Legal compliance

Compliance is not a document you attach.It is the tool that sends.

Consent, opt-outs, legal sending hours, sender registration and the data your assistant is allowed to read. All of it decided inside the platform, on the way out.

Where it has to work.Three things we do not leave to whoever writes the campaign.

01

Consent is two things, not one

Being suppressed and not wanting marketing are different states, and the platform keeps them apart. Someone who opts out of your promotions still hears that their order shipped.

02

Your assistant sees what you decide

Iris has a data policy per project: personal data in the clear, redacted, or nothing at all. It is a switch you set, not a promise we make.

03

The rules change at the border

Legal marketing hours, mandatory opt-out wording and sender registration are resolved for the destination country, message by message.

What is ours, and what stays yours.No compliance page should blur this.

Instasent is a processor. You are the controller: you decide what you collect, why, and on what lawful basis. What the platform does is make it hard for itself to be the reason you breach — the consent model, the opt-out flow and the audit trail are ours. The relationship with the person on the other end is yours.

Nothing on this page exempts you from your obligations. It is here to make them cheaper to meet.

The rest of the section.In the order the questions arrive.

Rules for sending

Soon

Legal time windows by country, opt-out wording per market, sender registration and platform policy.

GDPR

Soon

Roles, data subject rights, the processing agreement and the list of sub-processors.

Account security

Soon

Two-factor, organisation and project roles, active sessions and connected apps.

It is not only the GDPR.Which is exactly why this section is not called that.

Privacy and data

GDPR

EU · Regulation

The base framework for personal data: roles, lawful basis and the rights of the person behind the record.
ePrivacy

EU · Directive

The one that actually governs direct marketing and electronic communications. That is not the GDPR's job.
LSSI-CE

Spain · Law

Commercial communications in Spain. It applies to us by registered office and by customer base.
UK GDPR and PECR

United Kingdom · Regulation

The United Kingdom went its own way. It applies the moment a recipient is there.

Channel regulation

Legal sending hours

Per country · Law

Marketing is not legal at every hour, and the hours change with the border. The platform skips them where the rule exists.
Sender registration

Per country · Regulator

The CNMC in Spain and its equivalent elsewhere. Regulatory, and nothing to do with privacy.

Platform rules

WhatsApp Business Policy

Meta · Contractual

Meta's rules are contractual rather than law, and just as binding. Opt-in is not optional there.
RCS and the GSMA

GSMA · Standard

A verified agent answers to the standard, not only to the operator carrying it.

Emerging

EU AI Act

EU · Regulation

Transparency about the use of AI. The per-project data policy existed before it was asked for.

This is the map of what governs sending messages in Europe, not a claim of certification — none of these issues a badge, and the ones that do are regulators. Where a framework asks something of you as the controller, the page covering it says so.

Where to start

Read the part that worries you.

Most of it is decided in consent. It is also the part we are proudest of.

The consent model