Skip to content
DPDP Act 2023

Your rights.
Mechanically enforced.

India's Digital Personal Data Protection Act 2023 (DPDP) gives every Data Principal — that's you — a set of rights against any business that processes your personal data. SaudaFlow honours each of them, with a 7-day SLA, end-to-end.

Updated May 25, 2026

Right to Access (§11)

Obtain a complete copy of personal data being processed about you, along with the identities of any other Fiduciaries with whom that data has been shared.

Right to Correction (§12(a))

Correct, complete, update, or rectify any personal data that is inaccurate, incomplete, or outdated.

Right to Erasure (§12(b))

Have your personal data erased, subject only to retention obligations imposed by Indian law.

Right to Nomination (§13)

Nominate another natural person to exercise these rights in the event of your death or incapacity.

Right to Grievance Redressal (§14)

Lodge a grievance against the Data Fiduciary and receive a response within 7 days. The Grievance Officer for each SaudaFlow tenant is published on request.

Right to Withdraw Consent (§15)

Withdraw consent for processing at any time. We honour the withdrawal mechanically by initiating an erasure flow.

What actually happens when you file one

  1. You file the request

    In the Data Principal portal, or with the named Grievance Officer of the tenant holding your data.

  2. Identity is verified

    Nobody gets a copy of your data by asking nicely on your behalf. Verification precedes everything.

  3. 7-day SLA

    The clock starts

    Seven days to act, tracked by the system, not by somebody remembering to.

  4. Export or erase

    Whichever right you exercised — and only that one.

    One of 2 outcomes:
    • ExportThe encrypted bundle streams to your browser and decrypts on your device.
    • EraseWe destroy the wrapping key. The bytes stay for the 7-year audit floor; no key exists to read them.
  5. You get the receipt

    A tracking ID, plus an audit row for every step — readable by you in your Consent + Access Log.

Nothing in this chain waits on somebody noticing an email. The clock, the fork and the audit row are all product behaviour — which is the difference between a rights policy and a rights workflow.

How SaudaFlow honours these rights

  1. 1

    You file the request at app.saudaflow.in/privacy/my-data if you have a SaudaFlow account, or by contacting the named Grievance Officer of the SaudaFlow tenant holding your data.

  2. 2

    The Data Fiduciary acts within 7 days. For access, the encrypted bundle streams to your browser; decryption happens on your device with your own key.

  3. 3

    Erasure is cryptographic. We destroy the wrapping key for your data. The encrypted bytes remain for our 7-year audit retention floor, but no key exists in the system that can decrypt them. We verify this nightly.

  4. 4

    You receive a confirmation with a request tracking ID. The audit log records every step; you can read it via your Consent + Access Log.

Exercise a right

Use the Data Principal Rights portal to export, correct, or erase your data.

SaudaFlow is the Data Processor for tenant data. The Fiduciary is your SaudaFlow tenant (the agency, developer, or business that captured your information). For processor-side issues, write to support@saudaflow.in.

Your DPDP rights: access, correct, erase · Saudaflow