Skip to main content
Fini (usefini.com) stores and processes customer data in the region you choose, the United States or the European Union, encrypts it with AES-256 at rest and TLS 1.2+ in transit, and automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data. Fini is SOC 2 Type II compliant, ISO/IEC 27001:2022 certified, PCI DSS Level 1 certified, HIPAA-compliant and BAA-eligible, and supports GDPR and CCPA. Fini does not use customer data to train foundation models. Processing is governed by Fini’s Data Processing Addendum (v1.0.5), which sets a 30-day subprocessor change notice and 72-hour breach notification.

Roles

Under the Privacy policy, Fini acts in two roles:

What data Fini processes

What reaches Fini depends on what you connect. The categories below come from the product surfaces you configure. You control the largest variable: which attributes your endpoints return and which documents you sync. Send the minimum each workflow needs.

Where data is processed

The Azure deployment is bought through Microsoft Marketplace (MACC-eligible, on a single Microsoft invoice) and supports Private Link and VNet, customer-managed encryption keys, Entra ID and Conditional Access, and Azure Monitor and Sentinel integration.
Calls Fini makes to your APIs (Actions) come from four static IPs in Google Cloud’s europe-west4 region (Netherlands), for every workspace. See Static IP Addresses.
The diagram shows how data moves in the standard deployment. Every connection uses TLS 1.2 or higher. The Azure deployment through Microsoft Marketplace follows a different path: Fini runs in your Azure tenant and region, with models on Azure AI Foundry and Azure OpenAI Service, as described above.

Encryption

  • At rest: AES-256.
  • In transit: TLS 1.2 or higher.
  • Contact details in conversations: email addresses and formatted phone numbers in message text are encrypted at rest, which is why Inbox text search cannot match them. See Inbox.
  • Azure deployments: customer-managed encryption keys are supported.
The Data protection policy also describes role-based access to customer data and per-customer environments with PII masking. Endpoint disk encryption, data backups, access monitoring and data erasure are documented in the Trust Center.

Masking sensitive data

Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. You do not need to build a rule for this. Design your workflows so sensitive values never need to enter the conversation:
  • Don’t ask for what you don’t need. Never ask customers for full card numbers, CVVs or health details the workflow doesn’t require.
  • Route card actions through your payment provider. Card replacement, payment updates and refunds run as Actions against your payment provider, which holds the card data; the conversation only carries references. See PCI DSS.
  • Add Guardrails as an extra layer. Guardrails check what the agent says: a Confidential attributes check keeps the values of selected user attributes out of replies, and a Custom rule can fail any reply that repeats data your policy forbids.

Model training

Fini does not use customer data to train foundation models. Any per-customer learning happens only inside that customer’s environment and only with their written authorization. Fini’s LLM subprocessors are contractually barred from training on it, and the commitment is written into the DPA. This is different from how Fini improves your own agent. Magic Articles drafts articles from transcripts and documents you provide, and they land in Review or Published depending on your Status After Generation setting. Your team’s feedback in Inbox and Test Suite results shape your agent’s configuration. Those improvements stay in your workspace; they do not train a shared model. See Magic articles and Review.

Subprocessors

Fini’s subprocessors are: With EU data residency, data is stored and processed in the EU. The DPA sets a 30-day notice period for subprocessor changes, which gives you time to review a change before it takes effect.

Retention and deletion

You set your own retention period, and deletion removes all data. Two implementation details matter if you automate deletion:
  • Single delete returns success even for unknown IDs. It does not confirm that the ID matched a live conversation, so verify IDs with List conversations first.
  • Bulk delete is not atomic. If any ID is inaccessible, the request returns 406 Not Acceptable, but the matching conversations are still removed. Retry only the IDs that failed.

DPA terms at a glance

The Data Processing Addendum (v1.0.5) is the binding text. Key terms:

Data subject requests (GDPR and CCPA)

As your processor, Fini supports you in answering requests from your customers. You stay the controller and decide how to respond.
1

Find the conversations

In Inbox, use the Ticket Id filter with the customer’s ticket IDs from your helpdesk, or use the Conversations API to list them programmatically. Email addresses and formatted phone numbers are encrypted at rest in Inbox, so you can’t find a customer by searching for their email in the Question filter.
2

Fulfill access or portability requests

Export the conversations with a read-scoped API key, or open them in Inbox. See API keys.
3

Fulfill deletion requests

Delete the conversations through the deletion endpoints above, then delete the source records in your helpdesk and any system your Actions wrote to.
4

Escalate anything else

For requests you can’t complete yourself, contact [email protected]. The Data protection policy lists the data subject rights Fini supports.
If your agent receives a data request inside a support conversation, route it to your privacy team with a Reply Rule or a Planning Prompt escalation trigger rather than letting the agent answer. See Reply Rules.

Security overview

Posture table, evidence and reviewer FAQ.

HIPAA and BAAs

Requesting a BAA and configuring for PHI.

PCI DSS

PCI DSS Level 1 certification and card data in support conversations.

Delete conversation

API reference for single-conversation deletion.

API keys

Scopes, rotation and revocation for programmatic access.