Acceptable Use Policy

Last Updated: September 8, 2026

Introduction

This Acceptable Use Policy (“AUP”) is incorporated by reference into and governed by the Vail Terms of Service (“Terms”), available at www.vailsys.com/legal. Before you access or use our Services (defined in the Terms), including our websites, APIs, customer portals, telecommunications services, and related products and services, review this AUP carefully. This AUP describes prohibited uses of the Services and certain responsibilities applicable to users of the Services (“Users”).

Capitalized terms that are not defined in this AUP are defined in the Terms, which take precedence over any conflicting provisions in this AUP.

We may modify this AUP from time to time. We will post the revised AUP and update the “Last Updated” date when we make changes. Where required by applicable law, we will provide additional notice. Continued use of the Services after the effective date of any changes constitutes acceptance of the revised AUP, to the extent permitted by applicable law.

  1. Prohibited Conduct.
    • General: Users will not use the Services to transmit, distribute or store material in a manner that: (a) violates any applicable law or regulation; (b) may adversely affect the Services or Users; (c) may expose Vail to criminal or civil liability or (d) violate, infringe upon or otherwise misappropriate any third party rights, including intellectual property rights, rights of publicity and privacy rights. Users are prohibited from facilitating the violation of any part of this AUP or applicable third-party policies, including, but not limited to transmitting, distributing, or otherwise making available any product or service that violates this AUP or another provider's policy.
    • Inappropriate Content: Users will not use the Services to transmit, distribute or store material that Vail reasonably determines is unlawful, materially harmful to the Services, materially harmful to third parties, reasonably likely to expose Vail to civil or criminal liability, obscene, defamatory, libelous, tortious, infringing, threatening, abusive, hateful, or otherwise prohibited by applicable law. Users will also not use the Services to host terrorist-related web sites, including sites that advocate human violence and hate crimes based upon religion, ethnicity, or country of origin.
    • Intellectual Property: Material accessible through the Services may be subject to protection under privacy, publicity, or other personal rights and intellectual property rights, including but not limited to, copyrights and laws protecting patents, trademarks, trade secrets or other proprietary information. Users will not use the Services in any manner that would infringe, dilute, misappropriate, or otherwise violate any such rights. If a domain name is used with any of the Services, it may not be used in violation of the trademark, service mark, or other rights of any third party.
    • Harmful Content: Users will not use the Services to transmit, distribute or store content or material that may be harmful to or interfere with the Services or any third party's networks, systems, services, or websites. Prohibited harmful content includes, but is not limited to, viruses, worms, or Trojan horses, root kits, password crackers, adware, and key stroke capture programs.
    • Fraudulent/Misleading Content: Users will not use the Services to transmit or distribute content or material containing fraudulent offers for goods or services, or advertising or promotional materials that contain false, deceptive, or misleading statements, claims, or representations. Users will additionally not use the Services to facilitate fraud, identity theft, account takeover, social engineering, credential theft, payment fraud, subscriber fraud, toll fraud, telecom fraud, call laundering, traffic pumping, revenue-share fraud, PBX hacking, or any other fraudulent or deceptive telecommunications activity.
    • Email and Unsolicited Messages: Users will not use the Services to (i) transmit unsolicited email messages, SMS messages, MMS messages, RCS messages, voice messages, fax messages, or other electronic communications, including, without limitation, unsolicited bulk email, where such emails could reasonably be expected to provoke complaints; and (ii) send email messages which are excessive and/or intended to harass or annoy others (“Spam”). Further, Users are prohibited from using the service of another provider to send Spam to promote a site hosted on or connected to the Services. In addition, Users will not use the Services to (a) continue to send email messages to a recipient that has indicated that he/she does not wish to receive them; (b) send email with forged TCP/IP packet header information; (c) send malicious email, including, but not limited to, “mail-bombing”; (d) send or receive email messages in a manner that violates the use policies of any other service provider; or (e) use an email box exclusively as a storage space for data.
