Contact Controller
Introduction
The Contact controller manages contacts (people/companies linked to media, licenses etc) independently of AdmiralCloud user accounts. Each contact carries free-form metadata (name, email, company, etc.) and a flag that expresses its current lifecycle state.
Lifecycle states (flag)
0— active10— auto-created (e.g. from an IPTC copyright field on upload); becomes0on the first real edit11— bounced: the contact's email has failed delivery and is locked from further sends12— opted-out / locked: no further emails may be sent to this contact, for any reason (explicit opt-out, or the contact was deleted — see below)
GDPR compliance is built around three principles
-
Opt-out is POST-only. The recipient-facing opt-out link is a two-step flow (a static landing page, then a POST from a deliberate click) so that email security scanners that auto-fetch links can never trigger an opt-out by accident.
-
Deleting a contact never erases the fact that it must not be contacted.
destroy()(manual) and the automatic retention job (checkContactRetention, deletes contacts unused beyond a configurable period) both anonymize rather than hard-delete: metadata and history are wiped and the email is replaced with a one-way hash, but the record is kept and locked (flag: 12). If the same email is added again later, the system recognizes the hash and reactivates the locked record instead of creating a fresh, un-flagged duplicate — so a past opt-out can never be silently bypassed by re-adding the same person. A contact withsettings.deletionProtectionenabled is exempt from the automatic retention job (e.g. contacts sourced from IPTC copyright data that should never expire). -
Lifting a lock always requires a reason and leaves an audit trail. Resetting a bounce (
flag 11) or an opt-out (flag 12) requires an explicit reason (bounceResetReason/optOutResetReason) and records who reset it and when insettings.email.reset/settings.optOut.reset. Neither lock can be bypassed via a plain field update — only through these dedicated reset flows.
Merging duplicates
Two or more duplicate contact records can be consolidated via merge, which reassigns all license and media-container relations to the target contact before removing the source(s).