Anti-Spam & Outreach Policy
Last updated: 14 June 2026
This policy explains how Denha Nexus s.r.o. ("Tsoden", "we", "us") conducts business-to-business (B2B) email outreach, the legal bases we rely on across the markets we operate in, and how anyone can opt out or complain. It complements our Privacy Policy and Audit Practices page.
1. What we send, and to whom
We send a low volume of plain-text, individually relevant B2B emails to business addresses (typically role-based, e.g. info@ or contact@) to introduce our free website audit. Addresses are obtained from public sources only: the business's own website, OpenStreetMap, public business registries, and public listings such as Hacker News / Product Hunt. We do not buy purchased "spam lists", and we do not target consumers in a personal capacity. Our emails are sent via our email service provider, Resend.
2. Every email we send
- Identifies the sender truthfully — accurate "From", reply-to, and our legal identity (Denha Nexus s.r.o.) and our brand (Tsoden);
- Uses honest, non-deceptive subject lines and header information;
- States why you received it (your public business site appears relevant to the offer);
- Includes a valid physical postal address for us;
- Includes a one-click unsubscribe — both a visible unsubscribe link and standards-based one-click headers (
List-UnsubscribeandList-Unsubscribe-Post: List-Unsubscribe=One-Click); and - Offers "reply STOP" as an alternative opt-out.
3. Legal bases by jurisdiction
3.1 EU / EEA — GDPR (incl. Slovakia, the Netherlands, Ireland) and ePrivacy
For B2B outreach we rely on legitimate interests under Article 6(1)(f) GDPR (direct marketing of relevant services, expressly recognised in Recital 47), supported by a documented legitimate-interests assessment and balancing test set out in our Privacy Policy. Recipients have an absolute right to object to direct marketing (Article 21), which we honour immediately. We respect national ePrivacy implementations: where a member state requires prior consent to email a particular type of recipient (for example certain individual subscribers/sole traders), we apply that stricter rule, and we always provide an easy opt-out in every message.
3.2 United Kingdom — UK GDPR + PECR
Under the Privacy and Electronic Communications Regulations (PECR), marketing email to corporate subscribers (companies and other corporate bodies) is permitted without prior consent, provided the sender is identifiable and an opt-out is offered — which we do. We treat clearly individual/sole-trader subscribers more cautiously and honour all opt-outs. We rely on legitimate interests under the UK GDPR for the underlying processing.
3.3 United States — CAN-SPAM Act
For US recipients we comply with the CAN-SPAM Act, including:
- accurate "From", "To", and routing/header information and a truthful, non-misleading subject line;
- identification of the message as a solicitation/commercial message in substance;
- a valid physical postal address in every email;
- a clear and conspicuous opt-out mechanism that works for at least 30 days; and
- honouring opt-outs promptly and in any event within 10 business days (we act immediately), with no fee or extra information required to opt out, and no transfer of opted-out addresses except to comply with the law.
3.4 Canada — CASL
Where we send to Canadian recipients, we follow Canada's Anti-Spam Legislation (CASL): we send commercial electronic messages only where we have a lawful basis (such as an applicable consent or exception, e.g. messages to a published business address that is not accompanied by a statement refusing such messages, sent in relation to the recipient's role/business), and every message includes clear sender identification, our contact information, and a working unsubscribe that we honour within 10 business days (we act immediately). Because CASL is consent-based and strict, we are conservative about Canadian outreach and stop on any request.
4. Opt-out and suppression
- You can opt out at any time via the one-click unsubscribe link, the one-click email header, or by replying "stop".
- We add every opt-out, bounce, and complaint to a persistent suppression list and check it before sending, so you are not contacted again. We retain the minimum data (your address and opt-out flag) solely to honour your request — see retention in our Privacy Policy.
- Opting out is free, requires no account, and we never require you to provide extra information beyond your email address to opt out.
5. Tracking and analytics
We measure delivery, opens (via a tracking pixel) and clicks (via link wrapping) through Resend, and process webhook events, to manage deliverability and honour opt-outs and complaints. This is described in our Privacy Policy. You can disable open-tracking by blocking remote images in your email client, and you can opt out of all email at any time.
6. Volume, deliverability and good-sender practices
We send at controlled volumes with authenticated sending (SPF/DKIM/DMARC alignment via our provider), warm-up practices, and prompt suppression of bounces and complaints, to protect inboxes and avoid being a nuisance. We do not use deceptive routing, open relays, harvested addresses, or dictionary attacks.
7. How to complain or get removed
- Fastest: click unsubscribe or reply "stop".
- Complaints / removal of all data: email support@tsoden.ai. We will confirm removal and suppress the address.
- You may also complain to a supervisory or enforcement authority — for example the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov), the UK ICO, the Irish DPC, the Dutch Autoriteit Persoonsgegevens, the U.S. Federal Trade Commission (FTC), or Canada's CRTC, as applicable.
8. Contact
Denha Nexus s.r.o., Pekná cesta 2459/19, 831 52 Bratislava, Slovak Republic — support@tsoden.ai — unsubscribe: https://quicko.tsoden.ai/unsubscribe.
This document is provided for transparency. It is general information, not legal advice to you, and should be reviewed by qualified local counsel before being relied upon.