This Content Moderation Policy explains what GREYDOLL's AI services may and may not be used for, how we detect and investigate abuse, and what we do when our rules are broken. It forms part of our Terms of Service and applies to every Client, authorised user, and interaction handled by our AI agents.
1. Scope & Definitions
This Policy applies to all use of the GREYDOLL platform and services, including AI voice agents, chat and SMS agents, the digital concierge, the reservation and ordering engines, the Kitchen Display System (KDS), our dashboards, our APIs, and our public MCP server.
It binds the Client, everyone the Client authorises to use the Service, and any content or configuration submitted to or generated through the Service. Clients are responsible for ensuring their staff and any third party acting on their behalf comply with it.
2. Permitted Use
The Service is built for legitimate business communication. You may use it to handle the everyday customer interactions of a lawful business you own or are authorised to represent, including:
Permitted activities
- Answering inbound calls, chats, and messages on behalf of your business.
- Taking, confirming, modifying, and cancelling reservations, appointments, and bookings.
- Taking food and service orders and passing them to your KDS, POS, or dashboard.
- Answering questions about your opening hours, location, menu, services, staff availability, and prices.
- Capturing enquiries, callbacks, and waitlist requests, and routing them to your team.
- Sending transactional confirmations, reminders, and follow-ups that an End-Customer has asked for or reasonably expects.
- Handing an End-Customer over to a human member of your team when they ask, or when the AI agent cannot help.
Conditions that apply to all permitted use
- You must use the Service only for a lawful business that you own or are authorised to represent, and keep the business information you configure accurate and current.
- You must clearly disclose to End-Customers that they are interacting with an AI system, in line with Article 50 of the EU AI Act, and must not configure an agent to claim to be a human when asked.
- You must provide any notice and obtain any consent required for call recording, transcription, and processing of personal data under the GDPR and the ePrivacy Directive.
- You must offer a reasonable route to a human being for End-Customers who ask for one or who present an urgent or sensitive situation.
- You must review AI-generated orders, bookings, and data entries on your KDS or dashboard — the AI system is probabilistic and is not guaranteed to be accurate.
- You must not present AI output as professional advice (medical, legal, financial, or otherwise) unless Section 4 permits it and you have our written approval.
3. Prohibited Use
You must not use the Service, and must not permit anyone else to use it, for any of the following. This list is illustrative, not exhaustive.
(a) Illegal activity and regulated goods
- Any activity that breaches applicable Dutch, EU, or other applicable law.
- Selling, brokering, or arranging the supply of controlled substances, prescription medicines without the required licence, weapons, explosives, stolen goods, or counterfeit products.
- Unlicensed gambling, unlicensed financial services, money laundering, sanctions evasion, or human trafficking in any form.
- Facilitating the sale of goods or services that the business is not licensed or permitted to sell.
(b) Fraud, deception, and impersonation
- Impersonating another business, brand, individual, public authority, or emergency service.
- Configuring an agent to deny being an AI system, or to falsely present itself as a specific named human.
- Phishing, social engineering, or any attempt to obtain credentials, payment details, or identity documents under false pretences.
- Deceptive pricing, fake availability, fabricated reviews or testimonials, or bait-and-switch offers.
- Taking payments, deposits, or booking fees for services that will not be provided.
(c) Hate, harassment, and violence
- Content that demeans, dehumanises, or incites hatred or discrimination against people on the basis of race, ethnicity, national origin, religion, disability, age, sex, sexual orientation, gender identity, or any other protected characteristic.
- Threats of violence, incitement to violence, terrorist or violent extremist content, or glorification of either.
- Harassment, bullying, stalking, doxxing, or intimidation of any individual, including your own staff or End-Customers.
- Content that encourages, instructs on, or glorifies self-harm, suicide, or eating disorders.
(d) Sexual content and child safety
- Sexually explicit or pornographic content, or the use of AI agents for adult services or sexual solicitation.
- Any content that sexualises, endangers, or exploits a minor. We operate a zero-tolerance rule here: such content is removed immediately, the account is terminated, and the matter is reported to the competent authorities.
- Deliberately directing AI agents at children, or configuring agents to collect personal data from people known to be under 16 without verified parental consent.
