Anti-spam Policy
In this document
Introduction
SorviAI sends business email: invoices, quotes, purchase orders, statements, notifications and replies in a shared team mailbox. It is not a bulk marketing tool, and it must not be used as one.
You may email people you have a genuine business relationship with, or who asked to hear from you. You may not upload a purchased list, scrape addresses, disguise who you are, or keep emailing someone who told you to stop.
We act on the bounce and complaint reports that reach us, and on abuse reports sent to us directly. The section on enforcement explains what happens when an account needs to change what it is doing.
About this policy
This policy explains the rules for sending email through SorviAI. It applies to every customer, every user in a workspace, and every message sent using our sending infrastructure or a mailbox connected to our platform.
It forms part of our Terms of Service. Breaking it is a breach of your agreement with [REGISTERED COMPANY NAME] and can lead to your sending being suspended, as set out under enforcement.
What the email is for
The platform sends email in three ways, and all three are relationship-based rather than promotional.
| Type | What it is | Who it goes to |
|---|---|---|
| Business documents | Invoices, quotes, sales orders, purchase orders, credit notes, statements, payment receipts and delivery notes, sent from a record in your workspace | The named customer or supplier on that document |
| Team mailbox | Replies and conversations handled in TeamEmail through a mailbox your organisation connected | People already corresponding with you |
| Platform notifications | Workspace invitations, email verification, security alerts and system notices sent by us | Your users, and people you invite |
SorviAI is not a bulk email or marketing platform. It has no campaign builder, no list management and no mass-send feature, and that is deliberate. Using document sending or a connected mailbox to push out marketing to a large list is a misuse of the product, breaches this policy, and will get your sending suspended. If you need to run marketing campaigns, use a dedicated email marketing service built for it.
The rules, in short
- Have a reason to be emailing them. Either they asked, or you have a real business relationship, as defined under permission.
- Be honest about who you are. Real sender name, real address, real reply-to, from a domain you control.
- Make the subject line match the message. No bait, no fake replies, no fake urgency.
- Stop when asked. Promptly, permanently, and without making the person ask twice.
- Keep your own house in order. Keep addresses current, remove bounces, and do not email people whose details you obtained from someone else.
Permission: when you may email someone
You may only send to an address where at least one of these is true.
- They are your customer or supplier. You are sending a document arising from an actual transaction: an invoice for work done, a quote they requested, a purchase order you are placing.
- They asked to hear from you. They signed up, enquired, or otherwise gave you their address for this purpose.
- They wrote to you first. You are replying to a conversation they started.
- You have an existing business relationship and the message relates to it.
Records
You must be able to show where an address came from and why you were entitled to use it. If we receive a complaint we may ask, and “it was in our system” is not an answer. Keep enough of a record to demonstrate consent or the relationship it rests on.
Prohibited practices
There is no “sometimes” column on this table, which is the point of it.
| Practice | Allowed |
|---|---|
| Sending to purchased, rented, traded or scraped address lists | Never |
| Harvesting addresses from websites, directories or social media | Never |
| Generating addresses by guessing or combination, such as trying every common first name at a domain | Never |
| Falsifying sender names, From addresses, Reply-To addresses or message headers | Never |
| Using a domain or sender address you do not control or have permission to use | Never |
| Misleading subject lines, including fake “Re:” and “Fwd:” prefixes | Never |
| Continuing to email someone after they opted out or asked you to stop | Never |
| Hiding, obscuring or breaking an unsubscribe mechanism | Never |
| Sending mass marketing through document email or a connected mailbox | Never |
| Splitting a large send across accounts, workspaces or domains to avoid limits or detection | Never |
| Sending phishing, malware, or messages impersonating another business | Never |
| Repeatedly emailing addresses that hard bounce | Never |
Sender identity and domain authentication
Every message must clearly identify who sent it.
Authenticated domains
We support authenticating your whole sending domain by adding DNS records we generate for you. This publishes SPF and DKIM so that receiving mail servers can confirm the message genuinely came from you, and we check those records before the domain is treated as authenticated.
We strongly recommend authenticating your domain. Authenticated mail is far more likely to reach the inbox, and it protects your domain from being spoofed by someone else. We also recommend publishing a DMARC record.
Required in every message
- A sender name and address that accurately identify your organisation.
- A working reply-to address that a human monitors.
- Your business identity, and a valid postal address where the message is promotional in nature.
- Accurate headers throughout. Do not alter them to disguise the message’s origin or path.
Opting out
Transactional documents such as an invoice or a purchase order do not need an unsubscribe link, because the recipient needs them and cannot reasonably opt out of being invoiced.
Anything promotional is different. If a message markets your products or services, it must include a clear and working way to opt out, and you must honour it.
- The opt-out must be obvious and easy to use, needing no login, no account and no explanation from the recipient.
