Get them back: 10 AI skills for the list you already own

win-back

the people who came once and never came back

How the two work together

Claude thinks it through. Paste the Claude prompt into Claude Code, or drop the folder into your skills folder. Claude does the judgement: what to look for, what is worth doing, what is right.

Codex gets it done. At the hand-off point Claude runs Codex on your machine with one command and passes it the Codex prompt. Codex does the mechanical part and hands the result back. Claude checks it before you see it.

No API key to set up: Claude calls the Codex you already have installed. If Codex is not installed, Claude does that half itself and tells you.

Prompt for Claude

---
name: win-back
description: Sorts the people who came once and never came back into who you may lawfully email and who you may not, then writes the short sequence for the ones you may, with a close-out rule. Use before running any re-engagement, "we miss you" or re-permission campaign.
---

# Get back the people who came once and never came back, without emailing the ones who told you to stop

You give this your list with the last transaction or visit date against each address, and your do-not-contact list. You get back three separate files: the people you may lawfully email and a three-message sequence written for them, the people you may not email at any price with the reason, and the people whose route has aged out. The second file is the one that saves the money, because the single most expensive email a small business can send is the one that asks somebody who already said no whether they have changed their mind.

## What it does

1. **Split "lapsed" into three populations before a word of copy is written.** Population one: still on a live lawful route, and simply has not been in. Population two: objected, unsubscribed, or asked you to stop, by any means and to any part of the business. Population three: never had a lawful route in the first place, which usually means a bought list, a box of cards, or a spreadsheet from a previous manager. Only population one receives anything. Populations two and three receive nothing, ever, and the point of naming them is that in most venues they are a third of the file and have until now been sitting inside the same send.

2. **Learn the rule that ends the project, because it is counter-intuitive and it is enforced.** An email asking somebody whether they would like to hear from you is itself marketing. The ICO's own example says so: "A hotel sends an email to its previous guests asking them if they would like to consent to receiving its special offers and discounts. Whilst this email doesn't contain any of these discounts or offers, the hotel is still sending it for direct marketing purposes." And on objectors it is absolute: "If someone has objected to your direct marketing, you can't contact them at a later date to ask if they've changed their mind. This contact would still be for direct marketing purposes that they have specifically objected to." So the re-permission email, the one every agency suggests, is the one thing you cannot send to the people you most want to send it to.

3. **Read what it cost two companies that did it anyway, then move on.** On 27 March 2017 the ICO fined Flybe £70,000 and Honda Motor Europe £13,000 for exactly this. Flybe "deliberately sent more than 3.3 million emails to people who had told them they didn't want to receive marketing emails from the firm", with the subject line "Are your details correct?", asking people to update their marketing preferences with a prize draw attached. Honda sent 289,790 emails "aiming to clarify certain customers' choices for receiving marketing" and believed they were customer service emails. Steve Eckersley, then ICO Head of Enforcement, said: "Sending emails to determine whether people want to receive marketing without the right consent, is still marketing and it is against the law." Honda's defence, that it was a service message, is the exact defence a well-meaning venue would offer.

4. **Define lapsed by the venue's own rhythm, not by a borrowed number.** A city-centre sandwich bar's lapsed customer is three weeks gone. A Sunday-lunch pub's is four months. A wedding venue has no lapsed customers at all in this sense. Work it out from your own booking data: find the typical gap between visits for people who came more than twice, and call lapsed anything past double that gap. Write the number down and write down how you got it. Then check the seasonal trap before you send anything, because a venue that is quiet every January has not lost its customers, and a win-back campaign in the second week of January is a campaign against the weather.

5. **Check whether the route is still alive, not just whether it once existed.** The soft opt-in in regulation 22(3) rests on the contact details having been obtained "in the course of the sale or negotiations for the sale of a product or service", and the ICO adds that the marketing must be for "your similar products and services", meaning "you can't send messages about things that people wouldn't reasonably expect from you in that context". A single sale four years ago is a thin basis for an email today, and consent ages too: "Consent for direct marketing does not last forever", and how long "depends on the circumstances (such as people's expectations and their relationship with you)". Anything obtained through a third party more than six months ago, the ICO recommends you do not use at all. Move aged rows into the third file rather than sending to them and hoping.

