Legal
Data Processing Addendum
Last updated: June 18, 2026
This Data Processing Addendum (“DPA”) supplements the Finn General Terms and Conditions (the “Agreement”) entered into by and between AIforge Tech Private Limited (“Processor”) and the client agreeing to these terms (“Controller”).
This DPA governs the processing of Personal Data in connection with Controller’s use of the Finn voice agent infrastructure (the “Services”).
1. Definitions
- “Applicable Data Protection Laws” means all applicable federal, state, and international laws and regulations relating to the privacy and security of Personal Data, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the CPRA, the EU General Data Protection Regulation (GDPR), the UK GDPR, the Digital Personal Data Protection Act, 2023 (India), and applicable US State Privacy Laws (e.g., Virginia, Colorado, Connecticut, Utah, Florida).
- “Controller Data” means any Personal Data processed by Processor on behalf of Controller pursuant to the Agreement.
- “Personal Data” means any information relating to an identified or identifiable natural person contained within Controller Data (including voice audio, spoken names, and phone numbers).
- “Sub-processor” means any third-party data processor engaged by Processor to assist in fulfilling its obligations under the Agreement.
2. Roles and Scope of Processing
2.1 Roles of the Parties.For the purposes of Applicable Data Protection Laws, Controller is the Data Controller (or “Business”), and Processor sits strictly as the Data Processor (or “Service Provider”).
2.2 Scope of Processing. Processor shall process Controller Data strictly to provide the Services, and strictly in accordance with documented instructions from Controller (which include the settings, prompt configurations, and API Webhooks configured by Controller within the platform).
3. Specific AI & Telephony Restrictions
3.1 No Model Training.Processor acknowledges and agrees that Controller Data shall not be used to train, retrain, fine-tune, or benchmark any artificial intelligence, Large Language Model (LLM), or Speech-to-Text (STT) model, whether owned by Processor or by its third-party Sub-processors. Processor engages third-party model providers under API terms that prohibit training on Controller Data, uses zero-data-retention configurations wherever the provider offers them and they are included in Controller’s Subscription plan, and, where such a configuration is not offered or not so included, permits only short-lived operational retention that is never used for model training.
3.2 Ephemeral Audio Processing.Processor processes live conversational telephony streams. Processor warrants that live streaming audio payload is held in volatile memory (RAM) strictly for the duration required to convert speech to text and generate an artificial response. Once a call session is terminated, raw audio streams are written to storage strictly subject to the Controller’s configured Time-To-Live (TTL) retention settings (default: ninety (90) days, unless Controller configures otherwise).
3.3 Two-Party Consent Disclosure Engine.Where Controller operates in jurisdictions requiring two-party recording consent (e.g., Florida Stat. § 934.03), Processor provides the prompt-engineering infrastructure to deliver automated “First Utterance” recording disclosures; however, Controller remains solely legally responsible for instructing the AI agent to deliver said disclosure before logging or recording the call.
4. Sub-processing
4.1 Authorized Sub-processors.Controller grants Processor general authorization to engage Sub-processors to deliver the Services (e.g., cloud hosting, telecommunications carriers, and no-training LLM APIs with zero-data-retention configurations where offered and applicable to Controller’s plan). A current list of Sub-processors is maintained at hirefinn.ai/subprocessors.
4.2 Notice of New Sub-processors.Processor shall provide Controller with at least fourteen (14) days’ written notice of the addition of any new Sub-processor. Notice is given by email to Controller’s account owner and by updating the list at hirefinn.ai/subprocessors. If Controller has a reasonable, data-protection-related objection to the new Sub-processor, Controller may terminate the applicable portion of the Services without penalty.
4.3 Flow-down Obligations. Processor shall enter into a written agreement with each Sub-processor imposing data protection terms no less protective than those set forth in this DPA.
5. Security & Personal Data Breaches
5.1 Technical and Organizational Measures (TOMs). Processor shall implement and maintain the technical and organizational security measures set forth in Schedule B.
5.2 Security Incident Notification.If Processor becomes aware of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Controller Data (a “Personal Data Breach”), Processor shall notify Controller without undue delay, and in any event within forty-eight (48) hours.
6. Data Subject Requests
Processor shall, to the extent legally permitted, promptly notify Controller if Processor receives a request from a Data Subject (e.g., an individual who spoke with a Controller’s deployed agent) exercising their rights under Applicable Data Protection Laws (such as a request to erase their call transcript). Processor shall not respond to such requests directly, but will provide Controller with the API tools necessary to execute the Data Subject’s request.
7. Return and Deletion of Data
Upon termination or expiration of the Agreement, at Controller’s election, Processor shall either return Controller Data to Controller in a commonly used, machine-readable format or securely delete it, in each case within thirty (30) days, except to the extent that retention is required by applicable law. Controller may also request deletion of specified Controller Data at any time by written request to [email protected], and Processor shall complete such deletion within thirty (30) days.
In addition, Controller instructs Processor, as a documented instruction under this DPA, to automatically and permanently delete all stored Controller Data comprising call communications (including audio recordings and transcripts) associated with Controller’s account if that account remains entirely inactive for twelve (12) consecutive months.
Upon Controller’s written request, Processor shall confirm completion of any deletion under this Section in writing.
8. California (CCPA / CPRA) Specific Terms
To the extent Controller Data belongs to California residents:
- Processor is acting solely as a “Service Provider”.
- Processor shall not “Sell” or “Share” Controller Data (as those terms are defined under the CPRA).
- Processor shall not retain, use, or disclose Controller Data for any purpose other than for the specific business purpose of performing the Services specified in the Agreement.
