Miisk Acceptable Use and Compliance Policy
Miisk LLC · v1.5
Incorporated into the Miisk Service Agreement. Includes our data processing agreement at Part 4. Controls over the Terms of Service as to its subject matter.
This Policy is incorporated into the Miisk Service Agreement and controls over the Terms of Service as to its subject matter. It applies to every call, message, and email sent through the Service. Breach of this Policy is a material breach and we may suspend or terminate immediately, without a cure period.
Part 1. Acceptable use
1.1 Prohibited content and conduct
You must not use the Service, or configure it, to produce, send, or solicit any of the following:
- Content that is threatening, harassing, abusive, bullying, or intended to intimidate.
- Content that is hateful or that demeans, degrades, or promotes hostility toward a person or group on the basis of race, colour, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, disability, age, veteran status, or any other protected characteristic.
- Sexually explicit, obscene, or pornographic content, and any sexual content involving or directed at a minor.
- Content that incites, promotes, or provides instruction for violence, self-harm, terrorism, or criminal activity.
- Content that is defamatory, libellous, or knowingly false, or that disparages a competitor untruthfully.
- Deceptive content, including impersonating a person, business, government body, or Miisk itself; spoofed or misleading caller identification; false claims of affiliation, endorsement, or authority; and fake urgency or manufactured scarcity.
- Concealing that the caller is automated. You must not configure or instruct the Service to deny being an automated system, to claim to be a specific named human, or to mislead a person about its artificial nature.
- Content that infringes copyright, trademark, publicity, or other rights, including using a real person's name, voice, likeness, or cloned voice without their documented permission.
- Malware, phishing, credential harvesting, fraud, or any attempt to obtain payment card, bank, or account credentials through the Service.
- Unsolicited bulk or indiscriminate messaging, and content designed to evade carrier filtering, including deliberate misspelling, character substitution, link cloaking, or URL shorteners that mask the destination.
- Content in the categories carriers restrict for messaging traffic, including sexual content, hate content, alcohol, firearms, tobacco and vaping, cannabis, gambling, lending and debt relief, and high-risk financial offers, except where you have confirmed with us in writing that the traffic is permitted and correctly registered.
1.2 Prohibited data
A gym or studio intake conversation predictably surfaces information about injuries, medical conditions, pregnancy, medication, and physical limitations, and in a messaging deployment that information becomes a permanent written record. Unless we have signed a specific addendum covering it, you must not configure the Service to solicit, and must instruct it not to record or retain:
- Health, medical, injury, diagnosis, treatment, medication, mental health, reproductive, or biometric information, and anything that would constitute consumer health data under a state consumer health data statute;
- Protected health information subject to HIPAA;
- Payment card numbers, bank account or routing numbers, and any data subject to PCI DSS;
- Social security, passport, driver's licence, or other government identification numbers;
- Precise geolocation, immigration status, union membership, religious or political affiliation, or information about a person known to be under 18;
- Credentials, passwords, or security question answers.
If information in these categories is volunteered by a caller anyway, you must not build a workflow that relies on it, and you must tell us so the configuration can be reviewed.
1.3 Prohibited use contexts
The Service must not be used for emergency, medical, safety-critical, crisis, or life-safety communications, for medical triage or symptom assessment, for collections or debt recovery, for political campaigning, for the practice of any licensed profession, or to make any decision about a person's credit, insurance, housing, or employment.
1.4 Volume and integrity
You must not exceed a usage level agreed with us, generate automated or artificial traffic, test the Service against real consumers without telling us, or use the Service in a way that degrades it for others or threatens our carrier standing.
Part 2. Outbound contact. Consent and compliance
Text messages are treated as calls under the TCPA. Statutory damages are $500 per message or call, rising to $1,500 where the violation is wilful, with no aggregate cap and no minimum threshold, and these claims are commonly brought as class actions. A single campaign to a list without valid consent can generate exposure far exceeding the value of this Service. Read this Part carefully.
2.1 Consent is your responsibility
We do not obtain consent on your behalf. We do not review, approve, or verify your consent practices, and we make no representation that they comply with any law. Any sample opt-in wording, form, or template we may show you is an illustration only, is not legal advice, is not a representation of compliance, and does not shift responsibility to us. You are solely responsible for obtaining, evidencing, and maintaining valid consent for every contact.
