1. Purpose and Incorporation
This Acceptable Use Policy (the “AUP”) governs every use of the Satalya Service, including the AI Dialer, the Classic Dialer, the website, support channels, and any invitation or credential. It is incorporated into the Terms of Service. Capitalised terms have the meanings given in the Terms unless defined here.
The AUP exists to make one point legally and operationally clear: Satalya is a private software tool for Lawful Businesses. It is not a platform for fraud, social engineering, identity theft, unauthorised intrusion, or any other crime. If you use the Service badly, you — and not Satalya — bear the legal, civil, criminal, and financial consequences.
Satalya may refuse, suspend, or permanently terminate access where it has reasonable suspicion that this AUP has been or will be violated. Satalya is not required to prove a criminal conviction before acting.
2. Lawful-Use Mandate
The Service may be used only for purposes that are lawful in: (a) your place of establishment; (b) the place from which the communication is initiated; (c) the place in which the recipient is located, if known or reasonably knowable; and (d) any other jurisdiction whose law applies to the communication or the data.
You must maintain, at your own cost, all licences, registrations, and consents required for outbound calling, call recording, automated calling, marketing, collections, or client communications. Satalya does not obtain those permissions for you and does not verify that you have them.
A use that is customary in one industry is not therefore lawful. You must not treat industry practice, competitor behaviour, or the mere availability of a feature as legal authority.
3. Absolute Prohibitions
The following are strictly prohibited. Attempt, assistance, conspiracy, and wilful blindness are treated as violations.
3.1 Fraud and deception
You must not use the Service to commit, prepare, or facilitate fraud, including advance-fee fraud, romance or investment scams, invoice redirection, authorised-push-payment fraud, fake invoices, fake technical-support schemes, or any other deception intended to obtain money, crypto-assets, goods, or data.
3.2 Phishing and credential harvesting
You must not use the Service for phishing, vishing, smishing, or any attempt to induce a person to disclose passwords, one-time codes, recovery phrases, card numbers, bank details, or other credentials. You must not operate “verification” calls that imitate banks, payment firms, government agencies, delivery companies, or employers for that purpose.
3.3 Impersonation and identity misuse
You must not impersonate any natural person, legal person, public official, or brand. You must not claim to be Satalya, a bank, a tax authority, a police force, a court, or any other institution you are not. You must not use another person’s identity documents, voice, or personal data to open or operate an Account.
3.4 Financial crime and money laundering
You must not use the Service to launder money, place or layer criminal proceeds, evade sanctions, finance terrorism, operate unlicensed money transmission, or conceal beneficial ownership. You must not use calling campaigns to recruit money mules or to instruct recipients to move funds in a manner that would constitute money laundering.
3.5 Unauthorised access
You must not use the Service to gain, attempt, or facilitate unauthorised access to any computer, account, network, voicemail, or data. You must not probe Satalya systems except with prior written authorisation for a bona fide security assessment.
3.6 Misuse of others’ data
You must not upload, enrich, sell, or call against personal data obtained by hacking, scraping in breach of law, purchase from an unlawful source, or any other method lacking a lawful basis. You must not use the Service to dox, stalk, or compile dossiers for unlawful purposes.
3.7 Other illegal activity
You must not use the Service for any other illegal activity, including harassment, threats, extortion, child sexual exploitation (which will be reported), trafficking, drug trafficking, or the distribution of malware. This list is illustrative, not exhaustive.
4. Calling, Messaging, and Consent Rules
You must honour do-not-call, do-not-contact, and opt-out requests promptly. You must not call or message persons who have not been lawfully included in your programme. You must not use automated or AI-assisted calling where the applicable law requires prior express consent and you do not have it.
You must not call emergency numbers, premium-rate numbers for abuse, or numbers you know belong to persons who must not be contacted. You must comply with calling-time restrictions, identification requirements, and recording-notice rules in every relevant jurisdiction.
Collections use is permitted only where you have a lawful mandate and comply with collections and consumer-protection law. “Collections” is not a licence to threaten, deceive, or disclose debts to third parties unlawfully.
5. Identity, CLI, and Impersonation
You must present calling-line identity and organisational identity accurately to the extent the Service and upstream carriers allow. You must not spoof CLI, CNAM, or brand presentation in order to deceive a recipient about who is calling or why.
You must not instruct the AI Dialer to adopt the persona of a public authority, bank, or other trusted institution. Classic Dialer use is subject to the same identity rules. Human operators are not permitted to do what the AI is forbidden to do.
6. Data, Lists, and Third-Party Information
You are the controller of list data. You must be able to demonstrate a lawful basis for each record. You must not upload lists of children, special-category data, or criminal-offence data unless a written addendum authorises it and a lawful basis exists.
You must not use the Service to verify stolen card numbers, to test whether an identity is “live”, or to enrich a file of compromised credentials. You must not resell Satalya outputs as a skip-tracing product in violation of law.
7. Security and Unauthorised Access
You must protect credentials, enable available security controls, and restrict staff access to those who have a need to know. You must not share logins on public forums or with unknown vendors. You must not attempt to bypass rate limits, invitation controls, or geographic blocks.
