// DOC 003

Compliance Policy

COMPLIANCE POLICY

VANE Intelligence LLC
Effective Date: June 26, 2026
Last Updated: June 27, 2026


VANE operates in a regulated space. Visitor identification involves
processing personal information about individuals who have not directly
opted in to communicate with VANE or its End Clients. Outbound calling
conducted by Reps on VANE's behalf is subject to federal and state
telemarketing law. This policy describes the legal framework VANE operates
under and the rules that Reps and End Clients must follow without exception.

Failure to comply with this policy is grounds for immediate program
termination and may expose the violating party to civil and criminal
liability.


// 01 — APPLICABLE LAW

VANE's operations and the activities of Reps and End Clients are subject to,
at minimum, the following:

   - California Consumer Privacy Act (CCPA) and California Privacy Rights
     Act (CPRA)
   - Virginia Consumer Data Protection Act (VCDPA)
   - Colorado Privacy Act (CPA)
   - Connecticut Data Privacy Act (CTDPA)
   - Texas Data Privacy and Security Act (TDPSA)
   - Oregon Consumer Privacy Act (OCPA)
   - Other U.S. state comprehensive privacy laws as they take effect
   - Telephone Consumer Protection Act (TCPA)
   - National Do Not Call Registry rules (16 CFR Part 310)
   - CAN-SPAM Act
   - Federal Trade Commission Act, Section 5 (unfair and deceptive practices)
   - State data broker registration laws (California, Vermont, Texas,
     Oregon, and others as applicable)
   - State telemarketing laws and registration requirements as applicable

This list is not exhaustive. Reps and End Clients are responsible for
compliance with all laws applicable to their operations and the individuals
they contact.


// 02 — VISITOR NOTICE AND CHOICE

VANE requires that any website deploying the VANE pixel post:

   (a) A privacy notice disclosing that the website uses third-party visitor
       identification technology and identifying VANE (or VANE's white-label
       brand for that deployment) as the processor;

   (b) A clear opt-out mechanism that suppresses identification for the
       requesting visitor across future sessions;

   (c) Recognition of the Global Privacy Control (GPC) signal as a valid
       opt-out where applicable law requires;

   (d) For California: a "Do Not Sell or Share My Personal Information" link
       in the footer of the End Client's website, in conformance with CPRA
       requirements.

VANE supplies template language and a default opt-out endpoint. End Clients
deploying the pixel are responsible for implementation on their own site.


// 03 — GEOFENCING

VANE applies geographic restrictions to suppress identification of visitors
located in:

   - The European Union and European Economic Area
   - The United Kingdom
   - Other jurisdictions where applicable law conflicts with VANE's
     identification model

End Clients and Reps must not attempt to circumvent geofencing or request
identification of visitors located in restricted jurisdictions.


// 04 — TELEPHONE OUTREACH (TCPA & DNC)

Compliance responsibility for outbound calling is split between VANE
(list-level compliance) and Reps (execution-level compliance). Both layers
must function for the program to be lawful.

4.1. List-Level Compliance (VANE's Responsibility)
VANE assembles and maintains the call lists distributed to Reps. VANE is
responsible for:

   (a) Scrubbing lead lists against the National Do Not Call Registry on a
       frequency consistent with applicable law (no less than every 31 days);

   (b) Applying state-level DNC and telemarketing suppression where
       applicable;

   (c) Maintaining an internal suppression list of individuals who have
       requested no further contact from VANE, and ensuring suppressed
       numbers do not reappear in Rep call assignments;

   (d) Restricting Rep call lists to business contact fields; personal
       phone numbers are excluded from Rep assignments;

   (e) Excluding numbers identified by the upstream pixel data as carrying
       DNC indicators;

   (f) Suspending list deployment in any jurisdiction where applicable law
       would prohibit the outreach.

