Ethics · Responsible AI

Building voice AI we'd be proud to receive

NOVA places AI-generated calls on behalf of real businesses. Trust is the only reason this category survives. This page is the public, enforceable version of the rules we hold ourselves and our customers to — from the very first sentence of every call.

Last updated: 10 May 2026 Version: 1.0 Contact: ethics@novalabs.ae

01AI disclosure policy#

Every NOVA call placed to a phone number in the United States or Canada opens with an explicit, machine-spoken disclosure before any sales content is delivered. The exact opener is:

“Hi, this is an AI-generated voice agent calling on behalf of {company}. This call may be recorded for quality. Are you ok to continue?”

This is a pre-roll consent gate, not a footnote. If the prospect says no — or simply says “no”, “stop”, “remove me”, or “don't call me” — the agent ends the call immediately and the number is added to the customer's suppression list so we will not dial it again.

The disclosure is enforced in code at the agent state machine's first turn: there is no operator override, no “skip the script” flag, and no per-customer toggle. We honour TCPA (47 U.S.C. § 227) and the calling-disclosure rules of states with stricter regimes — including California (B&P Code § 17941, AB 2905), Florida (Fla. Stat. § 501.059), and Minnesota (Minn. Stat. § 325E.30+) — whose requirements feed back into the same enforced-in-code opener.

For calls outside the US/CA, NOVA still discloses that the caller is an AI-generated voice agent whenever the called party asks “is this a real person?” or any close paraphrase. We do not allow customers to instruct the agent to deny being AI.

02Voice cloning consent#

NOVA supports custom synthetic voices via xAI Custom Voices. The rules below are absolute — no exceptions, no enterprise tier, no NDA carve-out.

Whose voice we will clone

Source-recording integrity

Watermarking

Cloned voices include an inaudible watermark per the xAI Custom Voices specification. The watermark is preserved through normal telephony codecs and is designed to let downstream auditors fingerprint AI-generated speech back to its source. (Watermark spec and detection tooling are governed by xAI's published documentation; we will keep this page in sync if their spec materially changes.)

Revocation

The consenting party can revoke a cloned voice at any time by emailing ethics@novalabs.ae from a verifiable address. On revocation we purge the cloned voice model and every derived artifact (fine-tunes, cached embeddings, evaluation samples) within 24 hours and confirm completion in writing.

03BYO Twilio & caller-ID integrity#

Customers can place calls from their own Twilio (or other carrier) numbers via NOVA's Bring-Your-Own-Twilio integration. Caller-ID is one of the easiest places for voice-AI products to do harm. Our rules are non-negotiable:

04Data handling & retention#

We collect only what is needed to operate the service and prove what happened on a given call. Defaults below are minimums; customers can request shorter retention at any time.

Customers and called parties can request earlier deletion by emailing ceo@novalabs.ae. We honour deletion requests within 30 days, except where a longer retention is mandated by law (for example, an open financial-services compliance audit or regulator-issued litigation hold). When a longer retention applies we tell you why and when it will be released.

All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Production data is hosted on AWS in us-east-1, with a dedicated me-central-1 (UAE) region for customers whose data residency obligations require it.

Full data-collection categories, sub-processors, and rights-exercise procedures are documented in the Privacy Policy.

05Compliance frameworks#

NOVA is designed to operate inside the following frameworks:

We do not operate, market, or accept paying customers in any jurisdiction where outbound voice AI is prohibited by national law. Where a jurisdiction's rules tighten after we launch there, we wind down service in that jurisdiction in an orderly way and notify affected customers.

06Refusal categories — what NOVA will not do#

The following use cases are permanently off-limits. They are blocked at onboarding, refused at runtime by guardrails in the agent state machine, and grounds for immediate account termination if attempted after sign-up:

  • Political robocalling — including voter ID, voter persuasion, get-out-the-vote, voter suppression, or any campaign finance-funded outreach.
  • Debt collection on contested debts — in line with the Fair Debt Collection Practices Act (FDCPA) and equivalents.
  • Healthcare, mental-health, or addiction-services outbound — the regulatory and ethical risk to vulnerable callees is too high for an AI voice product.
  • Calls to numbers on the US National DNC Registry without a documented prior business relationship that satisfies TCPA's exemption rules.
  • Impersonating a real human. The agent must always disclose it is AI when asked, and must always lead US/CA calls with the disclosure in §1. Customer scripts that instruct the agent to deny being AI are rejected at script-load time.
  • Pretexting, social engineering, scams, or fraud — including fake-IRS calls, fake-utility-shutoff calls, gift-card scams, romance scams, or any pattern that materially resembles a known fraud playbook.

07Audit & transparency#

Every NOVA call is logged with a complete audit record:

Audit logs are retained for five years to support regulator-led compliance investigations. Customers can request the audit trail for any specific call from their dashboard. Regulators, law-enforcement, or the called party may request a specific call's audit trail by emailing ethics@novalabs.ae with the phone number called and the approximate timestamp; we honour valid requests within 5 business days.

Annual third-party AI ethics review. NOVA commits to an independent annual review of this policy and our enforcement track record. The first review will be conducted and published by Q1 2027.

08Opt-out & DNC#

09Reporting harm#

If you believe a NOVA-placed call was abusive, deceptive, or in any way violated this policy — or if you have concerns about how a voice has been cloned, how a number is being used, or any other AI-safety issue — email ethics@novalabs.ae. We triage every report within 5 business days and respond with the outcome.

Whistleblower protection. NOVA does not retaliate against employees, contractors, or customers who report concerns in good faith. Reports can be made anonymously; if an investigator needs to follow up, we will create a one-way contact channel at your request.

Material AI-safety incident disclosure. If we confirm a material AI-safety incident — e.g., a voice clone used outside its consent envelope, a sustained pattern of undisclosed AI calls, a data exposure that affects called parties — we commit to a public post-mortem within 30 days of confirmation, with enough detail for the ecosystem to learn from it.

10Contact#

Use the most specific address for fastest routing. All inboxes are monitored on UAE business hours (Sunday–Thursday).

General privacy
ceo@novalabs.ae
Ethics & abuse reports
ethics@novalabs.ae
Security disclosures
security@novalabs.ae
Legal & DPA
legal@novalabs.ae
Operations HQ
Dubai, United Arab Emirates
Street address available on request to legal@novalabs.ae.