Vulnerability research against Satalya is permitted only with prior written authorisation. Unauthorised testing is a breach of this AUP and may be a criminal offence.
8. Financial Crime and Crypto-Related Misuse
If you pay in cryptocurrency, you remain bound by the Cryptocurrency Payment Terms in the Terms of Service. You must not use those payment rails to obscure the source of funds. You must not use the Service to promote unlicensed investment schemes, fake recovery services, or “giveaway” scams.
Satalya may request source-of-funds information and may refuse or reverse onboarding where the explanation is inadequate. Refusal is not an accusation; it is a risk decision.
9. AI-Specific Restrictions
You must not prompt the AI Dialer to lie about identity, to claim legal powers it does not have, to threaten arrest, to request remote-access software, to request seed phrases, or to walk a recipient through a payment that the recipient does not already owe under a lawful relationship.
You must review AI scripts before production use. You must not treat model output as legal advice or as a factual record of the recipient’s circumstances. You must disable or correct any behaviour that tends toward Prohibited Activity, even if the model produced it without your specific sentence-level instruction.
The existence of an AI mode does not create a defence of “the software did it”. You chose the tool, the list, the prompt, and the campaign.
10. Customer Supervision Duties
You must train staff on this AUP, monitor campaigns, keep records sufficient to show consent and purpose, and terminate internal users who violate this AUP. You must not incentivise staff in a manner that foreseeably produces unlawful calling.
If you discover misuse, you must stop the campaign, preserve relevant records, and notify legal@satalya.com without undue delay. Notification does not immunise you, but concealment is an aggravating factor in Satalya’s termination decision.
11. Investigation, Suspension, and Termination
Satalya may investigate suspected violations, including by reviewing metadata, limited content, payment information, and correspondence. Satalya may suspend an Account pending inquiry. Suspension may be silent if notice would risk evidence destruction or further harm.
Where Satalya has reasonable suspicion of unlawful use, it may permanently terminate the Account, retain fees to the extent permitted by the Refund Policy and applicable law, preserve data for potential legal process, and decline any future request from related persons or entities.
Satalya has no duty to restore an Account. Appeals may be sent to legal@satalya.com. An appeal is a request, not a hearing, and creates no right of reinstatement.
12. Reporting and Law Enforcement
Satalya cooperates with competent authorities only when legally obliged or when valid legal process so requires, as more particularly described in the Terms of Service and the Compliance Policy. Satalya may also make a report where it reasonably believes there is an imminent risk of serious harm and a mandatory reporting duty or a narrowly tailored necessity exists.
Private complainants should provide evidence to legal@satalya.com. Satalya is not a court and does not adjudicate disputes between a Customer and a called party, except to decide whether to keep an Account open.
13. Relationship to Other Documents
Breach of this AUP is a material breach of the Terms of Service. The Warranty Disclaimer, Limitation of Liability, and Indemnification clauses in the Terms apply to all AUP matters. The Disclaimer confirms that Satalya is not responsible for your misuse. The Compliance Policy describes Satalya’s internal posture; it does not authorise any Prohibited Activity.
Questions: legal@satalya.com. A question does not grant permission. Only a written instrument signed by Satalya can vary this AUP.
Annex A — Internal Use by Customer Staff
Every person who receives a Satalya credential is bound by this AUP as if they had signed it. The Customer must impose this AUP on employees and contractors by written instruction. A staff member’s ignorance is not a defence for the Customer. A contractor’s separate legal personality is not a defence if the Customer supplied the credential or the list.
The Customer must maintain an internal register of users, revoke access on role change, and prohibit shared generic logins where individual attribution is feasible. If Satalya provides workspace roles, the Customer must use them in a least-privilege manner.
Annex B — Evidence Satalya May Consider
Without limitation, Satalya may treat any of the following as supporting reasonable suspicion: recipient complaints describing impersonation or payment extraction; scripts that request credentials or remote-access tools; calling patterns inconsistent with the access request; sanctions or adverse-media hits; payment from a high-risk wallet; spoofed identity presentation; refusal to identify beneficial owners when asked; or simultaneous use of the Account from mutually inconsistent geographies without explanation.
Satalya may weigh evidence in the aggregate. A single weak signal may be insufficient; several aligned signals may be sufficient. Satalya is not required to share its full investigative file with the Customer.
Annex C — Restoration Is Exceptional
If an Account is restored after suspension, restoration may be conditioned on script changes, volume caps, additional attestations, or payment of investigation costs. Restoration is exceptional. Most AUP terminations are permanent.
This AUP may be updated as described in the Terms. The version on the website at the time of the relevant conduct applies, together with any stricter version you accepted later if that later version is more favourable to enforcement of lawful-use rules.
14. Detailed Prohibitions — Fraud and Social Engineering
Without limiting Section 3, the Customer shall not design, test, rehearse, or deploy any conversation, whether spoken by a human operator using the Classic Dialer or generated or assisted by the AI Dialer, that is reasonably likely to induce a recipient to act on a false premise concerning identity, authority, urgency, legal process, account compromise, or the existence of a debt, prize, job, investment, shipment, tax, or refund. The prohibition applies even if the Customer subjectively believes the recipient “ought to know” the call is commercial.