    • Third Party Rules; Usenet: Users will not use the Services in violation of the rules, guidelines or agreements associated with search engines, subscription Web services, chat areas, bulletin boards, Web pages, USENET, or other services accessed via the Services.
    • Inappropriate Actions: Users will not use the Services to conduct activities that may be harmful to or interfere with the Services, a User's terminal session or any third party's networks, systems, services, or websites. Users will not engage in any activities designed to harass, or that will preclude or interfere with the use of Services (e.g., synchronized number sequence attacks) by any other User on the Vail network or on another provider's network. In addition, Users will not use the Services (a) by any means or device to avoid payment; (b) to access User's account or Vail Services after User has terminated User's account; (c) on behalf of persons or firms listed in the Spamhaus Register of Known Spam Operations database at www.spamhaus.org; or (d) to engage in phishing activities. Users will not use the Services to engage in any activities that may interfere with the ability of others to access or use the Services or the Internet.
    • Illegal Use: User will not use the Services in a manner that constitutes illegal activities, including but not limited to, death threats, terroristic threats, threats of harm to another individual, multilevel marketing schemes, HYIP or Ponzi schemes, invasion of privacy, credit card fraud, racketeering, defamation, slander, child pornography and violations of the Child Protection Act of 1984, or any other applicable law.
    • Telecommunications Compliance: Users will not use the Services in violation of any applicable telecommunications, consumer protection, telemarketing, anti-spoofing, call authentication, messaging, privacy, or similar laws or regulations. Without limitation, Users shall not use the Services to: (i) place unlawful robocalls; (ii) initiate calls or messages without any required consent; (iii) violate the Telephone Consumer Protection Act (TCPA), Telemarketing Sales Rule (TSR), state telemarketing laws, CAN-SPAM Act, or similar laws; (iv) circumvent, disable, evade, manipulate, impair, or interfere with STIR/SHAKEN or other call authentication frameworks; (v) engage in caller ID spoofing except to the extent expressly permitted by applicable law; (vi) originate or facilitate unlawful telemarketing campaigns; or (vii) engage in any activity that may cause Vail, its carriers, vendors, telecommunications partners, or customers to become subject to regulatory investigation, penalties, blocking, filtering, or enforcement action.
    • SMS and Messaging: Users shall not use the Services to send SMS, MMS, RCS, instant messages, or other electronic communications that violate applicable law, carrier policies, industry standards, campaign registration requirements, consent requirements, or messaging best practices. Prohibited activities include, without limitation, SMS spam, unsolicited messaging, traffic pumping, snowshoe messaging campaigns, artificially inflated messaging traffic, fraudulent campaign registration, phishing, smishing, and transmission of malicious links.
    • Call Recording and Monitoring: Users are solely responsible for compliance with all applicable laws relating to the recording, monitoring, storage, transcription, analysis, processing, disclosure, and use of communications. Users shall obtain all legally required notices, disclosures, authorizations, and consents before recording or monitoring any communication. Vail shall have no responsibility for determining whether recording, monitoring, transcription, storage, or analysis activities are lawful in any jurisdiction.
