This Policy forms part of the Terms of Service. It applies to you, your team members, and anyone using the Service through your account. We may suspend or terminate the Service immediately for a material breach.
1. Do not deploy the agent for these purposes
You must not configure or use Frosty Agent to:
- give medical, legal, financial or tax advice to individuals, or anything a reasonable person would rely on for a safety-critical decision;
- handle emergencies, crisis or self-harm situations as a substitute for human or emergency services;
- sell or promote illegal goods or services, weapons, controlled substances, gambling where prohibited, or adult content;
- operate in a sector where automated advice requires a licence you do not hold;
- make automated decisions with legal or similarly significant effects on an individual (credit, employment, insurance, housing) without human review.
1A. Children & Minors
If your audience may include people under 18:
- You are the Data Fiduciary. You must obtain verifiable parental consent under section 9 of the Digital Personal Data Protection Act, 2023 and Rule 10 of the DPDP Rules, 2025 before the agent processes a child’s personal data. Where the GDPR applies, the age of consent is 13 to 16 depending on the Member State and you must meet the applicable threshold.
- Do not deploy to minors without parental consent and age assurance. Do not deploy the agent to an audience you know, or ought reasonably to know, includes children unless you have implemented age assurance and verifiable parental consent to that statutory standard.
- No child profiling or tracking. Section 9(3) of the DPDP Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. Frosty Agent standardly performs automated enquiry scoring and lead qualification during conversations (which constitutes profiling as described in Section 7.2 of our Privacy Policy). Because the Service does not offer configurations to disable lead capture, enquiry scoring, or conversation persistence, you must not deploy the agent to children or configure it for child-directed interactions.
- Data retention and prompt erasure. Conversation data retention can be configured down to the platform’s minimum supported period of 30 days (configurable between 30 and 730 days in merchant settings). If you discover or suspect that a child’s personal data has been collected without verifiable parental consent, you must immediately delete the record via your dashboard or notify us at privacy@frostyagent.com for prompt erasure under our Section 18 procedure.
2. Do not misuse the agent’s identity
- Do not configure the agent to deny being an AI if a person asks directly.
- Do not impersonate a named real person, a government body, or another business.
- Do not use it to generate deceptive reviews, testimonials or endorsements.
3. Do not upload unlawful or harmful content
You must not upload to the knowledge base, catalogue or configuration any content that:
- you do not have the right to use;
- infringes intellectual property or contains someone else’s confidential information;
- is unlawful, defamatory, harassing, hateful, or promotes violence;
- contains malware or exploit code;
- contains special-category personal data (health, biometric, religious or political data, sexual orientation, or similar) unless you have told us in writing and we have agreed in the DPA.
4. Do not misuse other people’s data
- Only send messages to people who have opted in as the relevant channel requires. For WhatsApp this is a Meta requirement and you carry it.
- Do not upload contact lists you have no lawful basis to process.
- Do not use the Service for unsolicited bulk messaging or spam.
- Do not attempt to re-identify, scrape or harvest data about visitors beyond what your own privacy notice discloses.
4A. WhatsApp — Meta’s rules apply to you directly
If you use the WhatsApp channel:
- Record a valid opt-in before messaging anyone. Meta requires an active, affirmative action that names your business and confirms the person wants WhatsApp messages from you. A phone number sitting in your CRM is not opt-in. If Meta audits your account you must be able to produce the consent record immediately.
- Keep the agent task-specific. Since 15 January 2026 Meta permits only task-specific assistants on the WhatsApp Business Platform — support, order tracking, appointment booking and similar. Generic open-ended AI chat without a clear business purpose is prohibited and risks your WhatsApp account, not only ours.
- Provide an easy opt-out and honour it.
- Observe messaging windows and template approval rules.
We may suspend the WhatsApp channel on your account if we believe your use puts our platform access at risk.
4B. Voice — recording and consent
If you enable voice, you are recording a person’s voice and having it transcribed.
- Tell people before the recording starts.
- Some jurisdictions require all-party consent to record a conversation — several US states and a number of other countries. If you serve those markets, obtain it.
- Do not use voice features to attempt speaker identification, emotion inference, or any biometric categorisation of a person.
5. Do not attack or overload the Service
You must not:
- probe, scan or test the vulnerability of the Service except under a written agreement with us (see Section 7);
- circumvent authentication, rate limits, plan entitlements, quotas or billing;
- access another merchant’s data, or attempt to;
- use automated means to place unreasonable load on the Service;
- resell, sublicense or provide the Service to third parties as your own product without a written reseller agreement.
6. Do not attempt to extract or subvert the models
- Do not attempt to extract system prompts, model weights, or our proprietary configuration.
- Do not use the Service to train a competing model.
- Do not deliberately use prompt injection to make the agent violate this Policy.
7. Security research
We welcome good-faith reports. Write to security@frostyagent.com before testing. Do not test against another merchant’s account, do not access data that is not yours, and give us reasonable time to fix an issue before disclosing it.
8. Your responsibility for your team
You are responsible for your team members’ use, including any custom roles you create. Grant the narrowest permissions each person needs.
9. Enforcement & Abuse Reporting
We may investigate suspected breaches and may suspend access, remove content, or terminate. Where practicable we will give notice and an opportunity to cure — but for security risks, illegal activity, or risk to other merchants we may act immediately.