On this page
1. Lawful communications
Use communications features only for lawful purposes and with the notices, permissions and consent required in the relevant jurisdiction. Do not send unlawful spam, fraudulent messages, deceptive caller identity, harassment, threats or prohibited content. Respect provider rules, opt-outs and applicable direct-marketing restrictions.
2. Recording, monitoring and customer data
Establish a lawful basis and provide appropriate notice before recording, transcribing, monitoring or sharing conversations. Collect only necessary information, limit access and define retention. Do not deploy covert surveillance or expose another customer’s records. Sector-specific requirements may apply to schools, healthcare and employee communications.
3. System and network safety
Do not distribute malware, steal credentials, evade access controls, exploit another tenant, overload services or perform unauthorized scanning or testing. Keep administrative credentials private and report suspected compromise promptly. Any security assessment needs written authorization, a defined scope and agreed safeguards.
4. Responsible AI workflows
Use approved knowledge and authorized data sources. Test answers and routing, provide a human path and assess sensitive or consequential actions before use. Do not instruct AI to impersonate people deceptively, disclose protected information, make unlawful discriminatory decisions or bypass required notices. AI outputs need appropriate review.
5. Availability and emergency planning
Do not assume ordinary calling, AI reception or campus paging is a certified life-safety system. Agree carrier emergency-call support, location handling, power/network dependencies and alternative communication arrangements. Do not make test emergency calls without coordinating with the responsible carrier or emergency authority.
6. Reporting and enforcement
Report suspected abuse to info@telfron.com with the subject ‘Abuse report’, relevant times and a minimal factual description. Do not attach sensitive conversation contents or exploit data unnecessarily. Product restrictions, suspension, notice and remedies must follow the customer agreement, applicable law and any urgent protection needs; this public policy does not invent unilateral contract remedies.
Reference frameworks
References explain relevant frameworks; their inclusion is not a claim of certification or universal compliance.
- ISO/IEC 27001:2022
- ISO/IEC 27701:2025
- NZ Privacy Act principles
- NZ indirect-collection notice (IPP3A)
- NZ access and correction requests
- NZ international disclosures
- NZ breach notification guidance
- EDPB lawful processing
- EDPB controller and processor roles
- EDPB individual rights
- ICO cookies and similar technologies
- ICO consent withdrawal