Skip to content
Last updated: Sep 25, 2026

Privacy & Data Protection Policy ​

Governs how Finaisse processes personal data lawfully and upholds data-subject rights. Subordinate to the Information Security Policy; complements the Data Classification & Retention Policy.

Policy ownerCOO (Payeli) — acting data-protection lead until a DPO is appointed
Applies toAll personal data processed by Finaisse (customer and personnel)
Effective2026-08-27 (v0.1 draft)
Review cadenceAnnual + on change to processing or regulation
ClassificationInternal-confidential
Regulatory / SOC 2India DPDP · GDPR (where applicable) · SOC 2 P, C1

1. Purpose ​

Ensure personal data is processed lawfully, fairly, and transparently, and that data subjects can exercise their rights. Finaisse is a processor of customer personal data and a controller of its own personnel data.

2. Principles ​

  • Lawful basis — processing has a defined basis (contract for customer data).
  • Purpose limitation & minimisation — data is used only for the stated purpose; identifiers sent to the LLM are tokenised (LLM PII Tokenization).
  • Accuracy, storage limitation — retention per the Data Classification & Retention Policy.
  • Integrity & confidentiality — protected per the security policy set.

3. Records of processing & data map ​

Maintained in Data & Privacy — RoPA with data categories, purpose, basis, location, and retention. Data flows are documented in Data Flows.

4. Data-subject rights ​

🎯 Target — a documented process to handle access, correction, erasure, and grievance requests within statutory timelines, reaching the tenant DB, the [intelligence log], checkpoints, and confirming zero provider retention (owner: COO). Pseudonymised data remains personal data.

5. Cross-border transfer & subprocessors ​

Transfers use region-pinned processing; subprocessors are listed in Subprocessors and governed by the Vendor & Subprocessor Risk Policy with a DPA.

6. Breach notification ​

A personal-data breach follows the Incident Response Policy and, where required, triggers notification to the relevant authority and affected parties within statutory timelines.

7. Review ​

Reviewed annually and on any change to processing activities or applicable regulation.

Revision history ​

VersionDateAuthorChange
0.12026-08-27COOInitial draft

Finaisse Internal — Confidential. Access-restricted; not for external distribution.