Territory enablement, carrier conditions, calling and messaging controls, custom voices, regulated uses, and country-specific requirements
Canada and the United States are the default self-service territories. Another country is available only when ALEBEX enables it in the Account, an Order Form, or a signed agreement. International carrier rates and country restrictions may apply in addition to platform usage charges.
These ALEBEX AI Service and Country Requirements (“Country Requirements”) supplement the applicable ALEBEX agreement, AUP, Communications Policy, and DPA. They establish ALEBEX service rules and summarize certain legal and carrier topics that Customer must independently evaluate. They are not legal advice.
A country, route, number type, language, or feature is authorized only when enabled in Customer’s Account or expressly listed in an Order Form. An API endpoint, telephone route, or internet connection working from or to a country does not mean the country is enabled or legally approved.
Where multiple requirements apply, Customer must comply with all applicable mandatory laws, carrier and provider conditions, and ALEBEX contractual requirements. If they differ, Customer must follow the stricter requirement to the extent necessary to satisfy each applicable obligation, but ALEBEX does not require Customer to apply a foreign rule that is not applicable solely because it is stricter.
Customer must identify the actual account holder, caller, sender, sponsor, End Client, and communication purpose; use authorized numbers and domains; maintain accurate country, recipient, purpose, and consent information; honor opt-outs; comply with calling hours; and preserve records.
Customer must not use emergency-service numbers, emergency short codes, law-enforcement identifiers, or other protected numbers or identities unless ALEBEX expressly supports and approves the use. The Services must not be the sole path for emergency, crisis, urgent medical, safety, or other time-critical communications.
Customer must configure human escalation, error handling, and fallback suitable for its use. Customer must not present ALEBEX as a regulated telecommunications carrier, licensed professional, emergency provider, bank, government entity, school, or other institution unless the statement is accurate and authorized.
Customer must determine whether consent, written consent, express consent, implied consent, an existing relationship, a business-to-business rule, contract, legitimate interest, statutory exemption, or another lawful basis is required for the specific country, recipient, purpose, channel, and technology.
Customer must maintain internal do-not-call, unsubscribe, suppression, revocation, and channel-preference records and must screen against governmental or industry lists where applicable. Customer must update screening at the legally required frequency. Where the United States National Do Not Call Registry applies, Customer must access and use an updated registry version no less frequently than every thirty-one days.
Customer must retain evidence supporting the communication for at least five years, or longer where required by law or agreement. Evidence should include contact source, date, scope, consent or lawful basis, sponsor identity, opt-out status, applicable suppression checks, disclosure settings, and any custom-voice permission.
SMS, MMS, email, and other non-voice channels are authorized only when enabled. Customer must comply with channel-specific consent, identification, content, carrier-registration, unsubscribe, and anti-spam rules. Enabling voice or API access does not automatically enable SMS or email.
Customer is responsible for all call-monitoring, recording, transcription, summary, and storage notices and consent. Customer must account for the locations of participants and any law requiring all-party or one-party consent. If recording is not lawful or consent is withheld, Customer must use a no-recording, transfer, alternative-channel, or termination workflow.
Customer must not collect passwords, one-time passcodes, private keys, online-banking credentials, or other authentication secrets through an AI agent. Full payment-card data and regulated financial information require an expressly approved compliant workflow and appropriate provider and security controls.
Customer must obtain and preserve all rights and permissions required to create and use a custom or likeness-based voice. A rights certification is required before activation. The permitted geography, purpose, duration, audience, and ability to revoke should be documented where appropriate.
Customer must not use a voice to impersonate a public official, government body, law-enforcement officer, family member, bank, employer, school, professional, or other person or institution without authorization or to mislead a Recipient about identity, affiliation, endorsement, or authority. ALEBEX may require disclosure or technical identification for specific countries or uses.
Customer must comply with applicable federal and state requirements governing telephone calls, artificial or prerecorded voice, AI-generated voice, automated dialing, telemarketing, text messages, email, call recording, privacy, data security, consumer protection, unfair or deceptive practices, and sector-specific conduct. These may include the Telephone Consumer Protection Act and FCC rules, the Telemarketing Sales Rule, federal and state do-not-call requirements, CAN-SPAM, state mini-TCPA and telemarketing laws, state recording laws, and state privacy laws.
Customer acknowledges that an AI-generated human voice may be treated as an artificial or prerecorded voice under applicable FCC rules. Customer must determine whether prior express consent, prior express written consent, or another legally sufficient basis or exemption is required. Telemarketing and advertising calls using artificial or prerecorded voice may require written consent and additional identification and opt-out mechanisms.
