These Legal Documents are binding, internally consistent, and apply to the invite-only Satalya AI Dialer and Classic Dialer. There is no public registration. Misuse is the User’s sole responsibility.
Lawful businesses only. Fraud, phishing, impersonation, financial crime, money laundering, unauthorized access, and abuse of third-party data are strictly prohibited. Satalya and its project creator are not liable for a client’s unlawful use, to the maximum extent permitted by law. We may refuse, suspend, or permanently terminate any account on reasonable suspicion.
1. Purpose and Status
This Acceptable Use Policy (the “AUP”) is incorporated into the Satalya Terms of Service. It states rules that apply to every User of the website, the AI Dialer, the Classic Dialer, and any related system. Capitalized terms have the meaning given in the Terms unless defined here.
The AUP exists because communications software can cause serious harm if used for deception or crime. Satalya offers the Services only for lawful business. This AUP is a condition of access. Breach is a material breach of the Terms.
The examples below are illustrative, not exhaustive. Conduct that is substantially similar, or that is unlawful even if not listed, is prohibited. If you are unsure whether a campaign is permitted, you must not proceed until you have obtained your own legal advice and, if we request it, our written confirmation. Our confirmation, if given, may be withdrawn and is not legal advice to you.
2. Lawful Business Use Only
You may use the Services only to conduct legitimate commercial, professional, or institutional activities that you are authorized to conduct, including lawful outbound sales, customer support, account servicing, and operations. You must hold all licenses, registrations, and consents required for those activities.
You must not use the Services as an anonymous or disposable calling layer, as a tool to hide identity from victims, or as infrastructure for a scheme that would be unlawful if performed by any other means.
Satalya does not authorize use by unincorporated “teams” that cannot identify a responsible legal person. We may require a registered entity name, registration number, and business address.
3. Absolute Prohibitions — Fraud, Phishing, and Impersonation
You must not use the Services to commit, attempt, plan, test, or facilitate fraud. This includes inducing a person to pay money, disclose credentials, install software, or take any action by deception.
Phishing, vishing, smishing-adjacent call programs, and any contact that impersonates a bank, payment provider, tax authority, law-enforcement agency, delivery company, technology vendor, employer, or other trusted party are strictly forbidden, including “test” campaigns and so-called social-engineering exercises directed at persons who have not given informed written consent as part of an authorized security engagement.
Identity theft, synthetic-identity use, and the presentation of false names, false companies, or false caller identity for the purpose of misleading the recipient are prohibited. Technical capability to set a caller name or number does not grant a right to impersonate.
Advance-fee, romance, investment, cryptocurrency-recovery, tech-support, and government-impostor schemes are prohibited without exception.
4. Absolute Prohibitions — Financial Crime and Money Laundering
You must not use the Services in connection with money laundering, terrorist financing, unlicensed money transmission, structuring, or concealment of the source, ownership, or destination of funds.
You must not use the Services to solicit investments or credit in violation of securities, payments, or consumer-finance law, or to operate an unregistered financial product.
You must not use the Services to collect or relay payment-card data, one-time passwords, seed phrases, or account-recovery codes.
If your lawful business is licensed collections or financial servicing, you must operate only within that license, only with accounts you are entitled to work, and only with scripts and hours that Applicable Law allows. You must not use Satalya to threaten unlawful action or to disclose debts to third parties unlawfully.
5. Absolute Prohibitions — Unauthorized Access and Data Abuse
You must not use the Services to gain unauthorized access to any computer, account, voicemail, or locked facility, or to socially engineer access credentials.
You must not load, store, or dial against lists that you know or ought reasonably to know were stolen, leaked, scraped in violation of law, or compiled without a lawful basis. Trafficking in personal data through the Services is prohibited.
You must not use the Services to harvest personal data from recipients under false pretenses.
