Acceptable Use Policy
Last updated: July 10, 2026 | Effective: July 10, 2026
This Acceptable Use Policy (“AUP”) sets the rules for using AYBIZA — its AI voice and chat agents, CRM and service desk, automations and analytics, internal channels, APIs, MCP tools, webhooks, and integrations. It applies to every account holder, authorized user, and any system acting on their behalf. It is part of, and governed by, our Terms of Service. Violations can lead to immediate suspension or termination.
1. Scope and permitted use
AYBIZA is for lawful business use only. Typical permitted uses include:
- Deploying AI agents for customer support, sales, appointment scheduling, lead qualification, and other legitimate business communication.
- Running your operations through the CRM and service desk — sales pipelines, support tickets, and projects.
- Directing and approving your agents, and connecting MCP tools, through internal channels.
- Building integrations on our APIs and MCP tools for legitimate workflows.
You must comply with all applicable laws, and you must obtain every required consent before you contact anyone or process anyone’s personal data.
2. Prohibited activities
Illegal and harmful activities
- Using the Services for any purpose that violates applicable local, state, national, or international law.
- Facilitating fraud, deception, identity theft, money laundering, or terrorist financing.
- Transmitting or generating malware, ransomware, spyware, or any malicious code.
- Facilitating human trafficking, exploitation, or child sexual abuse material (CSAM).
- Using the Services for illegal drugs, weapons trafficking, illegal gambling, or other unlawful trade.
Unsolicited and unlawful communications
- Placing outbound calls or messages without the legally required prior consent under the TCPA, FCC rules, GDPR, and applicable state and international law.
- Contacting numbers on the National Do Not Call Registry, or any applicable state or internal do-not-call list, without a valid exemption.
- Sending unsolicited commercial messages (spam) through any channel — voice, chat, email, or any messaging platform you reach through the Services or your own integrations.
- Placing calls or messages to emergency service numbers (911, 112, 999, or equivalents).
- Transmitting false or misleading caller ID or email header information, or spoofing your identity.
- Failing to honor an opt-out, or failing to include a working unsubscribe mechanism and valid physical address in commercial email, as required by CAN-SPAM.
AI agent misuse
- Deploying AI agents that fail to disclose they are AI where the law requires disclosure.
- Configuring an agent to deny being AI, or to claim to be a specific human, when asked.
- Cloning or imitating the voice of an identifiable real person without their prior written consent.
- Impersonating emergency responders, law enforcement, government officials, or licensed professionals in a misleading way.
- Disabling or circumventing AYBIZA’s compliance controls, including AI-disclosure prompts, opt-out detection, and content filtering.
- Using agents for deepfakes, non-consensual intimate imagery, fake reviews, astroturfing, social engineering, or phishing.
Platform and infrastructure abuse
- Attempting to gain unauthorized access to AYBIZA systems, other customer accounts, or other customers’ data.
- Probing or scanning our systems for vulnerabilities without prior written authorization from our security team.
- Exceeding documented API rate limits, or intentionally degrading service for other customers.
- Circumventing or interfering with usage metering, credit consumption, or billing.
- Reverse-engineering, decompiling, or replicating AYBIZA’s proprietary software and platform architecture.
- Scraping or using automated means to extract data from the platform, website, or APIs beyond what we expressly permit.
- Reselling or providing access to the Services to third parties without our written authorization, or creating multiple accounts to evade limits or enforcement.
Data misuse
- Selling, renting, or commercially distributing the personal data of individuals processed through AYBIZA.
- Combining data processed through AYBIZA with other sources to build unauthorized profiles or surveillance databases.
- Processing special categories of personal data (such as health, biometric, genetic, or financial data) without a valid legal basis and, where required, explicit consent.
- Using data processed through AYBIZA beyond the purposes allowed by your agreement, your privacy policy, and your data subjects’ consent.
Harmful content
- Generating or distributing hate speech targeting people based on race, ethnicity, national origin, religion, gender, gender identity, sexual orientation, disability, or any other protected characteristic.
- Harassing, bullying, threatening, or intimidating any individual through any channel.
- Content that promotes self-harm, suicide, or dangerous activities, or that exploits or endangers minors.
- Disinformation campaigns or coordinated inauthentic behavior designed to mislead the public, and content that promotes terrorism or violent extremism.
3. Outbound communications
When you send calls or messages through AYBIZA, you are the legally responsible sender. The full allocation of telecom duties — consent standards, caller ID accuracy, and your indemnity for outbound programs — lives in our Terms of Service. In addition, these product-specific operating duties apply to your outbound programs:
- DNC scrubbing. Scrub your contact lists against every applicable do-not-call registry at least every 31 days before you dial or message.
