Security, privacy, GDPR, and compliance controls
Understand controller responsibilities, recipient rights, tracking policy, permission records, retention, exports, deletion, and security boundaries.
Elite provides technical controls that support a compliance program; it does not decide which law applies or choose your lawful basis. The customer sending/tracking email is generally responsible for deciding purpose, audience, notice, and lawful basis. Obtain counsel for your use case.
Compliance enforcement modes
Open Compliance controls:
- Standard: the customer determines lawful basis; tracking is not blocked for lack of a per-recipient register entry.
- Strict consent: no pixel or tracked links are created unless each recipient has an active permission record.
- Disabled: blocks all new trackers for the account/team scope.
Choose a default lawful basis—consent, legitimate interests, contract, or legal obligation—only after determining it is appropriate.
Recipient permission register
Record recipient email, basis, status (granted or withdrawn/objected), and an evidence reference such as a CRM/form ID. Store a reference, not sensitive evidence itself. Withdrawing permission or suppressing a contact should stop new outreach according to policy.
Retention
Set event retention from 1 to 2,555 days and network/IP retention from 0 to 365 days where authorized. Shorter network retention can remove IP/geo evidence while keeping a higher-level event. Choose the shortest period that meets a documented need.
Recipient rights and opt-out
The privacy-request page supports verified requests. Contacts can also be suppressed/unsubscribed. Honor access, deletion, objection, and opt-out requests according to applicable law and your controller obligations. Deletion can be limited by legitimate security/legal retention needs; communicate the result accurately.
Account data
Privacy settings provide paths for export and permanent deletion. Reauthentication and subscription checks reduce accidental deletion. Team administrators may have separate export/retention duties when a member leaves.
Security model
Opaque public tokens avoid placing recipient addresses in tracker URLs. OAuth scopes constrain inbox/MCP connections. Role scope is enforced server-side. Sensitive fields and links should still be treated carefully: anyone with an unprotected forwarded share/signing link may be able to access it.
Enable MFA where available, revoke lost devices and unused OAuth/MCP clients, use a unique password, verify sender aliases, and review team audit history. Report suspected abuse through the support/privacy channel.
Policies and subprocessors
Review the current Privacy Policy, Terms, DPA, Security page, and Subprocessor list for contractual and processing details. These documents, not this tutorial, govern the service.
Plans, subscriptions, payments, and invoices
Manage your plan, checkout, billing portal, payment method, receipts, team seats, renewal, cancellation, and payment problems.
Tracking not working or results look wrong
Diagnose missing trackers, no opens, delayed events, grey indicators, unexpected locations, and group-recipient ambiguity.