Skip to content
S Satalya
Product Contact Terms Privacy Request access

Legal

Compliance Policy

Effective: 7 September 2026 Last updated: 7 September 2026 Operator: Satalya · satalya.com
1. Policy Statement2. Governance and Roles3. Client Due Diligence4. Lawful-Use Standard5. Prohibited Conduct — Zero Tolerance6. Telecommunications Compliance Duties of the Client7. Privacy and Data-Protection Compliance8. Sanctions and Export Control9. Payments, Cryptocurrency, and Financial Crime Risk10. Monitoring, Audit, and Information Requests11. Suspension, Termination, and Refusal of Service12. Law Enforcement Requests Policy13. Complaints from the Public14. Internal Records and Training15. Relationship to Liability Allocation16. Updates and Contact17. Red-Flag Catalog for Access Review18. Ongoing Monitoring Triggers19. Record-Keeping Expectations for Clients20. Interaction with Carriers and Traceback21. No Certification Marketing22. Versioning23. Practical Operation of This Policy

These Legal Documents are binding, internally consistent, and apply to the invite-only Satalya AI Dialer and Classic Dialer. There is no public registration. Misuse is the User’s sole responsibility.

Lawful businesses only. Fraud, phishing, impersonation, financial crime, money laundering, unauthorized access, and abuse of third-party data are strictly prohibited. Satalya and its project creator are not liable for a client’s unlawful use, to the maximum extent permitted by law. We may refuse, suspend, or permanently terminate any account on reasonable suspicion.

Terms of ServiceAcceptable UsePrivacyRefundsDisclaimerCompliance

1. Policy Statement

This Compliance Policy describes how Satalya approaches lawful-use requirements, sanctions and export risk, payments including Cryptocurrency, cooperation with authorities, and the right to refuse or terminate service. It is binding on Users as part of the Legal Documents and guides our internal decisions. It is not a representation that Satalya holds a particular regulatory license, has completed a formal GDPR certification, or operates a full bank-grade anti-money-laundering program. We implement measures we consider proportionate to an invite-only software provider.

The Services exist only for legitimate businesses. We have zero tolerance for fraud, phishing, impersonation, financial crime, money laundering, unauthorized access, and abuse of third-party data.

2. Governance and Roles

Commercial correspondence is handled at contact@satalya.com. Legal and compliance correspondence is handled at legal@satalya.com. Privacy correspondence is handled at privacy@satalya.com.

Access decisions, suspensions, and disclosures under compulsory process are reserved to persons we designate. Individual support staff cannot waive the AUP.

We may engage external counsel or compliance consultants. Their involvement does not create a duty of care to you beyond the Legal Documents.

3. Client Due Diligence

Because access is invite-only, we may collect information before provisioning, including legal name, registration details, website, beneficial owners, jurisdictions of calling, nature of the business, sample scripts, and source of contact data. We may repeat diligence at renewal or upon a material change.

We may screen names and jurisdictions against publicly available sanctions lists and adverse information. Screening is risk management, not an accusation.

You must update us if your ownership, licensed status, or calling program changes in a way that would have been material to our decision.

We may refuse any applicant. We may also accept with conditions, such as Classic Dialer only, volume caps, recording disabled, or additional attestations.

4. Lawful-Use Standard

Every User must use the Services only for lawful purposes and must comply with all Applicable Law. This includes telecommunications, consumer-protection, privacy, recording, employment, collections, financial-services, marketing, and criminal law in every jurisdiction affected by a campaign.

You must be able to explain, if asked, the lawful basis for contacting each number, the source of the list, the licenses you hold, and the consent or exemption you rely on. Inability to do so is a compliance failure and may result in suspension.

Satalya does not approve campaigns by silence. Support that is technical in nature is not a compliance sign-off.