2.2 What you must have before we contact anyone
- Marketing contact. Prior express written consent from the person, satisfying every element the law requires, including a clear and conspicuous disclosure that they agree to receive calls or messages made with an automated system or an artificial or prerecorded voice, identification of the specific business authorised to contact them, a statement that consent is not a condition of purchase, and their signature.
- Non-marketing contact. Prior express consent, and the contact must genuinely remain transactional in content.
- Consent that actually covers us. Consent must extend to the channels being used and must name your business as the contacting party. Consent given to one location, franchisee, brand, or affiliate does not transfer to another. Each location must hold its own consent.
- No purchased, rented, scraped, harvested, or third-party lists, and no contacts obtained through a consent chain you cannot document.
2.3 Opt-out, revocation, and suppression
- Honour a revocation made by any reasonable means, including verbally during a call, a reply keyword, an email, or a request to your staff, and process it promptly and within any statutory window.
- Maintain and keep current your internal do-not-contact and suppression lists, and scrub against the National Do Not Call Registry and applicable state registries at the required frequency.
- Keep entity-specific and location-specific opt-outs separate. An opt-out at one location must not be treated as consent at another.
- Never re-contact a person who has opted out, and never use a different number, brand, or channel to reach someone who has opted out.
- Retain suppression records for at least as long as the longest applicable state requirement, and tell us before termination how your suppression list is to be preserved.
2.4 Contact hours and state requirements
You must not contact anyone outside the hours permitted where the recipient is located. Federal law is narrower than many operators assume, and several states are narrower still. Where a state imposes a stricter window, a stricter consent standard, a registration requirement, a callback number requirement, or a specific disclosure, that stricter requirement governs contact in that state and it is your responsibility to identify and meet it.
Requirements that commonly apply above the federal floor include, without limitation, narrower calling windows and enhanced consent standards in states such as Florida, Washington, Oklahoma, Connecticut, Texas, Virginia, Maryland, California, and Utah; state registration or bonding before soliciting into a state; long opt-out retention periods; and specific opt-out language and record retention rules. You must verify current requirements for every state you contact into before the first contact, and you must not rely on this list as complete or current.
2.5 Disclosure, recording, and voice
- The Service must identify your business and the purpose of the contact at the start of the interaction, and must disclose that it is automated where any law requires it.
- You must not disable, alter, or instruct the Service to omit any disclosure, sender identification, or opt-out instruction.
- Calls must not be recorded unless every consent the law requires has been obtained. Several states require the consent of all parties and attach criminal penalties and private rights of action.
- Caller identification transmitted on your behalf must be accurate and must not be used to mislead.
- You must not ask us to clone, imitate, or approximate the voice of any identifiable person, and you must not supply a voice sample you do not hold documented rights to.
2.6 Records
You must keep, for at least five years and in any event for longer than the applicable limitation period, records evidencing for each contact the method and date of consent, the exact disclosure presented, the number or address consented, and any revocation and the date it was processed. You must produce those records to us within 10 business days of request, and you must preserve them if a claim is threatened.
Part 3. Messaging registration
Text messaging in the United States operates under a carrier registration regime administered by the mobile carriers. It is separate from law, and its consequence is commercial rather than legal: unregistered or non-conforming traffic is filtered, throttled, blocked, or suspended, and carrier fees and penalties are passed through to you.
- You are the sender. The registered brand must be the business actually sending the messages, registered under your own legal name and employer identification number. Miisk cannot register as the brand for your messages.
- You must be verifiable. Registration requires a live website that clearly displays your opt-in and opt-out disclosures and privacy policy, an email address on your own domain, and a telephone number discoverable on that presence. You must keep all of it live and accurate for as long as you send messages.
- Registered opt-in language must match reality. The opt-in wording submitted at registration must be identical to what consumers actually see on your forms. A mismatch is a common basis for campaign suspension, and correcting it is your responsibility.
- Multi-location and franchise structures must be disclosed accurately, including every sub-entity, where a franchise or multi-location campaign structure is used.
- Registration, activation, per-campaign, and violation fees are yours, and are in addition to the monthly fee unless we have agreed otherwise in writing.
- You must tell us promptly of any change to your legal name, EIN, address, website, or ownership, because registration accuracy depends on it.
- Your registration is yours and stays with you. The brand is registered in your name and does not transfer to us. If you leave you keep it and do not need to rebuild it; only the association between a particular number and a campaign has to be re-established by your new provider.
Part 4. Data protection
This Part is our data processing agreement with you. It governs personal information we process on your behalf, and it controls over the rest of this Policy and over the Terms of Service as to that subject matter.
