Skip to main content

Overview

Gorillaa Mail provides API endpoints for GDPR compliance, allowing you to handle Data Subject Requests (DSRs) programmatically. All privacy endpoints require the privacy:read or privacy:manage scope.

Data export (Art. 15)

Export all data associated with an email address — the right of access.

Response

Export requests are processed synchronously. The response contains all data associated with the email address. Rate limit: 3 requests per 24 hours.

Data erasure (Art. 17)

Delete all data associated with an email address — the right to be forgotten.

Response

Data erasure is irreversible. All emails, events, and metadata associated with the address will be permanently deleted or anonymized. Rate limit: 1 request per 24 hours.

List GDPR requests

View the history and status of all GDPR requests:

Response

Request statuses


Privacy preferences

Manage per-address privacy preferences for data subjects.

Get preferences

Response

Update preferences

This respects the data subject’s right to object to processing (Art. 21). When preferences are updated, future email sends will respect these settings.

DSR request history

List all Data Subject Requests (both export and erasure):
Maintain an audit trail of GDPR requests for compliance. The Gorillaa Mail API retains request metadata even after data erasure is complete.