GDPR & DPDP compliance | Brixus365 Docs
Docs Getting Started GDPR & DPDP compliance

GDPR & DPDP compliance

Brixus365 handles opt-out enforcement, suppression, audit trails, and data deletion automatically. You are responsible for consent collection, privacy disclosures, and responding to data subject requests. This page covers both sides of the line.

This is not legal advice. The guidance below describes Brixus365’s features and common practice. Consult your legal team for advice specific to your business and jurisdictions.


What the regulations require

GDPR (EU General Data Protection Regulation) and DPDP (India’s Digital Personal Data Protection Act) both impose requirements on organisations that collect and use personal data, including email addresses used for marketing.

Key obligations for email senders:

ObligationGDPRDPDP
Lawful basis for processing (e.g. consent)YesYes
Right to withdraw consent / unsubscribeYesYes
Right to erasure (“right to be forgotten”)YesYes
Data breach notificationYesYes
Appointment of a Data Protection Officer (large processors)ConditionalConditional

Both regulations treat email addresses as personal data. If you collect and email EU or Indian residents, both frameworks apply.


What Brixus365 handles

Unsubscribe enforcement. Every Spark campaign email includes an unsubscribe link automatically. When a recipient opts out, Brixus365 immediately suppresses them from all future sends. The suppression is sticky — re-importing the address later does not re-enable sends. See Unsubscribes & suppression.

Audit trail. Every subscription preference change — unsubscribe, re-subscribe, manual toggle — is logged with a timestamp, the channel, and the source that triggered it. The log is visible under the Audit Trail tab of each recipient’s profile.

RFC 8058 one-click unsubscribe. Campaign emails include a machine-readable List-Unsubscribe header, meeting Google and Yahoo’s 2024 bulk sender requirements — and the consent withdrawal standard expected under GDPR for commercial email.

Bounce and complaint suppression. Hard-bounced and complained addresses are suppressed automatically and permanently. This prevents sending to contacts whose data has effectively become stale.

Data deletion. The Delete Recipient action in the dashboard permanently removes a contact and all associated data from your account. See Responding to erasure requests below.


What you are responsible for

Brixus365 is your data processor — it processes personal data on your behalf according to your instructions. You are the data controller — the entity legally responsible for the processing. This means:

Consent collection. You must collect and record lawful consent before adding someone to your list. Brixus365 does not validate consent on import — the legal responsibility for consent is yours. Under GDPR, pre-checked opt-in boxes are not valid consent.

Privacy policy. Your website must have a privacy policy that describes how you use personal data, including email addresses used for marketing.

Retention policy. You decide how long to retain recipient data. GDPR requires you not to keep personal data longer than necessary. Consider a periodic review and deletion of contacts who have not engaged in 24+ months.

Third-party disclosure. If you share recipient data with other services (CRMs, analytics platforms), your privacy policy must disclose this.

Data breach response. GDPR requires you to notify your data protection authority within 72 hours of discovering a breach that affects EU residents. DPDP has a similar obligation for Indian residents.


Responding to erasure requests

Under GDPR Article 17 and DPDP’s equivalent provisions, data subjects have the right to request deletion of their personal data.

To respond to an erasure request in Brixus365:

  1. Go to Spark → Recipients.
  2. Search for the recipient by name or email address.
  3. Click their name to open their profile.
  4. Click Delete Recipient in the profile actions.
  5. Confirm in the dialog — this action is permanent and cannot be undone.

The contact is removed from your Brixus365 account immediately, including their engagement history, subscription preferences, and audit log.

Suppression vs erasure. Toggling off a recipient’s subscription preference (unsubscribing them) stops future emails but retains the record. If the request is specifically about personal data erasure — not just stopping sends — use Delete Recipient. The distinction matters legally.

For transactional email, individual message records in Send History (Connect → Transactional) contain the recipient’s email address. If you receive an erasure request from someone you’ve sent transactional emails to, contact support for assistance with removing message-level records.


Data processing and DPA

Brixus365 acts as a data processor under GDPR. A Data Processing Agreement (DPA) — as required by GDPR Article 28 — is available for accounts on paid plans. Contact support or your account manager to request and execute a DPA.

Brixus365 infrastructure is hosted on AWS, which maintains certifications including ISO 27001, SOC 2 Type II, and GDPR-relevant data processing terms. AWS region selection for data storage is a platform-level configuration; contact support if you have specific data residency requirements.


What’s next

You want to…Go to
Understand how unsubscribes and suppression workUnsubscribes & suppression
Delete a recipient to respond to an erasure requestManage recipients
Understand bounce and complaint handlingBounce and complaint handling
Compliance built in

Opt-out enforcement, audit trails, and deletion — handled automatically.

Free signup. 9,000 emails a month, full compliance tooling, no card needed.