Legal
Privacy Policy
Last updated: June 18, 2026
This Privacy Policy explains how AIforge Tech Private Limited ("Finn", "we", "us", "our") processes personal and communications data. We provide an AI voice agent platform ("Software" or "Platform") accessible via hirefinn.ai.
Our practices are designed to meet the data protection frameworks that apply to us, including the Digital Personal Data Protection Act, 2023 (DPDP, India) and the General Data Protection Regulation (GDPR, EU/UK). For California residents, Section 9 sets out how we honor rights under the California Consumer Privacy Act, as amended by the CPRA (CCPA, USA).
1. Our Role: Controller vs. Processor
To clarify our legal responsibilities, Finn operates in two distinct capacities:
- Data Controller: We act as the Controller for the personal data of our direct customers ("Users") who register for an account, manage billing, and interact with our Website.
- Data Processor: We act strictly as a Processor for all data relating to the individuals our Users interact with via the Agents ("End Customers"). The User is the Controller of End Customer data and is responsible for obtaining any necessary consent for telephonic communication and recording.
Our services are designed for business use and are not directed to individuals under 18. We do not knowingly process the personal data of minors; if we learn that we have, we will delete it.
2. What Data We Collect
We collect data across the following categories to operate our Platform:
A. Account and Billing Data (User Data)
To register for our services, we collect the following personal data:
- First and last name
- Email address
- Company name
If you choose a paid service, we also collect your payment details.
Purpose: To fulfill our SaaS contract, manage subscriptions, and provide customer support.
B. Communications and Voice Data (End Customer Data)
Audio Recordings & Transcripts: Real-time audio inputs, voice recordings, and text transcripts generated during interactions with the AI Agents.
Telephonic Metadata: Specific Caller and Recipient phone numbers, routing data, call duration, and timestamps.
Analytics: Sentiment and mood detection analysis generated by the AI.
Purpose: To execute the core functionality of the AI voice agents on behalf of the User.
C. Visiting Our Website
When you visit our Website for informational purposes, we automatically collect and store certain "log data". This data is stored temporarily in server log files to ensure the stability and security of the Website, and is deleted on a rolling basis once it is no longer needed for those purposes. The data includes:
- IP address
- Browser and operating system information
- Referral URL
- Time and duration of access
- Retrieved files and services used
Purpose: The legal basis for this data processing is our legitimate interest in ensuring the proper operation of the Website.
D. Cookies and Third-Party Tracking
Our Website uses cookies to improve functionality and analyze your usage. You can manage cookie preferences via your browser settings or our cookie banner. We use two types of cookies:
- Session Cookies: These are deleted after your visit.
- Persistent Cookies: These remain on your device until deleted manually.
For product analytics we use PostHog, and we use Intercom to provide in-app support. These tools may set cookies to track usage and improve your experience; you can manage or revoke your consent at any time via the cookie banner.
E. Contact Form
When you use our contact form, we collect:
- Your name
- Email address
Purpose: This data is used solely to respond to your queries and will not be shared with third parties unless explicitly stated in this policy.
F. Third-Party Services
We use third-party services, such as PostHog, Sentry, Intercom, and Cloudflare, to help improve and monitor our services. These services may collect and process data, including cookies and usage information, to optimize user experience. A complete, current list of the third parties that process data on our behalf — including the purpose and region of each — is published at hirefinn.ai/subprocessors. For more information on how these services process your data, you can consult their respective privacy policies.
G. Newsletter and Marketing Communications
If you subscribe to our newsletter or updates, we collect your email address. Purpose: to send you product news, feature announcements, and related marketing communications. The legal basis for this processing is your consent, which you may withdraw at any time using the unsubscribe link included in every marketing email or at hirefinn.ai/marketing/unsubscribe. After you unsubscribe, we retain your email address on a suppression list solely to honor your opt-out. We do not use contact-form submissions or account emails for marketing without your consent.
3. AI Models and Your Data
We do not use your Input or Output (as defined in our General Terms and Conditions), or your transcripts, to train, retrain, or fine-tune any AI model. Our conversational AI is provided through third-party models engaged under API terms that prohibit training on your data. We use zero-data-retention configurations wherever the provider offers them and your plan includes them; otherwise, retention is limited to a short operational window and is never used for model training.
Users retain ownership of their data. Finn receives only a license to process that data as needed to provide the service, as set out in our General Terms and Conditions and Data Processing Addendum.
Automated decision-making and profiling. Sentiment and mood analysis is generated as analytics for the User (the Controller of End Customer data). Finn does not use it, or any other automated processing, to make decisions about you that produce legal or similarly significant effects.
Biometrics. We do not use voice recordings to identify individuals, create voiceprints, or process biometric identifiers for identification purposes.
4. Industry-Specific Compliance and Security
We provide enterprise-grade infrastructure designed to meet the strict security requirements of the healthcare, financial services, insurance, and debt collection sectors.
Security Measures: We implement robust technical and organizational safeguards, including data encryption in transit and at rest, and role-based access controls.
