Consent is two things, not one
Being suppressed and not wanting marketing are different states, and the platform keeps them apart. Someone who opts out of your promotions still hears that their order shipped.
Consent, opt-outs, legal sending hours, sender registration and the data your assistant is allowed to read. All of it decided inside the platform, on the way out.
Being suppressed and not wanting marketing are different states, and the platform keeps them apart. Someone who opts out of your promotions still hears that their order shipped.
Iris has a data policy per project: personal data in the clear, redacted, or nothing at all. It is a switch you set, not a promise we make.
Legal marketing hours, mandatory opt-out wording and sender registration are resolved for the destination country, message by message.
Instasent is a processor. You are the controller: you decide what you collect, why, and on what lawful basis. What the platform does is make it hard for itself to be the reason you breach — the consent model, the opt-out flow and the audit trail are ours. The relationship with the person on the other end is yours.
Nothing on this page exempts you from your obligations. It is here to make them cheaper to meet.
Legal time windows by country, opt-out wording per market, sender registration and platform policy.
Roles, data subject rights, the processing agreement and the list of sub-processors.
Two-factor, organisation and project roles, active sessions and connected apps.
EU · Regulation
EU · Directive
Spain · Law
United Kingdom · Regulation
Per country · Law
Per country · Regulator
Meta · Contractual
GSMA · Standard
EU · Regulation
This is the map of what governs sending messages in Europe, not a claim of certification — none of these issues a badge, and the ones that do are regulators. Where a framework asks something of you as the controller, the page covering it says so.
Most of it is decided in consent. It is also the part we are proudest of.
The consent model