If you are a current user, it's possible GPDR actually
requires them to send you notices of changes to policy and practices (where relevant to GPDR), without an opt-out?
At any rate, it seems good practice to send such notifications. I don't believe you can usually opt out of "business communications" like this.
Now, letsencrypt is a free service, and they may not be as good as they should about identifying who is a current user? If you don't have have certs that haven't expired, and they're still including you in business communications, then perhaps something isn't as targeted as it could be.