Handle a data request

Answer a request about one person: find them, read their consent trail, export the evidence, then archive or delete without losing your opt-out record.

An email arrives that reads "please tell me what you hold about me", or "delete all my data". For a nonprofit, a council, a school district or a law firm that is not a support ticket, it is a clock starting. This guide is the whole procedure, in the order you should do it, so you can act today and still have the paperwork afterwards.

Read the shape of it before you start. Mailsoftly does not have a request inbox, a status tracker, or a button that produces a signed certificate of erasure. What it has is a complete record of how each person arrived and how their consent changed, two exports, and two different ways to remove someone. The work is manual. The evidence is not.

Note

Nothing here is legal advice, and Mailsoftly does not give any. The Compliance page says so in one line of its own. Your counsel or your data protection officer decides what a request obliges you to do and by when. This guide only shows you where the facts and the controls are.

Know what you are being asked for

Two different requests arrive in the same inbox and they need different actions.

  • Access. "What do you hold about me?" You answer with what is on their contact record and how their consent was captured. Nothing is removed.
  • Erasure. "Delete my data." You remove the record. Whether that is the right answer depends on what else you are legally required to keep, which is a question for your counsel, not for this page.

Mailsoftly’s Compliance page names this row for you, and names it differently depending on the region you have selected. On the EU and UK tab it reads Data subject requests. On the United States tab it is Access and deletion requests, and on Canada it is Access and correction requests. In every case the description is the same short instruction: find the contact, then export or delete their data. The Open contacts button takes you straight to your audience.

The EU tab also states the expectation the product is built around, in the law card just above: requests answered within one month, covering access, deletion and portability. Turkish workspaces get a KVKK panel instead, whose three bullets say the same thing from the other direction: show a short aydınlatma notice on your forms, keep consent records with date and source because they carry your burden of proof, and expect people to ask what you hold and to ask for deletion.

Careful

There is no request queue in Mailsoftly and no automated erasure certificate. Nothing tracks that a request arrived, nothing counts down, and nothing produces a document at the end. Log the request wherever you log everything else, and treat this guide as the part that happens inside the product.

The needs you card on the Mailsoftly Compliance page showing the postal address row, the consent evidence report, the opt-out list, and the data subject requests row

Find the person in your audience

Open Audience from the left sidebar. The search box above the table is labelled Search by Name or Email, and it matches on a full name or on any part of an email address, so pasting the address the request came from is the fastest way in.

Two things can make a person look like they are not there, and both matter for a data request.

  • They are archived. The Audience list shows active contacts only. Archived people are on their own view.
  • Their address is on your suppression list. Suppressed addresses are filtered out of the Audience list, out of segment previews and out of your list health scores. The person still exists; they are just not shown where you are looking.

If a search comes back empty, check both before you reply that you hold nothing. Press the page title, Contacts, to open the dropdown underneath it: Subscribers, Archived, Unsubscribes and Suppressions are all one click away, and a suppressed contact is still reachable by opening the list they belong to and clicking their name there.

The Mailsoftly audience list filtered by a search term, showing the matching contacts with their email addresses and companies

Read what you hold on their profile

Click the person’s name to open their profile. The left card is the short answer to "what do you hold about me": their name, email, phone, when the record was created, and who owns it in your team. Empty fields read Not Specified. The right side splits into tabs, and Contact Details holds the rest, including any custom fields you import, their list memberships and their tags.

That is genuinely the whole of it for most workspaces. There is no hidden profile behind the profile, and nothing about a contact lives outside these tabs, so you can answer an access request by reading this screen out loud.

Careful

Do not quote the Opt-In Date field on the summary card as proof of consent. Today it mirrors the date the record was created rather than a captured opt-in event, so it tells a reviewer nothing the Created At line above it did not already say. The Activity tab in the next step is the field that actually carries provenance, and it is the one to quote.

A Mailsoftly contact profile with the summary card on the left and the detail tabs on the right

Use the Activity tab as your consent trail

Open the Activity tab. Its own subtitle states its purpose: how this contact was created and how their subscriptions changed. This is the individual version of the consent evidence report, and it is usually enough to answer "how did you get my address" in one reply.

Five kinds of event are recorded, newest first, twenty five at a time with a Load more link underneath:

  • Contact created
  • Subscribed, with the subscription it applies to, or All emails
  • Unsubscribed, the same way
  • Added to list, with the list name linked
  • Removed from list

Under each line sits the source, in plain words: Import, Form submission, Preference page, One-click unsubscribe, Added manually, Admin, API, Automation, Webhook or System. Where a specific origin was captured it is named after a colon, so a row can read Form submission: Newsletter signup, which is exactly the sentence a reviewer wants. When a teammate made the change, their name appears in brackets at the end.