    • Artificial Intelligence and Voice Technologies: Users shall not use the Services, including any AI, analytics, voice, transcription, fraud detection, routing, speech recognition, or related capabilities, to create, distribute, facilitate, or support: (i) deceptive synthetic voices; (ii) voice cloning without authorization; (iii) impersonation of individuals or organizations; (iv) deepfakes; (v) fraudulent identity verification schemes; (vi) unlawful automated decision-making; or (vii) any activity intended to deceive, defraud, manipulate, or misrepresent identity.
    • Security Breaches and Obligations: Users are prohibited from violating or attempting to violate the security of the Services or the computers, accounts, or networks of another party, including but not limited to, circumventing the user authentication or security of any host, network or account. Users will not use the Services to cause security breaches or disruptions of Internet communication and/or connectivity. Security breaches include, but are not limited to, accessing data, accounts or systems without authorization or logging into a server or account that the User is not expressly authorized to access and denial of service attacks. Disruptions include port scans, flood pings, email-bombing, packet spoofing, IP spoofing, forged routing information. User must use reasonable care in keeping its software, systems, applications, credentials, authentication tokens, APIs, user accounts, and devices secured, patched, updated, and protected from unauthorized access. Where available, Users shall implement multi-factor authentication (“MFA”) and maintain reasonable administrative, technical, and physical safeguards appropriate to the Services utilized.
    • API and Platform Abuse: Users shall not engage in unauthorized load testing, credential stuffing, automated scraping, excessive API requests, traffic flooding, account enumeration, automated abuse, denial-of-service activities, excessive use inconsistent with the intended design of the Services, or any activity that materially degrades the performance, reliability, integrity, or availability of the Services.
    • IP Allocation: Users are prohibited from using IP addresses not allocated for use or on unassigned VLANs or servers. All IP Addresses currently owned and registered to Vail are nontransferable and nonportable. User retains no ownership or transfer rights. User will only announce border gate protocol (“BGP”) prefixes for which the User owns, shows a valid LOA or WHOIS entry indicating the prefixes are leased or loaned for their use, or acquired from Vail.
    • IP Portability: Users using Vail IP space with other ISP's must also advertise the routes on a directly connected Vail session. The User's advertisement to Vail must not require significant traffic engineering (such as BGP prepending), and the User must have adequate transit capacity.
    • IP Records: Users must maintain current registrations of their ASNs and IP space from the regional registries that assigned such resources. Failure to maintain registration may result in Vail not providing routing transit for the ASNs and the IP space.
    • Infrastructure Investment and Jobs Act (IIJA) Grant Programs: Any User participating in an IIJA program, including but not limited to, the Middle Mile Grant, Tribal Connectivity Broadband, and the Broadband Equity Access and Deployment (BEAD) Grant Programs, will not pay for Services with funds obtained through the IIJA or other similar grants that would obligate Vail to provide certain information or perform certain regulatory compliance functions, unless each of those functions and obligations is explicitly identified and agreed to in writing by the parties in the Agreement or in an amendment to the Agreement.
  2. Rights of Vail:
    • Users shall promptly cooperate with Vail, carriers, vendors, law enforcement agencies, and regulatory authorities regarding investigations involving abuse, fraud, network security incidents, robocalling complaints, spoofing activity, unlawful messaging campaigns, phishing activity, or violations of this AUP. Failure to cooperate may constitute an independent violation of this AUP.
    • Vail may suspend, restrict, filter, block, terminate, modify, reroute, limit, quarantine, investigate, or otherwise take action regarding Services where Vail reasonably believes such action is necessary to: (i) protect the Services; (ii) protect customers, carriers, vendors, partners, or third parties; (iii) prevent fraud or abuse; (iv) comply with applicable law; (v) comply with carrier requirements; (vi) comply with governmental requests; or (vii) mitigate security risks.
