Browse Docs

Jump between feature areas and guides without leaving the article.

On This Page

Jump to the section you need.

GDPR FAQ

This FAQ explains how Mailrith's GDPR consent tools work, how double opt-in relates to consent, when to ask existing Subscribers for consent, how to store proof, and how to handle Subscriber privacy requests.

15 min read

Mailrith Workspaces page where workspace privacy and consent settings can be configured.
Workspace owners configure GDPR Consent from the Edit Workspace drawer, then use Segments and the GDPR Consent Link when they need to request consent from existing Subscribers.

Intro

This article explains how Mailrith's GDPR consent tools work. It is product help, not legal advice.

GDPR, UK GDPR, and Swiss privacy law can apply differently depending on where your business is located, where your Subscribers are located, what data you collect, and how you use that data. Talk to your own attorney if you have questions about your legal obligations.

Mailrith is operated by Rawool Publications in India. You can review Mailrith's Privacy Policy, Terms of Service, GDPR and CCPA overview, and DPA.

How Mailrith Transfers Personal Data From The EU/EEA, UK, And Switzerland To India And Elsewhere

Mailrith is operated from India, so Subscriber Personal Data may be processed in India. Mailrith also sends through customer-chosen email delivery services and other customer-connected tools. That means Subscriber Personal Data may also be handled by the email delivery services, webhooks, Zaps, CRMs, AI services, internal systems, or other tools you choose to connect.

Review these resources before you rely on a transfer setup:

  • Mailrith's DPA
  • Mailrith's Privacy Policy
  • The privacy and data processing terms for your selected email delivery services and other connected tools.
  • Your own transfer requirements with your attorney.

Mailrith does not decide whether your full setup is compliant.

Is Double Opt-In Enough To Prove Consent?

Double opt-in helps show that a Subscriber confirmed access to an email address. It does not automatically prove consent for every later purpose.

For example, double opt-in may help show that the Subscriber confirmed they wanted to join your list. It may not prove that they agreed to receive advertising emails, tracking, profiling, or other separate uses unless those purposes were clearly explained when consent was collected.

If you need to prove consent, keep records that show:

  • What the Subscriber agreed to.
  • When they agreed.
  • Where the consent was collected.
  • Which form, landing page, import, integration, or API workflow collected it.
  • Any wording shown to the Subscriber at the time.

When Is A Checkbox Needed?

A checkbox may be needed when you rely on consent for a specific purpose and need the Subscriber to take a clear action.

Common examples may include asking for permission to:

  • Send marketing email.
  • Use data for advertising or personalized marketing.
  • Share data with selected providers for a stated purpose.

Whether you need a checkbox depends on your legal basis, your location, your Subscribers' locations, and how you use the data. Ask your attorney if you are not sure.

Does GDPR Require Double Opt-In?

GDPR does not always require double opt-in. Double opt-in is a product and recordkeeping tool that can help confirm that the email address belongs to the Subscriber.

You may still need separate consent records depending on what you send and how you use Subscriber data. Double opt-in alone does not replace a clear consent request when consent is required.

Next Steps

To ask existing Subscribers for consent, first turn on GDPR Consent for your workspace.

  1. Open Workspaces.
  2. Choose the workspace row.
  3. Open the Edit Workspace drawer.
  4. Scroll to Privacy & Consent.
  5. Set GDPR Consent to one of these options:
    • Don't Ask Anyone
    • Ask Only In The EU, UK, And Switzerland
    • Ask All Subscribers

Then create a Segment for the Subscribers you want to contact and send them a broadcast with the GDPR Consent Link. You can insert the link from the email editor's Personalize menu when workspace GDPR Consent is turned on.

Sample re-permission email

Subject: Please Confirm You Still Want Emails From Us

Hi,

We are updating our email consent records. If you still want to receive emails from us, please confirm your preferences here:

GDPR Consent Link

If you do not confirm, we may stop sending you marketing emails.

Thank you.

Review the wording with your attorney before sending it.

Can Consent Checkboxes Be Pre-Checked?

Consent checkboxes should not be pre-checked if you are relying on consent under GDPR, UK GDPR, or similar rules that require a clear action from the Subscriber.

A Subscriber should be able to make an active choice. If you are not sure what your form should say or how consent should be collected, ask your attorney.

Do I Need A Checkbox For Every Tag In My Account?

Usually, consent should match a clear purpose, not every internal Tag.

For example, you may need consent for email marketing or advertising use. You usually do not need a separate checkbox just because you use Tags to organize Subscribers internally.

Mailrith uses consent Tags named GDPR: Email Consent and GDPR: Advertising Consent. For other Tags, decide whether they represent a separate purpose that needs separate consent. Ask your attorney if you are unsure.

What Happens If I Get Audited?

If you are audited or receive a legal request, you may need to show how you collected, stored, and honored consent.

You can use Mailrith tools such as Subscriber filters, Segments, Tags, exports, unsubscribe handling, and privacy-request support paths to help gather records.

You may also need records from systems outside Mailrith, including your email delivery service, webhook tools, Zaps, CRM, AI services, internal systems, forms, landing pages, or import sources.

Mailrith does not decide whether your records are legally enough. Work with your attorney.

What Type Of Data Can I Not Store In Mailrith?

Mailrith is not designed for special category data, health records, payment card numbers, government identity numbers, passwords, children's data, or similarly sensitive information.

Do not place that type of information in:

  • Subscriber fields.
  • Forms.
  • Landing pages.
  • Automations.
  • Email content.

Use systems designed for sensitive data if your business needs to collect it.

A Subscriber Asked Me To Delete Their Data. How Do I Do That?

First, verify the request using your own privacy process.

Then review where the Subscriber's data exists. Mailrith may hold Subscriber data in your workspace, but the same data may also exist in customer-connected tools such as email delivery services, webhooks, Zaps, CRMs, AI services, and internal systems.

If you need Mailrith support for a privacy request, email support@mailrith.com and include:

  • Workspace name.
  • Subscriber email address.
  • Request type.
  • Verification status.
  • Due date.

Do not include sensitive information that is not needed for the request.

Do I Need To Have My Own Privacy Policy?

In most cases, if you collect Subscriber Personal Data, you should have your own Privacy Policy that explains what you collect, why you collect it, how you use it, who you share it with, and how people can contact you.

Mailrith's Privacy Policy explains how Mailrith handles data. It does not replace your own Privacy Policy for your business.

Talk to your attorney about what your Privacy Policy should include.

Should I Delete Subscribers Or Unsubscribe Them?

Use unsubscribe when the Subscriber no longer wants marketing email but you still need to keep a limited record, such as suppression or compliance history.

Use deletion when the Subscriber has requested deletion and you have verified that request, unless you need to keep certain data for a valid legal or business reason.

Before deleting, check whether the Subscriber's data also exists in connected providers or internal systems. Deleting or changing a Subscriber in Mailrith may not remove data from customer-connected providers outside Mailrith.

Need Help?

Reach out to the Mailrith team if you need help with anything.

Contact Us →