You must not attempt to probe, scan, or test the vulnerability of Satalya systems except under a written authorization from us that defines scope and time. Accidental discovery of a vulnerability must be reported to legal@satalya.com and must not be exploited or disclosed until we have had a reasonable opportunity to remediate.
6. Telecommunications and Consumer-Protection Abuse
You must not place calls that violate do-not-call rules, consent rules, time-of-day restrictions, or abandoned-call or robocall restrictions that apply to you. You must not use automated dialing or prerecorded voice where your jurisdiction requires prior express consent and you do not have it.
You must not engage in unlawful spoofing. You must not display emergency numbers, government numbers, or a victim’s own number as the outbound identity.
You must not flood, auto-redial, or otherwise harass a person. You must honor stop requests promptly, including oral requests during a call, and you must suppress those numbers across your campaigns.
You must not use the Services for unlawful debt collection, unlawful political robocalling, or unlawful charitable solicitation.
7. Content and Conduct Standards
Client Content and live agent conduct must not include:
- content that is defamatory, obscene, or unlawfully discriminatory in the relevant jurisdiction;
- incitement to violence or crime;
- malware, malicious links, or instructions to disable security;
- content that infringes intellectual property or publicity rights;
- content directed at children in a manner that violates child-protection or children’s-privacy law;
- false statements that a recipient will be arrested, sued today, or lose essential services unless they pay or comply, unless such a statement is both true and lawful in context.
Human agents remain responsible even when the AI Dialer suggests a line. You must train agents not to follow an AI suggestion that would violate this AUP or Applicable Law.
8. Resource, Security, and Platform Integrity
You must not impose an unreasonable load on the Services, bypass rate limits, or use undocumented interfaces. You must not share credentials outside your authorized personnel. You must not resell seats as a calling bureau without written consent.
You must not introduce viruses or engage in cryptocurrency mining on our infrastructure. You must not use the Services to send bulk unsolicited email.
You must keep your integrations secure. A compromised CRM token that floods the dialer is your responsibility.
9. Sanctions, Export, and Circumvention
You must not use the Services for the benefit of a sanctioned person or jurisdiction, or to evade export or sanctions controls. You must not route traffic through Satalya for the purpose of concealing the location or identity of a restricted operator.
You must not use technical means to disguise your location from us in order to obtain an Account you would not otherwise receive.
10. Investigations, Evidence, and Cooperation
We may investigate suspected AUP violations using logs, recordings you stored, payment information, and information you provided in the access request. You must cooperate, including by providing campaign scripts, consent records, and the identity of agents, within the time we reasonably set.
Failure to cooperate is an independent breach and may result in immediate termination.
We may preserve evidence and, where the Law Enforcement Requests Policy applies, disclose it under compulsory process. We may also disclose information as needed to our professional advisers under confidentiality.
11. Enforcement
If we reasonably suspect a violation, we may, without limitation and without refund except where law requires: issue a warning; require a remediation plan; disable campaigns, numbers, or AI features; throttle usage; suspend the Account; terminate the Account permanently; delete or quarantine Client Content; apply usage-to-forfeiture of prepaid balances as liquidated compensation for investigation costs where permitted; and pursue damages and injunctive relief.
We may refuse future access to you and to persons we reasonably believe are your affiliates or successors. We may list identifiers internally to prevent re-enrollment.
Enforcement is discretionary. A decision not to enforce in one instance is not a waiver and is not a representation that the conduct was acceptable.
We are not a court. Our finding of reasonable suspicion is enough to act. You remain free to dispute the underlying facts in the forum specified in the Terms, but you are not entitled to continued access during a dispute if we reasonably believe risk continues.
12. Reporting
If you become aware that an agent or third party is using your Account in violation of this AUP, you must stop that use and notify legal@satalya.com promptly.
Third parties who believe Satalya is being used against them in a manner that violates law may write to legal@satalya.com with logs, numbers, times, and a description. We will review. We do not act as a private investigator for every complaint, and a complaint does not create a duty to a third party except as law requires.