4.2. Execution-Level Compliance (Rep's Responsibility)
Each Rep, in performing outbound calling on VANE's behalf, is responsible
for:

   (a) Calling only numbers assigned through the VANE dashboard; no
       freelancing, no list-padding, no use of numbers from outside sources;

   (b) Observing TCPA calling hours: no calls before 8:00 a.m. or after
       9:00 p.m. in the called party's local time zone;

   (c) Immediately ceasing contact attempts to any individual who requests,
       by any means, no further contact, and reporting the request to VANE
       within 24 hours for addition to the suppression list;

   (d) Following VANE-provided call scripts and required disclosures, which
       exist to ensure compliance with TCPA, state telemarketing law, and DNC
       requirements and to ensure accurate representation of VANE's services;
       Reps retain discretion over conversational style and delivery, but may
       not make claims about VANE's pixel technology, data sources, accuracy,
       or capabilities outside the substance of VANE-provided materials;

   (e) Not using automatic telephone dialing systems (ATDS), prerecorded
       messages, artificial or AI-generated voices, or any technology that
       could constitute auto-dialing under TCPA, unless VANE has provided
       prior written authorization;

   (f) Logging call outcomes in the dashboard accurately and contemporaneously;

   (g) Reporting any consumer complaint, threat of legal action, regulator
       inquiry, or unusual response from a called party to VANE immediately.

4.3. Personal Phone Numbers
VANE does not include personal phone numbers in Rep call assignments.
Outreach conducted by Reps on VANE's behalf is restricted to business
contact fields. Any future expansion of scope requires policy revision,
legal review, and explicit written authorization from VANE.

4.4. SMS Outreach
SMS outreach is not currently authorized for Reps. Any future SMS program
requires separate policy authorization, TCPA-compliant consent
infrastructure, and written approval from VANE.

4.5. Auto-Dialer and Synthetic Voice Restrictions
Use of any automatic telephone dialing system, prerecorded message,
artificial or AI-generated voice, voice-cloning technology, or similar
automation to contact individuals on VANE-assigned lists is prohibited
without VANE's prior written authorization and demonstrated TCPA-compliant
consent infrastructure.


// 05 — EMAIL OUTREACH (CAN-SPAM)

Email outreach using data returned by the platform must comply with the
CAN-SPAM Act, including:
   - Accurate header information and sender identification
   - Clear identification of the message as commercial in nature
   - A valid physical postal address of the sender
   - A clear and functional unsubscribe mechanism honored within 10 business
     days

End Client email outreach using pixel-returned data is the End Client's
responsibility. Reps do not conduct email outreach to leads as part of
VANE-directed activities; any future authorization of Rep email outreach
requires separate policy approval.


// 06 — PROHIBITED USES

Data returned by the VANE platform (whether full pixel outputs delivered to
End Clients, or curated lead lists assigned to Reps) must NOT be used for:

   (a) Discrimination on the basis of race, ethnicity, religion, gender,
       sexual orientation, disability, or other protected characteristics;

   (b) Stalking, harassment, or intimidation of any individual;

   (c) Adverse decision-making in employment, credit, housing, insurance,
       or any other context governed by the Fair Credit Reporting Act
       (FCRA). VANE data is NOT an FCRA-permitted consumer report and must
       not be used as one;

   (d) Sale or resale to third parties without VANE's written authorization;

   (e) Identification of minors (individuals under 18) for any purpose;

   (f) Political campaign outreach without independent compliance review;

   (g) Adult content marketing, gambling outside permitted jurisdictions,
       cannabis or controlled substance marketing in restricted
       jurisdictions, or any activity prohibited by applicable law.

Rep-facing prohibitions are necessarily narrower than End Client-facing
prohibitions because Reps access only the limited lead contact information
described in Section 3.2 of the Privacy Policy. Reps are nonetheless bound
by the entirety of this section with respect to any data they access or
encounter.


// 07 — REPRESENTATIONS BY REPS

Reps must not make representations to leads, prospects, or End Clients that:

   (a) Guarantee specific identification rates, lead quality, appointment
       conversion rates, or revenue outcomes;

   (b) Claim compliance certifications (SOC 2, ISO, HIPAA, GDPR adequacy,
       etc.) that VANE has not formally obtained;

   (c) Misrepresent the source, scope, or accuracy of data underlying
       VANE's services;

   (d) Describe the technical workings of VANE's pixel or upstream data
       sources beyond what is expressly stated in VANE-provided scripts and
       marketing materials;

   (e) Suggest that End Clients can use the data without their own legal
       review.