- Processor shall not combine Controller Data with personal information received from other sources, except as permitted for service providers under the CCPA/CPRA.
- Processor shall notify Controller if it determines that it can no longer meet its obligations under the CCPA/CPRA.
- Upon such notice, Controller may take reasonable and appropriate steps to stop and remediate any unauthorized use of Controller Data.
9. International Data Transfers
9.1 Restricted Transfers.Where Processor’s processing of Controller Data involves a transfer of Personal Data out of the European Economic Area (EEA), the United Kingdom, or Switzerland to a country without an adequacy decision, the mechanisms in this Section apply.
9.2 EU Standard Contractual Clauses.The parties incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) for transfers governed by the GDPR: Module Two (Controller-to-Processor) between Controller and Processor, and Module Three (Processor-to-Processor) for onward transfers to Sub-processors. The EU SCCs are governed by the law of Ireland, and the courts of Ireland have jurisdiction over disputes arising from them. The Annexes to the EU SCCs are completed in the executed copy of this DPA, which is available on request at [email protected].
9.3 UK and Swiss Transfers. For transfers governed by the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner. For transfers governed by the Swiss FADP, the EU SCCs apply with the amendments identified by the Swiss Federal Data Protection and Information Commissioner.
9.4 Supplementary Measures.The parties acknowledge the technical and organizational measures in Schedule B and Section 3 as supplementary measures protecting transferred data, including AES-256 encryption at rest, TLS 1.2/1.3 in transit, ephemeral in-memory audio processing, no-training model APIs with zero-data-retention configurations where offered and applicable to Controller’s plan (under which model providers do not use Controller Data for training), tenant isolation, and least-privilege access.
9.5 Precedence and Government Access. In the event of a conflict between the EU SCCs or UK Addendum and this DPA, the SCCs or UK Addendum prevail with respect to the Personal Data they govern. Processor shall, to the extent legally permitted, notify Controller of any binding request from a public authority for disclosure of Controller Data and challenge requests that are unlawful under Applicable Data Protection Laws.
10. Confidentiality, Assistance & Audit
10.1 Personnel Confidentiality. Processor ensures that persons authorized to process Controller Data are bound by an appropriate written or statutory duty of confidentiality.
10.2 DPIA and Prior-Consultation Assistance. Taking into account the nature of processing and the information available to it, Processor shall provide Controller with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities relating to the Services.
10.3 Audit.Processor shall make available to Controller the information reasonably necessary to demonstrate compliance with this DPA, and satisfies this obligation by providing its current ISO/IEC 27001 certificate, its SOC 2 report (once available), and responses to a reasonable security questionnaire. On-site audits are available only where these are insufficient to satisfy a mandatory legal requirement, and are limited to once per twelve (12) months, on at least thirty (30) days’ written notice, at Controller’s cost, under confidentiality, during business hours, and without disrupting Processor’s operations.
10.4 Governing Law. Except where the Standard Contractual Clauses or the UK Addendum mandate otherwise, this DPA is governed by the law governing the Agreement, and disputes under it are resolved through the same dispute-resolution mechanism as the Agreement.
Schedule A: Details of Processing
- Subject Matter: The processing of inbound and outbound voice telephony, real-time speech transcription, structured JSON data extraction, and call routing.
- Duration of Processing: The term of the Agreement plus the wind-down period until return or deletion under Section 7 (thirty (30) days).
- Categories of Data Subjects:Customers, employees, contractors, or job applicants of the Controller who speak with the Controller’s deployed Finn voice agents.
- Categories of Personal Data: Spoken names, phone numbers, caller-ID metadata, voice audio recordings, text transcripts of conversations, and any unprompted personal variables voluntarily spoken by the Data Subject during the phone call.
- Sensitive Data: Protected Health Information (PHI) may be processed only by enterprise Controllers who have executed a Business Associate Agreement (BAA) with Processor; that BAA governs the handling of PHI. Absent an executed BAA, the Services are not intended for PHI. By default, the Services are likewise not intended for cardholder data governed by the Payment Card Industry Data Security Standard (PCI DSS), and Controller is instructed not to prompt agents to request Social Security Numbers or full payment-card numbers over the voice line. Where a Controller requires the processing of cardholder data, such processing is supported only under a separate, custom Master Services Agreement and data-protection terms that define the applicable PCI DSS-aligned controls and the responsibilities of each party.
Schedule B: Technical & Organizational Measures (TOMs)
- Encryption in Transit: All telephony signaling (SIP/TLS) and API Webhook traffic passing between Controller, Processor, and Sub-processors is encrypted using TLS 1.2 or TLS 1.3.
- Encryption at Rest: All stored .wav audio files and .json transcripts sitting in cloud buckets are encrypted using AES-256.
- Access Controls: Access to production infrastructure containing Controller Data is restricted to authorized Processor personnel on a least-privilege basis, enforced via Multi-Factor Authentication (MFA) and SSH keys.
- Tenant Isolation:Controller Data is logically segregated inside Processor’s cloud databases; one Controller cannot query, call, or access the data tables or voice instances of another Controller.
AIforge Tech Private Limited · D-253, Kardhani Govindpura, Kalwar Road, Jaipur, Rajasthan, India - 302012 · CIN: U62099RJ2025PTC099494 · [email protected]
Get started
Hire Finn and scale with confidence.
Move from idea to live voice automation — securely, reliably, and without operational risk.
Fort-nightly Launches
We move quickly and get you what you need
Powerful Tools
Pre-built dashboards, reports, automations, more