    • Vail reserves the right to take down any material, or otherwise block access to, created or accessible on or through the Services and suspend or terminate any User creating, storing or disseminating material where Vail becomes aware that the material violates this AUP and/or exposes Vail to civil or criminal liability, including without limitation, under applicable copyright laws. Vail reserves the right to avail itself to the safe harbor provisions of the Digital Millennium Copyright Act.
    • DMCA Notices: Copyright infringement notices shall be directed to Vail's designated DMCA agent identified on Vail's website or otherwise designated by Vail from time to time. Vail may remove or disable access to allegedly infringing materials consistent with applicable law, including the Digital Millennium Copyright Act (see, e.g., https://www.copyright.gov/title17/92chap5.html#512).
    • Emergency Services: Unless expressly provided hereunder or under a separate written agreement, the Services are not intended to provide emergency calling capabilities or support for 911, E911, NG911, public safety answering points, or emergency communications. Users shall not represent that the Services provide emergency communications functionality and shall maintain alternative emergency communications capabilities where required.
    • Responsibility for Content: Vail shall not be responsible, and takes no responsibility, for any content or material created or accessible on or through the Services and will not exercise any editorial control over content or material. Vail is not obligated to monitor material or content but reserves the right to do so.
    • Users are responsible for configuring their own systems to provide the maximum possible accountability. Vail shall not be liable for any damage caused by such system configurations regardless of whether such configurations have been authorized or requested by Vail. For example, Users should ensure there are clear “path” lines in news headers so that the originator of a post may be identified. Users should also configure their Mail Transport Agents (MTA) to authenticate (by lookup on the name or similar procedures) any system that connects to perform a mail exchange, and should generally present header data as clearly possible. As another example, Users should maintain logs of dynamically assigned IP addresses. Users are responsible for educating themselves and configuring their systems with at least basic security. Should systems at a User's site be violated, the User is responsible for reporting the violation and then fixing the exploited system. For instance, should a site be abused to distribute unlicensed software due to a poorly configured FTP (File Transfer Protocol) Server, the User is responsible for reconfiguring the system to stop the abuse.
    • Vail reserves the right to cooperate with legal authorities and third parties in the investigation of any alleged wrongdoing related to this AUP, including the disclosure of the identity of the User that Vail deems responsible for the wrongdoing. Vail will not be liable for any damages of any nature suffered by any User, or any third party resulting in whole or in part from Vail's exercise of its rights under this AUP.
    • Vail reserves the right to install and use, or require that User install and use, any appropriate devices to prevent violations of this AUP, including devices designed to filter or terminate access to the Service. By accepting and using the Services, Users consent to allowing Vail to collect service information and routing information in the normal course of our business, and to use such information for general business purposes. Users may not use the Services to monitor any data, information or communications on any network or system without authorization. Users may not attempt to gain unauthorized access to the accounts or passwords of other Users.
    • In most cases, Vail will notify Users of complaints received by Vail regarding an alleged violation of this AUP. User agrees to promptly investigate all such complaints, assign a representative responsible for receiving communications, and take all necessary actions to remedy any violations of this AUP. Vail may inform the complainant that the complaint is being investigated and may provide the complainant with the necessary User contact information to resolve the complaint directly.
    • Vail reserves the right to modify this AUP from time to time. Modifications become effective upon posting or other reasonable notice. Continued use of the Services after the effective date of the modification constitutes acceptance of the modifications.

