Inovamail Legal
Anti-Spam & Outreach Policy
Inovamail has zero tolerance for spam. Before you send any commercial message through the Service — especially with the Outreach Tools — you must have the consent or other lawful basis required by the anti-spam laws that apply to you and your recipient (CASL in Canada, CAN-SPAM in the U.S., GDPR/ePrivacy in the EU/UK, and others), identify yourself accurately, and honour every unsubscribe request. You alone are responsible for your messages and your lists. This summary is for convenience and does not replace the full text below.
1. Our Commitment & Scope
1.1 Inovamail is a privacy-first email service, and we maintain zero tolerance for spam. Unsolicited bulk or commercial electronic messages damage recipients, the deliverability of every legitimate Inovamail user, and the integrity of the Service. We enforce this Anti-Spam & Outreach Policy (this "Policy") strictly.
1.2 This Policy is part of, and incorporated by reference into, the Inovamail Terms of Service (the "Terms") and supplements the Acceptable Use Policy. Capitalized terms not defined here have the meanings given in the Terms. This Policy applies to all messages sent through or by means of the Service — via the web application, IMAP/SMTP, aliases, custom domains, automated workflows, integrations, and APIs — and applies with particular force to the email finder / sender features (the "Outreach Tools").
1.3 This Policy states minimum rules. It is not an exhaustive statement of the law, and complying with this Policy does not guarantee that you comply with the law. You are solely responsible for knowing and complying with every law that applies to your messages and your recipients. Inovamail does not provide legal advice.
2. Definitions
2.1 In this Policy:
- "Commercial Electronic Message" or "CEM" means any electronic message that, considering its content, links, or contact information, has as a purpose (or one of its purposes) to encourage participation in a commercial activity — including offers to purchase, sell, or lease products or services, promotion of a person or business, and advertising or marketing of any kind. A message can be a CEM even if it is sent one-to-one, is personalized, or promotes something only incidentally.
- "Express Consent" means a recipient's affirmative, opt-in agreement to receive CEMs from you, given in response to a clear request that disclosed the purpose of the request, your identity, and the recipient's ability to withdraw consent. Pre-checked boxes, silence, or failure to opt out do not constitute express consent.
- "Implied Consent" means consent that a specific anti-spam law deems to exist in defined circumstances without an opt-in — for example, under CASL, an existing business or non-business relationship within the statutory look-back period, or the conspicuous publication or direct disclosure of an address in the circumstances described in Section 3.2. Implied consent is narrow, time-limited, and must be assessed per recipient.
- "Recipient" means each person or electronic address to which you send, or direct the Service to send, a message.
- "Unsubscribe" or "opt-out" means a recipient's indication, by any reasonable means (including an unsubscribe link, a reply, or any other request), that they no longer wish to receive messages from you.
- "Spam" means, for the purposes of this Policy, any message sent in violation of this Policy or of an applicable anti-spam law, and any unsolicited bulk message, whether or not commercial.
3. Canada — CASL Requirements
3.1 Canada's Anti-Spam Legislation ("CASL") applies, among other cases, whenever a computer system located in Canada is used to send or access a CEM. Because Inovamail's systems and many recipients are in Canada, you should assume CASL applies to your commercial sending through the Service. If you send CEMs through the Service, you must:
(a) Have consent before sending
Obtain Express Consent, or establish a valid basis for Implied Consent under CASL, before sending a CEM to an address. Under CASL, the burden of proving consent rests on the sender — you. You must keep records sufficient to prove, for each Recipient, when and how consent was obtained or on what specific facts you rely for Implied Consent.
(b) Identify yourself clearly
Each CEM must clearly and prominently identify you (and, if you send on behalf of another person or organization, that person or organization), and include your valid mailing address and at least one of a telephone number, email address, or web address at which you can be contacted, with that contact information remaining valid for at least 60 days after the message is sent.
(c) Include and honour a working unsubscribe
Each CEM must contain a clearly and prominently set out unsubscribe mechanism that can be readily performed at no cost to the Recipient (for example, a working link or reply address), that remains functional for at least 60 days after the message is sent. You must give effect to every unsubscribe request without delay and in any event within the statutory period (no later than 10 business days), and you must not send further CEMs to that Recipient thereafter.
(d) Not deceive
You must not send messages with false or misleading sender information, header information, subject lines, or locators (such as URLs). False or misleading representations in electronic messages may also violate the Competition Act.
3.2 Implied consent is narrow. If you rely on CASL's "conspicuous publication" basis (an address published openly, such as on a company website), that basis exists only if the publication is not accompanied by a statement that the person does not wish to receive unsolicited CEMs and your message is relevant to the person's business, role, functions, or duties in a business or official capacity. Generic marketing blasts do not qualify. Other implied-consent bases (such as existing business relationships) are time-limited by statute and must be verified per Recipient.
