Responsible Business Outreach and Anti-Abuse Policy
Symplichain Technologies Private Limited
Effective date: August 5, 2026
Last updated: August 5, 2026
1. About this policy
SymFlow is a product of Symplichain Technologies Pvt. Ltd. ("Symplichain", "we", "us", or "our"). We use email and other communication channels to engage with customers, prospective business customers, partners, and people who request information about our products.
This policy explains the standards that apply to business outreach conducted by Symplichain and by employees, contractors, affiliates, agencies, data providers, and service providers acting on our behalf.
It applies to every domain, subdomain, website, tracking domain, redirect domain, sending account, and email address owned, controlled, operated, or used to advertise SymFlow or another Symplichain product.
2. Prohibited conduct
Symplichain prohibits:
- Unsolicited bulk email and indiscriminate mass-email campaigns.
- Spam, phishing, malware distribution, impersonation, and deceptive messages.
- Email-address harvesting, automated scraping, or the use of guessed or generated addresses.
- Using addresses obtained from data breaches, credential leaks, malware, deceptive forms, or unauthorized sources.
- Sending to a person who has unsubscribed, objected, or asked not to be contacted.
- Moving a suppressed recipient to another domain, mailbox, campaign, sender, vendor, or affiliate.
- Using multiple domains or sending accounts to evade blocklists, provider restrictions, volume limits, reputation controls, or recipient objections.
- Misleading sender names, From addresses, Reply-To addresses, subject lines, or claims of an existing relationship, referral, or previous conversation.
- Concealing the identity of Symplichain or the purpose of a message.
The fact that an address is publicly visible, commercially available, or technically deliverable does not by itself justify bulk or repeated outreach.
3. Targeted business-to-business outreach
Symplichain may conduct limited, targeted business-to-business outreach when there is a documented and reasonable basis to believe that the subject is relevant to the recipient's professional responsibilities.
Before an initial business outreach message is sent:
- The sender must identify a specific organization and relevant professional role.
- The sender must review the recipient's apparent responsibilities and the reason the message may be relevant.
- The recipient's business contact information must come from a lawful, documented, and reviewable source.
- The recipient must be checked against the company-wide suppression list.
- The message must identify the sender, SymFlow, and the commercial purpose accurately.
- The message must not imply that the recipient opted in, requested contact, received a referral, or previously spoke with us unless that is true.
- The message must include a simple way to decline further communication.
- The frequency and number of follow-ups must be limited and reasonable.
Automated campaign tools must not replace human accountability for targeting, source quality, relevance, suppression, or recipient choice.
4. Harvested, scraped, and generated addresses
Symplichain does not permit addresses obtained through:
- Automated scraping or email harvesting.
- Guessing or generating address patterns.
- Data breaches or credential leaks.
- Malware, deceptive collection, or unauthorized access.
- Copying from a platform or directory in violation of its terms or applicable law.
- A source that cannot adequately explain how and when the address was collected.
Employees and service providers must not upload, transfer, sell, or send to such addresses using Symplichain infrastructure.
5. Purchased, licensed, enriched, and third-party data
Third-party data may not be used merely because a provider describes it as verified, compliant, accurate, or suitable for marketing.
Before third-party data is approved, Symplichain must evaluate and document:
- The identity and reputation of the provider.
- The original source and collection method.
- The age and accuracy of the information.
- The purposes for which the information may be used.
- Applicable privacy, consent, and communication restrictions.
- Whether the proposed message is relevant to the recipient's documented business role.
- Whether previous objections, unsubscribes, or suppression information are available.
Data must not be used when its source, permitted use, or accuracy cannot be reasonably established. Third-party data must never override an unsubscribe, objection, complaint, or suppression record.
6. Global suppression and cross-domain controls
Symplichain maintains an organization-wide suppression process covering all products, domains, mailboxes, campaigns, contractors, affiliates, and sending platforms.
Once an address is suppressed, it must not be contacted through a different:
- Domain or subdomain.
- Sender or mailbox.
- Campaign or product name.
- Sending platform.
- Contractor, affiliate, agency, or data provider.
Changing a domain, sender, campaign, message, or service provider does not cancel a previous unsubscribe or objection.
Before any campaign or outreach list is activated, it must be screened against the current global suppression list.
7. Unsubscribes and do-not-contact requests
Symplichain provides recipients with a clear and functional way to stop marketing communications.
A clear do-not-contact request will be acted upon immediately by stopping active sequences and suppressing the recipient across all Symplichain-controlled domains, campaigns, senders, and service providers. Other unsubscribe requests will be processed promptly and no later than 48 hours after receipt.
An unsubscribe or do-not-contact request will:
- Stop active automated follow-ups.
- Be applied across Symplichain-controlled outreach systems and domains.
- Be recorded using the minimum information required to prevent future contact.
