best practices.

By using the Platform, you agree to comply with this Policy.


2. APPLICABLE LEGISLATION

This Policy is designed to comply with the following laws and regulations:

LegislationJurisdictionKey Requirements
Regulation (EU) 2016/679 (GDPR)European UnionLawful basis for processing (Art. 6), consent requirements (Art. 7)
Directive 2002/58/EC (ePrivacy)European UnionArt. 13: opt-in for electronic marketing, soft opt-in exception
Legea nr. 506/2004RomaniaArt. 12: prior express consent for commercial emails; sender identification; unsubscribe mechanism
Legea nr. 365/2002RomaniaClear identification of commercial communications
CAN-SPAM Act (15 U.S.C. § 7701-7713)United StatesPhysical address, opt-out mechanism, honest headers and subject lines

3. FUNDAMENTAL PRINCIPLES

3.1. Consent-Based Sending. All email communications sent through the Platform must be based on verifiable consent. The recipient must have actively and knowingly agreed to receive the specific type of communication being sent.

3.2. Transparency. Every email must clearly identify the sender and provide recipients with straightforward means to understand who is contacting them and why.

3.3. Control. Recipients must have easy, free, and immediate control over the communications they receive, including the ability to unsubscribe at any time.

3.4. Accountability. Users are responsible for the consent they claim to have obtained and must be able to demonstrate valid consent upon request.


4. CONSENT REQUIREMENTS

4.1. Express Consent (Opt-In)

All email marketing sent through the Platform requires prior express consent from the recipient, in accordance with Legea 506/2004 Art. 12 alin. (1) and GDPR Art. 6(1)(a).

Valid consent must be:

  • (a) Freely given — not tied to unrelated conditions or services (EDPB Guidelines 05/2020);
  • (b) Specific — given for a clearly defined purpose (e.g., "weekly newsletter about IT news");
  • (c) Informed — the recipient was told: who the sender is, what they will receive, and how to unsubscribe;
  • (d) Unambiguous — demonstrated by a clear affirmative action (e.g., checking an unchecked checkbox, clicking a subscribe button).

Pre-ticked checkboxes, silence, or inactivity do NOT constitute valid consent (GDPR Recital 32; CJEU C-673/17 Planet49).

4.2. Soft Opt-In Exception

Under Legea 506/2004 Art. 12 alin. (2) (transposing ePrivacy Art. 13(2)), email marketing may be sent without prior express consent only when ALL of the following conditions are met simultaneously:

  • (a) the email address was obtained in the context of a sale of a product or service (including free/freemium services, per CJEU C-654/23 Inteligo Media);
  • (b) the communication promotes the sender's own similar products or services;
  • (c) the recipient was given a clear and free opportunity to object at the time of collection and in every subsequent message;
  • (d) the recipient has not objected to such use.

4.3. Double Opt-In (Recommended)

We strongly recommend implementing double opt-in (confirmation email) for all new subscribers. While not legally mandatory, double opt-in:

  • provides stronger evidence of consent;
  • reduces invalid email addresses and bot subscriptions;
  • improves email deliverability and sender reputation;
  • is recommended by ANSPDCP and most EU supervisory authorities.

4.4. Consent Records

Users must maintain verifiable records of consent for every subscriber on the Platform, including:

  • the identity of the Data Subject (email address);
  • the date and time consent was given;
  • the method of consent (e.g., web form, API, import with documented consent);
  • the information provided to the Data Subject at the time of consent;
  • the version of the privacy notice/terms presented.

The Platform's consent_given_at field records the timestamp of consent. Users are responsible for maintaining additional consent documentation outside the Platform if needed.