6. **Work out why they stopped, from what you already hold, before writing anything.** You have more than you think: the date of the last visit, what they ordered, whether it was a first visit, whether they had a complaint, whether they booked and did not turn up, whether they came for a one-off thing like a birthday or a work party. Group the lapsed into three or four honest reasons: came for one occasion and have no reason to return; were a regular and stopped; something went wrong; moved away. The emails to those groups are different emails. A "we miss you" sent to somebody who came once for a leaving do admits you do not know who they are, and the same email to someone who had a bad meal is worse.

7. **Write three messages, not one, and give each a job.** Message one, sent first: the honest one. Name how long it has been, say what has actually changed since (a new menu, a new chef, a refit, longer opening), and ask nothing. Message two, ten to fourteen days later: the one concrete reason to come, with a date attached that is real. Message three, ten to fourteen days after that: the short one that says you will stop emailing unless they want you to continue, and gives them a link to hear from you less rather than not at all. Then stop. Three is the cap, and the reason for the cap is that CAP Code rule 10.1 says "Marketers must not make persistent and unwanted marketing communications by any means", and it is asterisked as a prohibited practice.

8. **Send the inactive population separately and in small batches, because they are the most likely to report you.** Yahoo tells senders to "Monitor hard and soft bounces as well as inactive recipients", to "Remove invalid recipients from your list promptly" and to "Don't send bulk/marketing email from the same IPs you use to send user mail, transactional mail, alerts". Google advises senders to "Consider unsubscribing recipients who don't open or read your messages" and warns against "sudden volume spikes if you do not have a history of sending large volumes". A win-back campaign is, by definition, a bulk send to the least engaged addresses you own, which is the exact shape of a send that damages a sending reputation. Split it into batches across several days, watch the bounces after the first batch, and stop the run if bounces spike rather than pushing the rest out.

9. **Produce the three files, the three drafts and the close-out rule in writing.** `win-back-send.csv`: address, last visit date, reason group, route, and which of the three messages they are due. `do-not-contact.csv`: every objector and unsubscriber, untouched, with the date they said no. `route-expired.csv`: everyone whose consent or soft opt-in has aged out, with what would be needed to reach them again, which in most cases is nothing you can do by email. Then the close-out rule, written down: anyone who does not respond to message three is moved to a once-a-year contact or suppressed entirely, and the campaign is not run against them again next quarter. Without it the same three emails get sent to the same silent people every few months, which is how a list turns into a spam-complaint generator.

## Then it checks

1. Every address in the send file appears in neither the do-not-contact file nor the route-expired file, and the three files together account for every address in the source list with none counted twice.
2. No message in the sequence asks the recipient to confirm, update or re-give their marketing preferences, and no message is sent to anyone who has previously objected, unsubscribed or asked to stop by any channel.
3. The lapsed threshold is a number derived from the venue's own visit gaps, stated in the output with the working shown, and is not a round number carried in from elsewhere.
4. Every route in the send file is checked as current, not merely as having once existed, and anything obtained via a third party more than six months ago sits in the route-expired file.
5. The sequence is three messages, is capped at three, and message three offers a way to hear from you less as well as a way to stop entirely.
6. The send is split into batches with a written stop condition on bounces, and the close-out rule is written into the output rather than left to the manager to remember.

Any check fails: name it, redo that step once. Failed twice: say what is wrong and stop.

## Rules
- Public information only.
- Never invent a fact, a number or a quote.
- Anything sent in someone's name says whose name it is.
- Never email anyone to ask whether they would like to receive marketing. That email is marketing, the ICO's hotel example says so in terms, and it is the specific act that cost Flybe and Honda £83,000 between them. If a population cannot be reached lawfully by email, say so once and stop.
- Never delete an objector to tidy the file. Suppression is what stops them being re-imported next time a list arrives, and the ICO's own example shows a deletion causing exactly the breach it was meant to avoid.
- Never attach a prize draw to a preference update. That is the precise mechanic the ICO described in the Flybe penalty, and it converts a compliance question into an enforcement one.
- Never run the same win-back sequence at the same people again next quarter. Repeated unwanted contact is prohibited under CAP Code rule 10.1 regardless of how polite each individual message is.
- Never state a recovery rate, an open rate or a benchmark for win-back campaigns. The figures in circulation come from vendors with software to sell and none of them describe a single independent UK venue.
- This output is a working document prepared for the owner's solicitor or data protection adviser to check before any of it is sent. It sorts a list against published guidance and drafts copy; it is not legal advice and it is not a finding that any particular send is lawful.

