Rainmaker.
Trust · Compliance

Cold email compliance, written into the machine.

CAN-SPAM, GDPR, opt-out, privacy signals: not a policy page, a list of the controls that run on every send and what each one does.

What each rule means here

Most AI outbound tools ship an empty compliance page or none at all. This one names the mechanisms. If a control below is not enforced in the product, it does not belong on this page.

CAN-SPAM conduct
Truthful subject lines, clear sender identification, a physical postal address, and a working unsubscribe link plus RFC 8058 List-Unsubscribe headers on every email. A send missing any of them is blocked by the gatekeeper, not patched.
GDPR legitimate interest
Outreach only to business addresses, scored against a buyer persona for relevance to the recipient's professional role, with an opt-out in every message. European destinations get the controller and professional-data-source disclosures in the footer.
Notice at collection
The privacy notice and the source of the recipient's professional data are linked from the email itself for European recipients, so the notice travels with the message.
Opt-out mechanism
One-click unsubscribe in every email. The address goes into a permanent opt-out registry shared across every Rainmaker account, so no other workspace can contact it.
Cross-account suppression
Suppression is enforced at the platform level, on top of per-workspace suppression lists. A person who opted out of one sender has opted out of all of them.
Global Privacy Control
Privacy requests carrying the Sec-GPC signal are treated as opt-outs regardless of the request body.
Rights requests
Access, deletion and objection requests are confirmed by double opt-in to the mailbox concerned, so nobody can act on an address they do not control. Requests go to privacy@pyratzlabs.com or through the product.
Data Processing Agreement
Available inside the product for customers, alongside the operational detail: tenancy isolation, retention and scrub routines, vendor wiring.
Factual accuracy
Every factual claim in an email must link to a verifiable source or the draft is blocked before a human sees it. An email that cannot be deceptive about the recipient is an email that cannot be a CAN-SPAM complaint about deception.

Deliverability, the other half of not being spam, is on the anti-spam page. The commitments in one place are on the trust page.

Compliance questions

Is cold email legal? Here is the actual answer.

Written for the buyer, the lawyer, and the answer engine: the rule, then what the product does about it.

Is cold B2B email legal in the US?

Yes. Under CAN-SPAM, unsolicited commercial email to a business address is legal when the headers and subject line are truthful, the message identifies the sender and includes a physical postal address, and it offers a working unsubscribe that is honored promptly. Rainmaker's gatekeeper adds the identification, the address, and the unsubscribe mechanics to every email, and blocks any send where they are missing.

Is cold B2B email legal in the EU under GDPR?

Cold B2B email to a business address is legal under GDPR with a legitimate interest basis, when the message is relevant to the recipient's professional role, when the recipient is told where their data came from, and when the email includes a working opt-out. For European destinations Rainmaker adds the controller and professional-data-source disclosures to the footer and enforces the opt-out on every message.

What is a notice at collection?

A notice at collection tells a person, at the point their data is used, who is processing it, why, and how to object. Rainmaker includes a link to the privacy notice and the professional data source in outreach to European recipients, so the notice travels with the email rather than living only on a website.

How does opt-out work across Rainmaker accounts?

When a recipient opts out of outreach from any Rainmaker user, their address is added to a suppression registry shared across every account on the platform, not only the workspace that sent the email. Rights requests are confirmed by double opt-in so that nobody can suppress or delete an address they do not control.

Does Rainmaker honor Global Privacy Control?

Yes. A privacy request that arrives with the Sec-GPC signal is treated as an opt-out regardless of what the form says, and the address is suppressed the same way an unsubscribe is.

Can I get a Data Processing Agreement?

Yes. The Data Processing Agreement and the operational detail behind it, tenancy isolation, retention and scrub routines, live inside the product for customers. The public privacy notice describes what is collected, why, the legal basis, retention, and your rights.