What DPDP means for your data with us.
Your customer data is your data. We process it on your behalf, in your tenancy, under your encryption keys — never seeing your customer's personal information in plaintext. Consent is captured at ingestion, records are retained only as long as DPDP requires by class, withdrawal and deletion are supported, and the immutable audit log produces evidence of every data event on request.
Retention by class.
What we keep, for how long, and the legal basis for each.
| Class | Retention | Basis |
|---|---|---|
| KYC records | 7 years | RBI Master Directions |
| Customer interaction logs | 5 years | DPDP general retention |
| Transaction records | 10 years | RBI Banking Regulation Act |
| Clinical records (KidneyCare) | 5 years | ICMR 2017 guidelines |
| AI inference traces (non-PII) | 2 years | Internal audit + model improvement |
How customers exercise their rights.
- Consent withdrawal. Every deployment supports consent withdrawal. The system marks the user's records and prevents further processing within 24 hours.
- Data deletion. On request, records are deleted within the legal grace period (typically 30 days). Audit log retention follows the retention-class table.
- DPO contact. For DPDP grievances, contact our Data Protection Officer at [email protected]. Response within 5 business days; resolution within 30.
For security reviewers
Read our full security & compliance posture — regulatory alignment, technical controls, the sub-processor list, data residency, and full retention by class, the authoritative reference. Read the posture →