Data Protection Addendum

Last Updated: September 8, 2026

Introduction

This Data Protection Addendum (“DPA”) is incorporated by reference into the Vail Terms of Service (“Terms”), available at www.vailsys.com/legal, and forms part of the agreement between Vail Systems, Inc. (“Vail”) and the applicable customer (“Customer”) governing Customer’s use of the Services (collectively, the “Agreement”). This DPA applies to Vail’s Processing of Personal Information on behalf of Customer in connection with the Services.

Capitalized terms that are not defined in this DPA are defined in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Information, this DPA will control.

  1. Definitions: Capitalized terms used herein shall have the meanings set forth in the Agreement, except as expressly defined in this Section 1.
    • Aggregated Data” means data, information, statistics, metrics, analyses, benchmarks, models, insights, reports, or other materials generated, derived, compiled, combined, transformed, or created by Vail from Personal Information, Customer Data, service usage information, network information, traffic information, call detail records, telecommunications metadata, support information, operational data, or other information processed in connection with the Services, provided that such data has been aggregated, anonymized, de-identified, pseudonymized, or otherwise processed so that it does not reasonably identify, relate to, describe, reference, or permit the identification of any individual or Customer. Aggregated Data does not constitute Personal Information or Customer Confidential Information and may be used, disclosed, commercialized, transferred, licensed, published, distributed, or otherwise exploited by Vail and its Affiliates for any lawful business purpose, including product development, analytics, service improvement, benchmarking, security, fraud prevention, artificial intelligence, machine learning, research, reporting, network optimization, and creation of industry statistics.
    • Anonymous Data” means information derived from Personal Information that has been aggregated, anonymized, de-identified, or otherwise processed so that it cannot reasonably be used to identify an individual.
    • Authorized Persons” means Vail's employees, contractors, agents, auditors, affiliates, subcontractors, cloud providers, telecommunications carriers, hosting providers, and other third parties engaged by Vail in connection with the Services, who have a need to know or otherwise access Personal Information to enable Vail to perform its obligations under this Agreement and who are bound by confidentiality obligations.
    • Data Breach” means (i) any act or omission that materially compromises the security, confidentiality, or integrity of Personal Information or the physical, technical, administrative, or organizational safeguards put in place by Vail, or by Customer should Vail have access to Customer's systems, that relate to the protection of the security, confidentiality, availability, or integrity of Personal Information, or (ii) receipt of a complaint in relation to the privacy and data security practices of Vail or a breach or alleged breach of this Agreement relating to such privacy and data security practices.
    • Personal Information” means information that Customer provides or for which Customer provides access to Vail, or information which Vail creates or obtains on behalf of Customer, in accordance with this Agreement that: (i) directly or indirectly identifies an individual (including, for example, names, signatures, addresses, telephone numbers, email addresses, and other unique identifiers); or (ii) can be used to identify or authenticate an individual (including, without limitation, employee identification numbers, government-issued identification numbers, passwords or PINs, user identification and account access credentials or passwords, financial account numbers, credit report information, student information, biometric, genetic, health, or health insurance data, answers to security questions, an individual's internet activity or similar interaction history, inferences drawn from other personal information to create consumer profiles, geolocation data, an individual's commercial, employment, or education history, and other personal characteristics and identifiers). Customer's business contact information is not by itself Personal Information. Personal Information does not include Anonymous Data, Aggregated Data, de-identified information, or information that no longer identifies or can reasonably be linked to a particular individual.
    • Process[ing]” means any operation or set of operations performed on Personal Information, whether or not by automated means, including access, collection, use, storage, disclosure, transmission, analysis, recording, organization, combination, deletion, destruction, or disposition.
  2. Vail and Customer Obligations:
    1. Vail:
      1. will comply with the terms and conditions set forth in this DPA;
      2. will be responsible for any unauthorized creation, collection, receipt, transmission, access, storage, disposal, use, or disclosure of Personal Information under its control or in its possession;
      3. will use, access, retain, disclose, transfer, analyze, and otherwise Process Personal Information as reasonably necessary to provide, maintain, secure, support, improve, and administer the Services, perform obligations under the Agreement, comply with applicable law, prevent fraud, protect the security and integrity of the Services, enforce contractual rights, generate Anonymous Data, and as otherwise permitted under the Agreement;
      4. may aggregate, de-identify, or anonymize Personal Information and use such aggregated, de-identified, or anonymized data, which shall no longer be considered Personal Information, for its own research and development purposes;
      5. may create, compile, use, disclose, commercialize, and otherwise exploit Anonymous Data and Aggregated Data for product development, benchmarking, analytics, reporting, service improvement, artificial intelligence systems, machine learning, fraud detection, network optimization, security operations, and other lawful business purposes, provided such data does not identify Customer or any individual;
      6. will act as a processor, service provider, contractor, or analogous entity solely when Processing Personal Information on behalf of Customer; and
