Last updated: 2026-05-07
LeadAce ships compliance defaults that try to keep B2B cold-outreach sends within bounds. This page describes what we enforce server-side, what we leave to the workspace operator, and how to reach us about a complaint or data-subject request.
Outbound send paths currently allow recipients in the United States, Canada, and Japan. Other jurisdictions are blocked at send time with HTTP 422; a recipient with no country recorded surfaces a warning but is not blocked. UK, AU, and EU support is on the v1.x roadmap and depends on per-country footer / consent rules we have not finished implementing.
| Jurisdiction | Status | Notes |
|---|---|---|
| US (CAN-SPAM) | Supported | Default footer carries legal name + physical address + unsubscribe (§4). |
| CA (CASL) | Supported | B2B conspicuous-publication operational stance (see §3). |
| JP (特定電子メール法 / 特商法) | Supported | Sender identity + opt-out are carried in the same footer block by default (§4).特商法 disclosure on /legal. |
| UK (PECR + UK GDPR) | Roadmap (v1.1) | Requires LIA documentation + Article 14 transparency. |
| AU (Spam Act) | Roadmap (v1.2+) | ABN registration constraints for non-AU senders. |
| EU / others | Not supported | Send blocked. |
Each workspace must set the following before any outbound send is allowed:
The contact email is optional but strongly recommended; it is the route surfaced on this page for inbound requests.
These fields are configured per workspace under Workspace settings.
Canadian recipients are reached only when one of the following applies:
We do not currently store a per-prospect consent basis column; the workspace operator is responsible for sourcing prospects through public B2B channels. Per-prospect consent records ship in a future release.
Every outbound message — email, web form, or social DM — has a footer appended server-side at send time; the append step cannot be skipped. The one exception is the platform channel: in-platform responses to a posting the recipient published (e.g. a crowdsourcing job) are solicited messages delivered inside the platform's own messaging under the platform's terms, so no email-law footer is appended. By default the footer is the following block, assembled in the project's configured message language (English or Japanese); matching that language to the project's audience is the operator's responsibility. A workspace may replace the footer text per project; as the sender of record, the operator is then responsible for keeping the required sender identity, postal address, and opt-out mechanism in it.
---
<Legal name>
<Physical address>
To unsubscribe, reply to this email with "unsubscribe". Cold email is link-free by default: the opt-out is a reply instruction, honored server-side — a genuine reply asking to unsubscribe suppresses further contact. When a workspace opts into the inquiry landing page, that reply line is replaced by a link to the page, which carries its own opt-out.
The RFC 8058 List-Unsubscribe / List-Unsubscribe-Post: List-Unsubscribe=One-Click headers are available as a per-project option (off by default). Gmail and
Yahoo require one-click unsubscribe headers only of bulk senders (roughly
5,000+ messages per day); LeadAce's per-mailbox warmup caps keep sending
volume far below that threshold. When enabled, the one-click endpoint
ratchets the prospect's do_not_contact flag; unsubscribe
links in previously sent mail remain valid either way.
An unsubscribe is processed immediately and ratchets the prospect's do_not_contact flag on permanently — it does not
reset on re-import or workspace edits. CAN-SPAM allows up to 10 business days; we process
within seconds. Following ICO guidance, the prospect record itself stays in place — the
flag is what suppresses future contact, and removing the record would let the same
identity slip back into a fresh import.
Your own account: use Delete account on the Account settings page. Erasure is immediate — your workspace, every project in it, all prospect / outreach / response data, Gmail authorization, and your login are removed. Any active paid subscription is cancelled at the same time (no prorated refund). MCP client tokens you previously issued remain valid for up to 30 days; revoke them by disconnecting LeadAce from each MCP client (automated MCP revocation is on the v1.1 roadmap).
A prospect's record in your workspace: email [email protected] with the prospect's email address and we will pseudonymise the record (free-text PII set to NULL, structured DNC keys retained per Article 17(3)(b) and 6(1)(f) so the prospect cannot re-enter the funnel via a future import).
Self-host operators handle prospect-record erasure on their own database directly; an automated pipeline is on the v1.1 roadmap.
LeadAce is open source. Operators running their own deployment inherit responsibility for the workspace identity fields, the sender domain's authentication (SPF / DKIM / DMARC), the mailbox the unsubscribe email is addressed to, and the legal regime applicable to their sender country and recipient list. This page does not constitute legal advice.
Compliance complaints, abuse reports, and data-subject requests: [email protected].