Policies

Acceptable use policy

What you can and cannot send through Waving. Most of it the app enforces. This page is the rest.

Waving sends cold email. Cold email is legal in the UK when it is done properly and a nuisance when it is not, and the difference is mostly who you send to, what you say, and what you do when someone says no. The app enforces as much of that as software can. This page covers the rest, and it is part of your agreement with us.

The short version

  • Email businesses, not private individuals, unless they have asked to hear from you.
  • Say who you are in every message and make it easy to say no.
  • When someone says no, that is the end of it.
  • Send only what you would be happy to defend to the person who received it.
  • Do not try to get round the limits. They are the product.

Who you can email

Under the UK’s Privacy and Electronic Communications Regulations, unsolicited marketing email to a corporate subscriber does not need prior consent. That means limited companies, limited liability partnerships, public bodies, schools and incorporated charities. You can email a named person at one of those organisations about their work under legitimate interest, as long as you identify yourself and offer a way to opt out.

An individual subscriber is different. Sole traders, ordinary partnerships, unincorporated charities and anybody at a personal address such as Gmail or Outlook.com need to have opted in before you email them. Waving blocks these unless you record that consent against the lead, and it is on you that the consent is real.

If you do not know which a business is, treat it as an individual. The app does.

What every email must carry

Every message sent through Waving includes your registered company name, company number and registered office in the signature, and a plain sentence inviting the recipient to say no. The app will not let you save a brand without these. Do not remove them, hide them or make them misleading.

The From address must be a real mailbox on a domain you control, that a person reads. The subject line must describe the email. Do not use “Re:” on a first email, fake forwarding, or anything designed to look like an existing conversation. Waving only adds “Re:” to the one follow-up, because that one is a reply to your own message.

When someone says no

A reply that says no, in any words, is final. Waving suppresses the address across every brand on your account and checks that list again immediately before every send. You must not add the person back, email them from another account, or contact them another way to ask why.

The same applies to anyone who complains to their mail provider, and to any address that bounces as unknown. Both are suppressed and stay suppressed.

Where your leads come from

You are responsible for the lawful basis for every lead you add. In practice that means:

  • Business contact data from a tool like Apollo, from Companies House, or from a company’s own website, used under legitimate interest, is fine, provided you have written down your legitimate interest assessment. The app gives you a template.
  • Lists of private individuals, consumer data, scraped social profiles and bought “marketing lists” of people rather than companies are not fine, and you must not load them.
  • Data you have already been told not to use, from any source, must not be loaded.

Keep only what you need. A name, a work email, a company and a reason to write is enough. Waving is not a place to store a dossier.

What you must not send

  • Anything illegal in the UK or where the recipient is.
  • Anything misleading about who you are, what you sell or why you are writing.
  • Adult content, gambling, weapons, controlled substances, or get rich quick schemes of any kind, including cryptocurrency promotion.
  • Malware, phishing, or links to pages that collect credentials or payment details under false pretences.
  • Threats, harassment, or anything that targets a person rather than their business.
  • Anything a reasonable recipient would call spam. If you would not put your name to it in person, do not send it.

Volume and pacing

Waving sends a small number of emails a day, spread across your working hours, with a warm-up period for every new domain and a cap across all your domains. Those limits are why the emails land. You must not try to get round them by running more than one account, sending the same message from several brands, or using a domain you do not control.

Bounces and complaints

We watch bounce and complaint rates for every brand. If either rises past the level a mail provider would notice, the brand is paused automatically and you are told. If it keeps happening, sending is held for the whole account until we have spoken to you. If it is a pattern, the account is closed.

We do this quickly and without much discussion because every customer sends through shared infrastructure. One careless sender can hurt the deliverability of everyone else, and we will always choose everyone else.

Your responsibilities

  • You are the sender. Legally, you are the data controller for the people you email and we process that data on your instructions.
  • You keep a written legitimate interest assessment for your outreach and can show it if asked.
  • You answer any request from a recipient about the data you hold on them. We will give you what we hold within two working days so you can.
  • You keep your sign-in details safe and tell us at once if you think somebody else has them.

If you break this policy

We can pause a brand, hold an account, or close it, at our discretion and without notice where we think the risk to recipients or to other customers needs it. We will tell you what we did and why. Where the law requires it we will report to the relevant authority.

Reporting abuse

If you have received an email sent through Waving that you think breaks this policy, reply to it saying so, or forward it to hello@waving.co.uk. Replying to the email itself suppresses your address automatically. Forwarding it to us gets a person to look at the sender.

This policy is not legal advice. The rules on business email in the UK are set by PECR and UK GDPR and are explained by the Information Commissioner’s Office, whose guidance is the thing to read if you want to be sure.

Questions

If anything here is unclear, ask. A person answers.

hello@waving.co.uk