Skip to content
DPDP Built for the DPDP Act 2023 & DPDP Rules 2025

Privacy compliance that runs like a system, not a spreadsheet.

Map personal data, publish versioned notices, keep a tamper-evident consent ledger, answer every rights request on time and report breaches inside the 72-hour window, all from one secure workspace.

  • Strict tenant isolation
  • 2FA for privileged roles
  • Append-only audit trail
84DPDP requirements mapped
72 hBoard breach clock tracked
48 hPre-erasure notice sent
13Modules in one workspace
Everything in one place

Every DPDP obligation, with a workflow behind it

Each module maps to a section of the Act or a Rule, so your team always knows what is required and the evidence is collected as work happens.

Data inventory & mapping

Know what personal data you hold, where it lives and who receives it.

  • Systems, storage locations & vendors
  • Record of processing activities
  • Auto-generated data-flow map
s.8 · ROPA

Privacy notices

Versioned notices with a validator for every mandatory item.

  • Draft → review → publish
  • Locked once published
  • Multiple languages & effective dates
s.5 · Rule 3

Consent ledger & API

Collect, prove and withdraw consent with a tamper-evident record.

  • Append-only, hash-chained ledger
  • REST API for web & apps
  • Withdrawal as easy as consent
s.6 · Rule 4

Rights & grievances

Handle access, correction, erasure and nomination requests on time.

  • Identity verification
  • SLA timers & escalations
  • Full case timeline
ss.11–14

Breach management

From first report to Board intimation, with the clock always visible.

  • 72-hour Board & 6-hour CERT-In clocks
  • Rule 7 notices to Data Principals
  • Actions & root-cause analysis
s.8(6) · Rule 7

Retention & erasure

Delete on time, everywhere, and prove it.

  • Legal holds & separation of duties
  • 48-hour pre-erasure notice
  • SHA-256 erasure certificates
s.8(7) · Rule 8

Compliance register

A living register of requirements, owners, due dates and evidence.

  • Applicability by organisation profile
  • Live compliance score
  • Security posture checks
ss.8–10

Reports & audit trail

Board-ready reports and an audit log that cannot be edited.

  • 8 regulatory reports
  • Who did what, and when
  • Identifiers only, never personal data
Rule 6

Data Principal portal

A self-service privacy portal for your customers.

  • Passwordless one-time-code sign-in
  • Manage consents & nominees
  • Track requests and notices
ss.11–14
How it works

From first data map to provable compliance

Four stages, each feeding the next, so nothing depends on someone remembering to update a spreadsheet.

Map

Inventory systems, data and vendors, and record every processing activity with its purpose and lawful basis.

Notify & consent

Publish notices and collect consent through the portal or API, each tied to the exact notice version.

Respond

Work rights requests, grievances, breaches and erasure jobs with timers, assignments and alerts.

Prove

Track every requirement, attach evidence and export reports backed by an append-only audit trail.

Built for your whole team

Everyone lands on the work that matters to them

Role-based access with organisation, department or own-record scope. Each person sees only what their role allows.

Privacy Officer / DPO

Starts in the rights queue

Runs rights requests, grievances, notices and breaches, with every deadline in view.

Compliance Manager

Starts in the compliance register

Owns requirements, evidence and the compliance score, and approves erasure jobs.

Auditor

Read-only, starts in the audit log

Reviews the audit trail and exports reports without being able to change a thing.

Data Principals

Self-service privacy portal

Customers view and withdraw consent, raise requests and follow them to closure.

Security by design

Personal data deserves more than a checkbox

Every sensitive action passes four checks: who you are, which organisation, what you may do, and whether you may touch that record. The checks run on the server, never only in the browser.

Tenant isolation

Each organisation's data is separated in the app and, on PostgreSQL, by row-level security.

Enforced 2FA

Admins, DPOs, compliance managers and auditors must use two-factor sign-in.

Tamper-evident records

Consent and audit records are append-only and hash-chained.

No data leakage

Personal data is kept out of URLs, logs, notifications and error messages.

Least privilege

Granular permissions with organisation, department or own-record scope.

Separation of duties

Whoever raises an erasure job cannot approve it.

Make DPDP compliance part of how you work.

Set up your organisation in minutes, invite your team with the right roles and start with a ready-made catalogue of 84 requirements.