Skip to main content

Legal

Data Processing Addendum

Date: June 22, 2026

This Data Processing Addendum (“DPA”) supplements the Finn Terms of Service (the “Agreement”) entered into by and between AIforge Tech Private Limited (“Processor”) and the client agreeing to these terms (“Controller”).

This DPA governs the processing of Personal Data in connection with Controller’s use of the Finn voice agent infrastructure (the “Services”).

1. Definitions

  • “Applicable Data Protection Laws” means all applicable federal, state, and international laws and regulations relating to the privacy and security of Personal Data, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the CPRA, the EU General Data Protection Regulation (GDPR), the UK GDPR, the Digital Personal Data Protection Act, 2023 (India), and applicable US State Privacy Laws (e.g., Virginia, Colorado, Connecticut, Utah, Florida).
  • “Controller Data” means any Personal Data processed by Processor on behalf of Controller pursuant to the Agreement.
  • “Personal Data” means any information relating to an identified or identifiable natural person contained within Controller Data (including voice audio, spoken names, and phone numbers).
  • “Sub-processor” means any third-party data processor engaged by Processor to assist in fulfilling its obligations under the Agreement.

2. Roles and Scope of Processing

2.1 Roles of the Parties.For the purposes of Applicable Data Protection Laws, Controller is the Data Controller (or “Business”), and Processor sits strictly as the Data Processor (or “Service Provider”).

2.2 Scope of Processing. Processor shall process Controller Data strictly to provide the Services, and strictly in accordance with documented instructions from Controller (which include the settings, prompt configurations, and API Webhooks configured by Controller within the platform).

3. Specific AI & Telephony Restrictions

3.1 No Model Training. Processor acknowledges and agrees that Controller Data shall not be used to train, retrain, fine-tune, or benchmark any artificial intelligence, Large Language Model (LLM), or Speech-to-Text (STT) model, whether owned by Processor or by its third-party Sub-processors. Processor accesses third-party models exclusively through Zero-Data-Retention APIs, under which Controller Data is not retained by the provider or used for model training.

3.2 Ephemeral Audio Processing.Processor processes live conversational telephony streams. Processor warrants that live streaming audio payload is held in volatile memory (RAM) strictly for the duration required to convert speech to text and generate an artificial response. Once a call session is terminated, raw audio streams are written to storage strictly subject to the Controller’s configured Time-To-Live (TTL) retention settings.

3.3 Two-Party Consent Disclosure Engine.Where Controller operates in jurisdictions requiring two-party recording consent (e.g., Florida Stat. § 934.03), Processor provides the prompt-engineering infrastructure to deliver automated “First Utterance” recording disclosures; however, Controller remains solely legally responsible for instructing the AI agent to deliver said disclosure before logging or recording the call.

4. Sub-processing

4.1 Authorized Sub-processors. Controller grants Processor general authorization to engage Sub-processors to deliver the Services (e.g., cloud hosting, telecommunications carriers, and Zero-Data-Retention LLM APIs). A current list of Sub-processors is maintained at hirefinn.ai/subprocessors.

4.2 Notice of New Sub-processors.Processor shall provide Controller with at least fourteen (14) days’ written notice of the addition of any new Sub-processor. If Controller has a reasonable, data-protection-related objection to the new Sub-processor, Controller may terminate the applicable portion of the Services without penalty.

4.3 Flow-down Obligations. Processor shall enter into a written agreement with each Sub-processor imposing data protection terms no less protective than those set forth in this DPA.

5. Security & Personal Data Breaches

5.1 Technical and Organizational Measures (TOMs). Processor shall implement and maintain the technical and organizational security measures set forth in Schedule B.

5.2 Security Incident Notification.If Processor becomes aware of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Controller Data (a “Personal Data Breach”), Processor shall notify Controller without undue delay, and in any event within forty-eight (48) hours.

6. Data Subject Requests

Processor shall, to the extent legally permitted, promptly notify Controller if Processor receives a request from a Data Subject (e.g., a job applicant calling the staffing firm) exercising their rights under Data Protection Laws (such as a request to erase their call transcript). Processor shall not respond to such requests directly, but will provide Controller with the API tools necessary to execute the Data Subject’s request.

7. Return and Deletion of Data

Upon termination or expiration of the Agreement, at Controller’s election, Processor shall either return Controller Data to Controller in a commonly used, machine-readable format or securely delete it, in each case within thirty (30) days, except to the extent that retention is required by applicable law. Controller may also trigger deletion at any time via its manual API execution of a “Purge-on-Delivery” webhook request.

8. California (CCPA / CPRA) Specific Terms

To the extent Controller Data belongs to California residents:

  1. Processor is acting solely as a “Service Provider”.
  2. Processor shall not “Sell” or “Share” Controller Data (as those terms are defined under the CPRA).
  3. Processor shall not retain, use, or disclose Controller Data for any purpose other than for the specific business purpose of performing the Services specified in the Agreement.

