Privacy & Data Protection Policy
Governs how Finaisse processes personal data lawfully and upholds data-subject rights. Subordinate to the Information Security Policy; complements the Data Classification & Retention Policy.
| Policy owner | COO (Payeli) — acting data-protection lead until a DPO is appointed |
| Applies to | All personal data processed by Finaisse (customer and personnel) |
| Effective | 2026-08-27 (v0.1 draft) |
| Review cadence | Annual + on change to processing or regulation |
| Classification | Internal-confidential |
| Regulatory / SOC 2 | India DPDP · GDPR (where applicable) · SOC 2 P, C1 |
1. Purpose
Ensure personal data is processed lawfully, fairly, and transparently, and that data subjects can exercise their rights. Finaisse is a processor of customer personal data and a controller of its own personnel data.
2. Principles
- Lawful basis — processing has a defined basis (contract for customer data).
- Purpose limitation & minimisation — data is used only for the stated purpose; identifiers sent to the LLM are tokenised (LLM PII Tokenization).
- Accuracy, storage limitation — retention per the Data Classification & Retention Policy.
- Integrity & confidentiality — protected per the security policy set.
3. Records of processing & data map
Maintained in Data & Privacy — RoPA with data categories, purpose, basis, location, and retention. Data flows are documented in Data Flows.
4. Data-subject rights
🎯 Target — a documented process to handle access, correction, erasure, and grievance requests within statutory timelines, reaching the tenant DB, the [intelligence log], checkpoints, and confirming zero provider retention (owner: COO). Pseudonymised data remains personal data.
5. Cross-border transfer & subprocessors
Transfers use region-pinned processing; subprocessors are listed in Subprocessors and governed by the Vendor & Subprocessor Risk Policy with a DPA.
6. Breach notification
A personal-data breach follows the Incident Response Policy and, where required, triggers notification to the relevant authority and affected parties within statutory timelines.
7. Review
Reviewed annually and on any change to processing activities or applicable regulation.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | COO | Initial draft |