- Be shared with relevant contractors and service providers responsible for sending.
Requests such as "unsubscribe", "remove me", "do not contact me", "stop emailing me", and equivalent language are treated as objections even when they are submitted by replying rather than through an unsubscribe link.
We do not require recipients to create an account, pay a fee, or provide unnecessary personal information to stop marketing communications.
8. Accurate identity and message content
Business communications sent for SymFlow must accurately disclose:
- The individual sender.
- That the sender represents SymFlow or Symplichain.
- The commercial or business purpose of the message.
- A working reply address.
- A functional way to decline further outreach.
We prohibit forged headers, misleading display names, deceptive subject lines, false reply chains, impersonation, and fabricated claims of familiarity, referrals, customer relationships, or previous conversations.
Links and calls to action must accurately describe their destination. Public URL shorteners, misleading redirects, and unauthorized tracking infrastructure must not be used.
9. Authentication and infrastructure security
Authorized sending domains must use appropriate technical and administrative safeguards, including:
- SPF, DKIM, and DMARC authentication.
- Alignment between authenticated domains and the visible From domain where required.
- TLS for email transmission where supported.
- Secure management of DNS, domains, mailboxes, websites, and sending platforms.
- Multi-factor authentication for administrative accounts where available.
- Review of redirects, tracking domains, and website content for compromise or unauthorized changes.
New or materially changed infrastructure must be tested before production use. A domain must not be used to bypass an unresolved blocklist, restriction, or reputation incident.
10. Bounce, complaint, and reputation monitoring
Symplichain monitors available indicators of unwanted or unsuccessful communication, including:
- Hard and soft bounces.
- Sender-level failures and provider deferrals.
- Spam complaints and block events.
- Unsubscribes and negative replies.
- Authentication failures.
- Domain and IP reputation.
- Domain, URL, and IP blocklist status.
- Unexpected changes in sending volume or behavior.
Campaigns and mailboxes may be paused when these indicators suggest authentication problems, poor data quality, unexpected sending, recipient dissatisfaction, or abusive activity.
Permanent delivery failures must be suppressed. They must not be repeatedly retried through alternate domains, senders, or providers.
11. Contractors, affiliates, and service providers
Anyone sending or sourcing contacts on behalf of Symplichain must follow this policy.
They may not:
- Use harvested, guessed, breached, or undocumented addresses.
- Send indiscriminate bulk outreach advertising SymFlow.
- Continue contacting a person who objected or unsubscribed.
- Move suppressed contacts into another system or campaign.
- Rotate recipients across domains or senders to evade restrictions.
- Conceal their identity or relationship with Symplichain.
- Use unauthorized domains, links, tracking infrastructure, or mailboxes.
- Delegate sending or data collection without written authorization.
Symplichain may require contact-source documentation, message samples, suppression records, sending logs, authentication evidence, and compliance audits from service providers.
12. Reporting suspected abuse
Suspected spam, abuse, impersonation, phishing, malware, or unauthorized communication involving SymFlow, Symplichain, or a company-controlled domain may be reported to:
Email: reports@symplichain.com
Please include, where available:
- The complete email headers.
- The original message body.
- The sender address.
- The date and time received.
- URLs contained in the message.
- A brief description of the concern.
Information unrelated to the report may be redacted. Credible reports will be investigated, and an abuse report will never be used to add the reporting person to a marketing list.
13. Incident response
When Symplichain becomes aware of a material email-abuse, domain-reputation, or security incident, we may:
- Suspend affected campaigns, domains, or sending accounts.
- Preserve relevant logs, headers, messages, and recipient records.
- Investigate contact sources, sending practices, links, websites, accounts, and service providers.
- Secure compromised DNS, domain, website, mailbox, or platform access.
- Expand suppression where recipients may have been affected.
- Correct authentication or infrastructure problems.
- Notify relevant providers or authorities where appropriate.
- Implement corrective and preventive measures before sending resumes.
We will not transfer substantially similar traffic to another domain or provider merely to avoid an unresolved blocklist, suspension, restriction, or recipient objection.
14. Enforcement
Violations of this policy may result in:
- Immediate campaign or account suspension.
- Removal of access to sending systems.
- Suppression or deletion of improperly sourced data.
- Mandatory remediation and compliance review.
- Termination of a contractor, affiliate, agency, or service provider.
- Employee disciplinary action.
- Notification to relevant platforms or providers.
- Permanent prohibition on using Symplichain infrastructure.
- Legal action where appropriate.
Attempts to evade this policy through alternate domains, mailboxes, vendors, identities, or platforms are treated as serious violations.
15. Policy review
Symplichain reviews this policy periodically and following a material abuse, security, or deliverability incident. Updates will be published on this page with a revised "Last updated" date.
Related policies
See also our Privacy Policy and Terms of Use.