4.1 Our roles
You are the business and the controller of the personal information you ask us to process. We act as your service provider and processor. We process that information only on your documented instructions, which are the instructions set out in your agreement, in Exhibit A, and in the configuration you approve.
4.2 The restrictions we accept
We will not:
- sell or share personal information, as those terms are defined under California law;
- retain, use, or disclose personal information for any purpose other than performing the Service for you, including for any commercial purpose of our own;
- retain, use, or disclose personal information outside the direct business relationship between you and us;
- combine personal information we receive from you with personal information from any other source, except where doing so is necessary to perform the Service for you or is permitted by law.
We certify that we understand these restrictions and will comply with them.
4.3 What you are responsible for
Giving your customers the privacy notices they are entitled to, having a lawful basis for the processing you ask us to perform, the accuracy and lawfulness of your instructions, and not instructing us to process in a way that would put either side in breach.
4.4 Confidentiality and personnel
We limit access to personnel who need it to deliver or support the Service, and those personnel are bound by confidentiality obligations that survive their engagement.
4.5 Security
We maintain technical and organisational measures appropriate to the risk, including encryption of personal information in transit and at rest, access controls limiting access to authorised personnel, multi-factor authentication on administrative access, logging of access to production systems, change management for production changes, and diligence on any Supplier before it processes personal information.
4.6 Sub-processors
We use Suppliers to deliver the Service. On written request we will give you a current list of the Suppliers that process personal information on your behalf. We remain responsible for their performance, and we impose data protection obligations on them no less protective than those in this Part.
We will tell you before a new Supplier begins processing personal information. You may object on reasonable data protection grounds within 30 days. If we cannot resolve your objection, you may cancel on the terms set out in Part 6.
4.7 Helping you answer your customers
We will give you reasonable assistance in responding to a request from an individual to access, correct, delete, or opt out, and with any assessment or record you are required to maintain. Where such a request reaches us directly, we will not respond to it on our own account; we will refer it to you.
4.8 Security incidents
We will notify you without undue delay after we confirm a security incident affecting personal information we process for you, and we will pass on any notice we receive from a Supplier promptly after we receive it. We will give you the information you reasonably need in order to meet your own notification obligations.
4.9 Demonstrating compliance
On reasonable written request, no more than once in any twelve months unless a regulator requires it or a security incident has occurred, we will make available the information reasonably necessary to demonstrate our compliance with this Part.
4.10 Deletion and return
On termination we will return or delete personal information as set out in Section 6 of the Service Agreement and Part H of the Terms of Service, except where we are required to retain it.
4.11 De-identified data
We may create and use aggregated and de-identified data as described in Part B7 of the Terms of Service. We will not attempt to reidentify it and will not permit a Supplier to do so.
4.12 If this Part conflicts with anything else
Where this Part conflicts with any other part of your agreement as to personal information, this Part controls.
Part 5. Monitoring, cooperation, and consequences
- We may monitor use of the Service for security, quality, and compliance, and may review call and message content where we reasonably need to for those purposes or to respond to a complaint, carrier enquiry, or legal process.
- We may refuse, modify, or halt any campaign, content, or configuration we reasonably believe breaches this Policy or exposes us to legal or carrier risk.
- You must cooperate promptly and fully with any complaint, carrier enquiry, regulator request, or litigation touching communications sent through the Service, including preserving records.
- We may suspend or terminate immediately and without a cure period for breach of this Policy. Suspension does not shorten your term, reduce fees owed, or entitle you to a refund.
- Your indemnity in the Terms of Service — which extends to our licensors and the service providers we use to deliver the Service — applies in full to any breach of this Policy.
Part 6. Changes to this Policy
We may update this Policy. We will give you at least 30 days' written notice of a material change, and the version in force when you signed continues to apply until the change takes effect.
Immediate changes. Where a change is required by law, by a regulator, or by a carrier, or is needed to address an urgent security or compliance risk, it may take effect immediately on notice to you. Carrier and state requirements change without warning and we cannot wait 30 days to prohibit something that has just become prohibited.
If you do not accept a change. If a material change is adverse to you and you do not accept it, you may cancel by written notice before the change takes effect, or within 30 days of notice where the change took effect immediately. Your service will then end at the end of that calendar month, no further monthly fees will be charged, and the six-month minimum term in the Service Agreement does not apply to that cancellation. The month in progress remains payable under Section 3 of the Service Agreement. If you keep using the Service after a change takes effect, you accept it.