5. MANDATORY EMAIL REQUIREMENTS

Every email sent through the Platform must comply with the following requirements:

5.1. Sender Identification

RequirementLegal BasisDetails
Accurate "From" name and addressLegea 506/2004 Art. 12(3); CAN-SPAM § 7704(a)(1)The "From" field must truthfully identify the sender. Spoofing or misleading sender information is prohibited.
Valid "Reply-To" addressCAN-SPAM § 7704(a)(1)The reply address must be monitored and functional for at least 30 days after sending.
Physical postal addressCAN-SPAM § 7704(a)(5)(A)(iii)Every commercial email must include a valid physical postal address of the sender.
Clear identification as commercialLegea 365/2002 Art. 6; Legea 506/2004 Art. 12(3)Commercial communications must be clearly identifiable as such.

5.2. Subject Line

The email subject line must not be misleading or deceptive about the content of the message (CAN-SPAM § 7704(a)(2); Legea 506/2004 Art. 12(3)).

5.3. Unsubscribe Mechanism

RequirementLegal BasisDetails
Visible unsubscribe linkLegea 506/2004 Art. 12(3); CAN-SPAM § 7704(a)(3)Every email must include a clearly visible and easily accessible unsubscribe mechanism.
One-click unsubscribeRFC 8058; EDPB Guidelines 05/2020Unsubscribe must be as easy as subscribing. We recommend one-click unsubscribe (List-Unsubscribe header).
Free of chargeLegea 506/2004; CAN-SPAMUnsubscribing must not require payment or providing additional information beyond the email address.
Processed promptlyCAN-SPAM § 7704(a)(4)Unsubscribe requests must be honoured within 10 business days (CAN-SPAM). Best practice: immediately.
Functional for 30 daysCAN-SPAM § 7704(a)(3)(A)(ii)The unsubscribe mechanism must remain functional for at least 30 days after sending.

The Platform automatically includes an unsubscribe link in every email and processes unsubscribes immediately upon click.

5.4. Email Content

  • (a) Email content must not contain malware, viruses, or malicious code;
  • (b) Links in emails must not redirect to phishing sites, malware downloads, or deceptive destinations;
  • (c) Content must not violate applicable laws, including intellectual property rights;
  • (d) Health claims, financial promises, or other regulated claims must comply with applicable sector-specific regulations.

6. PROHIBITED PRACTICES

The following practices are strictly prohibited on the Platform:

6.1. List Practices

  • (a) Sending to purchased, rented, borrowed, scraped, or harvested email lists
  • (b) Sending to lists obtained without verifiable consent
  • (c) Using email append, co-registration, or similar services without transparent consent
  • (d) Sharing subscriber lists between clients without each subscriber's explicit consent

6.2. Sending Practices

  • (a) Sending unsolicited commercial email (spam)
  • (b) Sending after a recipient has unsubscribed
  • (c) Concealing or falsifying sender identity, headers, or routing information
  • (d) Using deceptive subject lines or misleading content
  • (e) Sending to non-existent addresses or known spam traps

6.3. Content Practices

  • (a) Phishing, social engineering, or impersonation
  • (b) Distribution of malware, ransomware, or harmful software
  • (c) Content promoting illegal activities
  • (d) Content that is discriminatory, harassing, threatening, or incites violence
  • (e) Unsolicited adult content
  • (f) Fraudulent or deceptive commercial practices

6.4. Technical Practices

  • (a) Bypassing or circumventing the Platform's unsubscribe mechanisms
  • (b) Intentionally exceeding sending rate limits
  • (c) Using the Platform to relay email for third parties not authorised under the Service Agreement
  • (d) Attempting to manipulate email engagement metrics (fake opens, fake clicks)
  • (e) Harvesting email addresses from emails sent through the Platform

7. TECHNICAL COMPLIANCE REQUIREMENTS

7.1. Email Authentication

Users should configure the following DNS records for their sending domains to ensure email authenticity and deliverability:

StandardRequirement LevelPurpose
SPF (Sender Policy Framework)Strongly RecommendedAuthorises which mail servers can send on behalf of your domain
DKIM (DomainKeys Identified Mail)Strongly RecommendedCryptographic signature proving the email was not altered in transit
DMARC (Domain-based Message Authentication)RecommendedPolicy for handling emails that fail SPF/DKIM checks. Minimum: p=quarantine

7.2. Sending Limits

The Platform enforces sending limits to protect deliverability and comply with email provider policies. Specific limits are defined per service plan. Users must not attempt to circumvent these limits.

