1. Customer responsibility and legal review
Customers are responsible for their contacts, campaigns, purposes, scripts, destinations, data, agents, and instructions. They must determine which laws, rules, industry obligations, and contractual restrictions apply and obtain qualified advice where needed.
CXRove controls can help enforce an approved policy but do not make a use case lawful. Vendor permission, a purchased number, a lead source, or recipient contact information is not by itself consent.
2. Consent and campaign authority
Before an automated or AI-assisted communication, the customer must hold the consent or other authority required for the exact seller, channel, purpose, recipient, destination, and technology. Consent evidence must remain linked to the form and disclosure the person accepted.
Revocation, opt-out, ambiguity, expiration, transfer to a different seller, or a material purpose change must block further communication unless another lawful basis has been approved. AI telemarketing remains disabled unless the exact campaign passes legal approval and verified seller-specific consent controls.
3. Do-not-contact and suppression
Customers must honor applicable national and state do-not-call rules, CXRove-wide suppression, their own organization and seller lists, channel opt-outs, and provider restrictions before every attempt.
A voice, keypad, written, or human request to stop must be captured promptly and applied to the required scope. Suppression data may be used only to prevent prohibited contact and must not be repurposed as a marketing list.
4. Caller identity and disclosure
Customers may use only approved caller identity and must accurately identify the responsible seller or organization and the communication's commercial purpose where required.
The first-utterance rule requires disclosure that an AI-generated voice is being used where the approved workflow applies it. Customers must not spoof identity, impersonate a person or organization, conceal the responsible seller, or use deceptive subjects, headers, scripts, or claims.
5. Recording, transcription, and notice
Recording and transcription are off by default unless separately enabled for an approved workflow. Permission to call is separate from permission to record or transcribe.
Before enabling either feature, the customer must use the approved disclosure and consent process for the parties' jurisdictions and purpose. Uncertain location, silence, timeout, ambiguity, decline, participant change, transfer, or material purpose change must follow the stricter approved rule or keep recording off.
6. Destination, timing, and route controls
A communication may proceed only through an enabled country, prefix, number type, use case, provider, and cost route. New or stale routes, restricted parties, premium or high-fraud destinations, and unverified number requirements fail closed.
Customers must follow the strictest approved local calling window and frequency rule for the recipient. The federal U.S. telemarketing baseline is not a universal permission or a substitute for stricter state, local, sector, or international rules.
7. Prohibited conduct
- Fraud, phishing, scams, impersonation, deceptive claims, caller-ID spoofing, or evasion of carrier or platform controls.
- Harassment, threats, hate, exploitation, repeated unwanted contact, spam, illegal content, or communications intended to annoy, abuse, or intimidate.
- Unlawful surveillance, recording, transcription, profiling, biometric use, or collection of sensitive information.
- Buying, scraping, sharing, or using contact lists without the rights, notices, consent, and suppression controls required for the exact use.
- Circumventing rate, destination, identity, spend, capacity, safety, opt-out, or human-approval controls.
- Using CXRove to develop malware, compromise systems, interfere with networks, or violate another person's intellectual-property or privacy rights.
8. Emergency and high-risk decisions
CXRove is not an emergency service and must not be used to place or replace emergency calls, dispatch, crisis response, or other time-critical safety communications unless a separately built and approved capability expressly supports that use.
CXRove must not make final decisions about employment, housing, lending, insurance, health care, legal rights, education, essential services, or similar high-impact matters without the legally required process, qualified human decision-maker, explanation, review, and appeal. The initial launch does not authorize those uses.
9. Payment and sensitive-data handling
Customers must not send card numbers, security codes, passwords, authentication codes, government identifiers, health information, or other sensitive data into a call, transcript, prompt, log, or tool unless the exact workflow is separately approved and technically isolated.
Recording and transcription must stop before card capture. A provider feature or certification does not expand the approved CXRove scope.
10. Human oversight
Customers must test agents, knowledge, actions, disclosures, escalation, and failure handling before use. A qualified person must monitor material outcomes and be able to pause, correct, or take over when risk, uncertainty, a request, or policy requires it.
AI output must not be represented as guaranteed, professional advice, or a verified fact without appropriate review. Human handoff must not be hidden when the conversation or decision requires a person.
11. Provider, carrier, and sanctions rules
Customers must follow the applicable terms and acceptable-use rules of activated carriers, AI services, networks, storage, email, payment, and infrastructure providers. CXRove may enforce a narrower rule than a vendor console permits.
Restricted-party, sanctions, export, number-registration, and destination controls must be approved for the exact customer and use. CXRove may block a route or account while those checks are missing, stale, or unresolved.
12. Enforcement and evidence
CXRove may block an attempt, disable a campaign or destination, limit features, preserve relevant evidence, suspend access, or terminate service when it reasonably believes use violates the activated agreement, creates harm, threatens a network, or exposes CXRove or a provider to legal or security risk.
Where appropriate, CXRove may request consent records, scripts, lead source, identity, purpose, suppression process, licenses, or legal approval. Failure to provide credible evidence keeps the affected use disabled.
13. Reports, appeals, and changes
Suspected abuse may be reported through the accessible contact shown on this page. CXRove will review reports and any available appeal without exposing reporters, recipients, or security evidence unnecessarily.
This Policy identifies its version, approver, effective date, prior version, and material change record. New channels, destinations, use cases, or laws require renewed review rather than broad global wording.
Change record
Published the substantive policy for consent, suppression, identity, recording, prohibited uses, human oversight, and enforcement.
This is the first published version; no prior operative version exists.