What this page covers
Finn handles phone calls, transcripts, recordings and whatever personal data callers say out loud. This page lists what Finn has in place, what you can request for a security review, and what stays your responsibility.
This isn't legal advice. For that, talk to a lawyer who works on telecom or privacy in the places you call.
Certifications
These are listed on the Trust Center at hirefinn.ai/trustcenter.
| Item | Detail |
|---|---|
| SOC 2 Type II | Audited by A-LIGN. The report is confidential and shared under NDA. |
| ISO/IEC 27001:2022 | Information security management. |
| ISO/IEC 20000-1:2018 | IT service management. |
| ISO 9001:2015 | Quality management. |
Documents on request
Email [email protected] for any of these.
| Document | Notes |
|---|---|
| SOC 2 Type II report | Under NDA. |
| HIPAA Business Associate Agreement | For enterprise customers processing PHI. Executed per engagement. |
| Standard Contractual Clauses | Executed copy for EU, UK and Swiss transfers. |
| ISO 27001 Statement of Applicability | Under NDA. |
| Data residency attestation | Which region your workspace's data is stored in. See data residency. |
The Data Processing Addendum (hirefinn.ai/dpa), the subprocessor list (hirefinn.ai/subprocessors) and the privacy policy are public.
Who does what
| Area | Finn | You |
|---|---|---|
| Encryption | AES-256 at rest, TLS 1.2/1.3 in transit. | Nothing to configure. |
| Storage region | Recordings and transcripts stored in your workspace's assigned region. | Ask support for a specific region before you go live. |
| Retention | Deletes recordings and transcripts after the window you set. | Choose the window under Settings → Data. See retention. |
| Deletion requests | Carries out workspace and specific deletion requests. | Receive the request, send it to Finn, and delete your own copies. |
| Consent to call | Nothing. | Hold a consent record or lawful basis for every call you place. |
| Recording disclosure | Nothing automatic. | Put the disclosure in the Finn's welcome message where required. See recording consent. |
| Opt-outs and do-not-call | Nothing. Deployments dial every number in the audience. | Remove opted-out numbers from your audiences and scrub lists against national registries before upload. |
| Calling hours | Nothing. A deployment calls whenever it runs. | Start and pause deployments within the hours allowed where your contacts are. |
| What the agent collects | Nothing. | Don't have the agent ask for card numbers, government IDs or health details you aren't covered for. |
The rows marked "Nothing" are the ones that get missed. Finn can't know whether you had permission to call someone, and if a regulator asks, the record has to come from you.
Settings → Compliance
Settings → Compliance is where you submit a business compliance application and track its status (Submitted, Approved, Rejected). For businesses registered in India it collects business details, an authorized representative, and the Certificate of Incorporation and GST Certificate.
Renting a phone number is refused until your workspace has an approved application. See number capabilities and phone numbers.
HIPAA
If you'll send Protected Health Information through Finn, you need a signed BAA first. BAAs are available to enterprise customers. Under the Data Processing Addendum, Finn isn't intended for PHI without one.
- Sign the BAA before any PHI reaches Finn. Calls made before it was signed aren't covered, and their transcripts and recordings are still stored under your retention window.
- Keep reminder scripts to date, time and provider, and send anything clinical to a person with a transfer tool. A reminder agent that answers "so what did my bloodwork say?" has just put PHI in a transcript.
See compliance-industry for the healthcare design.
Payment card data
Under the Data Processing Addendum, Finn isn't intended for cardholder data, and you're instructed not to have agents ask for Social Security numbers or full card numbers. If you need to take payments by phone, contact your account team about separate terms before you build it.
GDPR and other privacy laws
| Requirement | What it means for you |
|---|---|
| Lawful basis | Yours to establish and record. Cold marketing calls to EU consumers generally need prior consent. |
| Deletion and access requests | Answer within the legal deadline. Send deletion requests to Finn as described in retention. The workspace export under Settings → Data helps with access requests. |
| Data minimization | Ask only the post-call questions you use. Every answer is data you have to defend and delete. |
| Transfers | Your workspace's region is assigned at provisioning. Finn executes SCCs on request. See data residency. |
The Trust Center also lists India's DPDP Act, TRAI and RBI rules, and US TCPA and FTC Telemarketing Sales Rule as regimes Finn designs for. Designing for a regime doesn't make your campaign compliant with it: consent, calling hours and opt-outs are still yours.