Acceptable use

Customer responsibility & acceptable use policy

Last updated: · Plain-English summary. The signed master services agreement (MSA) is the controlling contract.

Plain-English summary

Yappa provides the tooling — a managed AI voice agent that dials, qualifies, and warm-transfers leads on your behalf. You provide the lead list and the legal basis for calling it.We give you strong defaults and fail-closed compliance gates; we cannot verify the lawfulness of every lead you upload. If a lead was put in front of us in breach of Australian telemarketing law, the responsibility for that breach sits with you, not us.

1. What Yappa is — and isn't

Yappa is a managed AI voice-agent service. We operate the dialler, the conversational AI, the warm-transfer routing, the per-call reporting, and the technical compliance gates described in §3.

Yappa is not a lead-generation service. We do not source, scrape, purchase, or verify leads. Every lead we call is one that you uploaded or made available via your CRM integration.

2. Your lead list — your responsibility

By using Yappa to call a lead, you represent and warrant that, for that lead, you have:

  • A lawful basis under the Privacy Act 1988 (Cth), the Spam Act 2003 (Cth), and the Do Not Call Register Act 2006 (Cth) to contact them by telephone for the purpose of the campaign;
  • Either express consent, inferred consent based on an existing business relationship, or a recognised exemption (e.g. registered charities, governments, educational bodies);
  • Performed your own check against the Australian Do Not Call Register (or arranged for us to run that check on your behalf — see §3);
  • Honoured any prior opt-outs or DNC requests that originated outside the Yappa platform.

If a lead on the list is on the federal DNC Register and was called via Yappa, the breach belongs to the uploading customer, not to Yappa.Yappa will cooperate fully with regulators (ACMA), but the client carrying the AFSL/ABN that owns the campaign is the party liable under the relevant Act.

Your attestation. When you upload a lead list or complete onboarding, you attest to the lawful basis above — including the lawful-basis tick-box at upload and the declaration in your onboarding form. That attestation is your binding representation: Yappa relies on it and does not independently verify the consent, source, or accuracy behind each lead. Keeping consent and DNC status current for your list remains your responsibility; the controls in §3 are guardrails, not a transfer of that responsibility.

3. What Yappa provides as a safety net

The Yappa compliance gate fails closed — if any of the following checks deny, the call does not place:

  • Federal DNC mirror. We maintain a mirror of the Do Not Call Register and refuse to dial any number whose HMAC matches a listed number, provided the lead has no overriding express-consent record.
  • Internal DNC list. Any number that has requested "stop calling" on any prior Yappa call is added to the workspace's permanent internal DNC list.
  • State-specific calling-hour windows. AU state holidays and time-of-day restrictions are enforced per the lead's recorded state.
  • Consent record check. Where consent records exist, the gate verifies the record is current and not revoked.
  • AI identification. Every Yappa call identifies as an AI on the first line. Clients cannot override this.
  • Recording, transcript, and audit log.Every call is recorded, transcribed, and committed to an immutable internal audit log for the configured retention window.

These controls are protective but not exhaustive. The gate cannot validate the original lawful basis for calling the lead — only the current technical eligibility at dial time.

4. Lead-list hygiene at onboarding

Before your first paid campaign, Yappa scrubs the lead list you provide against the federal DNC Register and your internal opt-out list. Leads that fail either check are quarantined and reported back to you, not dialled.

This scrub is a courtesy using point-in-time DNC data. It does not transfer responsibility for the lawfulness of the list to Yappa.

5. Prohibited use

You agree not to use Yappa to:

  • Contact leads on the federal DNC Register without an applicable consent or exemption;
  • Misrepresent the AI as a human caller, or instruct the AI to deny being an AI when asked;
  • Sell, market, or attempt to qualify leads for gambling, adult services, scams, multi-level marketing, or other categories prohibited under AU law or by Yappa's published acceptable-use list (provided on request);
  • Use scraped, purchased, or otherwise non-consented lead lists outside the exemptions in §2;
  • Attempt to bypass, disable, or interfere with the compliance gate, audit log, or AI-identification line.

Breach of this section is grounds for immediate suspension under §7 and may be reported to ACMA where appropriate.

6. Indemnification

You indemnify Lead Bridge Group Pty Ltd (trading as Yappa) and its officers, employees, and contractors against any claim, fine, penalty, or liability arising from:

  • The unlawfulness of any lead you upload, including breaches of the DNC Register, Spam Act, or Privacy Act attributable to the source or use of that lead;
  • Misrepresentations made in your own marketing, product, or sales claims passed through to the lead via the agent script;
  • Use of Yappa in a manner that breaches §5.

Yappa's own liability is capped at the fees paid by the client in the 12 months preceding the claim, except for gross negligence or wilful misconduct.

7. Suspension & termination

Yappa may suspend a workspace immediately, without liability, if:

  • The compliance gate detects a pattern of attempted DNC-listed calls suggesting a list-sourcing breach;
  • ACMA or another regulator initiates a complaint against the workspace's campaign;
  • The client breaches §5;
  • The client falls more than 14 days past due on a paid plan.

We will work in good faith to restore service once the underlying issue is resolved. Repeat breaches are grounds for termination of the MSA.

8. Data, recordings & retention

Call recordings, transcripts, and structured outcomes are retained for the period specified in your service tier (default 90 days). PII is encrypted at rest with a per-workspace key; the database never sees plaintext phone numbers or names.

On termination, you may request export of your call data and recordings; we retain encrypted compliance audit logs for 7 years per AU record-keeping requirements.

9. Changes to this policy

We may update this policy from time to time. Material changes — anything that shifts a responsibility or right — will be notified by email at least 30 days before they take effect. Continued use of Yappa after the effective date constitutes acceptance.

10. Contact

Questions or compliance reports: hello@yappa.com.au.

Important — this is a summary, not the binding contract

This page is a plain-English summary of how Yappa operates. The signed Master Services Agreement (MSA) and Data Processing Agreement (DPA) are the controlling legal documents. If you haven't seen those yet, ask us before relying on anything here for your own compliance posture.