(e) Privacy and data misuse
- Uploading or processing personal data without a lawful basis, or beyond the purposes agreed in our Data Processing Agreement.
- Processing special categories of personal data (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation) outside an approved, documented use case.
- Using the Service for covert surveillance, secret recording, behavioural profiling, or scoring of individuals.
- Scraping, harvesting, or building marketing lists from End-Customer data captured through the Service.
- Selling or otherwise disclosing End-Customer data obtained via the Service to third parties without a lawful basis and appropriate notice.
(f) Spam and unsolicited communication
- Bulk unsolicited outbound calls, messages, or marketing that breach telemarketing, ePrivacy, or anti-spam rules.
- Automated dialling of numbers that were not lawfully obtained, or contacting numbers registered on an applicable do-not-call or opt-out list.
- Ignoring an End-Customer's request to stop being contacted.
- Using the Service to generate call or message volume for the purpose of inflating metrics, testing telecom routes, or traffic pumping.
(g) Misuse of synthetic voice and AI output
- Cloning or imitating the voice or likeness of a real person without that person's explicit, documented consent.
- Creating deepfakes or synthetic media intended to deceive as to identity, endorsement, or the occurrence of events.
- Generating content designed to manipulate elections, mislead voters, or spread political disinformation.
- Presenting AI-generated statements as verified professional advice or as fact where they have not been verified by a qualified human.
(h) Platform, security, and integrity abuse
- Reverse-engineering, decompiling, or attempting to extract the underlying models, prompts, weights, or source code of the Service.
- Prompt injection, jailbreaking, or any attempt to bypass, disable, or degrade safety filters, guardrails, moderation systems, or usage limits.
- Introducing malware, conducting denial-of-service attacks, penetration testing without our prior written consent, or attempting unauthorised access to any account, system, or data.
- Sharing credentials or API keys, reselling or sublicensing the Service, or providing access to third parties without our prior written consent.
- Using the public MCP server to place fictitious, duplicate, or automated bookings and orders that the requester does not intend to honour, or to place load on partner businesses.
4. Restricted, Sensitive & High-Risk Activities
Some uses are not banned outright but carry heightened risk to people, and are therefore restricted. They require our prior written approval, additional safeguards, and — where applicable — a documented risk assessment before they may go live. Using the Service for any of these without approval is a Prohibited Use.
Health, dental, and clinical settings
AI agents may schedule, reschedule, remind, and answer logistical questions. They must not diagnose, triage by clinical severity, give medical advice, alter medication, or interpret test results. Every agent operating in a health setting must recognise urgent situations and route them to a human or to emergency services without delay.
Emergencies
The Service is never a substitute for emergency services. AI agents must not be positioned as an emergency line, and must direct any caller reporting an emergency to 112 (or the local equivalent) immediately.
Legal, financial, tax, and insurance advice
Agents may provide general, publicly available information and take appointments. They must not give individualised legal, financial, tax, or insurance advice, or make representations about entitlements, claims, or outcomes.
Decisions with legal or similarly significant effects
The Service must not be used to make or materially influence automated decisions about a person's employment, credit, insurance, housing, education, or access to essential services. This includes CV screening, creditworthiness assessment, and eligibility scoring.
Biometrics and emotion inference
Biometric identification or categorisation of individuals, and emotion recognition in workplace or educational settings, are not permitted. Voice data may be used to deliver the conversation, not to identify or profile the speaker.
Allergens, dietary, and food-safety information
Allergen and dietary information supplied through an agent is drawn from the Client's own configuration. The Client remains responsible for its accuracy and for confirming it operationally before service. Agents must direct End-Customers with a serious allergy to confirm with a member of staff.
Payments and deposits
Deposits, prepayments, and order payments may only be taken through the payment flows we support, with clear disclosure of the amount, the business taking payment, and the refund position. Agents must never ask an End-Customer to read out full card numbers, CVV codes, or banking credentials.
Minors and vulnerable people
The Service is not directed at children under 16. Where an agent may foreseeably interact with minors or with people in vulnerable circumstances, additional safeguards and an escalation path to a human are required.