The Customer shall not use urgency tropes that imitate public authorities, including countdowns to arrest, deportation, account seizure, or warrant execution, unless the Customer is in fact that authority and the statement is true. Satalya is a software vendor and is never a public authority. No Customer may state or imply that Satalya itself is conducting an investigation of the recipient.
The Customer shall not request remote-access software, screen-sharing for the purpose of watching a recipient open a wallet or banking application, one-time passcodes, recovery phrases, card verification values, or photographs of identity documents, except where the Customer already has a pre-existing, documented, lawful relationship that independently requires identity verification under a written policy and the request is not made by impersonation. Even then, the Customer remains solely responsible for the lawfulness of that verification.
15. Detailed Prohibitions — Financial Crime
The Customer shall not use the Service to place, layer, or integrate criminal property, to recruit money mules, to instruct recipients to purchase gift cards, cryptocurrency, or precious metals for a stranger, or to operate an unlicensed payment, remittance, or investment scheme. The Customer shall not describe Satalya, in any script, as a bank, exchange, recovery firm, or government compensation programme.
If the Customer’s lawful business is collections, the Customer must possess a valid mandate, must identify the creditor accurately, must not threaten action the Customer cannot lawfully take, and must not disclose the alleged debt to third parties except as permitted by applicable law. Collections use does not authorise deception.
If the Customer’s lawful business is sales, the Customer must not sell investments, credit, insurance, or other regulated products through the Service unless the Customer holds every required licence and the call complies with the conduct rules of every relevant regulator. Satalya does not sponsor, introduce, or approve any financial product.
16. Detailed Prohibitions — Data and Lists
The Customer shall not upload lists obtained from unauthorised access to a computer, from a data-breach dump, from scraping that violates law or a website’s enforceable terms where such scraping is unlawful, or from a broker that cannot explain a lawful source. The Customer shall not use the Service to “cleanse” a file of stolen identities by seeing who answers the telephone.
The Customer shall not combine Satalya usage data with other sources in order to build a dossier for stalking, discrimination that is unlawful in the relevant jurisdiction, or political micro-targeting that the Customer is not permitted to conduct. The Customer shall not transfer list data to another Satalya Account in order to evade a suspension.
The Customer shall honour suppression requests at the organisation level, not merely at the individual user level. If one operator is told to stop calling, the Customer’s other operators and the AI Dialer must also stop, unless a distinct lawful basis independently applies and is documented.
17. Technical Abuse
The Customer shall not attempt to exceed rate limits, to enumerate other tenants, to extract model weights, to bypass invitation controls, to forge administrative tokens, or to interfere with metering. The Customer shall not use the Service as a traffic generator for denial-of-service against a third party. Load testing against Satalya requires prior written authorisation.
The Customer shall not publish credentials, invitation links, or internal documentation. The Customer shall not offer Satalya access for sale on a marketplace. Any such offer is a material breach and a ground for permanent termination without refund.
18. Recording, Transcripts, and Quality Monitoring
Where the Service makes recording or transcription available, the Customer must give any notice required by the law of the caller’s location and the recipient’s location, and must not record a line in a two-party-consent jurisdiction without the required consents. The Customer must secure recordings, limit access, and delete them when the purpose expires, subject to legal holds.
The Customer must not use recordings to blackmail, to humiliate, or to train a public model in violation of the Terms. The Customer must not represent a transcript as a certified official record of a court or regulator.
19. Cross-Border Campaigns
A campaign that crosses borders must satisfy the stricter of the applicable rules when those rules cannot be reconciled. The Customer must not treat a permission available in one country as a licence to call the world. The Customer must not route calls through Satalya for the purpose of concealing the true originator from a regulator.
20. Complaints Handling by the Customer
The Customer shall maintain a published or readily provided complaint channel for persons it contacts. The Customer shall not instruct recipients to “call Satalya” as if Satalya were the originator. Satalya may forward a complaint to the Customer and may independently suspend the Account.
21. Representations Repeated
Each time the Customer launches a campaign, the Customer repeats the representations in the Terms that it is a Lawful Business, that the list is lawfully held, that the script is not a Prohibited Activity, and that staff have been trained on this AUP. A campaign launch is an electronic affirmation of those representations.
22. No Safe Harbour by Silence
If Satalya does not comment on a script the Customer sends for “review”, that silence is not approval. Satalya has no duty to pre-clear campaigns. The Customer may not market itself as “Satalya-approved” or “compliance-certified by Satalya”.
23. Survival and Construction
This AUP survives termination as to conduct occurring during the term and as to residual duties of deletion, cooperation with compulsory process, and indemnification. Ambiguity shall not be construed against Satalya as drafter to the extent a court would otherwise do so; the parties are commercial actors and the Customer had an opportunity to read the instrument before requesting access.
For questions of interpretation, write to legal@satalya.com. An interpretive email from Satalya, if issued, controls only the point it addresses and does not waive any other clause.