Skip to main content

Anti-Spam & Email Policy

Last updated: June 15, 2026

Language notice: This legal text is currently available in German (DE) and English (EN) only. The authoritative version is German; the English text is a courtesy translation. Full translations in other languages are planned for a future update.

1. Scope

This policy applies to all emails sent by Scanara UG (haftungsbeschränkt) from the @scanara.io domain.

2. Email types

Scanara sends only:

(a) Transactional and service emails on the legal basis of contract performance (Art. 6(1)(b) GDPR) or legitimate interests (Art. 6(1)(f) GDPR). These include:

  • Account access and authentication (verification codes, password resets, invitations)
  • Scan results, compliance dossiers, and platform notifications
  • Organisation and membership events (e.g. invitations, removal from an organisation)
  • Billing and contract communications (including statutory notices such as the right-of-withdrawal notice under §§ 312f, 355 BGB)
  • Data-subject communications (e.g. deletion confirmations under Art. 17 GDPR)

(b) Marketing emails (the newsletter "EU AI Act Developer Digest") only with explicit consent (Art. 6(1)(a) GDPR in conjunction with § 7(2) No. 3 UWG).

Scanara does not send unsolicited commercial email (spam), phishing emails, or fraudulent messages.

3. Opt-in policy

  • No purchased or rented lists. All addresses are provided directly by the individual user.
  • Newsletter: Only with explicit consent; sign-up uses a confirmed double opt-in procedure. A record of consent (timestamp, IP address, confirmation link) is stored pursuant to § 7(3) UWG.
  • Transactional emails are required for contract performance and cannot be unsubscribed from during an active membership.

4. Unsubscribing (opt-out)

  • Notification emails: Every eligible email includes a List-Unsubscribe header (RFC 8058 one-click) and an unsubscribe link in the body. Preferences can also be managed in the account dashboard.
  • Newsletter: Unsubscribe at any time via the unsubscribe link in any newsletter email, or by emailing support@scanara.io.
  • Unsubscribe requests are processed without undue delay and persisted permanently.

5. Bounce and complaint handling

Scanara operates an automated system for managing delivery failures and spam complaints:

  • Hard bounce: immediate permanent suppression of the address.
  • Soft bounce: suppression after two consecutive soft failures.
  • Complaint (spam report): immediate suppression of the address.

Suppressed addresses are not contacted again. The suppression list is enforced at both application level (PostgreSQL) and AWS SES account level.

6. Sender authentication

All emails are sent with authentication:

  • From address: notifications@scanara.io
  • Reply-To / contact: support@scanara.io
  • SPF: TXT record on scanara.io and mail.scanara.io
  • DKIM: EasyDKIM (3 CNAME records) on scanara.io
  • DMARC: v=DMARC1; p=reject; rua=mailto:dmarc-reports@scanara.io
  • Delivery: AWS Simple Email Service (SES), eu-west-1 region (EU, Dublin) — processing within the EU

7. Reporting abuse / contact

To report abuse, file spam complaints, or ask questions about this policy, please contact: support@scanara.io

Further information: Privacy Policy · Imprint