
Sound familiar?
"We collect customer data on our website, app and WhatsApp, and we've no idea if we're DPDP-ready."
- Our privacy policy was copied from another site years ago.
- Leads come in from forms, ads and WhatsApp, and nobody asked for clear consent.
- We don't know where all our customer data lives or who can see it.
- If someone asks us to delete their data, there's no process to do it.
- An EU customer sent a data processing agreement, and we don't know what to sign.
Built for
What we do
What's included in DPDP Act & GDPR Compliance.
DPDP Gap Assessment
A clear check of how you collect, use, store and share personal data against the DPDP Act 2023 and DPDP Rules 2025, with a ranked fix list.
Data Mapping & Records of Processing
A map of what personal data you hold, where it lives, why you have it, who you share it with and how long you keep it.
Privacy Notices & Policies
Plain-language privacy notices for your website, app and WhatsApp, plus internal policies on retention, access and data sharing.
Consent Management
Consent flows built into your forms, checkout, app sign-up and WhatsApp opt-ins, with records you can show if asked. We build them, not just advise.
Data Breach Response Process
A breach playbook covering DPDP and GDPR 72-hour notification and CERT-In's 6-hour incident reporting, with templates ready to send.
DPO-as-a-Service & DPIA
An outsourced data protection officer for rights requests, vendor contracts and data protection impact assessments (DPIA) for risky processing.
Who delivers this
Senior security people, not juniors.
Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.
Security & Compliance Partner
Leads this serviceA hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.
GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC
Principal Security Advisor
AdvisesA serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.
ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance
Pricing
Transparent packages. Fixed quotes.
Your final quote is fixed after a 20-minute call — no surprise bills.
Gap Assessment
- DPDP Act and DPDP Rules gap assessment
- High-level data map
- Review of current privacy policy and forms
- GDPR check if you serve EU users
- Ranked fix list with effort estimates
DPDP Implementation
- Everything in Gap Assessment
- Detailed data map and retention schedule
- Privacy notices for website, app and WhatsApp
- Consent flows built into your site, app and WhatsApp
- Data principal rights request process
- Breach response playbook and templates
DPO-as-a-Service
- Named data protection contact for your business
- Handling of access, correction and deletion requests
- Vendor and data processing agreement reviews
- DPIAs for new products or features
- Breach response support
- Quarterly privacy review
Ongoing costs after launch
No surprises: here's everything you may pay every month, stated upfront.
Consent management tool, if used
- —Consent management platform licences, if you choose one, are paid directly by you.
- —Legal opinions or contract drafting by a law firm, where needed, are paid directly to the firm. We work alongside your lawyers.
- —Changes to third-party systems we don't have access to are done by those vendors.
- —WhatsApp platform and message fees for opt-in flows are paid directly to your provider.
Want a quick estimate for your exact project? Try the cost estimator.
Process
From first message to launch.
Clear stages, a live preview link every week, and payments tied to milestones you approve.
- Step 01Day 1
20-min call
We learn what data you collect and where, and whether you have EU users. You get a fixed quote.
- Step 02Weeks 1–2
Discover & map
Workshops with your team and a review of forms, apps, CRM, WhatsApp and vendors to build the data map.
- Step 03Weeks 3–6
Fix & build
We write notices and policies, and our engineers build consent and rights-request flows into your journeys.
- Step 04Weeks 6–8
Train & hand over
A short team training, the breach playbook and a compliance pack you can show customers and auditors.
Technology
Tools we trust.
Our promises
Working with us is low-risk.
Fixed quote
A clear, fixed price after a 20-minute call. No surprise bills.
Pay in milestones
Projects: 40% to start, 30% on design approval, 30% at launch.
You own everything
Code, domain, ad accounts, WhatsApp number and data — in your name.
Weekly previews
See real progress on a live link every week, not just status updates.
30 days of free fixes
Anything not working as agreed after launch, we fix at no cost.
Talk to the builder
No account managers. You speak with the engineers doing the work.
FAQ
Questions, answered.
When does the DPDP Act actually apply?+
The DPDP Rules were notified on 13–14 November 2025. Most duties, including notice and consent, security safeguards, breach intimation and data principal rights, apply from 13 May 2027 under the notified schedule. Building consent and breach processes takes months, so starting now is the safe choice.
What are the penalties under the DPDP Act?+
Up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to notify a breach to the Data Protection Board and affected people. Breaches must be reported to the Data Protection Board without delay, with a detailed report within 72 hours. Good preparation is far cheaper than a penalty.
What decides the cost?+
The number of products and channels collecting data, how many vendors you share data with, whether you serve EU users and whether you want us to build the consent flows or just specify them.
Will you certify us as DPDP or GDPR compliant?+
No. There is no official DPDP certificate today, and GDPR has no single 'certified' badge for most businesses. We get you prepared and documented, so you can show customers and the Data Protection Board what you've done.
Are you a law firm?+
No. We are privacy and security practitioners who also build the website, app and WhatsApp flows. For legal opinions or complex contracts we work alongside your lawyers.
Will you sign an NDA, and will you see our customers' data?+
Yes, we sign an NDA first. Data mapping is about the types of data and where they flow, so we rarely need to see actual customer records.
What happens after the project?+
You get a compliance pack: data map, notices, consent records, breach playbook and rights process. Many clients then take DPO-as-a-Service at ₹35k a month to handle requests and keep things current.
Often paired with
Official WhatsApp Business API, green tick, chatbot, catalogue and broadcasts that reply in seconds.
Fast, mobile-first business websites and landing pages that turn visitors into calls, WhatsApp chats and bookings.
An incident response plan, tabletop drills, a response retainer, and phishing and secure-coding training.
Let's scope your project.
One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.