This Acceptable Use Policy applies to Customer's use of the Services provided by Agent360 LLC and is incorporated by reference into the Terms of Service.
Last updated: April 20, 2026 · Version: v2026.04.20-4
Disclaimer: This document is a draft generated for review. Before publishing, have a licensed SaaS attorney review specifically for: IP protection, TCPA outbound compliance, CCPA compliance, and enforceability in California courts.
This Acceptable Use Policy (“AUP”) applies to Customer’s use of the Services provided by Agent360 LLC (“Agent360”). It is incorporated by reference into the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
Customer is responsible for the conduct of its users and for all activity through Customer’s account. Violations of this AUP may result in suspension or termination under Section 12 of the Terms.
1. General prohibitions
Customer will not use the Services to:
(a) Violate any law, regulation, court order, or third-party right (including privacy, publicity, intellectual property, and consumer-protection laws).
(b) Engage in fraud, deception, false advertising, identity fraud, or impersonation of any person or organization.
(c) Send unsolicited, spam, deceptive, or harassing communications.
(d) Generate or distribute defamatory, threatening, hateful, sexually explicit, or unlawful content.
(e) Interfere with or disrupt the Services or other users’ use of the Services, including denial-of-service, scraping at unreasonable rates, or attempts to circumvent rate limits or security measures.
(f) Access or attempt to access any account, system, or data not belonging to Customer.
(g) Reverse engineer, decompile, or attempt to extract the underlying models, prompts, training data, or workflow configurations of the Services.
(h) Resell, sublicense, or expose the Services to third parties as a standalone product.
(i) Use the Services to develop or improve a competing AI voice-receptionist or competing call-handling product.
(j) Generate or distribute malware, exploits, phishing content, or content designed to harvest credentials.
(k) AI impersonation. Use the Services to impersonate a real, identifiable human being (including any specific employee, attorney, agent, or public figure) without that person’s express, documented authorization, or to deceive a Caller into believing they are speaking with a specific human person other than as expressly authorized.
(l) Caller-ID spoofing / neighbor spoofing. Place outbound calls or SMS using a calling number that the Customer is not lawfully authorized to use; engage in “neighbor spoofing” (selecting a calling number based on the called party’s NPA-NXX); or otherwise transmit misleading or inaccurate caller-ID information in violation of the Truth in Caller ID Act, 47 U.S.C. § 227(e), the FCC’s implementing rules, the TRACED Act, or applicable STIR/SHAKEN attestation requirements.
(m) CAN-SPAM, TRACED Act, and carrier-abuse violations. Operate any campaign that has been the subject of a STIR/SHAKEN traceback, USTelecom Industry Traceback Group request, FCC enforcement action, FTC enforcement action, state attorney-general inquiry, or carrier abuse-team takedown without disclosing that fact to Agent360 LLC and without cooperating in good faith with the inquiring authority (see §2.12 below).
2. TCPA and outbound calling — REQUIRED COMPLIANCE
These obligations apply whenever Customer uses any outbound calling, ringless voicemail, automated voice, pre-recorded voice, or AI-initiated calling features of the Services. Failure to comply is a material breach of the Terms.
2.1 Consent
Prior express written consent is required for any call to a wireless number using an automatic telephone dialing system or pre-recorded voice that constitutes “telemarketing” under the TCPA (47 U.S.C. § 227 and 47 C.F.R. § 64.1200).
Prior express consent is required for any informational call to a wireless number using an automatic telephone dialing system or pre-recorded voice.
Customer must maintain records sufficient to prove consent for each called number for at least four (4) years and produce them on Agent360’s request.
2.2 Time-of-day restrictions
No call may be initiated to any number outside the hours of 8:00 a.m. to 9:00 p.m. local time at the called party’s location, unless a stricter state or local restriction applies (in which case the stricter restriction controls).
2.3 Do-Not-Call (DNC) lists
Scrub all outbound campaign lists against the federal National Do-Not-Call Registry, applicable state DNC lists, and Customer’s internal DNC / opt-out list, before each campaign and at least every 31 days.
Honor opt-out requests within a reasonable time, not to exceed ten (10) business days, and do not call any number that has opted out from the same party within five (5) years (or the period required by applicable state law, whichever is longer).