## Built from
- Information Commissioner's Office, "Respect people's preferences", https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/respect-peoples-preferences/, no publication date shown on the page, read 14 September 2026: the rule that an objector cannot be asked to reconsider, which is step 2 and the defining constraint of the whole skill, plus the suppression rule behind the second standing rule.
- Information Commissioner's Office, "Identify direct marketing", https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/identify-direct-marketing/, latest update shown 20 August 2025, read 14 September 2026: the hotel example establishing that a consent-request email is itself sent for direct marketing purposes, and the service message boundary in step 2.
- Information Commissioner's Office press release, "ICO warns UK firms to respect customers' data wishes as it fines Flybe and Honda", 27 March 2017, read on wired-gov.net at https://www.wired-gov.net/wg/news.nsf/articles/ICO+warns+UK+firms+to+respect+customers+data+wishes+as+it+fines+Flybe+and+Honda+27032017142000, read 14 September 2026: the two penalties, the volumes, the prize draw mechanic and the Eckersley quotation used in step 3. The ICO's own copy of this release no longer resolves; see SOURCES.md.
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22, https://www.legislation.gov.uk/uksi/2003/2426/regulation/22, in-force text carrying amendments commenced 5 February 2026, read 14 September 2026: the statutory soft opt-in limbs that step 5 tests for currency rather than mere existence.
- Information Commissioner's Office, "Plan direct marketing", https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/, latest update shown 20 August 2025 on sibling pages, read 14 September 2026: that consent "does not last forever", the similar products limb, and the six-month limit on third-party consent, all in step 5.
- Yahoo, "Sender Best Practices", https://senders.yahooinc.com/best-practices/, and Google, "Email sender guidelines", https://support.google.com/a/answer/81126, no publication dates shown on either page, both read 14 September 2026: the inactive-recipient and volume-spike warnings behind step 8.
- Committee of Advertising Practice, CAP Code (Edition 12), Section 10 rule 10.1, https://www.asa.org.uk/type/non_broadcast/code_section/10.html, no publication date shown on the page, read 14 September 2026: the prohibition on persistent and unwanted marketing communications, which is the cap of three in step 7.

Prompt for Codex

# win-back

## You are given
A folder from one UK hospitality business holding: the customer list with a last transaction or last visit date against each address, exported from the booking system, the till, an online ordering platform or a spreadsheet; the full visit history where one exists, so gaps between visits can be counted; the do-not-contact and suppression list, with the date each person objected and how; the record of where each address came from and on what route, with the date it was collected; a note from the owner of the venue's seasonally quiet weeks; any complaint, no-show or one-off-occasion markers held against a booking; and the three draft messages once they have been written. Column names differ between files and dates are in mixed formats.

## Produce
Write into a `./win-back-output/` folder. Every file whose name carries `PERSONAL-DATA` holds contact details and is stored, moved and deleted as personal data.

1. `lapsed-threshold-working.csv` with these columns in this order: `item`, `value`, `how_it_was_worked_out`, `source_file`. Rows in exactly this order: `Customers with more than two recorded visits`, `Total gaps measured`, `Median gap between visits (days)`, `Threshold, double the median (days)`, `Threshold date`, `Seasonally quiet weeks supplied by the owner`, `Send weeks excluded as seasonally quiet`. Any row whose figure could not be counted reads `not derivable` and goes in `gaps.md`.
2. `win-back-send-PERSONAL-DATA.csv` with columns: `email_lower`, `first_name`, `last_visit_date`, `days_since_last_visit`, `visits_recorded`, `reason_group`, `route`, `date_route_obtained`, `route_evidence_source_file`, `message_due`, `send_batch`, `send_date`, `source_file`, `source_row`. `reason_group` is exactly one of `one occasion only`, `was a regular and stopped`, `something went wrong`, `moved away`, `not determinable`. `message_due` is `1`, `2` or `3`.
3. `do-not-contact-PERSONAL-DATA.csv` with columns: `email_lower`, `date_they_said_no`, `how_they_said_no`, `channel`, `source_file`, `source_row`. Copied through untouched. No address is ever removed from it, edited in it, or moved out of it.
4. `route-expired-PERSONAL-DATA.csv` with columns: `email_lower`, `route_as_recorded`, `date_route_obtained`, `months_since`, `obtained_via_a_third_party`, `last_visit_date`, `what_would_be_needed_to_reach_them`, `source_file`.
5. `partition-check.txt` - the distinct address count from the source list, the row count of each of the three files above, their sum, and a line stating whether the sum equals the distinct address count. Plus the count of addresses appearing in more than one of the three files, which must be zero.
6. `message-1.md`, `message-2.md`, `message-3.md` - one draft per file, each with headed blocks in exactly this order: `Job of this message`, `Send delay from previous`, `Subject line`, `Preview text`, `Body`, `Footer`, `Signed by`. Body copy is the supplied draft, unchanged. Message three carries both a link to hear from the venue less and a link to stop entirely.
7. `batches.csv` with columns: `batch_no`, `send_date`, `addresses_in_batch`, `stop_condition`, `bounces_after_this_batch`, `bounce_rate`, `run_continued`. The last three columns are left empty for a person to fill in after each batch.
8. `close-out-rule.txt` - the written rule in plain sentences: what happens to anybody who does not respond to message three, the date the campaign is closed, and the statement that the same sequence is not run against these addresses again.
9. `reason-groups.csv` with columns: `reason_group`, `addresses`, `share_of_send_file`, `evidence_used`, `source_file`. One row per group including `not determinable`.
10. `gaps.md` - a numbered list of: every address with no last visit date; every route with no date obtained; every address that could not be placed in a reason group; every figure in `lapsed-threshold-working.csv` that could not be counted; and every draft block left empty.