5. Prohibited Conduct — Zero Tolerance

The following are strictly prohibited and are grounds for immediate suspension or permanent termination:

  • fraud, phishing, vishing, pretexting, and social engineering directed at persons who are not participating in an authorized, consented security test;
  • impersonation of any person, brand, bank, government, or institution, and unlawful caller-identity spoofing;
  • financial crime, investment or crypto-recovery scams, unlicensed money transmission, and money laundering or terrorist financing;
  • unauthorized access to systems, accounts, or data, and trafficking in stolen or leaked personal data;
  • harassment, extortion, unlawful threats, and systematic do-not-call violations;
  • use for the benefit of sanctioned persons or to evade export or sanctions law;
  • any other crime or regulatory offense facilitated by the Services.

We need only a reasonable suspicion to act. We are not required to prove a criminal case before protecting the platform, other clients, or the public interest as we understand it.

6. Telecommunications Compliance Duties of the Client

You are the calling party and the operator of the campaign. You must implement a compliance program appropriate to your volume and industry, including: written policies; agent training; consent capture and retention; revocation handling; time-zone and calling-hour controls; abandonment-rate monitoring if you use automated dialing; caller-ID accuracy; and complaint handling.

If you use prerecorded voice, artificial voice, or AI-generated speech, you must comply with every statute that treats those technologies as restricted. If you use the Classic Dialer, the same consent and conduct rules apply.

You must not rely on Satalya to maintain your do-not-call list, although we may offer tools that help you do so. Tool failure does not transfer your duty.

7. Privacy and Data-Protection Compliance

You must process personal data in Call Data only with a lawful basis and appropriate notices. You must not upload special-category data without a written arrangement.

Where we act as processor, you instruct us only to process data for lawful campaigns. An instruction to commit a crime is void, and we may refuse it and terminate the Account.

Our Privacy Policy describes GDPR-oriented principles. It does not claim certification. You must not market Satalya as a certified GDPR product unless we have given you a written statement that such a certification exists.

If you are established in the EEA, UK, or another regime with extra-territorial rules, you remain responsible for your own controller duties even if we host infrastructure elsewhere.

8. Sanctions and Export Control

We will not knowingly provide the Services to a sanctioned person or for a prohibited end use. You must not request access if you are such a person or if you intend such a use.

You must not allow users in comprehensively sanctioned jurisdictions to operate the Account. You must not route the Services as a means of circumvention.

We may geo-filter, block payments, or terminate without notice when we believe sanctions law requires it. Amounts may be frozen or returned as those laws require; the Refund Policy yields to sanctions law.

Export-control classifications for encryption or communications software can be complex. You must not export your configurations or our software to a prohibited destination. The Terms’ Export Control section is incorporated here.

9. Payments, Cryptocurrency, and Financial Crime Risk

We may accept fiat and, at our option, Cryptocurrency. We may refuse any payment method. We may request source-of-funds information, particularly for large Cryptocurrency payments or for applicants in higher-risk sectors.

We do not operate an exchange and do not hold customer float as a money-transmission business by virtue of software invoices. If a regulator characterizes a particular flow differently, we may change payment options immediately.

You represent that payments are not the proceeds of crime. We may file a report where law requires or permits when we suspect that they are. We will not tip off a person where tipping-off is unlawful.

The Cryptocurrency Payment Terms in the Terms of Service apply in full, including irreversibility, network-fee allocation, and wrong-address risk.

10. Monitoring, Audit, and Information Requests

We may monitor metadata, volumes, complaint rates, and, where recordings are stored on our systems, samples of recordings for AUP and security purposes. You consent to that monitoring as a condition of the Services.

We may require an audit questionnaire or the production of consent records, licenses, and agent lists on reasonable notice, or immediately if we reasonably suspect Prohibited Use.

Failure to respond accurately and on time is an independent breach.

11. Suspension, Termination, and Refusal of Service

We may refuse service to any person to the fullest extent permitted by Applicable Law. We may suspend or permanently terminate an Account where we reasonably suspect Prohibited Use, sanctions risk, non-payment, security compromise, or material breach, or where a provider or authority requires us to do so.