7.3. Bounce and Complaint Management

MetricThresholdAction
Bounce rate< 5%Exceeding triggers review and potential throttling
Complaint rate< 0.1%Exceeding triggers immediate review
Spam trap hits0Any hit triggers immediate investigation

The Platform automatically processes hard bounces (permanent delivery failures) by deactivating affected subscriber addresses.


8. SHARED RESPONSIBILITY

8.1. User (Controller) Responsibilities

The User is responsible for:

  • (a) obtaining and maintaining valid consent from all subscribers;
  • (b) the accuracy and legality of subscriber lists uploaded to the Platform;
  • (c) the content of emails sent through the Platform;
  • (d) responding to subscriber complaints and data subject requests;
  • (e) complying with all applicable anti-spam and data protection laws.

8.2. DeviDevs (Processor) Responsibilities

DeviDevs is responsible for:

  • (a) providing a compliant email sending infrastructure;
  • (b) automatically including an unsubscribe mechanism in every email;
  • (c) processing unsubscribe requests immediately;
  • (d) monitoring bounce rates, complaint rates, and spam trap hits;
  • (e) maintaining email authentication standards (SPF, DKIM);
  • (f) enforcing this Policy and taking action against violations.

9. ENFORCEMENT AND CONSEQUENCES

9.1. Monitoring

DeviDevs monitors the following indicators for all accounts:

  • bounce rates, complaint rates, and spam trap activity;
  • sending patterns and volume anomalies;
  • content analysis for prohibited material (automated and manual);
  • subscriber engagement metrics.

9.2. Escalation Procedure

LevelTriggerAction
WarningFirst minor violation (e.g., bounce rate 5-8%)Written notification with corrective actions required within 7 days
ThrottlingRepeated minor violations or moderate violationSending rate reduced; corrective actions required within 48 hours
SuspensionSerious violation or failure to correctSending privileges suspended pending investigation and remediation
TerminationSevere violation (spam, phishing, malware) or repeated serious violationsImmediate account termination without prior notice

9.3. Immediate Suspension

DeviDevs reserves the right to immediately suspend sending privileges without prior notice in cases of:

  • (a) spam or phishing activity;
  • (b) malware distribution;
  • (c) complaint rate exceeding 0.3%;
  • (d) spam trap hits;
  • (e) law enforcement or regulatory request;
  • (f) any activity that poses an immediate risk to the Platform's infrastructure, reputation, or other users.

10. REPORTING ABUSE

If you receive an unwanted email sent through the DeviDevs Platform, or if you wish to report a violation of this Policy, please contact us:

All reports will be investigated promptly. We take abuse reports seriously and will take appropriate action, up to and including account termination.


11. CHANGES TO THIS POLICY

DeviDevs may update this Policy from time to time. Material changes will be communicated to Users at least thirty (30) days before they take effect. Continued use of the Platform after the effective date of changes constitutes acceptance of the updated Policy.


12. LEGAL REFERENCES

  • Regulation (EU) 2016/679 (GDPR) — Art. 6, 7
  • Directive 2002/58/EC (ePrivacy) — Art. 13
  • Legea nr. 506/2004 (Romania) — Art. 12
  • Legea nr. 365/2002 (Romania) — Art. 5, 6
  • Legea nr. 190/2018 (Romania) — GDPR implementation
  • CAN-SPAM Act, 15 U.S.C. § 7701-7713
  • EDPB Guidelines 05/2020 on consent
  • CJEU C-673/17 Planet49 (pre-ticked checkboxes)
  • CJEU C-654/23 Inteligo Media (soft opt-in scope)
  • ANSPDCP enforcement decisions (Legea 506/2004 Art. 12)

Document ID: ASP-v1.0.0 Classification: Public This document does NOT constitute legal advice and should be reviewed by a qualified legal professional before publication.