## Rules
- Codex writes drafts and files only. Never send an email. Never connect to an email platform's API, a marketing service, a booking system or any sending service to send, schedule, queue, automate or import. Never add anybody to a list, an audience, a segment or an automation anywhere.
- Never write, draft or place any message that asks a recipient to confirm, update, renew, re-give or check their marketing preferences, and never draft anything to an address in `do-not-contact-PERSONAL-DATA.csv`. If the supplied copy contains such a request, leave it in place, do not send it anywhere, and list it in `gaps.md`.
- Never move, edit or delete a row in `do-not-contact-PERSONAL-DATA.csv`, and never suppress it by deleting it. Every objector stays in the file with the date they said no.
- Never scrape, guess, construct, correct or complete an email address, and never look up a new address for anybody whose old one bounced.
- Anybody without a recorded consent or lawful basis, or whose route has aged out, goes in `route-expired-PERSONAL-DATA.csv` and never into the send file. Anything obtained through a third party more than six months ago goes there regardless of the last visit date.
- The three address files must partition the source list. Every distinct address appears in exactly one of them, no address appears in two, and the counts must sum to the distinct address count. Never adjust a number to make the sum balance: report the difference in `partition-check.txt` and `gaps.md`.
- Never attach a prize draw, a competition or an incentive to any of the three messages.
- Never exceed three messages, and never write a fourth file, a follow-up or a reminder.
- Never write a recovery rate, an open rate, a click rate, a benchmark or an industry average into any file.
- Never derive the lapsed threshold from a round number, a rule of thumb or a figure carried in from elsewhere. It is counted from the supplied visit history and the working is shown. Where the history cannot support it, the threshold reads `not derivable` and no send file is written.
- Every date, figure and route must trace to a supplied input file named in the row.
- Use British English, £ and DD Month YYYY dates. No em dashes.
- Every file ends with this line: this is a working document prepared for the owner's solicitor or data protection adviser to check before any of it is sent. It sorts a list against supplied guidance and drafts copy, it is not legal advice, it is not a finding that any send is lawful, and nothing in this folder has been sent.

## Return
The absolute path of each file written, the row count of each CSV, the distinct address count with the three file counts, their sum and whether it balances, the number of addresses appearing in more than one file, every line of `lapsed-threshold-working.csv`, the reason group breakdown with shares, the number of batches and the addresses in each, the stop condition as written, and the `gaps.md` item count. State plainly that no email was sent, no platform was contacted, and that no address was moved out of the do-not-contact file.

Built from the best public work on this

Sources for win-back

Everything below was opened and read on 14 September 2026. Nothing is cited that could not be loaded, with one exception noted in full at section 3.

1. Information Commissioner's Office, "Respect people's preferences"

https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/respect-peoples-preferences/, no publication date shown on the page, read 14 September 2026.

This page contains the sentence that decides what a win-back campaign may and may not be. Under "Respect their objection", the ICO writes: "If someone has objected to your direct marketing, you can't contact them at a later date to ask if they've changed their mind. This contact would still be for direct marketing purposes that they have specifically objected to."

