Skip to main content

Security and compliance

Data residency

Where your call data is stored, and asking for a region.

What data residency covers

Each workspace has one storage region. Call recordings and transcripts come to rest in that region.

Finn assigns the region when your workspace is provisioned, from these six:

Region
Iowa
Mumbai
Singapore
Sydney
London
Frankfurt

You don't pick the region at signup, and there's no setting or API for it.

Finding your region

Ask support at [email protected]. Support can tell you which region your workspace is in, and can provide a written residency attestation for a vendor review.

Settings → Data → Regional data lists all six regions Finn stores data in. It doesn't mark which one is yours.

If you need a specific region

Contact support before you start making production calls, and say which region you need and why. Moving data that is already stored to another region isn't self-serve, so raise it early. If you're likely to process EU residents' data, ask before your first deployment, not after.

What residency doesn't cover

Residency is about where recordings and transcripts are stored. It doesn't cover:

  • Processing. Speech recognition, voice synthesis and model inference run on Finn's subprocessors. The Subprocessors page at hirefinn.ai/subprocessors lists them with their processing locations per workspace region.
  • Who you may call. Your workspace's region doesn't change the rules of the country you call into. See compliance-regions.
  • Carrier routing. Voice traffic crosses carrier networks to reach the person wherever they are. See telephony-overview.
  • Your own systems. Data you send out through webhooks, integrations or exports lands wherever your endpoint, CRM or laptop is. That transfer is yours to justify. If residency matters, host your webhook receiver in the same region.

For transfers out of the EU, UK and Switzerland, Finn executes Standard Contractual Clauses on request. The Data Processing Addendum at hirefinn.ai/dpa has the contractual terms, and the Trust Center at hirefinn.ai/trustcenter lists both.

Storing less

Residency is one control. Storing less is another.

  • Leave the recording add-on off on deployments that don't need recordings. See recording consent.
  • Shorten the retention window under Settings → Data → Data retention, so recordings and transcripts are deleted sooner. See retention.
  • Ask only the post-call questions you use. Every answer is data you have to defend.
  • Don't have the agent collect card numbers, government IDs or similar values over the phone.
  • Retention: how long data is kept and how to delete it.
  • Compliance: certifications and the split of responsibilities.