- You must act on it within [OPT-OUT WINDOW] and permanently.
- An opt-out request is valid however it arrives, including a plain reply saying “stop” or a phone call.
- You must not charge a fee, require a reason, or make someone opt out more than once.
- You must keep a suppression record so the address is not re-added later by an import.
Content rules
Whatever the legal position, you must not use SorviAI to send:
- Anything unlawful, defamatory, harassing, discriminatory or obscene.
- Malware, ransomware, or attachments and links intended to compromise a recipient’s device.
- Phishing, or anything designed to trick a recipient into revealing credentials, card details or bank details.
- Messages impersonating another business, a bank, a government body or a tax authority.
- Chain letters, pyramid schemes, “get rich quick” offers or fraudulent investment promotions.
- Content that infringes someone else’s copyright or trademark.
- Anything requiring a licence you do not hold, such as regulated financial promotions.
Connected mailboxes and TeamEmail
When your organisation connects a Microsoft 365 mailbox to TeamEmail, messages are sent through your own mail provider rather than our sending infrastructure. This policy still applies to them.
- Your mail provider’s own acceptable use terms apply in addition to ours, and they may act independently of us.
- Abuse from a connected mailbox risks your own domain’s reputation, which we cannot repair for you.
- We may suspend the connection if we receive credible abuse reports about mail sent through it.
- A shared mailbox does not dilute responsibility. Your organisation is accountable for every message any of your users sends from it.
How we monitor
We do not read your business correspondence. We do keep a record of what was sent, and we act on the abuse signals that reach us, because deliverability is shared across all customers.
- Send logs. We keep a record of messages sent from your workspace: the sender name and address, the recipients including any cc and bcc, the subject, the message body, the time, the delivery outcome and any error returned. Where a message is opened or a link in it is clicked, that is recorded too. The record is used for delivery troubleshooting, audit and abuse investigation. Our Privacy Policy covers how long we keep it.
- Bounce and delivery outcomes. Each message carries the outcome our sending provider returned, including a hard bounce.
- Abuse reports. We act on complaints from recipients, mailbox providers and blocklist operators.
- Rate limiting. We apply limits to domain verification to contain abuse and protect the platform.
Enforcement
Our aim is to fix problems, not to catch people out. Most breaches are a customer misunderstanding what the product is for, and a conversation resolves them.
- We get in touch. We tell you what we are seeing and what needs to change, and give you a reasonable chance to fix it.
- We may throttle or pause sending while it is investigated, so the problem does not get worse.
- We may suspend sending if it is not resolved, while leaving the rest of your workspace working normally.
- We may terminate for serious or repeated breaches, in line with the Terms of Service.
For severe abuse, specifically phishing, malware or a large unsolicited send in progress, we will suspend sending immediately and contact you afterwards. Refunds in these circumstances are covered by our Refund Policy, which excludes refunds where an account is suspended for breach of terms.
Your legal duties
This policy sets our rules. The law sets its own, and you are responsible for meeting it in every country you send to.
| Where | What applies |
|---|---|
| United Kingdom | The Privacy and Electronic Communications Regulations 2003 and UK GDPR. Marketing email to individuals generally needs consent, with a narrow exception for existing customers offering similar products who were given a chance to object. |
| European Union | The ePrivacy Directive as implemented locally, and the GDPR. |
| United States | The CAN-SPAM Act: accurate headers, honest subject lines, a valid postal address, a working opt-out, honoured within 10 business days. |
| Canada | CASL, which requires consent before sending and is stricter than most. |
| Elsewhere | Local marketing and data protection law. Check before sending. |
Where you use SorviAI to send to your own contacts, you are the data controller for those contacts. Our respective roles are set out in our Privacy Policy.
Reporting spam
If you received unwanted email sent through SorviAI, tell us at [ABUSE CONTACT EMAIL]. Include the full message with headers if you can, since headers are what let us identify the sending account.
We investigate every report. We aim to acknowledge within [ACKNOWLEDGEMENT TIME] working days and act sooner where the report involves phishing or malware.
Because we are usually the processor rather than the sender, we may pass your request to the customer who sent the message so they can act on it, and we will tell you when we have. If you asked them to stop and they did not, tell us: that is a breach of this policy and we will treat it as one.
Changes to this policy
We may update this policy as sending standards and the law change. The version and effective date at the top tell you which one you are reading, and previous versions remain available at [ARCHIVE URL].
We will give notice of material changes to workspace owners by email at least [POLICY CHANGE NOTICE PERIOD] in advance, except where an immediate change is needed to address abuse or meet a legal requirement.
How to contact us
For abuse reports, or questions about whether a planned send is acceptable, use the details below. If you are not sure whether something is allowed, ask first. It is a great deal easier than unwinding a suspension.