Unsubscribes and data deletion requests

5 min read

One-click unsubscribe

Every email you send contains a subscriber-specific unsubscribe link in the footer. Once used, that person is excluded from later sends on that client's list. If they are also subscribed to other lists on the platform, those keep sending to them.

How someone requests data deletion

There is a public page for GDPR Art. 17 data deletion requests. The link in the email footer leads straight there and carries the list the person is subscribed to; they still fill in the email address and submit, like any form, except the address can already be pre-filled from the link.

Anyone who lands on the page without that link (typing the address in directly, for instance) sees an incomplete-link message and is directed to write to privacy@devidevs-agency.com; that request is handled manually.

What happens after they submit the request

The page always answers with the same success message, even if the address is not on the list: it neither confirms nor denies who is subscribed. If the address exists, an email with a confirmation link goes out. The actual deletion happens the moment the person clicks that link, not later: the subscriber row is removed, their active automations are cancelled, and the address is added to an internal list that stops it from being re-imported onto that same client's list by mistake. A later, voluntary re-subscription is honoured as such.

The request touches one list only: the one whose link was used. Each client is its own data controller, so deleting the same person's data on a shop's list, for example, does not touch their data on another client's list.

If nobody clicks the confirmation link, the request does not sit unresolved forever: an internal alert goes out at 25 days, and at 30 days, the legal deadline, the platform executes the deletion automatically so it is never missed.

What you configure

Two fields in Client settings, the Your brand card, land in the footer of every email:

  • Company address: sender identification, required by Romanian e-commerce law (Law 365/2002, articles 5 and 6), which implements the European directive
  • Privacy policy link: the link to your privacy policy

Which address to use if your company is registered at home

The address field is empty until you fill it in, and whatever you write there reaches every recipient. For a company registered at the founder's home address, filling it in out of habit means that home address goes to the entire list, on every campaign.

The practical rule: if you have a commercial address or a PO box, use it. If your registered office is your home, leave the field empty. There is no separate toggle, only the text field. You stay identifiable through your privacy policy, whose link is in the footer anyway. Both fields are in the same form, Your brand, with a single save button. One more place can contain the address and is independent of the field above: the Email signature field, which is free text, so if you put it there, remove it separately.

For agency accounts

Each client managed by an agency has its own physical address and privacy policy link, set separately, in Client settings, the Your brand card, for that client. There is no shared address at the agency level: with several clients on one account, each is configured in turn, from the client selector.

When a deletion request is confirmed, the affected client's owner gets an email with the deleted address, so they know someone left the list a way other than unsubscribing.

Frequently asked questions

How does a recipient unsubscribe from a newsletter?

Through the one-click unsubscribe link in the footer of any email they received. Once used, they no longer receive emails from that list.

How does a recipient request deletion of their data?

Through the dedicated link in the email footer: it opens the page with the right list already identified. They enter their email, submit the request, then confirm from the email they receive, and only then does the deletion happen.

Does unsubscribing also delete their data?

No. Unsubscribing stops sends, and the address stays on the list marked as unsubscribed, so it is not re-added by mistake on a later import. Deleting data is a separate request, through the dedicated link in the email footer.

What happens if nobody confirms a deletion request?

The legal deadline is 30 days. If the person never clicks the confirmation link, the platform executes the deletion automatically at that deadline, so it is never missed.

Does a deletion request clear the person from every ClevMail list?

No. It only touches the list whose link was used. Another list on the platform needs its own request, through the link in that list's emails.

Articles in the same category

  • GDPR consent on subscription forms

    Hosted forms are embedded on the client's site with an iframe. The GDPR Consent toggle adds a required checkbox before the form can be submitted. Subscription confirmation (double opt-in) is a second, separate toggle, in Client settings.