We may do so without a court order and without a completed investigation. We may disable the AI Dialer, the Classic Dialer, or both.

Termination for compliance reasons is generally without refund, as described in the Refund Policy, except where law requires otherwise.

We may share necessary identifiers internally to prevent a terminated operator from re-entering under another name.

12. Law Enforcement Requests Policy

Satalya cooperates with competent authorities only when legally obliged to do so, except for the narrow emergency and self-protection cases described below. We do not sell data to investigators and we do not provide informal “lookups” to private parties.

Upon receipt of a request, we examine whether it is a legally compulsory instrument that applies to us — for example a warrant, court order, binding subpoena, or equivalent process — or whether another statute independently requires disclosure. If it is not compulsory and no emergency exception applies, we will not disclose Client Content merely because someone asked.

We may challenge process that we reasonably believe is invalid, overbroad, or issued by a body without jurisdiction. We are not obliged to fund litigation in every case.

Where legally permitted, we may notify the Client before disclosure. We will not notify where the process is under seal, where notice is forbidden, or where we reasonably believe notice would create a risk of death or serious harm or would frustrate an investigation in a manner the demanding authority has identified in the demand.

In an emergency involving an imminent risk of death or serious bodily injury, we may disclose limited information if we believe in good faith that disclosure is necessary and legally permitted.

We may preserve data on a valid preservation request.

Separately, if we reasonably believe the Services are being used to commit a serious crime, we may make a voluntary report to a competent authority and may share information necessary to protect Satalya, the Services, or third parties from ongoing fraud directed at us. A voluntary report is not an undertaking to monitor all traffic and does not create a duty to victims.

This policy creates no third-party beneficiary rights and does not require us to resist process at your request.

13. Complaints from the Public

Persons who believe they were contacted unlawfully through a number associated with Satalya may write to legal@satalya.com. We will review complaints that include time, calling number, called number, and a factual description.

We may contact the Client, suspend campaigns, or terminate an Account. We are not a tribunal and we do not award damages to complainants. Complainants should also use public authorities and, where appropriate, their own counsel.

A complaint does not, by itself, constitute compulsory legal process.

14. Internal Records and Training

We aim to keep records of access decisions, sanctions hits, AUP enforcement, and compulsory disclosures for a period aligned with legal-claim limitation periods and regulatory expectations for a software vendor of our size.

Personnel who handle access requests will be instructed that lawful use is a condition of sale and that they must escalate red flags rather than “close the deal”.

15. Relationship to Liability Allocation

This Policy does not make Satalya responsible for a Client’s campaigns. The Warranty Disclaimer, Limitation of Liability, and Indemnification clauses in the Terms apply to the maximum extent permitted by law, including protection of the project creator and operators from liability for a User’s misuse.

Compliance measures are for our protection and for the integrity of the platform. They are not a service-level commitment to police your industry, and they are not a warranty that unlawful use is impossible.

16. Updates and Contact

We may update this Policy as described in the Terms. Material changes will be dated on this page.

This Policy is intended to be consistent with the Terms, AUP, Privacy Policy, Refund Policy, and Disclaimer. Those documents control formation, privacy mechanics, refunds, and liability wording.

Compliance contact: legal@satalya.com. Website: https://satalya.com.

17. Red-Flag Catalog for Access Review

The following are examples of facts that may lead us to refuse or to demand more information. The list is not exhaustive and is not a promise that we will catch every problem.

  • unwillingness to name a legal entity or beneficial owner;
  • use of only anonymous email or messaging accounts with no corporate domain;
  • a proposed script that impersonates a bank, government, or “support” brand;
  • a proposal to dial leaked databases, “fullz”, or similar argot;
  • payment exclusively from a mixer, sudden third-country payer, or a person unrelated to the applicant;
  • sanctions-list proximity, including ownership by a listed person;
  • prior termination for abuse on a communications platform, if known to us;
  • a request for features whose only practical use is concealment of identity from victims;
  • inconsistency between the stated business and the requested calling volume or countries.

