Trust and safety

When the Desk is uncertain, it holds the record back.

This page explains what the audit does with restrictions, unclear evidence, masking, human review and deletion. It is written so you can check each claim against what you see in the Desk.

Explicit restrictions are locked

An opt-out, a complaint, or a match against a suppression list you declare is restrictive evidence. It applies to the exact contact point and channel it was recorded for. Nothing in the Desk clears it: not a later purchase, not a newer enquiry, not a button. If a documented review ever adds new evidence, the record shows "restriction removed on evidence" with the reference, and the original event stays in the history. It never shows "permission verified".

A bounce is not an objection

A hard bounce or an invalid address means that one address, on that one channel, is unavailable. The Desk records it as "email address unavailable". It does not mark the person as having said no, and it does not touch any other address for the same person.

Unclear evidence is held

Two rows with different opt-out dates. A relationship field that is empty. A date so old the rule set treats it as stale. A suppression match that names an address but not the channel. Each of these is held for review and shown with its reason. Held records stay held until a versioned rule or a documented review resolves them. Free text and notes never resolve anything; they can only trigger a hold.

Two rows are the same person only with evidence

The Desk links records only on an exact contact point. It never decides that two names, two addresses at the same company, or two similar spellings belong to the same person. Where it cannot link, it shows an unresolved identity and keeps both rows.

Nothing is inferred about where people are

You state which country the contacts are in and how you know. The Desk does not guess from addresses, email domains, phone prefixes, language or currency. Where the country and purpose you declare have a reviewed rule set, the checks run. Where they do not, every record shows "not assessed" and the page says why. Version one has one reviewed rule set: United Kingdom, business customer, email, follow-up with your own past contacts.

The strongest state, and what it means

"No blocking signal found in the supplied data" appears only when every part of the declared scope was assessed for that exact contact point and channel, and every suppression source you declared was checked. Wherever it appears, this sentence sits beside it:

This means only that the completed checks found no blocking signal in the supplied and declared sources. It does not establish consent, lawful basis, soft-opt-in eligibility, deliverability, or permission to contact.

Priority is not permission

Inside the paid audit, records also carry a priority based on recency and activity in your data. It is shown in its own column with its own note: priority says nothing about whether you may contact the person. The two are never combined into one verdict.

Masking is not anonymisation

In the free preview, contact details are masked on the server before anything reaches your screen, and any group smaller than five is shown as "fewer than five". That protects the people in your list from being picked out on screen. It does not make the data anonymous: the rows exist in your private Desk until you delete them or they expire after 48 hours.

A review is not an approval

If a person reviews a record, the Desk records who, in what role, what scope, which rule version, when, and any limitation. That is a review status. It is never displayed as legal approval, certification, or compliance with anything.

Sensitive data is quarantined, and screening is fallible

If a file looks like it holds card numbers, passwords, keys, health details, or anything about children or vulnerable people, the whole file is held before screening and the category is shown, never the value. Automated screening cannot guarantee it catches every sensitive item. Your own checklist is the first line.

You control deletion

Delete at any time. The receipt lists each storage class separately: uploaded rows, counts and reasons, audit events, backups. It says what was deleted, what remains, and when backups expire. It never claims erasure while a backup still holds a copy. Read how deletion works.

What the Desk does not do

  • It does not decide whether you may lawfully contact anyone. You do.
  • It does not confirm consent, lawful basis or soft opt-in for any record.
  • It does not promise delivery, replies, bookings or revenue.
  • It does not send anything from the free preview.
  • It does not read a phone channel in this version. Numbers are stored as contact points and shown as "not assessed".