Everything in this system exists for a conversation that happens rarely and matters disproportionately: somebody asks why they were contacted, and the quality of the answer determines whether it ends there.
Key takeaways
The answer names a date, a source, the exact wording, and what proves it was them.
It is produced in seconds, from one query, by whoever answers the email.
Retention of consent evidence outlives the consent itself, and that is deliberate.
Deleting a person’s data and keeping the record that they withdrew are both required.
The number to watch is unconfirmed suppressions, not consent rate.
What an answer looks like
“Why are you emailing me?”
You subscribed on 14 March 2025 through the newsletter form on our pricing page.
The wording you agreed to was: “Email me occasional product news and offers. You can unsubscribe at any time.”
You confirmed it by clicking the link in a confirmation email sent to this address on the same day.
You have not withdrawn from marketing since. Your last change was on 14 March 2025.
If you would like to stop, here is the link — it takes effect immediately across everything we use.
That is producible in about ten seconds by whoever is answering the email, from one query, and it ends the conversation in the large majority of cases. The version without this system — “our records show you are subscribed” — does not, and escalates at a meaningfully higher rate.
What makes it credible
Fig 1. How a challenge is answered. The two branches downward are what an imported or legacy consent produces, and being honest about them is better than dressing them up.
Database
App integration
Security & identity
Management
Analytics
Front-end & mobile
Imported consent
Every business that adopts a system like this has a pile of existing subscribers whose consent predates it, and those produce the weak answer: a date, maybe a source, no wording, no proof.
The honest handling is to mark those events explicitly as imported, with whatever provenance exists, and to know that the answer for those people is weaker. Some businesses respond by re-permissioning the imported list, which costs subscribers and produces a list where every remaining person has a strong record. That is a commercial decision rather than a technical one, and the system’s job is to make the distinction visible enough that somebody can make it.
The retention question
Fig 2. The retention conflict that has no clean answer. Both obligations are real and they point in opposite directions.
Machine learning
Security & identity
People
This is the one place in the whole series where the right answer is genuinely contested and depends on jurisdiction. The common resolution is a minimal suppression record — a hash of the address and the fact of withdrawal, nothing else — retained separately from everything else, on the basis that it exists solely to honour the withdrawal.
What the system can do is make that record genuinely minimal and genuinely separate, so that whoever has to defend the decision has something defensible to point at rather than a full customer record that was supposed to be deleted.
The numbers
Fig 3. A quarter of consent activity in five numbers. Only the last two describe a problem; the first three are the system working.
Machine learning
Security & identity
Management
Consent rate is deliberately not on that list. It is a marketing metric and putting it in a compliance report creates a quiet pressure to make the wording less clear, which is precisely the thing that makes the evidence weaker later.