9. International Data Transfers

9.1 Restricted Transfers.Where Processor’s processing of Controller Data involves a transfer of Personal Data out of the European Economic Area (EEA), the United Kingdom, or Switzerland to a country without an adequacy decision, the mechanisms in this Section apply.

9.2 EU Standard Contractual Clauses.The parties incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) for transfers governed by the GDPR: Module Two (Controller-to-Processor) between Controller and Processor, and Module Three (Processor-to-Processor) for onward transfers to Sub-processors. The EU SCCs are governed by the law of Ireland, and the courts of Ireland have jurisdiction over disputes arising from them. The Annexes to the EU SCCs are completed in the executed copy of this DPA, which is available on request at support@hirefinn.ai.

9.3 UK and Swiss Transfers. For transfers governed by the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner. For transfers governed by the Swiss FADP, the EU SCCs apply with the amendments identified by the Swiss Federal Data Protection and Information Commissioner.

9.4 Supplementary Measures. The parties acknowledge the technical and organizational measures in Schedule B and Section 3 as supplementary measures protecting transferred data, including AES-256 encryption at rest, TLS 1.2/1.3 in transit, ephemeral in-memory audio processing, Zero-Data-Retention model APIs (under which model providers do not retain Controller Data), tenant isolation, and least-privilege access.

9.5 Precedence and Government Access. In the event of a conflict between the EU SCCs or UK Addendum and this DPA, the SCCs or UK Addendum prevail with respect to the Personal Data they govern. Processor shall, to the extent legally permitted, notify Controller of any binding request from a public authority for disclosure of Controller Data and challenge requests that are unlawful under Applicable Data Protection Laws.

10. Confidentiality, Assistance & Audit

10.1 Personnel Confidentiality. Processor ensures that persons authorized to process Controller Data are bound by an appropriate written or statutory duty of confidentiality.

10.2 DPIA and Prior-Consultation Assistance. Taking into account the nature of processing and the information available to it, Processor shall provide Controller with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities relating to the Services.

10.3 Audit.Processor shall make available to Controller the information reasonably necessary to demonstrate compliance with this DPA, and satisfies this obligation by providing its current ISO/IEC 27001 certificate, its SOC 2 report (once available), and responses to a reasonable security questionnaire. On-site audits are available only where these are insufficient to satisfy a mandatory legal requirement, and are limited to once per twelve (12) months, on at least thirty (30) days’ written notice, at Controller’s cost, under confidentiality, during business hours, and without disrupting Processor’s operations.

Schedule A: Details of Processing

  • Subject Matter: The processing of inbound and outbound voice telephony, real-time speech transcription, structured JSON data extraction, and call routing.
  • Duration of Processing:The term of the Agreement plus Controller’s selected data cache window (default 90 days).
  • Categories of Data Subjects:Customers, employees, contractors, or job applicants of the Controller who speak with the Controller’s deployed Finn voice agents.
  • Categories of Personal Data: Spoken names, phone numbers, caller-ID metadata, voice audio recordings, text transcripts of conversations, and any unprompted personal variables voluntarily spoken by the Data Subject during the phone call.
  • Sensitive Data: Protected Health Information (PHI) may be processed only by enterprise Customers who have executed a Business Associate Agreement (BAA) with Processor; that BAA governs the handling of PHI. Absent an executed BAA, the Services are not intended for PHI. By default, the Services are likewise not intended for cardholder data governed by the Payment Card Industry Data Security Standard (PCI DSS), and Controller is instructed not to prompt agents to request Social Security Numbers or full payment-card numbers over the voice line. Where a Customer requires the processing of cardholder data, such processing is supported only under a separate, custom Master Services Agreement and data-protection terms that define the applicable PCI DSS-aligned controls and the responsibilities of each party.

Schedule B: Technical & Organizational Measures (TOMs)

  1. Encryption in Transit: All telephony signaling (SIP/TLS) and API Webhook traffic passing between Controller, Processor, and Sub-processors is encrypted using TLS 1.2 or TLS 1.3.
  2. Encryption at Rest: All stored .wav audio files and .json transcripts sitting in cloud buckets are encrypted using AES-256.
  3. Access Controls:Access to production infrastructure containing Controller Data is strictly restricted to Processor’s core engineering staff via Multi-Factor Authentication (MFA), SSH keys, and the Principle of Least Privilege.
  4. Tenant Isolation:Controller Data is logically segregated inside Processor’s cloud databases; one Controller cannot query, call, or access the data tables or voice instances of another Controller.

AIforge Tech Private Limited · D-253, Kardhani Govindpura, Kalwar Road, Jaipur, Rajasthan, India - 302012 · CIN: U62099RJ2025PTC099494 · support@hirefinn.ai

Get started

Hire Finn and scale with confidence.

Move from idea to live voice automation — securely, reliably, and without operational risk.

Book a Demo

Fort-nightly Launches

We move quickly and get you what you need

Powerful Tools

Pre-built dashboards, reports, automations, more