13. Relationship to Other Documents
This AUP is consistent with the Terms, Privacy Policy, Refund Policy, Disclaimer, and Compliance Policy. Prohibited Use under this AUP is Prohibited Use under all Legal Documents. Limitation of liability, warranty disclaimer, and indemnification in the Terms apply fully to claims arising from AUP enforcement or from your breach.
We may update this AUP as described in the Terms. Questions: legal@satalya.com.
14. Industry-Specific Notes
Financial services, insurance, healthcare, legal services, collections, political organizations, and charities often have extra rules. If you operate in those sectors you must identify the extra rules that apply to you and configure the Services accordingly. Satalya does not maintain a catalog of every sector rule.
Licensed collectors must not use the AI Dialer to generate threats, to imply government affiliation, or to contact third parties except as their licensing law allows.
Healthcare and similar entities must not place protected information into notes, transcripts, or prompts unless a written arrangement covering that data is in place.
15. Testing and Red-Team Exceptions
A security test that involves calling real members of the public without their informed consent is not an authorized test. An authorized test requires: (a) a written engagement with the target organization; (b) a defined population that has consented or is in-scope employees; and (c) our prior written approval if the test will use Satalya infrastructure.
“We were only testing the script” is not a defense to phishing a member of the public.
16. Consequences Beyond the Platform
Termination under this AUP does not protect you from criminal, civil, or regulatory action by others. We may preserve evidence. We may disclose under the Law Enforcement Requests Policy.
You remain bound by indemnification, limitation of liability, and confidentiality after termination.
17. Detailed Fraud and Social-Engineering Ban
For the avoidance of doubt, the following patterns are prohibited whether or not they succeed and whether or not money changes hands: (a) calls that claim a recipient’s bank account, wallet, tax file, social-security number, or package is at risk unless the recipient dials a number, installs an application, or reads a code; (b) calls that pretend to be a helpdesk, “verified merchant”, card network, or crypto-exchange recovery desk; (c) calls that recruit money mules or ask a recipient to receive and forward value; (d) calls that sell a fabricated investment, token, or “guaranteed” return; (e) calls that impersonate counsel, a court clerk, or a process server to extract payment; and (f) any rehearsal of the foregoing against a live public list.
You must not use the AI Dialer to generate a voice, accent, or script designed to impersonate a real individual. You must not clone a third party’s voice. You must not instruct the model to “sound like a bank”.
If your lawful business includes security awareness, you may only contact persons who are in-scope under a written engagement and who have been lawfully included. You must identify the exercise in after-action materials and must not use harvested credentials from the exercise for any other purpose.
A claim that a script was “only marketing” does not legalize deception about identity, authority, or the existence of an account relationship.
18. Data Provenance and List Hygiene
Before you load a list you must be able to state: where each record came from; whether the person gave consent or whether another lawful basis applies; when that basis was obtained; and how revocation is honored. If you purchased a list, you must perform due diligence on the vendor. “Everyone does it” is not a lawful basis.
You must suppress known wrong numbers, numbers that produced a “stop” request, litigation holds that forbid contact, and numbers associated with emergency services or government switchboards that you are not authorized to call.
Enrichment of a list through skip-tracing or data brokers does not cleanse an originally unlawful compilation. You inherit the defect.
Uploading a list to Satalya is a representation that you have rights and a lawful basis. That representation is relied upon by us when we decide to keep the Account open.
19. Agent, Vendor, and Seat Control
You must not place contractors in jurisdictions that would cause a sanctions or export problem. You must not allow an unaudited call center to operate your Account as an unnamed bureau.
Each natural person who uses the Services should have identifiable access where the product permits. Shared generic logins are discouraged and, if used, remain your responsibility.
If a vendor is terminated for fraud elsewhere, you must remove that vendor from Satalya immediately and notify us if their conduct may have touched our platform.
