Compliance & Regulations

Our Compliance Approach

We Are SMS supports campaigns that are designed to be permission-based, transparent, relevant, measurable and easy to opt out of.

We do not support spam, misleading messaging, unlawful data use or campaigns where consent, permissions or lawful basis cannot be evidenced.

Where consent is required, it should be freely given, specific, informed, unambiguous, recorded and easy to withdraw.

Clients should be able to evidence when, where and how consent was obtained, what wording was shown, what the recipient agreed to, and which business was authorised to contact them.

Every marketing campaign should provide a clear and simple way for recipients to opt out.

Where a recipient opts out, that request should be actioned promptly. Suppression records may be maintained to help ensure the person is not contacted again for the same type of marketing.

AI may be used to support message drafting, lead qualification, conversation routing, response suggestions, campaign testing, webchat support and follow-up workflows.

AI should not be used to mislead customers, dishonestly impersonate people, pressure vulnerable individuals or make regulated claims without appropriate approval.

We Are SMS takes reasonable steps to protect personal data handled through its services. Controls may include access permissions, secure systems, supplier checks, audit logs, data minimisation and deletion or return of data where appropriate.

We Are SMS does not support unlawful marketing, purchased data without appropriate permissions, misleading campaigns, harassment, fraud, impersonation, high-risk regulated claims without approval, sensitive data misuse or any activity that may cause harm.

  • Reply STOP to opt out.
  • Text STOP to stop receiving messages.
  • Reply STOP and we will not contact you again about this.

The UK GDPR and Data Protection Act 2018 set rules for how personal data must be collected, used, stored and protected.

Where We Are SMS uses personal data for its own business purposes, it may act as a data controller. Where it processes data on behalf of a client, it will usually act as a data processor.

Clients remain responsible for ensuring data supplied to We Are SMS has been collected fairly, lawfully and transparently.

The Privacy and Electronic Communications Regulations apply to electronic marketing, including SMS and certain forms of direct messaging.

Marketing texts to individuals normally require valid consent unless a specific compliant exception applies, such as the limited soft opt-in route for existing customers.

We Are SMS expects clients to confirm that recipients can lawfully be contacted before a campaign is launched.

Clients using We Are SMS are responsible for the data, campaign purpose, campaign content, lawful basis, consent status, privacy information, suppression lists and any sector-specific approval requirements that apply.

We Are SMS may refuse, pause or stop a campaign if it may create legal, compliance, reputational, technical or consumer harm risk.

Some industries have additional rules around marketing, financial promotions, customer vulnerability, advice, claims, health, insurance, credit, investments, legal services and funeral plans.

Where a campaign relates to a regulated sector, the client is responsible for ensuring the campaign meets all relevant legal and regulatory requirements before it is launched.

Before launching a campaign, We Are SMS may review the campaign objective, message wording, target audience, data source, consent position, opt-out process, landing pages, web forms and regulated-sector requirements.

This review supports responsible use but does not replace the client’s own legal and compliance responsibilities.

We Are SMS is committed to responsible communication, transparent data use and compliant lead engagement. We work with businesses that want to build genuine customer conversations, not spam people.