A red flag is not a finding. You may be asked to explain. Failure to explain to our satisfaction is enough to refuse.

18. Ongoing Monitoring Triggers

After provisioning we may reopen diligence if we observe sudden geography changes, spike patterns associated with fraud, elevated complaint volume, carrier “traceback” notices, chargeback-like payment behavior, or public allegations that we consider credible enough to investigate.

We may disable AI features first and leave Classic Dialer active, or the reverse, if that reduces risk. We may require you to stop a campaign while leaving the Account technically open.

19. Record-Keeping Expectations for Clients

You should keep, for at least the longer of your local limitation period and twenty-four months: consent logs; suppression lists; versions of scripts; agent identities per shift; and a map of which list fed which campaign. If you cannot produce these when we or a competent authority ask, we may treat the gap as a compliance failure.

You should also keep licenses and insurance certificates current and available.

20. Interaction with Carriers and Traceback

If a carrier, analytics provider, or traceback consortium contacts us about traffic that appears to originate from your Account, we may share your identity and campaign metadata with that party to the extent we believe it is necessary to respond and legally permitted. We will treat many such notices as risk events even if they are not court orders.

You must respond to our questions about a traceback on the timeline we set, which may be measured in hours, not weeks.

21. No Certification Marketing

You must not tell your customers or regulators that Satalya is “GDPR certified”, “OFAC approved”, “TCPA compliant”, or similar, unless we have issued a dated certificate that uses those words. You may say that you use a private vendor that publishes an AUP and an invite-only model.

22. Versioning

This Compliance Policy is version 2026-09-07. Prior informal emails do not survive as compliance commitments. If we publish a later version, the later version applies to conduct after its effective date, and the Terms’ modification clause applies.

23. Practical Operation of This Policy

This Section 23 describes how compliance work is done in practice so that Users cannot later say they assumed we were a silent utility.

Access requests are read. We may search public registers and the open web. We may decline without a call. We may ask for a video meeting or for documents. We may ask you to describe a day in the life of your calling floor. Implausible answers are a reason to stop the process.

If we provision you, we may still watch volume and destination mix at a summary level. We do not promise 24-hour human listening. We do promise that if a credible complaint or traceback arrives we will treat it as urgent.

Our staff are instructed not to suggest workarounds that defeat consent law, caller-ID law, or sanctions. If a staff member ever does so, that remark is unauthorized and is not a modification of the Legal Documents. You must report it to legal@satalya.com.

We may maintain an internal watchlist of names, domains, wallet addresses, and telephone numbers associated with abuse. That list is our confidential information. You have no right to know whether you are on it except as data-protection law requires us to confirm processing about you as an applicant.

We may share watchlist data with a professional adviser or with another vendor in our group if a group exists in the future, under confidentiality. We do not operate a public “bad actor” bulletin.

Training materials we give you, if any, are optional aids. They are not a complete compliance program. You must still hire your own counsel for jurisdiction-specific questions.

If law changes — for example a new restriction on AI voice — you must adjust immediately. We may disable a feature globally to reduce risk. That disablement is not a breach of contract if we continue to offer a remaining lawful mode such as the Classic Dialer, or if we refund unused prepaid fees as the Refund Policy requires for a discontinuation.

This Policy should be read yearly by your account owner. A change of your account owner should be notified to contact@satalya.com so that we know who is responsible.

S Satalya

A private AI dialer and classic dialer for lawful enterprise. Access by request only. satalya.com

Product

  • AI Dialer
  • Classic Dialer
  • Invite-only access
  • Contact

Legal

  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Refund Policy
  • Disclaimer
  • Compliance Policy

Contact

  • contact@satalya.com
  • legal@satalya.com
  • privacy@satalya.com
© 2026 Satalya. All rights reserved. For lawful businesses only. Misuse is prohibited and is the user’s responsibility.