Compliance Frameworks: We hold ISO/IEC 27001:2022 (Information Security Management), ISO/IEC 20000-1:2018 (IT Service Management), and ISO 9001:2015 (Quality Management) certifications, issued by UKBIZ Certification Inc and independently verifiable. Our infrastructure is additionally aligned with SOC 2 standards, with a Type II audit in progress.
Healthcare & Finance: For Users processing Protected Health Information (PHI) or highly sensitive financial data, specific obligations are governed by our separate Data Processing Addendum (DPA) and a Business Associate Agreement (BAA), which must be executed before PHI may be processed.
5. Data Retention and Deletion
We retain User account data for the duration of the active subscription and as required by tax and commercial laws. Communications Data (including audio recordings and transcripts) processed on behalf of Users is retained according to the User's configured retention window — 90 days by default — or until the User requests deletion. On termination, this data is deleted within thirty (30) days as set out in our Data Processing Addendum.
Automatic Inactivity Wipe: To enforce strict data minimization, if a User account remains entirely inactive for a period of twelve (12) months, all associated End Customer Communications Data (including audio and transcripts) will be automatically and permanently deleted.
6. Your Data Protection Rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data ("Right to be Forgotten").
- Restrict or Object to certain processing activities, including marketing.
- Data Portability to receive your data in a machine-readable format.
- Withdraw Consent at any time where processing is based on consent.
- Lodge a Complaint with a supervisory authority: if you are in the EU or UK, with your local data protection authority; if you are in India, with the Data Protection Board of India after first raising your grievance with our Grievance Officer (see Section 10).
To exercise these rights, End Customers must contact the User (the Controller) directly. Users can contact Finn to exercise their own rights.
7. International Data Transfers
If we transfer personal data outside of its originating jurisdiction (e.g., outside the EEA or India), we ensure appropriate legal safeguards are in place, such as Standard Contractual Clauses (SCCs) or other safeguards recognized under applicable law, to maintain data security. A current, per-workspace-region view of where each subprocessor processes data is published at hirefinn.ai/subprocessors.
8. Security Measures
We implement technical and organizational measures to protect your personal data from unauthorized access, loss, or manipulation. These measures are continually updated to reflect new security developments.
9. California Privacy Rights (CCPA/CPRA)
For call recordings, transcripts, and other End Customer data processed through our platform, we act as a service provider; requests concerning that data should be directed to the business you interacted with (our User, the Controller). For the account and billing data of our direct Users, we act as a business.
We do not sell or share personal information, as those terms are defined in the CCPA as amended by the CPRA, and we have not done so in the preceding twelve (12) months. We do not use or disclose sensitive personal information for purposes that would require a right to limit.
If you are a California resident, you have the right to:
- Know and access the personal information we collect about you, including the categories collected, their sources, and the purposes of collection.
- Correct inaccurate personal information.
- Delete your personal information, subject to statutory exceptions.
- Opt out of the sale or sharing of personal information (not applicable — we do not sell or share).
- Limit the use of sensitive personal information (not applicable — see above).
- Not be discriminated against for exercising any of these rights.
To exercise these rights, email [email protected]. We will verify your request and respond within forty-five (45) days. You may designate an authorized agent to submit a request on your behalf; we will require proof of the agent's authorization and may verify your identity directly.
10. Contact Information
For data protection inquiries, to exercise your rights, or to access our Data Processing Addendum (DPA) — published at hirefinn.ai/dpa — please contact:
- AIforge Tech Private Limited (CIN U62099RJ2025PTC099494), D-253, Kardhani Govindpura, Kalwar Road, Jaipur, Rajasthan - 302012, India.
- Email: [email protected]
- Grievance Officer (under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023): Rajvirendra Singh Shekhawat, Director, AIforge Tech Private Limited, D-253, Kardhani Govindpura, Kalwar Road, Jaipur, Rajasthan - 302012, India. Email: [email protected]
We acknowledge grievances within 72 hours and resolve them within 30 days. If you are in India and your grievance is not resolved within that period, you may escalate it to the Data Protection Board of India.
EU Representative (Article 27 GDPR): We have appointed Prighter Group as our EU representative for data protection matters. If you are located in the European Union, you may contact our representative directly to exercise your data subject rights (such as access or erasure of your personal data) at https://app.prighter.com/portal/portier
UK Representative (UK GDPR): We have appointed Prighter Group as our UK representative for data protection matters. If you are located in the United Kingdom, you may contact our representative directly to exercise your data subject rights (such as access or erasure of your personal data) at https://app.prighter.com/portal/portier
Commencer
Recrutez Finn et passez à l'échelle en toute confiance.
Passez de l'idée à l'automatisation vocale en production — en toute sécurité, fiabilité et sans risque opérationnel.
Lancements bimensuels
Nous avançons vite et vous donnons ce dont vous avez besoin
Des outils puissants
Tableaux de bord, rapports, automatisations et plus, prêts à l'emploi