3.3 Address harvesting is prohibited. You must not collect electronic addresses through automated means (address harvesting), and you must not use lists that were compiled by harvesting, purchased, rented, or generated by guessing or dictionary techniques. Section 82 of CASL amended Canada's federal privacy law (PIPEDA) so that its protections apply, without the usual exemptions, to the collection of electronic addresses by automated means and to the use of addresses so collected, and to personal information collected through unauthorized access to computer systems. Harvesting and use of harvested lists are also independent violations of this Policy regardless of jurisdiction — see Section 7.
CASL penalties are severe — and they are yours. CASL provides for administrative monetary penalties of up to CAD $1,000,000 per violation for individuals and up to CAD $10,000,000 per violation for organizations, and officers and directors can be personally liable. All penalties, investigations, undertakings, and claims arising from your messages are your responsibility alone, not Inovamail's. See Section 9 (Your Indemnity).
4. United States — CAN-SPAM Requirements
4.1 If you send commercial email to Recipients in the United States (or your sending is otherwise subject to U.S. law), you must comply with the CAN-SPAM Act and its regulations, including the following. You must:
- Not use false or misleading header information — your "From", "To", "Reply-To", originating domain, and routing information must accurately identify you as the person or business that initiated the message;
- Not use deceptive subject lines — the subject line must accurately reflect the content of the message;
- Identify the message as an advertisement where applicable — commercial messages must disclose clearly and conspicuously that they are an advertisement or solicitation, unless the recipient has given prior affirmative consent;
- Include a valid physical postal address — your current street address, a registered post office box, or a private mailbox registered under applicable postal regulations;
- Provide a clear opt-out — a clear and conspicuous explanation of how to stop receiving email from you, with a mechanism that can process opt-out requests for at least 30 days after the message is sent, that requires no more of the Recipient than sending a reply or visiting a single web page, and no fee or provision of personal information beyond an email address; and
- Honour opt-outs within 10 business days — and thereafter not send further commercial email to, or sell or transfer, the opted-out address (other than to a party engaged to help you comply).
4.2 You cannot outsource responsibility. Under CAN-SPAM, both the business whose product or service is promoted and the party that actually sends the message can be held legally responsible. You remain responsible for compliance even if a third party (or an automation or integration) sends messages on your behalf, and each separate non-compliant email can attract a separate civil penalty. Deceptive commercial email is additionally subject to laws against unfair or deceptive practices.
5. EU/UK & Other Regions
5.1 EU and UK. If you send electronic marketing to Recipients in the European Economic Area or the United Kingdom, the ePrivacy rules (implemented nationally, e.g., PECR in the UK) generally require the Recipient's prior consent to email marketing, subject to a narrow "soft opt-in" for your own existing customers in respect of your similar products or services — and only where the Recipient was given a simple, free way to refuse at the time their details were collected and in every subsequent message. In addition, the GDPR / UK GDPR require a lawful basis for processing each Recipient's personal data (including their email address), transparency about your processing, and honouring the Recipient's absolute right to object to direct marketing. Rules for business-to-business messages vary by country; you must verify the rules of each Recipient's country before sending.
5.2 Everywhere else. Many other jurisdictions (including Australia, and various U.S. states and Canadian provinces through privacy and consumer-protection statutes) impose their own consent, identification, content, or opt-out requirements on electronic marketing. You must identify and comply with the marketing, anti-spam, privacy, and consumer-protection laws of every jurisdiction connected to your sending — where you are, where you send from, and where each Recipient is. Where the laws of more than one jurisdiction apply to a message, you must satisfy all of them.
6. Using the Outreach Tools Correctly
6.1 The Outreach Tools discover publicly available email addresses from the public web at a rate-limited pace and let you send messages individually, one by one. They are designed for targeted, lawful, professional outreach — not for mass mailing. When using the Outreach Tools you must:
- Send individually. Compose and send messages one at a time to individually considered Recipients. Do not use the Outreach Tools, automations, integrations, scripts, or multiple accounts to simulate or assemble bulk blasts, sequences of identical messages, or mass campaigns;
- Respect rate limits. Sending and discovery rate limits are a compliance control, not an inconvenience. Do not attempt to circumvent, spread across accounts, or otherwise defeat them;
- Verify a lawful basis for every address. Before contacting any address, confirm you have the consent or other lawful basis required by every applicable law (Sections 3–5) for that specific Recipient, and keep evidence of it;
- Do not contact where the context indicates no consent. If an address was published with a no-solicitation statement, appears in a context unrelated to your message (so that CASL's conspicuous-publication basis or an equivalent does not apply), or otherwise gives you no reasonable basis to believe you may lawfully contact it — do not contact it;
- Identify yourself accurately. Use your real identity, an address/domain you are authorized to use, truthful subject lines, the sender-identification details required by applicable law (including a valid physical mailing address where required), and a working reply or opt-out path in every message;
- Keep and honour suppression lists. Maintain a suppression (opt-out) list of every Recipient who has unsubscribed, objected, or asked you to stop — by any means, including a simple reply — and never message a suppressed address again through the Service or otherwise, except as applicable law permits (e.g., a one-time confirmation of the opt-out where lawful).