      7. will own all right, title, and interest in Aggregated Data and Anonymous Data, subject to Customer's ownership of the underlying Customer Data and Personal Information.
    2. Customer:
      1. will comply with the terms and conditions set forth in this Agreement;
      2. will be responsible for any unauthorized creation, collection, receipt, transmission, access, storage, disposal, use, or disclosure of Personal Information under its control or in its possession;
      3. will comply with any applicable laws and regulations and use only secure methods, according to accepted industry standards, when transferring or otherwise making available Personal Information to Vail;
      4. will act as the controller, business, or analogous entity with respect to Personal Information;
      5. authorizes Vail to engage affiliates, subprocessors, carriers, cloud hosting providers, telecommunications providers, technology vendors, contractors, consultants, and service providers in connection with the Services. Vail shall impose obligations on such subprocessors that are substantially similar to the obligations contained herein, as appropriate for the nature of the services performed.
    3. Nothing in this DPA transfers ownership of Customer Data or Personal Information to Vail. Nothing in this DPA limits Vail's ownership of Aggregated Data, Anonymous Data, fraud intelligence, Risk Scores, benchmarking information, security intelligence, service metrics, or other information that does not identify Customer or an individual.
  3. Information Security:
    1. Vail will comply with applicable laws and regulations in its creation, collection, receipt, access, use, storage, disposal, and disclosure of Personal Information.
    2. Vail will maintain and implement commercially reasonable administrative, technical, organizational, and physical safeguards designed to protect Personal Information against unauthorized access, acquisition, disclosure, alteration, destruction, or loss. Such safeguards shall take into account the nature of the Services, the sensitivity of the Personal Information Processed, the state of the art, implementation costs, industry practices, and the risks presented by the Processing. Security measures may include controls aligned with recognized industry security frameworks, including NIST, ISO 27001, SOC 2 principles, or substantially equivalent security programs, as determined by Vail in its reasonable discretion.
  4. Data Breach Procedures:
    1. Vail maintains a cyber incident breach response plan in accordance with accepted industry standards (“Cyber Incident Response Plan”) and will implement the procedures required under such plan on the occurrence of a Data Breach.
    2. Vail will notify Customer of a Data Breach as soon as reasonably practicable after confirmation of a Data Breach, taking into consideration the need to investigate and verify the scope and impact of the incident, but in no event later than seventy-two (72) hours after such confirmation.
    3. Immediately following Vail's notification to Customer of a Data Breach, the parties will coordinate with each other, as necessary, to investigate the Data Breach in accordance with Vail's current Cyber Incident Response Plan.
    4. The parties' respective rights and remedies arising from a Data Breach shall be governed exclusively by the Agreement, including any applicable limitation of liability provisions.
    5. Vail may communicate with regulators, law enforcement authorities, telecommunications providers, vendors, affected individuals, and other third parties regarding a Data Breach where reasonably necessary to comply with law, protect the Services, mitigate harm, or respond to the incident.
  5. Audit Rights: No more than once annually, Customer may request a summary of Vail's then-current independent security assessments, certifications, or audit reports, to the extent available and subject to confidentiality obligations. Customer audit rights shall be limited to review of such materials unless otherwise required by applicable law.
  6. International Transfers: Customer authorizes Vail and its affiliates and subprocessors to transfer Personal Information internationally as reasonably necessary to provide the Services. Where required by applicable law, the parties agree that applicable standard contractual clauses, transfer mechanisms, or successor frameworks shall automatically apply and are incorporated herein by reference. Customer provides general authorization for Vail to appoint, replace, remove, and utilize subprocessors in connection with the Services without additional notice or consent.
  7. Data Subject Requests: Where required by applicable law, Vail will provide commercially reasonable assistance to Customer in responding to requests from individuals relating to their Personal Information. Vail reserves the right to charge reasonable fees for assistance requiring material operational efforts.
  8. Return or Disposal of Personal Information: Upon termination or expiration of this Agreement, Vail will delete or return Personal Information, at Vail's option, except to the extent retention is required for legal, regulatory, tax, accounting, security, fraud-prevention, backup, archival, dispute resolution, enforcement, telecommunications compliance, or legitimate business continuity purposes. Any retained Personal Information will remain subject to the protections of this DPA.
  9. Telecommunications Data: Customer acknowledges that the Services may Process telecommunications-related information including calling party numbers (ANI), called party numbers (CPN), SIP signaling data, call detail records, routing information, voice recordings, voice transcripts, fraud scoring information, CNAM information, authentication data, network traffic data, and related telecommunications metadata. Vail may Process such information as necessary to provide, secure, support, maintain, improve, and comply with legal obligations relating to the Services.
  10. Artificial Intelligence and Analytics: Except as expressly prohibited in an Order or SOW, Vail may utilize automated tools, machine learning systems, artificial intelligence technologies, speech analytics tools, fraud detection tools, and similar technologies in connection with the provision, support, maintenance, improvement, and operation of the Services. Vail will not use Personal Information to train publicly available generalized AI models unless otherwise authorized by Customer.