Reps may share VANE-provided marketing materials, sales decks, and example
case studies as published by VANE. Reps must not modify these materials or
add unsupported claims.


// 08 — INDIVIDUAL RIGHTS REQUESTS

Individuals identified through the platform may exercise rights under
applicable law, including the right to access, delete, correct, or opt out
of processing of their personal information.

When an End Client receives such a request directly, the End Client must
forward it to VANE within five (5) business days. VANE will process verified
requests within statutory timeframes.

When a Rep receives a verbal or written "do not call me" request, or any
other rights-related request from an individual on a call, the Rep must:

   (a) Immediately cease contact attempts to that individual;
   (b) Log the request in the dashboard;
   (c) Forward the request to VANE (privacy@vaneintelligence.com) within
       24 hours.

Direct individual requests received by VANE will be processed regardless of
whether the request is routed through the original End Client or Rep.


// 09 — DATA SECURITY EXPECTATIONS

Data security obligations are tiered based on the data each party accesses.

9.1. Rep Dashboard Access
Reps with dashboard access must:
   - Use unique, non-shared login credentials
   - Enable multi-factor authentication where offered
   - Not export, copy, photograph, screenshot, or otherwise extract lead
     lists or contact information from the dashboard for use outside
     VANE-directed activities
   - Not share dashboard contents (including lead names, phone numbers, or
     call notes) with any third party
   - Not transmit dashboard data over unencrypted channels
   - Not log into the dashboard from shared, public, or untrusted devices
   - Report any suspected security incident, lost or stolen device, or
     credential compromise to VANE within 24 hours

9.2. End Client Pixel Data Access
End Clients with access to identified visitor data must:
   - Use unique, non-shared login credentials and enable MFA where offered
   - Not export or store identified data in unsecured locations
   - Not transmit identified data over unencrypted channels
   - Treat the data consistent with applicable privacy law and these
     obligations as an independent controller
   - Report any suspected security incident to VANE within 24 hours

End Clients receiving identified data are independent controllers under
most applicable privacy laws and bear independent responsibility for the
security of data once it leaves the VANE platform.


// 10 — TRAINING REQUIREMENT

All Reps must complete VANE's compliance training module and acknowledge
this Compliance Policy before being granted dashboard access. Training
covers, at minimum: TCPA calling rules and hour restrictions, DNC handling,
"do not call me" intake and escalation, prohibited claims, dashboard data
handling, and incident reporting. Training is required to ensure Reps
understand their legal compliance obligations and can accurately represent
VANE's services; it does not constitute employment direction and does not
alter the independent contractor relationship. Re-acknowledgment is required
when this policy is materially updated.


// 11 — AUDIT AND ENFORCEMENT

VANE may audit Rep and End Client activity, including call records,
communication logs, dashboard access logs, and data export activity, for
compliance with this policy. Reps consent to call recording where VANE has
implemented it, subject to applicable state two-party consent laws.

Violations may result in:
   - Warning and required remediation
   - Suspension of platform access
   - Termination of the Independent Contractor Agreement or End Client
     services
   - Forfeiture of unpaid commissions
   - Referral to law enforcement where criminal violations are suspected
   - Civil action for damages caused to VANE


// 12 — DISCLAIMERS

This Compliance Policy summarizes VANE's expectations and the principal
legal frameworks applicable to platform use. It is not a complete statement
of applicable law and is not legal advice. Reps and End Clients should
consult their own counsel regarding their specific obligations.

VANE makes no representation that following this policy ensures compliance
with all applicable laws in all jurisdictions where Reps or End Clients
operate.


// 13 — CONTACT

To report a compliance concern, submit a data subject request, or ask a
compliance question:

VANE Intelligence LLC
Attn: Compliance
322 South College Road #1193
Wilmington, NC 28403
compliance@vaneintelligence.com