Discovery is not permission. The fact that the Outreach Tools return an address means only that the address appeared on the public web. It does not mean the address is accurate, current, deliverable, or lawful for you to contact, and Inovamail makes no representation or warranty that it is. You are the sole sender and sole data controller for every address you discover, upload, or contact, and for every message you send. Verifying the lawfulness of each contact is entirely your responsibility.
7. Prohibited Practices
7.1 The following are strictly prohibited on the Service, in any jurisdiction, regardless of whether they are unlawful where you are:
- sending unsolicited bulk email or unsolicited commercial email of any kind;
- harvesting, scraping, or compiling email addresses by automated means for bulk or unsolicited messaging, or using the Outreach Tools to build mailing lists for such messaging;
- buying, renting, borrowing, or otherwise acquiring third-party address lists, or using purchased, rented, co-registered, appended, or scraped lists, to send messages through the Service;
- generating addresses by dictionary attacks, permutation, or guessing;
- attempting to detect, evade, or "clean" against spamtraps, or otherwise manipulating deliverability signals to disguise non-consensual sending;
- operating or relaying through open relays, open proxies, botnets, or compromised systems, or routing mail to conceal its true origin;
- sending messages with false, misleading, or deceptive sender information, headers, subject lines, or content, or impersonating any person or brand;
- continuing to message any Recipient after they have opted out or objected;
- using the Service to send, relay, or manage mail through or from another provider in order to evade that provider's anti-spam, volume, or reputation controls (or using another provider to evade ours); and
- assisting, enabling, or profiting from any of the above by any person.
7.2 A practice may violate this Policy even if no individual message violates a statute. This Policy is deliberately stricter than the strict letter of some anti-spam laws; on the Service, this Policy controls.
8. Monitoring & Enforcement
8.1 Inovamail cannot read end-to-end encrypted message content, and does not undertake any obligation to monitor messages. However, we may monitor non-content signals — including sending volumes and velocity, discovery-query patterns, bounce rates, complaint and abuse-report rates, blocklist status, and recipient-domain feedback — to protect the Service, our users, and recipients.
8.2 If we believe, in our sole discretion acting in good faith, that your sending violates this Policy or threatens the Service's deliverability or reputation, we may, with or without notice: throttle or rate-limit your sending or discovery; disable the Outreach Tools for your Account or Organization; quarantine or refuse to transmit messages; suspend or terminate your Account or Organization under the Terms of Service and Acceptable Use Policy; and preserve evidence of the activity.
8.3 We may require you to produce proof of consent or of another lawful basis for any Recipient or list within a reasonable time upon request. Failure to produce satisfactory proof is itself a violation of this Policy and grounds for suspension or termination.
8.4 We may report violators, and share relevant account and traffic information as permitted by law and our Privacy Policy, to law enforcement, regulators (including the CRTC, the Competition Bureau, the Office of the Privacy Commissioner of Canada, and the U.S. FTC), receiving mail operators, and recognized anti-abuse organizations and blocklist operators.
8.5 To the maximum extent permitted by applicable law, Inovamail has no liability for enforcement actions taken in good faith under this Section, including lost messages, lost business, or suspension of service, and no fees are refunded for periods of suspension or following termination for breach, except where required by law or the Refund Policy.
9. Your Indemnity
You indemnify Inovamail for your sending. To the maximum extent permitted by applicable law, you will defend, indemnify, and hold harmless Inovamail, [LEGAL ENTITY NAME], and their officers, directors, employees, and agents from and against any and all claims, complaints, investigations, enforcement proceedings, administrative monetary penalties, fines, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or related to: (a) messages you send or cause to be sent through the Service; (b) addresses or lists you discover, upload, import, use, or contact (including through the Outreach Tools); (c) your violation of this Policy or of any anti-spam, privacy, data-protection, marketing, or consumer-protection law, including CASL, CAN-SPAM, PIPEDA, the GDPR/UK GDPR, and ePrivacy rules; or (d) any recipient, regulator, or third-party complaint concerning your sending. This indemnity is in addition to, and does not limit, your indemnification obligations under the Terms of Service, and survives termination of your Account.
10. Reporting Spam & Complaints; Changes
10.1 Report spam. If you receive spam sent through Inovamail, or believe an Inovamail user is violating this Policy, report it to [ABUSE EMAIL] with the full message headers and body where possible. We review reports and take the actions described in Section 8 where warranted. We cannot guarantee an individual response to every report, and we do not disclose the outcome of enforcement against other accounts.
10.2 Complaints about our own messages. Inovamail's own service and marketing communications comply with applicable law; every Inovamail marketing message includes a working unsubscribe. To opt out or complain, use the unsubscribe link or contact [SUPPORT EMAIL].
10.3 Changes to this Policy. We may update this Policy from time to time, including to reflect changes in law, guidance from regulators, or new abuse patterns. The "Last updated" date above reflects the current version, and material changes will be notified as described in the Terms of Service. Continued sending through the Service after a change takes effect constitutes acceptance of the updated Policy.
10.4 Questions about this Policy may be sent to [LEGAL EMAIL].