It then describes the only narrow thing you may do, and the skill quotes the limits rather than the permission: "you may be able to remind people about their direct marketing preferences, if the reminder forms a minor and incidental addition to a message that you are sending anyway. The content must be for another purpose and not include marketing material. For example, an annual statement that includes a message at the end saying how they can update marketing preferences (but not encouraging them to change their mind)." A restaurant sends no annual statements, so in practice this exception is not available to the businesses this pack is written for.

The page also supplies the asymmetry that step 1 relies on. An objection is general; an opt-out "is more likely to cover a specific method of contact or a particular direct marketing activity". Its worked example has a customer texting STOP while continuing to receive email, and the company being compliant in continuing the email. That is why the do-not-contact file records the channel and not only the address. And it supplies the suppression rule already quoted in this pack: deleting an objector rather than suppressing them is what caused the breach in the ICO's own example.

Where the skill departs: the ICO permits a single confirmation message after an opt-out, "to confirm they have unsubscribed and provide information about how to resubscribe if they change their mind". The skill does not use this in a win-back context, because a message mentioning resubscription to someone who has just left is one drafting error away from the thing that is prohibited.

2. Information Commissioner's Office, "Identify direct marketing"

https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/identify-direct-marketing/, page shows "Latest updates - 20 August 2025", read 14 September 2026.

The page that makes the prohibition make sense, because on its own the objector rule sounds like a technicality. It explains that direct marketing purposes are wider than direct marketing messages, and that the activities included cover "contacting people to ask them for consent to direct marketing".

Its example is written for exactly this pack's audience: "A hotel sends an email to its previous guests asking them if they would like to consent to receiving its special offers and discounts. Whilst this email doesn't contain any of these discounts or offers, the hotel is still sending it for direct marketing purposes." A hospitality owner reading that recognises the plan they were about to execute.

The same page draws the service message line a well-meaning venue will try to hide behind. Service messages are "for administrative or customer services purposes", and the ICO's examples include messages to "check their contact details are correct". A reader could stop there and conclude that "Are your details correct?" is a service message. Section 3 below is what happens when a company does exactly that. The reconciling sentence is on this page too: "If your service message has elements that are direct marketing, even if that is not the main purpose of your message, then it will count as direct marketing", and "simply using a neutral tone doesn't necessarily avoid messages being direct marketing... the context in which you send the message is also important."

Where the skill departs: the ICO offers a test for borderline cases and invites the reader to weigh phrasing, tone and context. The skill does not invite a small business owner to make that judgement about their own campaign, because the incentive runs one way and the downside is a penalty. It gives a bright line instead: if the purpose of the email is to get somebody back onto a marketing list, it is marketing.

3. Information Commissioner's Office press release, "ICO warns UK firms to respect customers' data wishes as it fines Flybe and Honda", 27 March 2017

Read at https://www.wired-gov.net/wg/news.nsf/articles/ICO+warns+UK+firms+to+respect+customers+data+wishes+as+it+fines+Flybe+and+Honda+27032017142000, which reproduces the ICO's official press release in full and labels it as such, read 14 September 2026.

Stated plainly: the ICO's own copy of this release no longer resolves. The action-we-have-taken pages for both penalties, the 2017 news URLs and the monetary penalty notice PDFs at their usual paths all returned 404 when tried on 14 September 2026. What was read is a verbatim reproduction of the ICO press release hosted by wired-gov.net, a public sector news service, including the release's own Notes to Editors reproducing the regulation 22 rules. The figures and the quotation below come from that page and nowhere else.

The facts it gives: Flybe "deliberately sent more than 3.3 million emails to people who had told them they didn't want to receive marketing emails from the firm"; the emails, sent in August 2016, carried the title "Are your details correct?" and "advised recipients to amend any out of date information and update any marketing preferences", adding that "by updating their preferences, people may be entered into a prize draw"; the airline was fined £70,000. Honda Motor Europe "had sent 289,790 emails aiming to clarify certain customers' choices for receiving marketing" and "believed the emails were not classed as marketing but instead were customer service emails"; it was fined £13,000.

The quotation that carries the whole point, attributed in the release to Steve Eckersley, then ICO Head of Enforcement: "Both companies sent emails asking for consent to future marketing. In doing so they broke the law. Sending emails to determine whether people want to receive marketing without the right consent, is still marketing and it is against the law." And his warning, the sentence to hand an owner planning a tidy-up before a new system goes in: "Businesses must understand they can't break one law to get ready for another."

