Product
One workspace for every DPDPA engagement
From the first intake question to a delivered assessment, with the registers, evidence and risk work in between.
The engagement workflow
- 1
Intake
Business-language questions for the client. Follow-ups appear only when they're relevant, like parental consent for an EdTech client.
- 2
Findings
A rule-based assessment gives one finding per obligation. Each finding's citation is checked against the text of the Act and Rules.
- 3
Documents
Gap report, RoPA, privacy notice, breach playbook and a draft DPA for the client's lawyer. A person reviews each one before it can be downloaded as .docx.
- 4
Delivery
Blocked until every check passes. There is no override, so nothing half-finished reaches a client.
Registers for each engagement
Privacy operations
- Personal dataDiscovery scans and a data inventory with purpose, legal basis, retention and owner.
- ConsentConsent records for each purpose, with withdrawals.
- RequestsAccess, correction, erasure, grievance and nomination, on a response clock of up to 90 days (Rule 14(3)).
- BreachesEach breach tracked against the Board's detailed report, due 72 hours after awareness (Rule 7(2)(b)).
Compliance
- ControlsThe client's status for every obligation. "Not applicable" needs a reason and an admin; "implemented" needs evidence.
- TasksTurn any gap, risk or control into assigned work with an owner and due date.
- EvidenceA library of files checked against their type, stored under random names, downloadable only when signed in.
- PoliciesVersion, approver and next review date for each policy.
Risk
- Risk registerEvery gap and failed check becomes a risk, scored likelihood × impact on a 5×5 matrix, with treatment and owner.
- Vendors and processorsContract, data location and review date for each one.
- DPIAData protection impact assessments for Significant Data Fiduciaries.
- Data-flow mapWhere personal data is collected, stored and shared, and which flows leave India.
Across the workspace
- DashboardWhat needs attention, the pipeline by stage, readiness per client, top risks and recent activity.
- Work queueEverything open across clients, most urgent first.
- GRC AnalystAnswers questions about any client from live workspace data, citing the Act and Rules. Read-only.
- Data flowsA map of where each client's personal data goes, with flows leaving India flagged.
- ConnectorsRead-only GitHub and AWS checks that back findings with evidence.
- CorpusThe text of the DPDP Act and Rules that every citation is checked against.
- Team and rolesAdmins, members and read-only viewers.
- Audit logEvery change, who made it and when.
- Search and shortcutsCtrl K to jump to any page or action, and keyboard shortcuts for the common ones.