These rows cannot be edited or removed by anyone, including you. That is the point of them.

Note

A contact who joined you before this trail existed shows a single Contact created row derived from the record’s own creation date and its stored source. It is a reasonable statement about where they came from, but it is a derivation rather than a captured event, so if a reviewer asks for the original opt-in paperwork on an older list, expect to supply it from wherever you collected it.

The Activity tab on a Mailsoftly contact profile listing created, subscribed and unsubscribed events with the source under each one

Export the evidence before you change anything

This is the step people skip and regret. Once a contact is deleted, the Activity tab has no contact to hang on and the consent evidence report has no row to include. The records survive inside Mailsoftly, but nothing in the interface will show them to you again. Export first, then act.

Open Settings, then Compliance under the Account group, and use Consent evidence report. Pick a scope in the list next to it, then press Download. There is no single-contact scope, so choose the list the person belongs to, or All contacts, and filter the CSV for their address in your spreadsheet. The nine columns give you the whole answer in one row: their name and address, whether they are recorded as an individual or a business recipient, the consent date and the time zone it is printed in, the source and the specific thing it came from, whether they currently read as consented or opted out, and the opt-out date if there is one.

Keep that row, or the whole file, with your reply. A dated export you already had is worth more in a review than one produced after the question arrived.

Tip

If you have developers, one person’s record can be pulled directly with the API instead. Look the contact up by their exact address, then read the full record back as JSON. Use the Mailsoftly API covers the key, the endpoint list and a first call. There is no delete endpoint, so the removal in the next step is always done in the interface.

The consent evidence report row on the Mailsoftly Compliance page with a list picker and a Download button

Archive or delete, and know the difference

Hover a row in your audience and a three dot button appears at the end of it. Open it and you get Show, Edit, Archive, then a divider and a red Delete. The same two choices exist on the profile and in the bulk bar. They are not two strengths of the same action; they do genuinely different things.

Archive flips one flag. The person leaves your Audience list and appears on the Archived view, where the same control reads Unarchive and puts them back. Nothing else changes: their lists, tags, subscriptions and activity trail are all exactly as they were. It is reversible, and it is the right choice when you want the record out of the way while you work out what you owe.

Delete is permanent. The contact record and its list memberships, tags and notes are removed and there is no undo, no trash can and no restore. The confirmation warns you that the action is irreversible, and it means it.

Careful

Archiving is not an opt-out. An archived contact who is still on a list you send to will still receive that campaign, because sending decides from the suppression and opt-out records, not from whether a record is archived. If the request is "stop emailing me", unsubscribe them or take them off the lists. Archiving alone will not do it, and finding that out from the recipient is the worst way to find out.

Delete one person from their own row or their own profile, and read the toast that follows. Do not use Delete selected in the bulk bar for a request like this: it reports success whether or not each record actually went, so it is the one control here that can leave you believing a job is finished when it is not.

The row actions menu open on a Mailsoftly contact, offering Show, Edit, Archive and a red Delete

Know what survives, and what you cannot delete

Deleting a contact does not delete their opt-out. The record of who unsubscribed lives against the email address itself rather than against the contact, so it stays behind and keeps working. If that same address is imported again next year, it is still excluded from your sends. This is deliberate, and it is the reason deleting someone at their request cannot quietly turn into emailing them again later.

The consent trail survives too, for the same reason: those events are recorded against the address. Deleting the person even adds to it, because coming off each list is itself written down. You just cannot see any of it in the interface once the contact is gone, which is why step 5 comes before step 6.

One delete will be refused outright. If the address is on your suppression list, because it hard bounced or someone marked a message as spam, Mailsoftly will not let the contact be deleted and tells you so. That guard exists for a specific reason: the suppression record is what keeps you from ever mailing that address again, and deleting the contact would have taken it with it. The suppression stays, the contact stays, and removing a suppression is something only support can do. Read your suppression list explains how addresses get there and why they cannot be edited.

Two more things worth having ready before the next request arrives. If your recipients should be able to answer half of these themselves, Design your preference center is where you set up the page that lets them choose what they receive and unsubscribe on their own terms. And if you send to Türkiye, Meet your İYS obligations covers the separate reporting that sits alongside KVKK, including the three business day rule for opt-outs.

Work the steps in order and a data request becomes ordinary: find them, read the trail, export it, then archive or delete on purpose. Prove your compliance does the same thing at the level of your whole audience, for the questionnaire that turns up once a year rather than the email that turns up today.

The Mailsoftly suppression list showing suppressed addresses with their status and the date each was added

Ready to try it in your own account?

Free to start with your Google Workspace or Microsoft 365 account. No credit card required.

Keep going