2.4 Identification, opt-out scripting, and disclosures
Every pre-recorded or AI-voice call must, at the outset, identify the business on whose behalf the call is being made and provide a call-back telephone number that connects to a live representative or system that can take opt-out requests.
Pre-recorded calls must include an automated, interactive opt-out mechanism announced at the start and activatable at any time.
Calls to wireless numbers must include any required disclosures regarding charges that may apply to the called party.
2.5 Recording-consent statutes
Where Customer enables call recording, Customer is responsible for obtaining two-party (all-party) consent in two-party-consent jurisdictions (including California — Cal. Penal Code § 632 — and other states with similar statutes), which can be satisfied by an audible disclosure at the start of the call where supported by Customer’s script.
2.6 SMS / text messaging
Where the Services place SMS messages, Customer must comply with the TCPA, the CTIA Messaging Principles and Best Practices, 10DLC registration requirements, and any carrier rules; Customer must include a clear STOP/HELP mechanism and honor opt-outs immediately.
2.7 Industry-specific rules
Debt collection: Comply with the FDCPA (15 U.S.C. §§ 1692 et seq.), Regulation F frequency caps (12 C.F.R. § 1006.14), and applicable state collection statutes.
Healthcare: Customer must independently determine whether HIPAA applies and obtain a Business Associate Agreement (BAA) before submitting Protected Health Information through the Services. Standard accounts are not configured for HIPAA workloads.
Legal services: Comply with applicable state-bar rules on solicitation, advertising, and intake.
2.8 Customer is the “caller” / “telemarketer” (as between the parties)
For purposes of the TCPA and analogous laws, as between the parties, Customer (or Customer’s authorized end-customer) is the party “making” the call. Agent360 LLC is a service provider that operates the platform on Customer’s behalf and does not initiate any call without Customer’s instruction or configuration. Nothing in this paragraph purports to limit any liability that any statute, regulation, or court may directly impose on Agent360 LLC notwithstanding this allocation.
2.9 Consent recordkeeping — four (4) years (NON-NEGOTIABLE)
Customer shall retain documentary proof of prior express written consent (or, where applicable, prior express consent) for each called party for not less than four (4) years from the date of the call, and shall make such records available to Agent360 LLC upon request within ten (10) business days.
“Documentary proof” means a record sufficient to demonstrate to a court, the FCC, or a state attorney general that consent was obtained, including (at minimum): (i) the consenting party’s name and the wireless or landline number for which consent was given; (ii) the date, time, and source (URL, form ID, IVR script, signed paper, or recorded oral confirmation) of the consent capture; (iii) the exact language to which the party consented; (iv) the IP address, browser, or call-recording reference where applicable; and (v) any subsequent revocation and the date it was honored.
Customer’s failure to produce such records on request is itself a material breach of the Terms and grounds for immediate suspension under §4.1, separate from any underlying TCPA / DNC liability.
This recordkeeping obligation survives termination for the full four-year retention period (and any longer period required by applicable law).
2.10 Cross-timezone dialing
Customer is responsible for resolving each called party’s local time before dialing, including for campaigns spanning multiple time zones, and shall not initiate outbound calls outside the permitted local-time window of the called party (see §2.2).
Agent360 LLC’s time-zone enforcement tooling (where provided) is offered for Customer’s convenience and does not relieve Customer of this obligation.
2.11 Allocation of liability — between the parties (NON-NEGOTIABLE)
As between the parties, Customer is fully and solely responsible — and shall defend and indemnify Agent360 LLC under §10.1 of the Terms — for any claim, demand, fine, settlement, judgment, government action, or attorney-general inquiry arising from any call, message, or communication placed by, on behalf of, or to or from Customer through the Services, including any claim under the TCPA, the federal and state Do-Not-Call (DNC) rules, two-party recording-consent statutes (including Cal. Penal Code § 632), the FDCPA, the CAN-SPAM Act, CTIA Messaging Principles, 10DLC carrier rules, the Truth in Caller ID Act, the TRACED Act, and any analogous federal, state, local, or international law (collectively, the “Outbound Calling Laws”). Nothing in this section purports to limit any liability that any statute, regulation, or court of competent jurisdiction may directly impose on Agent360 LLC notwithstanding this allocation.