Legal compliance

Unsubscribed and not wanting marketingare not the same thing.

Most platforms keep a single flag and call it consent. We keep two, because someone who wants your promotions to stop still needs to hear that their order shipped.

Two attributes, two jobs.Mixing them is the classic mistake.

Channel suppression
Takes the contact out of the channel. Only critical messages get through — not marketing, not service.
Marketing consent
Governs marketing and nothing else. An active contact who said no to promotions still receives what they are waiting for.

Between the two they describe four states: accepted marketing, no preference expressed, refused marketing, and suppressed.

Three kinds of message.Only one of them stops.

Marketing
Promotions and campaigns. This is what an opt-out stops, and the only thing it stops.
Service
Order status, an appointment moved, anything the contact is waiting for. Keeps reaching active contacts.
Critical
What has to arrive: security codes and legally required notices. Reaches everyone.

Three policies, and you choose.Default compliance policy, in the platform.

Opt-in

Only contacts who said yes

An opt-out is recorded. If the contact was already opted out, it becomes a suppression.

Opt-out

Everyone except who said no

Same consequence: an opt-out, and a suppression if there already was one.

Basic

Every active contact

Unsubscribing suppresses straight away. This policy ignores marketing consent, so anything softer would leave the request with no effect.

The logic holds by design: the wider the reach, the blunter the consequence of unsubscribing.

A different default per channel.Each one has a different regulator behind it.

SMS · Basic
The industry's legacy model, and the widest reach.
RCS · Basic
Shares consent with SMS: it is the same conversation on a better screen.
WhatsApp · Opt-in
Meta requires opt-in for everyone. Contractual rather than legal, and just as binding.

Set per project and per channel, and inherited: a channel can override the project, and a campaign or a flow can override the channel message by message.

How consent gets in.Rarely from a single place.

Opt-in on reply

Any inbound reply can mark the contact as opted in on that channel. Optional, precisely because not every framework accepts it.

Bulk import

Opt-ins and opt-outs by CSV or data source, with a downloadable template, and blocklists as a source of their own.

Endpoints of their own

Dedicated data source endpoints to unsubscribe a contact, mark a marketing opt-in and mark a marketing opt-out.

Consent per channel

Each channel keeps its own, including multi-level consent for double opt-in or a record of complaints.

Contact auto-creation

On inbound and on outbound, each switchable on its own. Turn the outbound one off and messages to unknown numbers are rejected.

Leaving has to be easy.Otherwise it is not consent, it is inertia.

Keywords you configure

Opt-out and opt-in keywords per channel, matched case-insensitively against the whole message, with wildcards.

Confirmation in their language

The confirmation reply is resolved by the contact's language. It can also be turned off, to process opt-outs in silence.

Across channels, or not

An opt-out can apply only to the channel it arrived on, or to every marketing channel in the project. You decide which.

Coming back

Reactivation through START or any other flow. Leaving is not a one-way door.

Opt-out by link

For markets with no inbound SMS, with the wording each country requires and a fallback for the rest of the world.

Your domain, not ours

Opt-out links go through your own tracking domain instead of a generic one.

Redundant wording, flagged

If the text beside the unsubscribe link repeats the instruction, the editor says so. It wastes characters and confuses the reader.

And then it has to go out right.Consent that is not enforced on send is a checkbox.

Consent branch

A flow forks on whether the contact meets the channel's policy. Blocked contacts take another path instead of vanishing in silence.

Legal time windows

Skips the hours when marketing is not legal in the contact's country, and only in the countries where that rule exists.

Their hour, not yours

Sending in the recipient's local time, by country.

Unsubscribed excluded

Taken out of the campaign before it goes, with the count in plain sight.

A/B on fewest opt-outs

You can make 'lost the fewest contacts' the winning criterion, not only who got the most clicks.

And a record that proves it.

Every opt-out, opt-in, suppression and reactivation is logged per contact and per project, typed, with its reason and its origin — a campaign, a person, or the API. That log is what you produce when someone says they never gave consent.

Next

The other half of the question.

You know who you can write to. The next thing buyers ask is what your assistant is allowed to read.

What Iris sees