Overview
Gorillaa Mail provides API endpoints for GDPR compliance, allowing you to handle Data Subject Requests (DSRs) programmatically. All privacy endpoints require theprivacy:read or privacy:manage scope.
Data export (Art. 15)
Export all data associated with an email address — the right of access.Response
Export requests are processed synchronously. The response contains all data associated with the email address. Rate limit: 3 requests per 24 hours.
Data erasure (Art. 17)
Delete all data associated with an email address — the right to be forgotten.Response
List GDPR requests
View the history and status of all GDPR requests:Response
Request statuses
Privacy preferences
Manage per-address privacy preferences for data subjects.Get preferences
Response
Update preferences
This respects the data subject’s right to object to processing (Art. 21). When preferences are updated, future email sends will respect these settings.