How Finnoto handles your data - aligned with the IT Act 2000, ISO 27001:2022 and SOC 2 Type II.
At Finnoto Solutions Private Limited (FSPL), we place the utmost importance on the privacy, confidentiality and security of our clients’ data. We are committed to safeguarding personal information, including Personally Identifiable Information (PII), by continually enhancing our security posture and aligning our practices with regulatory requirements such as the IT Act 2000 and its associated rules. Our information security management framework is grounded in internationally recognised standards: Finnoto operates controls aligned with the ISO 27001:2022 and SOC 2 Type II security frameworks, covering security, availability, processing integrity, confidentiality and privacy. Independent audit reports, certification status and scope details are available under NDA where applicable.
PII refers to any data that can be used to identify a natural person, either on its own or in conjunction with other accessible information. This encompasses names, contact details, government-issued IDs, tax information, and any other information relating to customers, employees, consultants or vendors. We also recognise the sensitivities associated with data governed by international regulations like the GDPR, and commit to processing such data with due care and compliance.
Finnoto collects only the data necessary for legitimate business operations. This typically occurs when users create an account, sign up for an event, or interact with our services. Data collected includes basic details such as name, contact number and address, as well as identity documents such as PAN or Aadhaar. In the context of employment or engagement, we may also retain agreements, performance records and related documentation. When using FSPL’s digital assets, certain monitoring data may be captured to ensure security and compliance.
As part of our service delivery, we also collect and process client business data such as order information, payment records, invoice details and settlement data. All such business-critical data is handled with the same degree of care and subject to the same principles of privacy, integrity and security - including secure storage, role-based access, consent-driven sharing and rigorous processing controls under controls aligned with the ISO 27001:2022 and SOC 2 Type II security frameworks.
The information we collect is used solely to facilitate and enhance our services, maintain contractual obligations, fulfil payroll and administrative functions, ensure legal compliance, and strengthen our IT and cybersecurity infrastructure. Every piece of data serves an agreed business purpose, and any additional processing is undertaken only after receiving informed consent. Internal systems incorporate validation mechanisms, role-based access controls and audit logs; system-generated outputs such as invoices or reports are reviewed and verified before dissemination.
Customer data is securely hosted on Amazon Web Services (AWS) in India, utilising regions such as Mumbai and Hyderabad. Our infrastructure is designed for redundancy and disaster recovery, with all sensitive information encrypted both at rest and in transit. Encryption keys are managed through AWS Key Management Service (KMS), and data access is logically partitioned per customer.
We implement rigorous access-control protocols, disabling employee access to production systems by default and enabling it only through a tightly governed approval process. Customer data is not stored on any local devices or endpoints; it remains within our cloud environment. Monitoring tools such as AWS, Sentry, CloudWatch and Oh Dear allow real-time visibility and rapid incident response, with alerts directed to key personnel through multiple channels. Operating controls aligned with SOC 2 Type II, Finnoto follows comprehensive practices including continuous monitoring, periodic reviews and risk assessments to safeguard sensitive data throughout its lifecycle.
Finnoto has a clear and strict policy: we do not sell or share personal information for profit. Disclosure may be required in some situations, such as compliance with legal mandates or regulatory inquiries; in such cases disclosures are conducted transparently and, wherever feasible, individuals are informed of the nature and purpose. Data may be shared with affiliates, service providers or business partners who are contractually bound to process data only on our behalf under stringent privacy and security clauses. Where disclosures are based on customer consent, we ensure such consent is explicit and purpose-specific. All disclosures are documented in our Personal Information Disclosure Log, and only designated roles - such as the CEO, CTO, CISO or Legal Counsel - are authorised to approve them.
Finnoto retains data only for as long as necessary to fulfil business purposes or to comply with legal, contractual or operational requirements. Once data is no longer needed, we anonymise or securely dispose of it in accordance with legal standards. For former employees or contractors, some data may be preserved for legitimate purposes such as references or benefit claims. We maintain archival records of transactions, kept encrypted and under strict access controls. Our disposal practices align with both data-protection regulations and our internal record-retention policies.
Our information security framework is aligned with the ISO 27001:2022 and SOC 2 Type II security frameworks; independent audit reports and certification status are available under NDA where applicable. We implement strong technical safeguards, conduct regular vulnerability assessments, and maintain a culture of security awareness. Access to production systems is logged and audited; intrusion detection and vulnerability scanning are conducted regularly. Employees undergo mandatory security training on joining and regular refreshers thereafter. Accountability is core to our culture - employees follow best practices such as a clean-desk policy and prompt reporting of suspicious activity. Despite our efforts, the internet is not entirely secure, and we encourage users to keep credentials confidential and use secured systems.
Finnoto offers individuals the ability to access, rectify, delete or request portability of their personal data, and to opt out of marketing communications at any time. Requests can be directed to our Grievance Officer at grievance@finnoto.com and will be handled promptly and transparently. In some cases, residual copies may be retained to comply with legal or backup requirements.
In the event of a data breach, we follow a defined notification protocol that includes informing affected individuals, regulators and business partners depending on severity and applicable regulations. If you have concerns about your personal data, please contact our Global Privacy Office or the Grievance Officer in India at +91-7506390511 or via grievance@finnoto.com.