Fini (usefini.com) stores and processes customer data in the region you choose, the United States or the European Union, encrypts it with AES-256 at rest and TLS 1.2+ in transit, and never uses it to train foundation models. Processing is governed by Fini’s Data Processing Addendum (v1.0.5), which sets a 30-day subprocessor change notice and 72-hour breach notification.

Roles

Under the Privacy policy, Fini acts in two roles:

What data Fini processes

What reaches Fini depends on what you connect. The categories below come from the product surfaces you configure. You control the largest variable: which attributes your endpoints return and which documents you sync. Send the minimum each workflow needs.

Where data is processed

The Azure deployment is bought through Microsoft Marketplace (MACC-eligible, on a single Microsoft invoice) and supports Private Link and VNet, customer-managed encryption keys, Entra ID and Conditional Access, and Azure Monitor and Sentinel integration.
Outbound calls from Fini to your systems, when an Action runs, originate from four static IP addresses in Google Cloud’s europe-west4 region (Netherlands). See Static IP addresses.
To confirm (internal, remove before publish): (1) For US-residency workspaces, do Action calls still egress through the europe-west4 static IPs, and if so, is any customer data stored or only transited there? (2) The subprocessor data embedded in the Trust Center page (not shown publicly) gives OpenAI and Anthropic a location of “US” (“LLM inference (enterprise agreement)”), while Supabase, PostHog and Sentry are “EU / US (config dependent)”. For EU-residency workspaces, is LLM inference performed in the US, and is that transfer covered by the SCCs? If so, say it plainly on this page. EU banks and insurers will ask both.
The diagram shows how data moves in the standard deployment. Every connection uses TLS 1.2 or higher. The Azure deployment through Microsoft Marketplace follows a different path: Fini runs in your Azure tenant and region, with models on Azure AI Foundry and Azure OpenAI Service, as described above.

Encryption

  • At rest: AES-256.
  • In transit: TLS 1.2 or higher.
  • Contact details in conversations: email addresses and formatted phone numbers in message text are encrypted at rest, which is why Inbox text search cannot match them. See Inbox.
  • Azure deployments: customer-managed encryption keys are supported.
The Data protection policy also describes role-based access to customer data and per-customer environments with PII masking. Endpoint disk encryption, data backups, access monitoring and data erasure are documented in the Trust Center.

Model training

Customer data is never used to train foundation models. Fini’s LLM subprocessors are contractually barred from training on it, and the commitment is written into the DPA. This is different from how Fini improves your own agent. Magic Articles drafts articles from transcripts and documents you provide, and they land in Review or Published depending on your Status After Generation setting. Your team’s feedback in Inbox and Test Suite results shape your agent’s configuration. Those improvements stay in your workspace; they do not train a shared model. See Magic articles and Review.
To confirm (internal, remove before publish): The Trust Center’s Data Privacy Officer entry says “When we train our custom models for our customers we remove any personally identifiable information from data.” Does Fini train custom models per customer today? If yes, describe what is trained, on which data, with what opt-in, and how that squares with “never used to train foundation models”. If no, ask for that Trust Center text to be removed.

Subprocessors

Exhibit A of the DPA lists Google Cloud, Supabase, OpenAI and Anthropic. Fini’s published subprocessors also include PostHog, Sentry, Stripe, Linear and Langfuse. The DPA sets a 30-day notice period for subprocessor changes, which gives you time to review a change before it takes effect.
To confirm (internal, remove before publish): The Trust Center has a Subprocessors entry, but its subprocessor section is hidden with the placeholder “We are working on our subprocessors. Please contact us for more details.” Its Subprocessors tile shows logos for OpenAI, Supabase, Amazon Web Services (AWS), Microsoft Azure and Google Cloud; AWS appears in no other Fini source. The hidden list in the page data has nine entries: Supabase, OpenAI, Anthropic, PostHog, Sentry, Stripe, Linear, Langfuse and Google (Email); Google Cloud appears separately. Where is the full, current list published, should Google (Email) be added here, is AWS a subprocessor, and how do customers subscribe to change notices?

Retention and deletion

Two implementation details matter if you automate deletion:
  • Single delete returns success even for unknown IDs. It does not confirm that the ID matched a live conversation, so verify IDs with List conversations first.
  • Bulk delete is not atomic. If any ID is inaccessible, the request returns 406 Not Acceptable, but the matching conversations are still removed. Retry only the IDs that failed.
To confirm (internal, remove before publish): What exactly does the “default 30-day retention” apply to (conversation transcripts, AI Steps traces, logs, backups), and does it conflict with conversations being visible in Inbox for longer? Is API deletion a hard delete or a soft delete (the endpoint docs describe an “update query”), and how long until deleted data is purged from backups? Can customers configure a custom retention period?

DPA terms at a glance

The Data Processing Addendum (v1.0.5) is the binding text. Key terms:

Data subject requests (GDPR and CCPA)

As your processor, Fini supports you in answering requests from your customers. You stay the controller and decide how to respond.
1

Find the conversations

In Inbox, use the Ticket Id filter with the customer’s ticket IDs from your helpdesk, or use the Conversations API to list them programmatically. Email addresses and formatted phone numbers are encrypted at rest in Inbox, so you can’t find a customer by searching for their email in the Question filter.
2

Fulfill access or portability requests

Export the conversations with a read-scoped API key, or open them in Inbox. See API keys.
3

Fulfill deletion requests

Delete the conversations through the deletion endpoints above, then delete the source records in your helpdesk and any system your Actions wrote to.
4

Escalate anything else

For requests you can’t complete yourself, contact legal@usefini.com. The Data protection policy lists the data subject rights Fini supports.
If your agent receives a data request inside a support conversation, route it to your privacy team with a Reply Rule or a Planning Prompt escalation trigger rather than letting the agent answer. See Reply Rules.

Security overview

Posture table, evidence and reviewer FAQ.

HIPAA and BAAs

Requesting a BAA and configuring for PHI.

Delete conversation

API reference for single-conversation deletion.

API keys

Scopes, rotation and revocation for programmatic access.