Skip to main content

Security and compliance

Compliance overview

What the platform covers and what stays your obligation.

What this page covers

Finn handles phone calls, transcripts, recordings and whatever personal data callers say out loud. This page lists what Finn has in place, what you can request for a security review, and what stays your responsibility.

This isn't legal advice. For that, talk to a lawyer who works on telecom or privacy in the places you call.

Certifications

These are listed on the Trust Center at hirefinn.ai/trustcenter.

ItemDetail
SOC 2 Type IIAudited by A-LIGN. The report is confidential and shared under NDA.
ISO/IEC 27001:2022Information security management.
ISO/IEC 20000-1:2018IT service management.
ISO 9001:2015Quality management.

Documents on request

Email [email protected] for any of these.

DocumentNotes
SOC 2 Type II reportUnder NDA.
HIPAA Business Associate AgreementFor enterprise customers processing PHI. Executed per engagement.
Standard Contractual ClausesExecuted copy for EU, UK and Swiss transfers.
ISO 27001 Statement of ApplicabilityUnder NDA.
Data residency attestationWhich region your workspace's data is stored in. See data residency.

The Data Processing Addendum (hirefinn.ai/dpa), the subprocessor list (hirefinn.ai/subprocessors) and the privacy policy are public.

Who does what

AreaFinnYou
EncryptionAES-256 at rest, TLS 1.2/1.3 in transit.Nothing to configure.
Storage regionRecordings and transcripts stored in your workspace's assigned region.Ask support for a specific region before you go live.
RetentionDeletes recordings and transcripts after the window you set.Choose the window under Settings → Data. See retention.
Deletion requestsCarries out workspace and specific deletion requests.Receive the request, send it to Finn, and delete your own copies.
Consent to callNothing.Hold a consent record or lawful basis for every call you place.
Recording disclosureNothing automatic.Put the disclosure in the Finn's welcome message where required. See recording consent.
Opt-outs and do-not-callNothing. Deployments dial every number in the audience.Remove opted-out numbers from your audiences and scrub lists against national registries before upload.
Calling hoursNothing. A deployment calls whenever it runs.Start and pause deployments within the hours allowed where your contacts are.
What the agent collectsNothing.Don't have the agent ask for card numbers, government IDs or health details you aren't covered for.

The rows marked "Nothing" are the ones that get missed. Finn can't know whether you had permission to call someone, and if a regulator asks, the record has to come from you.

Settings → Compliance

Settings → Compliance is where you submit a business compliance application and track its status (Submitted, Approved, Rejected). For businesses registered in India it collects business details, an authorized representative, and the Certificate of Incorporation and GST Certificate.

Renting a phone number is refused until your workspace has an approved application. See number capabilities and phone numbers.

HIPAA

If you'll send Protected Health Information through Finn, you need a signed BAA first. BAAs are available to enterprise customers. Under the Data Processing Addendum, Finn isn't intended for PHI without one.

  • Sign the BAA before any PHI reaches Finn. Calls made before it was signed aren't covered, and their transcripts and recordings are still stored under your retention window.
  • Keep reminder scripts to date, time and provider, and send anything clinical to a person with a transfer tool. A reminder agent that answers "so what did my bloodwork say?" has just put PHI in a transcript.

See compliance-industry for the healthcare design.

Payment card data

Under the Data Processing Addendum, Finn isn't intended for cardholder data, and you're instructed not to have agents ask for Social Security numbers or full card numbers. If you need to take payments by phone, contact your account team about separate terms before you build it.

GDPR and other privacy laws

RequirementWhat it means for you
Lawful basisYours to establish and record. Cold marketing calls to EU consumers generally need prior consent.
Deletion and access requestsAnswer within the legal deadline. Send deletion requests to Finn as described in retention. The workspace export under Settings → Data helps with access requests.
Data minimizationAsk only the post-call questions you use. Every answer is data you have to defend and delete.
TransfersYour workspace's region is assigned at provisioning. Finn executes SCCs on request. See data residency.

The Trust Center also lists India's DPDP Act, TRAI and RBI rules, and US TCPA and FTC Telemarketing Sales Rule as regimes Finn designs for. Designing for a regime doesn't make your campaign compliant with it: consent, calling hours and opt-outs are still yours.