Where the skill departs, and it matters: this is a 2017 action under the Data Protection Act 1998 and the pre-GDPR regime, against two large companies sending millions of emails, and the penalty ceiling described in the release is £500,000 rather than today's. The skill does not tell an owner they face a £70,000 fine. It uses the case for one thing only: a regulator has actually enforced this rule against the specific email a win-back campaign is tempted to send, and the "it was a service message" defence was tried and did not work.

4. The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22, and ICO "Plan direct marketing"

https://www.legislation.gov.uk/uksi/2003/2426/regulation/22, in-force text carrying amendments commenced 5 February 2026, and https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/, sibling pages showing a latest update of 20 August 2025. Both read 14 September 2026.

Used together for step 5, the part owners skip. Regulation 22(3)(a) ties the soft opt-in to details obtained "in the course of the sale or negotiations for the sale of a product or service", and 22(3)(b) limits it to "that person's similar products and services only". The ICO's gloss turns that into a test you can apply to a four-year-old row: the similar products limb means "you can't send messages about things that people wouldn't reasonably expect from you in that context". On consent it adds that "Consent for direct marketing does not last forever" and depends on "people's expectations and their relationship with you", and on third parties that "we generally recommend that you should not use consent for direct marketing that was given via a third party more than six months ago".

Where the skill departs: neither source names a point at which a soft opt-in dies, because there is not one, and the skill does not invent one. It requires the owner to state the age of the route in the file and to move anything they would not be comfortable explaining into the expired file, which puts the judgement where it belongs and leaves it visible.

5. Yahoo, "Sender Best Practices", and Google, "Email sender guidelines"

https://senders.yahooinc.com/best-practices/ and https://support.google.com/a/answer/81126, no publication date shown on either page, both read 14 September 2026.

The commercial half of the risk, as distinct from the legal half. Yahoo advises senders to "Monitor hard and soft bounces as well as inactive recipients", to "Remove invalid recipients from your list promptly" and to "Consider sending a reconfirmation email to inactive subscribers periodically". Google warns: "Avoid introducing sudden volume spikes if you do not have a history of sending large volumes", and "If messages start bouncing or start being deferred, reduce the sending volume until the SMTP error rate decreases."

That is step 8. A win-back send is the highest-risk send a venue ever makes, because every characteristic these two pages warn about is present at once: old addresses, high bounce probability, unengaged recipients and a volume spike against a quiet baseline.

Where the skill deliberately departs from Yahoo: it suggests "sending a reconfirmation email to inactive subscribers periodically". For a UK sender that collides directly with sections 1 to 3 above the moment the inactive subscriber is an objector, and it collides with the hotel example even when they are not. The skill takes Yahoo's hygiene advice, rejects its reconfirmation advice, and says why rather than quietly dropping it. A deliverability page written for a global audience is not a compliance source for the United Kingdom.

Best public prompt we found for this job

The best public artefact is the `email-sequence` skill in Anthropic's `knowledge-work-plugins`, raw source at https://raw.githubusercontent.com/anthropics/knowledge-work-plugins/main/marketing/skills/email-sequence/SKILL.md. The repository has 24,016 stars, read from api.github.com on 14 September 2026. It carries both a re-engagement and a win-back template, and the line worth copying is its suppression instruction:

**Suppression rules** - do not send if the recipient is already in another active sequence, has unsubscribed from marketing, or has contacted support in the last 48 hours

The third clause is the thoughtful one and most small venues never think of it: somebody who complained on Friday should not receive "we miss you" on Monday. Step 6 is that idea widened out.

What we did not copy is most of the rest. Its win-back template runs to "3-5 emails over 30 days"; the skill here caps at three, because CAP Code rule 10.1 prohibits persistent and unwanted marketing communications and a five-email sequence to somebody who has ignored the first four is the definition of persistent. Its re-engagement template escalates to "Last chance with clear deadline"; we require any deadline to be real under rule 8.22. It instructs the model to supply expected open, click, conversion and unsubscribe benchmarks per sequence type, with no publisher and no date attached to any of the figures, and this skill states no such figure anywhere. And, most importantly, nothing in it distinguishes a lapsed customer you may lawfully email from one who has objected. That distinction is the entire first half of this skill, it is the thing the ICO has actually fined companies over, and a generic sequence generator cannot supply it because it never sees the list.

Want this running in your business?

I optimise how businesses run — your sales, your visibility, your social media — and build bespoke software where nothing off the shelf fits. The first conversation is free. Work starts from £150 a day.