legal

Acceptable Use Policy

What you may and may not do with CallHQ. This is short and specific on purpose — a vague policy cannot be enforced fairly, and outreach tooling that is not enforced becomes a spam platform.

Version 1.0 · last updated 2026-08-09

Draft — not yet in force

These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.

Why this policy exists

Any tool that sends email, SMS and calls at volume attracts people who want to abuse it. When that happens everyone pays: shared sending reputation degrades, domains get blocklisted, telephony carriers throttle numbers, and customers doing careful, lawful outreach see their delivery rates fall because of someone else.

So this is not boilerplate. It is the rule set that keeps the platform working for the people using it properly, and we would rather lose a customer than let it slip.

Breach of this policy is a material breach of the Terms of Service.

Never

These result in immediate suspension, without a cure period:

  • Sending to purchased, scraped-from-a-breach, rented or otherwise unlawfully obtained contact lists.
  • Ignoring, circumventing or attempting to reset an opt-out, unsubscribe or do-not-call request.
  • Falsifying sender identity, headers, caller ID or reply-to addresses.
  • Sending phishing, malware, fraudulent, or deceptive commercial messages.
  • Targeting individuals rather than businesses in their business capacity.
  • Harassment — repeatedly contacting someone who has asked you to stop.
  • Uploading special-category personal data (health, biometrics, political or religious belief, sexual orientation) or criminal-offence data.
  • Using the platform for anything unlawful in the jurisdiction of either the sender or the recipient.

Outreach rules

  • Every marketing email must identify who is sending it and offer a working opt-out in every message.
  • Honour opt-outs immediately. CallHQ enforces this technically across every channel; do not try to work around it.
  • Do not email individuals — sole traders and unincorporated partnerships count as individuals under PECR — without a lawful basis that permits it.
  • Do not send SMS marketing without a basis that permits it in the recipient's jurisdiction.
  • Warm up new sending domains and respect the platform's throttles. They exist to protect your deliverability, not to inconvenience you.

Calling rules

  • Call only within the recipient's local permitted hours. The platform will not surface a number outside them; do not attempt to defeat that.
  • Screen against applicable do-not-call registers.
  • Where you record calls, announce it before recording starts. The product asks you to confirm you have. That confirmation is a control, not a legal opinion — in all-party-consent jurisdictions, obtaining consent is still your responsibility.
  • Do not use synthetic or prerecorded voice where the recipient's jurisdiction requires prior express consent and you do not have it.
  • Identify yourself and the company you are calling for, promptly, on every call.

Sourcing rules

  • Source from public records, as the platform is designed to. Do not import lists whose provenance you cannot establish.
  • Respect robots directives and rate limits when the platform crawls on your behalf; do not reconfigure it to ignore them.
  • Do not use CallHQ to build a contact database for resale. Records are for your own outreach.

Content and conduct

  • No content that is defamatory, obscene, hateful, or that infringes someone's intellectual property.
  • No impersonation of another business or person, including in AI-generated content, voice or video.
  • Where you use the platform's AI features, you remain responsible for what it produces on your behalf. Read it before it goes out.

Technical limits

  • Do not attempt to access another workspace's data, probe for vulnerabilities without permission, or bypass rate limits and plan caps.
  • Do not resell, sublicense or white-label access without a written agreement.
  • Automated access is via the documented API. Do not script the web interface.
  • Good-faith security research is welcome — see the reporting address in the Privacy Policy. Report it; do not exploit it.

How we enforce this

For most issues we will contact you first and give you a chance to put it right. For anything in Never, or where there is an immediate risk to other customers, a recipient, or the platform's sending reputation, we may suspend first and explain immediately afterwards.

We do not monitor the content of your campaigns as a matter of course, and we do not want to. We act on complaints, on abuse signals from carriers and mailbox providers, and on the platform's own compliance telemetry.

Reporting abuse

If you have received unwanted contact from someone using CallHQ, tell us and we will suppress your details across every workspace on the platform immediately — that stops all further contact through CallHQ, whoever was sending it.

Use the chat widget on any page or the contact form. You do not need an account, and you do not need to identify which customer contacted you.

Questions about this document? Ask through the contact form or the chat widget on any page.