20. Platform Abuse Examples
The following are non-exhaustive platform-integrity violations: credential stuffing against the login; scraping the website beyond ordinary browsing; attempting to escalate privileges; using the API, if any, in excess of documented rates; creating multiple access requests under false names after a refusal; and paying with a Cryptocurrency address associated with mixers or known illicit clusters if you cannot explain the source of funds when asked.
We may use blockchain-analytics or similar tools. A hit is not a finding of guilt, but it is a sufficient basis to pause onboarding or to request more information.
21. Reservation of Rights
All rights not expressly granted in the Terms are reserved. This AUP does not grant any license to use Satalya marks in your outbound caller name.
We may update illustrative examples without narrowing the general prohibitions. When in doubt, do not proceed.
22. Extended Operational Rules
This Section 22 sets out additional operative rules that apply in every jurisdiction in which you use the Services. You acknowledge that communications fraud is often transnational, that victims and investigators may sit in a different country from your agents, and that Satalya may therefore evaluate your conduct under more than one body of law when deciding whether a use is acceptable. A use that is marginally tolerated in one place may still be prohibited by this AUP if it would be unlawful or deceptive in the place where the recipient answers the phone.
You must not structure a campaign to exploit gaps between national rules. You must not place agents in a loosely regulated location for the purpose of calling into a strictly regulated location while pretending that only the agent’s location matters. You must not use number rotation, simultaneous aliases, or disposable brands to make a suppression request ineffective. You must not instruct an agent to refuse to identify the true seller. You must not run “two books” of scripts — a mild script shown to Satalya and a harsh script used live.
If you operate multiple brands, each brand’s identity must be true and must not be used to confuse a recipient about who will take their money. If you sell a third party’s product, you must have authority to represent that party. If you are an agency placing calls for a principal, both you and the principal are Users for purposes of this AUP, and each of you is responsible. Satalya may terminate the agency Account, the principal’s future access, or both.
You must maintain a complaint register. Each complaint about identity, consent, or payment should be logged with time, number, agent, and outcome. Repeated similar complaints are a signal that you must stop the campaign and investigate. Continuing after a pattern of complaints is an aggravating factor in our enforcement decision.
You must not coach agents to hang up on persons who ask for a license number, a mailing address, or a written offer, where those questions are reasonable in context. Evasion of ordinary commercial identification is treated as a deception indicator.
You must not use the Services to collect one-time passwords, card CVV codes, full magnetic-stripe or chip data, seed phrases, recovery phrases, private keys, or remote-access permissions. Any script that asks for those items is prohibited even if you claim the caller is the account holder. There is no legitimate reason to collect a seed phrase through a Satalya call.
You must not threaten arrest, deportation, utility disconnection, or immediate lawsuit unless the statement is both true and lawful for your licensed activity. Collections agents must stay inside the language their regulator allows. Sales agents must not invent a legal crisis to close a deal.
You must not target recent data-breach victims with “we can lock your account” narratives, except where you are the actual institution that holds the account and you use your own verified numbers and identity. You must not buy “lead lists” marketed as breach extracts.
When we ask for information under this AUP you must answer through the email domain we have on file, not through a newly created anonymous address. You must not coach staff to destroy evidence after we ask a question. Litigation holds, once we notify you of an investigation, require you to preserve relevant recordings and lists.
22.1 Enforcement sequence we may use
We may skip steps when risk is acute. A typical sequence is: (1) automated or human detection; (2) preservation of logs; (3) optional request for explanation; (4) feature disablement; (5) suspension; (6) termination; (7) consideration of a legally compulsory or emergency disclosure. You are not entitled to a hearing. You may send a written statement to legal@satalya.com. We will read it if we still have the Account file.
22.2 Public statements
You must not publicly claim that Satalya reviewed and approved a script unless we did so in a signed writing that describes the exact script version. A support reply that answers a technical question is not approval.
The remainder of this AUP, the Terms, and the Compliance Policy continue to apply. This long-form section is not surplus: it is an independent set of obligations. Breach of any paragraph is a material breach.