Political, electoral, and public-interest communication
Use of AI agents for political campaigning, canvassing, referendum campaigns, or public-health messaging requires prior written approval and explicit AI disclosure in every interaction.
5. How We Moderate: Detection and Review
We combine automated safeguards with proportionate human review. We do not carry out general, indiscriminate monitoring of the content of Client interactions, and we are under no general obligation to do so. Review is triggered by an automated signal, a report, an operational incident, or a legal obligation.
Automated safeguards
- Safety filters and guardrails applied at the model layer, including those operated by our AI sub-processors under their own usage policies.
- Configuration-time checks on agent instructions, greetings, and knowledge-base content for prohibited categories.
- Runtime classifiers and blocked-topic handling that can stop an agent from producing or continuing prohibited content.
- Rate limiting, anomaly detection, and fraud signals across call volume, destination numbers, order patterns, and payment behaviour.
- Integrity checks on the public MCP server to detect automated, fictitious, or abusive booking and ordering traffic.
Human review
- Trained personnel may review flagged configurations, transcripts, recordings, and metadata where necessary to investigate a suspected violation.
- Access is limited to the staff who need it, is granted on a least-privilege basis, is logged, and is subject to confidentiality obligations.
- Review is limited to what is proportionate to the suspected violation, and is carried out in accordance with our Privacy Policy and our Data Processing Agreement with the Client.
- Where content is reviewed as part of a legal request, we follow the process set out in Section 7.
6. Reporting Abuse
Anyone — a Client, an End-Customer, a member of the public, or an authority — can report content or behaviour that appears to breach this Policy. Reports go to [email protected], or through the contact form on this website.
What to include in a report
- The business, phone number, or agent involved, and the approximate date and time of the interaction.
- What happened, and which part of this Policy you believe was breached.
- Any evidence you can share — a recording, transcript, screenshot, message, or reference number.
- How we can contact you if we need more information.
How we handle reports
- We aim to acknowledge reports within two (2) business days and to assess them without undue delay.
- Reports concerning child safety, an imminent threat to life, or serious criminal activity are escalated immediately and may be reported to the competent authorities.
- We treat the identity of a reporter as confidential and do not disclose it to the reported party unless we are legally required to.
- We do not penalise Clients or individuals for making a report in good faith. Repeated bad-faith or abusive reports may themselves be treated as a violation.
- Where the report concerns a decision we have taken, we will tell the affected Client the outcome and the reasons, unless the law prevents us from doing so.
7. Our Rights to Detect, Investigate, Prevent, and Address Abuse
We reserve the right, but do not assume the obligation, to detect, investigate, prevent, and address any use of the Service that breaches this Policy, our Terms of Service, or applicable law.
In an investigation we may
- Access, review, and retain agent configurations, prompts, transcripts, call recordings, order records, and technical logs to the extent needed to investigate.
- Preserve evidence, including where deletion would otherwise be scheduled, for as long as necessary for the investigation or to meet a legal obligation.
- Request information, records, or written assurances from the Client, and set a reasonable deadline for a response.
- Apply temporary protective measures — including rate limits, disabling outbound calling, or restricting a specific agent — while an investigation is open.
- Engage security, legal, or forensic specialists, and cooperate with law enforcement, data protection authorities, and other regulators.
- Disclose information where we are legally required to, or where we believe in good faith that disclosure is necessary to prevent imminent harm to a person.
How we exercise these rights
Investigations are proportionate to the suspected violation and are conducted in accordance with our Privacy Policy and our Data Processing Agreement. Where we act as processor for Client Data, we act on the Client's documented instructions except where EU or Member State law requires otherwise — in which case we inform the Client unless the law prohibits it. We will normally notify the Client that an investigation is under way, unless doing so would prejudice the investigation, endanger a person, or breach a legal requirement.
8. Enforcement: Measures We May Take
Where we determine that this Policy has been breached, we may take one or more of the following measures. We choose the measure proportionate to the circumstances, and we may escalate if a breach continues or recurs.
Measures
- Warning and remediation notice — we tell the Client what is wrong and set a deadline to fix it.
- Content removal — we remove or disable specific content, prompts, greetings, menu entries, or knowledge-base material.
- Configuration rollback — we revert an agent to a previously compliant configuration.
