DPDP · india's digital personal data protection act

dpdp — by design, audited.

Plain-English plus technical detail of how our products comply with DPDP. Consent capture, retention by class, withdrawal flow, sub-processor list, DPO contact.

01 · plain-english summary
what dpdp means for your data with us

When you deploy an Aminobots system, your customer data is your data. We process it on your behalf, in your tenancy, under your encryption keys. We never see your customer's personal information in plaintext. We retain processed records only as long as DPDP requires by class — KYC for 7 years, customer interaction logs for 5 years, transaction records for 10 years.

If your customer requests their data be deleted, the system supports that. If your customer requests their consent be withdrawn, the system supports that. If your auditor requests evidence of every data event, the immutable audit log produces it.

02 · retention class table
what we keep, for how long
class retention basis
KYC records7 yearsRBI Master Directions
Customer interaction logs5 yearsDPDP general retention
Transaction records10 yearsRBI Banking Regulation Act
Clinical records (KidneyCare)5 yearsICMR 2017 guidelines
AI inference traces (non-PII)2 yearsInternal audit + model improvement
03 · withdrawal + dpo
how customers exercise their rights
  • consent withdrawalEvery deployment supports consent withdrawal. The system marks the user's records and prevents further processing within 24 hours.
  • data deletionOn request, records are deleted within the legal grace period (typically 30 days). Audit log retention follows the retention-class table.
  • DPO contactFor DPDP grievances, contact our Data Protection Officer at [email protected]. Response within 5 business days; resolution within 30.
DPDP-ready by design AWS · Azure · GCP blueprint · patent pending India residency · on-prem option