Miisk LLC · v1.7
Incorporated into the Miisk Service Agreement. Includes our data processing agreement at Part 4. Controls over the Terms of Service as to its subject matter.
This Policy is incorporated into the Miisk Service Agreement and controls over the Terms of Service as to its subject matter. It applies to every call, message, and email sent through the Service. Breach of this Policy is a material breach and we may suspend or terminate immediately, without a cure period.
You must not use the Service, or configure it, to produce, send, or solicit any of the following:
A gym or studio intake conversation predictably surfaces information about injuries, medical conditions, pregnancy, medication, and physical limitations, and in a messaging deployment that information becomes a permanent written record. Unless we have signed a specific addendum covering it, you must not configure the Service to solicit, and must instruct it not to record or retain:
If information in these categories is volunteered by a caller anyway, you must not build a workflow that relies on it, and you must tell us so the configuration can be reviewed.
The Service must not be used for emergency, medical, safety-critical, crisis, or life-safety communications, for medical triage or symptom assessment, for collections or debt recovery, for political campaigning, for the practice of any licensed profession, or to make any decision about a person's credit, insurance, housing, or employment.
You must not exceed a usage level agreed with us, generate automated or artificial traffic, test the Service against real consumers without telling us, or use the Service in a way that degrades it for others or threatens our carrier standing.
Text messages are treated as calls under the TCPA. Statutory damages are $500 per message or call, rising to $1,500 where the violation is wilful, with no aggregate cap and no minimum threshold, and these claims are commonly brought as class actions. A single campaign to a list without valid consent can generate exposure far exceeding the value of this Service. Read this Part carefully.
We do not obtain consent on your behalf. We do not review, approve, or verify your consent practices, and we make no representation that they comply with any law. Any check we run against your published pages is limited to carrier-registration readiness, is described in Part 3, and is not a review or approval of your consent practices. Any sample opt-in wording, form, or template we may show you is an illustration only, is not legal advice, is not a representation of compliance, and does not shift responsibility to us. You are solely responsible for obtaining, evidencing, and maintaining valid consent for every contact, on every channel you use — calls, texts, and email alike.
You must not contact anyone outside the hours permitted where the recipient is located. Federal law is narrower than many operators assume, and several states are narrower still. Where a state imposes a stricter window, a stricter consent standard, a registration requirement, a callback number requirement, or a specific disclosure, that stricter requirement governs contact in that state and it is your responsibility to identify and meet it.
Requirements that commonly apply above the federal floor include, without limitation, narrower calling windows and enhanced consent standards in states such as Florida, Washington, Oklahoma, Connecticut, Texas, Virginia, Maryland, California, and Utah; state registration or bonding before soliciting into a state; long opt-out retention periods; and specific opt-out language and record retention rules. You must verify current requirements for every state you contact into before the first contact, and you must not rely on this list as complete or current.
You must keep, for at least five years and in any event for longer than the applicable limitation period, records evidencing for each contact the method and date of consent, the exact disclosure presented, the number or address consented, and any revocation and the date it was processed. You must produce those records to us within 10 business days of request, and you must preserve them if a claim is threatened.
Text messaging in the United States operates under a carrier registration regime administered by the mobile carriers. It is separate from law, and its consequence is commercial rather than legal: unregistered or non-conforming traffic is filtered, throttled, blocked, or suspended, and carrier fees and penalties are passed through to you.
About any sample wording we give you. We may share a sheet of example website language that has cleared registration for other clients. It is an illustration only. It is not legal advice, we do not review or approve what you publish, and we make no representation that it satisfies any law or carrier rule as applied to your business. Have your own counsel review anything you publish, and see Part 2.1.
About checks we run. Before filing a registration we may examine your published pages — your opt-in forms, privacy policy, terms, and site footer — for the presence of the wording and mechanics the carrier regime expects, and we may tell you what we could not find. That examination is operational assistance with the filing and nothing more: it is not legal review, it is not approval of your practices, it is not a representation that anything on your site complies with any law or carrier rule, and it does not move any responsibility in Part 2 from you to us. What your site, your forms, and your messages say remains yours on every channel, and consent for each channel — including email — remains your responsibility under Part 2.1, whether or not we looked at the page it appears on.
This Part is our data processing agreement with you. It governs personal information we process on your behalf, and it controls over the rest of this Policy and over the Terms of Service as to that subject matter.
You are the business and the controller of the personal information you ask us to process. We act as your service provider and processor. We process that information only on your documented instructions, which are the instructions set out in your agreement, in Exhibit A, and in the configuration you approve.
We will not:
We certify that we understand these restrictions and will comply with them.
Giving your customers the privacy notices they are entitled to, having a lawful basis for the processing you ask us to perform, the accuracy and lawfulness of your instructions, and not instructing us to process in a way that would put either side in breach.
We limit access to personnel who need it to deliver or support the Service, and those personnel are bound by confidentiality obligations that survive their engagement.
We maintain technical and organisational measures appropriate to the risk, including encryption of personal information in transit and at rest, access controls limiting access to authorised personnel, multi-factor authentication on administrative access, logging of access to production systems, change management for production changes, and diligence on any Supplier before it processes personal information.
We use Suppliers to deliver the Service. On written request we will give you a current list of the Suppliers that process personal information on your behalf. We remain responsible for their performance, and we impose data protection obligations on them no less protective than those in this Part.
We will tell you before a new Supplier begins processing personal information. You may object on reasonable data protection grounds within 30 days. If we cannot resolve your objection, you may cancel on the terms set out in Part 6.
We will give you reasonable assistance in responding to a request from an individual to access, correct, delete, or opt out, and with any assessment or record you are required to maintain. Where such a request reaches us directly, we will not respond to it on our own account; we will refer it to you.
We will notify you without undue delay after we confirm a security incident affecting personal information we process for you, and we will pass on any notice we receive from a Supplier promptly after we receive it. We will give you the information you reasonably need in order to meet your own notification obligations.
On reasonable written request, no more than once in any twelve months unless a regulator requires it or a security incident has occurred, we will make available the information reasonably necessary to demonstrate our compliance with this Part.
On termination we will return or delete personal information as set out in Section 6 of the Service Agreement and Part H of the Terms of Service, except where we are required to retain it.
We may create and use aggregated and de-identified data as described in Part B7 of the Terms of Service. We will not attempt to reidentify it and will not permit a Supplier to do so.
Where this Part conflicts with any other part of your agreement as to personal information, this Part controls.
We may update this Policy. We will give you at least 30 days' written notice of a material change, and the version in force when you signed continues to apply until the change takes effect.
Immediate changes. Where a change is required by law, by a regulator, or by a carrier, or is needed to address an urgent security or compliance risk, it may take effect immediately on notice to you. Carrier and state requirements change without warning and we cannot wait 30 days to prohibit something that has just become prohibited.
If you do not accept a change. If a material change is adverse to you and you do not accept it, you may cancel by written notice before the change takes effect, or within 30 days of notice where the change took effect immediately. Your service will then end at the end of that calendar month, no further monthly fees will be charged, and the six-month minimum term in the Service Agreement does not apply to that cancellation. The month in progress remains payable under Section 3 of the Service Agreement. If you keep using the Service after a change takes effect, you accept it.