The compliance engine
In Europe, spam isn't a bad look. It's a fine.
There is no EU-wide 'B2B email is fine' rule. The ePrivacy Directive is implemented nationally, and the rules differ per country. Operator One encodes those rules and enforces them in code. This page describes our enforcement model; it is not legal advice.
One law per country, not one law for Europe
GDPR applies everywhere, but the email-specific rules come from national ePrivacy implementations. What is workable in the Netherlands is a violation in Germany. The engine treats every country as its own rulebook.
Consent-first markets are blocked by default
Germany, Austria, Denmark, and Italy require consent for cold email even B2B under our operating model. The engine cannot cold-email these markets; those leads route to other motions or are parked. No configuration reaches around this.
No verification, no sends. It fails closed.
Every launch country gets a formal verification pass before its profile enables email. Until then, zero cold emails go out. Not reduced volume: zero. Markets we currently operate under verified or verification-pending profiles include:
- Workable with conditions: NL, FR, ES, UK, PL, IE (relevance and opt-out required)
- Verify-then-enable: BE, PT, SE, FI, CZ and others, parked until verified
- No cold email, ever: DE, AT, DK, IT (routed to non-email motions)
- Beyond the EU: the US (CAN-SPAM) and other markets run under their own rulebooks, verified before launch like everywhere else
Where email is blocked, the motion changes channel
Consent-first markets keep their research and ranking; the engine just refuses the illegal channel. LinkedIn runs in supervised early access: replies land in the same approval inbox, and approved responses are sent by a human at human pace (platform automation bans are real, so volumes stay human, and we never hold your credentials). Phone-ready briefs and trade-fair or distributor motions carry the rest.
What every send carries
Compliance is per-message, not just per-country. Every lead is stamped with its country profile before outreach.
- Sender identity and physical address in the footer
- Working opt-out: instant, global across campaigns, logged
- Platform-wide suppression: one opt-out is respected everywhere
- Send decisions audit-logged
Enforced by architecture, not policy
The sending layer physically cannot dispatch cold email into a blocked or unverified country. The gate sits below every UI control, and readiness checks must all pass before a single message moves. Data lives in EU Postgres; booking runs on our own EU scheduler.