- Feature restriction — we restrict access to specific features, channels, or destinations, including disabling outbound calling, SMS, payments, or MCP access.
- Throttling — we reduce call, message, or API volume limits.
- Account suspension — we suspend the account, a specific location, or a specific phone number or agent, with or without prior notice depending on severity.
- Termination for cause — we terminate the agreement under our Terms of Service. Prepaid credits are non-refundable in the case of termination for a breach of this Policy.
- Withholding or reversing payouts — where we reasonably suspect fraud or unlawful activity, pending investigation and subject to applicable payment rules.
- Reporting to authorities — we report the matter to law enforcement, a supervisory authority, or another competent body where required or appropriate.
- Permanent ban — we refuse future service to the Client and to related entities or individuals responsible for a serious violation.
How we decide
We weigh the severity and type of the violation, whether it appears deliberate or accidental, whether it has happened before, the actual and potential harm to End-Customers or third parties, whether personal data or safety is affected, and how quickly and fully the Client cooperates in fixing it.
Immediate action without prior notice
We may suspend or terminate access immediately, without prior warning, where there is a risk of serious harm to a person, content involving child safety, clear illegality, a security threat to the platform or other Clients, suspected fraud, or where immediate action is required by law or by a competent authority.
9. Appeals & Reinstatement
If we restrict, suspend, or terminate your access, we will tell you what measure we took, which part of this Policy it relates to, and — where we can — what you would need to do to put it right.
How to appeal
- Send an appeal to [email protected] within fourteen (14) days of the decision, explaining why you believe it was wrong or what you have already fixed.
- Where practicable, the appeal is reviewed by someone who was not involved in the original decision.
- We aim to decide appeals within ten (10) business days and will give you the reasons for our decision.
- If the appeal succeeds, we restore access promptly and remove any related restriction.
- An appeal does not suspend the measure while it is being considered, and does not affect your right to pursue a remedy before a competent court or authority.
10. Client Responsibilities
You remain responsible for what your AI agents say and do. Content you configure — agent instructions, greetings, menus, service catalogues, prices, and knowledge-base entries — is your content, and you act as the data controller for the End-Customer personal data processed through your agents.
Your obligations
- Disclose clearly that End-Customers are interacting with an AI system, and give the required notice for call recording and transcription.
- Keep an escalation path to a human available, and make sure your team monitors the KDS and dashboard and verifies AI-generated orders and bookings.
- Make sure everyone you authorise to use the Service — employees, contractors, agencies — knows and follows this Policy.
- Tell us promptly if you discover misuse, a security issue, or a complaint relating to your agents, using the reporting channel in Section 6.
- Cooperate with our investigations and act on remediation notices within the deadline we give you.
- Indemnify GREYDOLL for claims arising from your breach of this Policy, as set out in our Terms of Service.
11. Transparency & Records
We keep records of the reports we receive and the enforcement measures we take, for as long as necessary to operate this Policy, to defend legal claims, and to meet our legal obligations.
We inform the affected Client of any enforcement measure that applies to them, together with the reasons, unless the law prevents us from doing so or notice would prejudice an ongoing investigation or endanger a person.
We may publish aggregate, anonymised statistics about reports and enforcement. We do not identify individual Clients or End-Customers in such reporting.
12. Relationship to Other Terms, Changes & Contact
This Policy forms part of, and is incorporated into, our Terms of Service. It supplements — and does not replace — the Prohibited Use section of those Terms, our Privacy Policy, and any Data Processing Agreement between us. Where a signed enterprise agreement conflicts with this Policy, that agreement prevails to the extent of the conflict.
We may update this Policy as our services, the law, and the risks change. Where a change materially reduces what is permitted, we will give Clients at least thirty (30) days' notice by email or in the dashboard, unless a shorter period is required by law or by an urgent safety or security need. Continued use of the Service after a change takes effect means you accept the updated Policy.
Questions, reports, and appeals: [email protected] — GREYDOLL Technology, Bernadottelaan 22, 3527GB Utrecht, Netherlands. This Policy is governed by Dutch law, and disputes are subject to the exclusive jurisdiction of the competent court in the district of Midden-Nederland (Utrecht).