Skip to main content

Legal

Consent & Legal Guidance

Last Updated: 17th July, 2026

Finn provides enterprise AI voice infrastructure as a Software-as-a-Service (SaaS), used by customers across India, the United States, and Europe. The operational intent, data sourcing, and legal compliance of all calls executed on our platform are strictly your responsibility, under the telemarketing and data-protection laws of the region you operate in.

To ensure uninterrupted service and prevent the disconnection of your assigned telecom resources, you must explicitly agree to the following operational standards.

1. Mandatory Compliance Artifacts & Declarations

By utilizing Finn’s platform for voice automation, you formally warrant that every call complies with the telemarketing and financial communication laws applicable to your region — including but not limited to TRAI and RBI guidelines and the Digital Personal Data Protection Act 2023 (India), the TCPA and FCC/FTC rules and state Do-Not-Call laws (United States), and the GDPR and ePrivacy Directive (European Union/EEA). Upon any regulatory complaint, you must provide one of the following artifacts to Finn at support@hirefinn.ai within 24 hours:

  • Explicit End-User Consent: Verifiable proof (timestamped digital opt-in, signed document, or CRM log) that the customer explicitly agreed to receive promotional or commercial communications from your entity, meeting the consent standard of the applicable region (e.g. prior express written consent under the TCPA, or freely-given consent under the GDPR).
  • Verified Inbound Call Proof (The 3-Day Rule): Call Detail Records (CDRs) proving the end-user initiated contact (incoming or missed call) within the preceding 72 hours for unsolicited callbacks.
  • Strictly Transactional Intent: Voice recordings or approved script logs proving the call’s intent was purely transactional, support-oriented, or informational, and entirely devoid of promotional messaging.
  • Proper Numbering & Registry Allocation: Proof of using the numbering series or registration mandated in your region for promotional campaigns where prior explicit consent has not been secured — e.g. the 140XX series and DLT registration in India, a caller-ID compliant with FCC rules and scrubbed against the National Do-Not-Call Registry in the US, or a registered sender identity under local telecom rules in the EU.
  • AI Disclosure & Recording Consent: The User assumes sole responsibility for ensuring the Agent’s script legally complies with all regional requirements to disclose that the call is being recorded and/or that the End Customer is interacting with an Artificial Intelligence system, including two-party consent recording laws in applicable US states, and GDPR transparency and EU AI Act (Article 50) disclosure requirements in the EU.

2. Zero-Tolerance Penalty & Disconnection Clause

If you fail to provide the necessary consent artifacts within 24 hours of a request, immediate enforcement action will be taken:

  • Permanent Bans: Your dedicated phone numbers (DIDs) and compliance applications will be immediately suspended by our telecom partners, in India, the US, or Europe as applicable.
  • Zero Refund Policy: Finn assumes zero liability for your failure to maintain compliance. No refunds, prorated credits, or financial compensations will be issued for accounts, usage minutes, or resources suspended due to regulatory violations.

3. Total Indemnification

You agree to fully indemnify, defend, and hold harmless Finn (AIforge Tech Private Limited) against any penalties, operational losses, legal actions, or telecom resource disconnections resulting from your telemarketing activities, in any jurisdiction in which you operate — except to the extent caused by Finn’s own fraud, wilful misconduct, or gross negligence, or any liability that cannot be excluded under applicable law.

4. Uploading Your Own Contacts

By using the audience upload feature you confirm that you have obtained the necessary consent from each contact you upload, per the regulator obligations set out in Section 1 above.

What you must not do:

  • Upload phone numbers you do not have permission to contact.
  • Use uploaded lists for unsolicited cold-calling or spam campaigns.
  • Ignore opt-out, Do-Not-Call, or do-not-disturb (DND) preferences, whichever registry applies in your region.

Best practices:

  • Keep records of consent for each contact.
  • Respect opt-outs promptly, across every region you contact.
  • Follow any additional local regulations that apply to your region — state, national, or EU-wide.

This page provides guidance and does not constitute legal advice. If you need specific legal assistance, please consult your legal counsel in the relevant jurisdiction.

Get started

Hire Finn and scale with confidence.

Move from idea to live voice automation — securely, reliably, and without operational risk.

Book a Demo

Fort-nightly Launches

We move quickly and get you what you need

Powerful Tools

Pre-built dashboards, reports, automations, more