Skip to main content

Security and compliance

Rules by industry

Healthcare, finance, collections and legal.

Before you start

Regulated industries add rules on top of the regional rules. Finn doesn't enforce any of them: it doesn't limit calling hours or attempts, check do-not-call lists, detect sensitive data in a transcript, or add disclosures. You meet these rules through how you build the audience, the prompt, the welcome message and the deployment schedule.

This page is general guidance, not legal advice. Check your design with a lawyer who specializes in your industry and jurisdiction.

Healthcare

The dividing line is whether a call touches Protected Health Information.

Appointment reminders that mention only date, time and provider are generally treated as treatment, payment or operations communication under HIPAA. Once a call discusses diagnosis, test results or treatment, you're handling PHI.

To send PHI through Finn you need a signed Business Associate Agreement. BAAs are available to enterprise customers, executed per engagement. Request one from [email protected], and sign it before any PHI reaches Finn. Without a BAA, Finn isn't intended for PHI. See compliance.

The practical design is to keep the script generic and send anything clinical to a person:

Guardrail:
If the caller asks about test results, diagnosis, medication changes, or
anything clinical, do not answer. Say you will transfer them to the clinic
and use the transfer tool. Never read back medical details.

Wire that as a guardrail (agents-guardrails) plus a transfer tool (tools-transfer). A guardrail is a prompt instruction and can be talked around. The transfer is what actually ends the conversation.

If a caller volunteers PHI on a Finn without a BAA, it lands in the transcript, and in the recording if recording is on. Finn doesn't detect or remove it. Shorter retention limits how long it's stored (retention), and for a specific call you can ask support to delete it.

Some states require a separate disclosure when AI is used in healthcare communication. Put it in the welcome message (agents-welcome) for the states you call into.

Financial services

Several regimes can apply at once: TCPA, the FTC Telemarketing Sales Rule, FDCPA for collections, GLBA and state consumer-protection laws in the US, and TRAI and RBI rules in India.

Decisions to make before launch:

DecisionWhere you make it
Marketing or informationalYour campaign design. It decides whether you need prior written consent.
Calling hoursWhen you schedule, pause and stop deployments.
Do-not-call scrubbingYour list, before you upload the audience.
Recording disclosureThe Finn's welcome message. See recording consent.
How long recordings are keptSettings → Data → Data retention. The longest window is 2 years, or Never delete.

If a regulator expects multi-year call records, set retention to cover it before you start calling, and keep your own copies of what you must retain. Recordings already deleted under a shorter window can't be restored.

Account-servicing calls such as balance alerts and payment confirmations are usually informational. A cross-sell inside the same call can turn it into a marketing call. Keep those flows in separate Finns rather than branching mid-call, so the consent basis for each deployment is clear.

Don't have the agent collect full card numbers or government IDs. Finn's Data Processing Addendum excludes cardholder data unless you have separate terms.

Collections

Debt collection has extra limits on time, frequency and content. None of them are enforced by Finn.

  • Time. Schedule and pause deployments within allowed hours in the debtor's time zone.
  • Frequency. Finn doesn't cap attempts per person. Count attempts yourself across deployments and sequences, and keep people who've reached your limit out of new audiences.
  • Third parties. The script must handle someone other than the debtor answering. Write that branch explicitly.
Guardrail:
If the person on the line is not the named contact, do not state the reason
for the call, the company name in a way that implies debt, or any amount.
Ask only whether the named contact is available, then end the call.

Opt-outs matter most here. Add a Yes/No post-call question such as opt_out so requests are easy to find (analysis fields), and act on them yourself: remove the number from every audience and keep it out of future uploads. The question records the request. It doesn't stop the next call.

The general rules apply, and they matter more here:

  • Recording disclosure is required in all-party-consent jurisdictions. See recording consent.
  • Let the Finn say it's an AI when asked. Using an AI voice agent is generally legal. Denying it to someone who asks directly is not.
Guardrail:
If the caller asks whether you are a real person, tell them honestly that
you are an AI assistant.

What Finn doesn't do for you

You might expectWhat actually happens
Finn blocks PHI without a BAAIt doesn't. Nothing detects PHI in a transcript.
Finn keeps calls inside allowed hoursIt doesn't. A deployment calls whenever it runs.
Finn skips do-not-call numbersIt doesn't. It dials every number in the audience, including contacts marked Do not call on the Contacts page.
An opt-out on a call stops future callsIt doesn't. Remove the number from your audiences.
Finn limits attempts per personIt doesn't. Track attempts yourself.
Finn adds a recording or AI noticeIt doesn't. Put notices in the welcome message.