Where the Telemarketing Sales Rule applies, Customer must comply with calling hours, caller identification, required disclosures, do-not-call rules, abandonment restrictions, misrepresentation prohibitions, and recordkeeping. Customer must account for more restrictive state rules, including state-specific consent, registration, bonding, disclosure, recording, or calling-hour requirements.
Customer must not rely solely on a national rule where the Recipient’s state imposes additional obligations. Consumer outbound marketing, healthcare, financial, insurance, debt-collection, political, fundraising, or high-volume use may require specialized legal review even if the Account gate is complete.
Customer must comply with applicable CRTC Unsolicited Telecommunications Rules, including National Do Not Call List, Telemarketing, Automatic Dialing-Announcing Device, caller-identification, calling-hour, internal do-not-call, registration, subscription, and recordkeeping requirements. Customer must separately comply with Canada’s anti-spam law for commercial electronic messages and with applicable federal and provincial privacy laws.
A business-to-business or other exemption from the National DNCL rules does not automatically exempt Customer from Telemarketing or ADAD rules. Customer must determine the specific exemption and the requirements that continue to apply.
Solicitation calls using an automatic dialing-announcing device or synthesized or prerecorded voice may require prior express consent. Customer must determine whether its specific real-time AI voice workflow falls within an ADAD or another category and must document the legal basis before use.
Customer must identify the caller and the person or organization on whose behalf the call is made, display or provide accurate contact information as required, observe applicable local-time calling windows, maintain internal do-not-call records, and process requests within required periods.
For commercial email or text messages, Customer must determine and document express or implied consent, identify the sender and any person on whose behalf the message is sent, provide a functioning unsubscribe mechanism, and retain consent and unsubscribe evidence.
These territories are not enabled by default. Before use, Customer must complete an ALEBEX territory-enablement process addressing data roles, international transfers, privacy notices, lawful basis, direct-marketing and electronic-communications rules, call recording, AI transparency, provider/deployer roles, data-subject requests, retention, security, language, and local complaint handling.
Where applicable, Customer must comply with the GDPR, UK GDPR, ePrivacy and national implementing laws, PECR, the EU AI Act, consumer law, local telemarketing rules, and recording laws. For an AI system that directly interacts with individuals, Customer must provide the legally required notice that the individual is interacting with AI unless a lawful exception applies.
A partner placing a system on the market or operating it under its own name or trademark may have independent provider, deployer, distributor, importer, or other obligations. Contractual allocation does not change a role imposed by law.
An EEA, Swiss, or UK launch may require a transfer mechanism and completed data-processing details before Customer Personal Data is transferred. Customer must not remove transparency, logging, documentation, or user-facing controls that ALEBEX requires for the enabled territory.
A country outside the default territories requires ALEBEX enablement. Customer must identify the country, recipient type, purpose, channel, data category, number type, caller identity, consent or lawful basis, recording rules, AI disclosure rules, privacy and transfer requirements, taxes, sanctions, and local complaints process.
ALEBEX may require local counsel confirmation, additional KYC, prepayment, deposits, lower limits, specific scripts or disclosures, number registration, local presence, or other conditions. ALEBEX may disable a country immediately where law, carrier, provider, sanctions, fraud, payment, or security conditions change.
International carrier, number, termination, messaging, regulatory, and pass-through rates may apply and will be displayed in the Account, billing page, pricing page, or Order Form. Customer is responsible for charges generated by its traffic.
ALEBEX does not represent that the Services are, by default, certified or authorized for healthcare, financial services, insurance, debt collection, legal services, immigration services, government, political communications, minors, education records, biometric identification, or high-impact automated decisions.
A regulated or high-impact use requires an enabled Account setting, ALEBEX approval, appropriate legal authority, human oversight, sector-specific terms, and any additional privacy, security, insurance, or provider controls ALEBEX requires. Customer must not market the Services as a licensed professional service or use Output as the sole basis for a consequential decision.
Carriers and number providers may require registration, brand verification, traffic descriptions, proof of consent, sample scripts, identity verification, local address, emergency-address information, or other records. Customer must provide accurate information and comply with carrier codes and platform conditions.
ALEBEX may block destinations, limit throughput, rotate routes, require new numbers, suspend traffic, or disclose required account and traffic information to carriers, providers, regulators, or authorities where legally permitted or required. Customer must not use number rotation, call duration manipulation, or account switching to evade carrier controls.
ALEBEX may update these Country Requirements as laws, carrier conditions, provider rules, enabled territories, or services change. A country or feature may be restricted or disabled on immediate or short notice where reasonably required for law, safety, security, fraud, sanctions, carrier, provider, or service-integrity reasons.
Questions may be sent to legal@alebex.ai. Abuse, fraud, recipient complaints, or suspected unauthorized communications may be reported to abuse@alebex.ai. Security incidents must be reported to security@alebex.ai.
Questions about this document: legal@alebex.ai