New — live in production across lending, industrial & clinical. See the customers →
Trust / DPDP
DPDP · India's Digital Personal Data Protection Act

DPDP — by design, audited.

The DPDP essentials — consent, retention by class, withdrawal, and DPO contact. For the full reference, including sub-processors and technical controls, read our posture post.

Read our full posture ← Back to trust + security

What DPDP means for your data with us.

Your customer data is your data. We process it on your behalf, in your tenancy, under your encryption keys — never seeing your customer's personal information in plaintext. Consent is captured at ingestion, records are retained only as long as DPDP requires by class, withdrawal and deletion are supported, and the immutable audit log produces evidence of every data event on request.

Retention by class.

What we keep, for how long, and the legal basis for each.

ClassRetentionBasis
KYC records7 yearsRBI Master Directions
Customer interaction logs5 yearsDPDP general retention
Transaction records10 yearsRBI Banking Regulation Act
Clinical records (KidneyCare)5 yearsICMR 2017 guidelines
AI inference traces (non-PII)2 yearsInternal audit + model improvement

How customers exercise their rights.


For security reviewers

Read our full security & compliance posture — regulatory alignment, technical controls, the sub-processor list, data residency, and full retention by class, the authoritative reference. Read the posture →

We'll send you the full security pack.

Architecture diagrams. Sub-processor DPAs. Pentest summary. ISMS scope statement. DPDP compliance questionnaire. Available under NDA for enterprise prospects.

Request security pack