Trust and compliance
Outbound only works if it's lawful, verifiable and respectful of the inbox. Here's exactly how we run it, in writing.
Conduit processes business contact data under legitimate interest (Art. 6(1)(f)) for B2B prospecting, with a documented Legitimate Interest Assessment available on request. Every record carries source, timestamp and processing-basis metadata.
Data subjects can request access, rectification, erasure or restriction at any time. Requests are honoured within 30 days. Erasure propagates to suppression lists within 72 hours so contacts are never re-added.
EU and UK data of EU residents is processed with SCCs in place with every sub-processor. A current sub-processor list is maintained in our DPA annex.
A DPA is executed with every client before the first prospect is touched. No campaigns run without it. It covers processing scope, confidentiality, sub-processors, breach notification (within 72 hours), and deletion or return on termination.
Client CRM data accessed via HubSpot, Salesforce or Pipedrive integrations is used solely to execute the client's campaigns and is never pooled, resold or used to train shared models.
Every email we send carries accurate header information, a non-deceptive subject line, the client's valid physical postal address, and a clear, functioning opt-out mechanism.
Opt-outs are honoured within 24 hours (the statute allows 10 business days) and are synced back to the client's CRM so no other channel re-touches the contact.
One click, no login, no confirmation page. The opt-out link in every email acts instantly. Verbal and reply-based opt-outs ('remove me', 'unsubscribe', 'not interested, stop') are treated identically and processed within one business day.
Suppression is permanent and global across all Conduit client campaigns: an opted-out contact is never emailed by any Conduit client again.
All sending domains are authenticated with SPF, DKIM and DMARC (enforced at p=quarantine minimum) before a single email is sent. Custom tracking domains are used so client primary domains are never exposed to deliverability risk.
Sending identities are real, named people with verifiable LinkedIn profiles. Never spoofed, never alias farms. Every mailbox passes Google Postmaster and Microsoft SNDS monitoring with published thresholds.
Our bounce SLA, under 3% or credits refunded, is enforceable because verification is 3-layer: SMTP handshake, pattern validation, and human QA on every list before it enters a sequence.
Privacy, DPA and data-subject requests: reach the team through your client channel or the contact listed in your DPA. This page is informational and not legal advice.