A!AlloBoss AI BACK OFFICE
Trust & SafetyPrivacyTerms
Back to site ↗

Trust & safety

Automation with a clear exit to a human.

Our standard is simple: tell people when AI is answering, ask before recording, collect only what the job needs, and escalate when automation is no longer the right tool.

Effective August 10, 2026 · Applies to the AlloBoss AI founding beta
ON THIS PAGEOperating principlesCall Recording StandardHuman handoffSafety boundariesCustomer data protectionProduction readinessOfficial sources

1. Operating principles

01Be transparent

The dispatcher identifies itself as an AI assistant. It must not pretend to be a human employee.

02Consent before storage

Where all-party consent may apply, audio and persistent transcripts stay off until the caller agrees.

03A human remains reachable

A caller can request a person. High-risk and low-confidence calls are escalated automatically.

04Collect less

The call flow asks only for details needed to quote, schedule, dispatch, and support the requested service.

2. Call Recording Standard

Recording laws vary by state and by the locations of every person on a call. Florida requires prior consent from all parties to intercept a wire, oral, or electronic communication. Our safest nationwide default is therefore all-party disclosure and affirmative consent.

RECOMMENDED OPENING

“Hi, I’m the AI assistant for [Business Name]. This call may be recorded and transcribed to help with your service request. Is that okay?”

  1. Disclose first. Identify the business, disclose that the caller is speaking with AI, and explain recording and transcription.
  2. Wait for a clear answer. Do not treat silence or an unrelated response as consent.
  3. If the caller says yes: store the consent event, then enable the recording and persistent transcript.
  4. If the caller says no: keep recording off and offer a human transfer, callback, or another non-recorded channel.
  5. If another person joins: repeat the notice and obtain that person’s consent before continuing to record.

For outbound AI or prerecorded voice calls, the business must separately satisfy applicable consent, identification, do-not-call, and opt-out obligations. The inbound dispatcher must not be repurposed for automated outbound marketing without a legal and product review.

3. Transfer to a person

Every live account must have a tested escalation number, business hours, after-hours behavior, and callback owner. Saying “human,” “representative,” or an equivalent request triggers handoff without requiring the caller to explain why.

Automatic handoff triggers

  • Two failed attempts to understand a critical detail such as address, date, price, or service type.
  • A complaint, refund request, billing dispute, legal threat, discrimination concern, or privacy request.
  • A caller who appears distressed, vulnerable, impaired, or unable to provide meaningful consent.
  • A safety concern, suspected crime in progress, or any request outside the approved business workflow.
  • A quote or commitment above a business-defined limit.

For a warm transfer, the AI may provide a short summary to the human after telling the caller. If no one answers, the AI must say that the transfer failed and offer a callback; it must never pretend a person or technician was reached.

4. Safety boundaries

  • Not emergency dispatch: direct immediate threats to 911 or the appropriate local emergency service.
  • No fabricated certainty: do not promise an arrival time, price, availability, or completed dispatch unless confirmed by configured business data.
  • No high-impact decisions: do not make final decisions about employment, housing, credit, insurance, healthcare, legal rights, or essential services.
  • No unnecessary sensitive data: do not ask for SSNs, bank passwords, complete payment-card details, medical records, or government IDs in routine calls.
  • No deceptive identity: the AI identifies itself and may not imitate a real employee or public official.

5. Customer data protection

Our data rule is to collect the minimum needed to complete the service request. Access should be limited to authorized staff of the correct business and vendors required to operate the service.

CollectOnly job-relevant details→UseBook, dispatch, support→ProtectRestrict and monitor access→DeleteWhen no longer needed

Call content is not sold or used for targeted advertising. It should not be used to train a shared AI model without separate written agreement. Privacy requests are verified before data is exported, corrected, or deleted.

6. Honest production-readiness status

Policies alone do not make a product secure. Before taking unrestricted paid production traffic, AlloBoss AI must document and test the following controls:

REQUIREDPer-business data isolation and role-based access

REQUIREDEncryption in transit and at rest, with managed secrets

REQUIREDAudit logs for access, changes, exports, and deletion

REQUIREDConfigurable retention, deletion, and account export

REQUIREDVendor inventory, data agreements, and incident-response plan

REQUIREDRecorded consent event and tested no-consent call path

Current certification status

The founding beta does not claim SOC 2, HIPAA, PCI DSS, or ISO certification. Payment-card data should be handled by the payment provider, not by the AI call transcript or AlloBoss database.

7. Official sources

This standard is operational guidance, not a substitute for advice from qualified counsel. Laws may change and may depend on the caller’s and business’s locations.

  • Florida Statutes § 934.03 — interception and all-party prior consent ↗
  • 18 U.S.C. § 2511 — federal interception rules ↗
  • FCC 24-17 — AI-generated voices under the TCPA ↗
  • FTC — protecting personal information and data security ↗
AlloBoss AIYour AI Back Office for Service Businesses
Trust & SafetyPrivacy PolicyTerms of Use
© 2026 AlloBoss AI. These beta documents should be reviewed by qualified counsel before public launch.
Trust & Safety — AlloBoss AI