- Calling hours. Place calls only between 8:00 AM and 8:00 PM in the called party’s local time, and observe any stricter state limits.
- Opt-out. Honor a request to stop made by any reasonable means, and process it within 10 business days. You may not require contacts to use a single exclusive opt-out method.
- Consent records. Keep consent records — including any voice-clone consent — for at least five years, or longer where the law requires.
- Call recording. Where recording requires the consent of all parties, obtain that consent before recording.
- AI-voice disclosure. Disclose that the call uses an artificial or AI-generated voice at the start of the call (California AB 2905), and within the first 30 seconds where required (Texas SB 140).
Scheduled and batch outbound calls are subject to every duty above.
4. AI disclosure and high-risk decisions
Your agents must tell people they are AI when the law requires it. For voice calls, an artificial or AI-generated voice triggers TCPA disclosure duties (FCC 24-17) and state disclosure laws. For commercial chat, disclose the bot to consumers where required (California Bot Disclosure Law, Bus. & Prof. Code §17940). Where an agent’s output reaches people in the EU, provide the transparency notice required by the EU AI Act (Article 50). An agent must never affirmatively deny being AI when asked.
No fully automated consequential decisions. You may not use AYBIZA to make a final decision that has a legal or similarly significant effect on a person — including employment, credit, housing, or insurance — without meaningful human review and compliance with the laws that govern that decision.
5. Regulated industries
Some uses carry extra legal duties, and you remain responsible for your own compliance in every case.
- Healthcare. No Protected Health Information may be processed without an executed Business Associate Agreement; see the HIPAA terms in our Terms of Service.
- Financial services. Nonpublic personal financial information is subject to the GLBA Safeguards Rule and fair-lending laws — contact us before activating.
- Debt collection. Use for debt collection must meet FDCPA and Regulation F requirements and state licensing — contact us before activating.
- Political outreach. Political calls and advocacy carry extra FCC and disclosure duties — contact us before activating.
- Legal services. Agents must not give legal advice or imply an attorney-client relationship, and must include a clear disclaimer — contact us before activating.
6. Channel and provider policies
When you connect a channel or provider, you must follow that channel or provider’s own rules, not only ours. This includes:
- Messaging registration. Your own messaging integrations must complete and honor your carrier’s application-to-person messaging registration and policies, such as US A2P 10DLC, and any carrier messaging rules.
- Messaging-platform policies. Follow the business messaging policies of any messaging platform you connect through the Services or your own integrations.
- BYOK providers. If you bring your own keys, you are solely responsible for complying with your chosen model provider’s terms and usage policies, for the security of your keys, and for rotating and notifying us if a key is compromised. AYBIZA is not responsible for content those providers generate or for actions they take against your account.
7. Embedded widget
If you embed an AYBIZA chat widget on your own site, you must:
- Post your own privacy notice where the widget appears, describing what you collect and why.
- Avoid deceptive or hidden data collection through the widget.
- Not target the widget at children or use it to knowingly collect data from minors.
8. Monitoring, enforcement, and reporting
We may — but are not obligated to — monitor use of the Services for AUP compliance, using automated systems, manual review, or both. Choosing not to act on a violation does not waive our right to act later.
Reporting. To report a suspected violation, platform abuse, or a security concern, contact info@aybiza.com. You may report anonymously, and we will not retaliate against good-faith reporters.
Consequences. We may take any of these actions, at our discretion and in proportion to the violation:
- Warning with a timeframe to fix the issue.
- Feature restriction, such as pausing outbound communications while the account stays otherwise active.
- Suspension of account access pending investigation or remediation.
- Termination of the account without refund.
- Regulatory reporting to authorities such as the FCC, FTC, state attorneys general, or data protection authorities.
Immediate action without warning may follow severe violations — including illegal activity, unauthorized access, CSAM, serious telecom violations, conduct posing imminent harm, or anything that exposes AYBIZA to significant legal or regulatory risk.
9. Changes and contact
We may update this AUP. We will announce material changes by email to your registered address at least 30 days before they take effect; minor clarifications may take effect without notice. The current version is always at aybiza.com/aup, and continued use after a change takes effect means you accept it.
Questions or reports: info@aybiza.com
AYBIZA LLC, a Wyoming limited liability company. Business address: 32222 Tamina Rd Ste A5-11, The Woodlands, TX 77354. Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801.