Before you start
Regulated industries add rules on top of the regional rules. Finn doesn't enforce any of them: it doesn't limit calling hours or attempts, check do-not-call lists, detect sensitive data in a transcript, or add disclosures. You meet these rules through how you build the audience, the prompt, the welcome message and the deployment schedule.
This page is general guidance, not legal advice. Check your design with a lawyer who specializes in your industry and jurisdiction.
Healthcare
The dividing line is whether a call touches Protected Health Information.
Appointment reminders that mention only date, time and provider are generally treated as treatment, payment or operations communication under HIPAA. Once a call discusses diagnosis, test results or treatment, you're handling PHI.
To send PHI through Finn you need a signed Business Associate Agreement. BAAs are available to enterprise customers, executed per engagement. Request one from [email protected], and sign it before any PHI reaches Finn. Without a BAA, Finn isn't intended for PHI. See compliance.
The practical design is to keep the script generic and send anything clinical to a person:
Guardrail:
If the caller asks about test results, diagnosis, medication changes, or
anything clinical, do not answer. Say you will transfer them to the clinic
and use the transfer tool. Never read back medical details.
Wire that as a guardrail (agents-guardrails) plus a transfer tool (tools-transfer). A guardrail is a prompt instruction and can be talked around. The transfer is what actually ends the conversation.
If a caller volunteers PHI on a Finn without a BAA, it lands in the transcript, and in the recording if recording is on. Finn doesn't detect or remove it. Shorter retention limits how long it's stored (retention), and for a specific call you can ask support to delete it.
Some states require a separate disclosure when AI is used in healthcare communication. Put it in the welcome message (agents-welcome) for the states you call into.
Financial services
Several regimes can apply at once: TCPA, the FTC Telemarketing Sales Rule, FDCPA for collections, GLBA and state consumer-protection laws in the US, and TRAI and RBI rules in India.
Decisions to make before launch:
| Decision | Where you make it |
|---|---|
| Marketing or informational | Your campaign design. It decides whether you need prior written consent. |
| Calling hours | When you schedule, pause and stop deployments. |
| Do-not-call scrubbing | Your list, before you upload the audience. |
| Recording disclosure | The Finn's welcome message. See recording consent. |
| How long recordings are kept | Settings → Data → Data retention. The longest window is 2 years, or Never delete. |
If a regulator expects multi-year call records, set retention to cover it before you start calling, and keep your own copies of what you must retain. Recordings already deleted under a shorter window can't be restored.
Account-servicing calls such as balance alerts and payment confirmations are usually informational. A cross-sell inside the same call can turn it into a marketing call. Keep those flows in separate Finns rather than branching mid-call, so the consent basis for each deployment is clear.
Don't have the agent collect full card numbers or government IDs. Finn's Data Processing Addendum excludes cardholder data unless you have separate terms.
Collections
Debt collection has extra limits on time, frequency and content. None of them are enforced by Finn.
- Time. Schedule and pause deployments within allowed hours in the debtor's time zone.
- Frequency. Finn doesn't cap attempts per person. Count attempts yourself across deployments and sequences, and keep people who've reached your limit out of new audiences.
- Third parties. The script must handle someone other than the debtor answering. Write that branch explicitly.
Guardrail:
If the person on the line is not the named contact, do not state the reason
for the call, the company name in a way that implies debt, or any amount.
Ask only whether the named contact is available, then end the call.
Opt-outs matter most here. Add a Yes/No post-call question such as opt_out so requests are easy to find (analysis fields), and act on them yourself: remove the number from every audience and keep it out of future uploads. The question records the request. It doesn't stop the next call.
Legal services and other regulated work
The general rules apply, and they matter more here:
- Recording disclosure is required in all-party-consent jurisdictions. See recording consent.
- Let the Finn say it's an AI when asked. Using an AI voice agent is generally legal. Denying it to someone who asks directly is not.
Guardrail:
If the caller asks whether you are a real person, tell them honestly that
you are an AI assistant.
What Finn doesn't do for you
| You might expect | What actually happens |
|---|---|
| Finn blocks PHI without a BAA | It doesn't. Nothing detects PHI in a transcript. |
| Finn keeps calls inside allowed hours | It doesn't. A deployment calls whenever it runs. |
| Finn skips do-not-call numbers | It doesn't. It dials every number in the audience, including contacts marked Do not call on the Contacts page. |
| An opt-out on a call stops future calls | It doesn't. Remove the number from your audiences. |
| Finn limits attempts per person | It doesn't. Track attempts yourself. |
| Finn adds a recording or AI notice | It doesn't. Put notices in the welcome message. |