New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now liveSee changelog →
Privacy & compliance
DPDP compliance operations built into daily IT work
Handle data-subject requests, keep a breach register and consent records, and support per-organization crypto-erasure with annual key rotation — privacy operations built in.
Product illustration · sample data
Platform Security
18/18 evidence
RLS2FAAudit logsCompliance
9.3/10
DIY assurance score · verified May 2026
Tenant tables with RLS10
Privileged roles · 2FAEnforced
Immutable audit eventsLive
Security controls verified18/18
Product proof
Already live in the product
Backed by app modules
Running in production today: data-subject request handling, consent logging, and crypto-erasure.
Protected app route: /compliance
How it works
Built around real workflows
Highlights below describe capabilities already present in the protected app behind this page.
Data-subject request handling
Breach register and consent records
Per-organization crypto-erasure
Annual key rotation
Workflow
What teams can do here
Step 1
Log a data-subject request
Step 2
Track to fulfilment
Step 3
Record consent and breaches
Step 4
Erase on offboarding
How it works
How it works
01
Log a data-subject request
Record access, correction, erasure or portability requests against the tenant. Each request opens with a status and an SLA due date (30 days by default) and is flagged the moment it breaches.
02
Work the request to closure
Move a request through pending, in-progress and completed (or rejected), keeping requester notes and internal handling notes separate on the same record.
03
Keep a breach register
Open a security-incident record with a severity and the affected organizations. Each incident carries a 72-hour authority-notification clock so the deadline is tracked, not remembered.
04
Capture consent evidence
Consent records store which document (terms or privacy policy), which version, the IP address and the timestamp, giving a defensible history of what each person accepted.
05
Erase on offboarding
When a tenant is offboarded, erasure is scheduled after a grace window (90 days by default). Final erasure clears the wrapped per-tenant encryption key before the cascade delete, so the data cannot be reconstructed from backups.
Example
A worked example
Say an NBFC winds down a partnership and the partner's data-protection officer asks for full deletion. The team logs an erasure data-subject request, which stamps a 30-day SLA and starts the clock; handling notes record each verification step. On approval the organization is scheduled for crypto-erasure with a 90-day grace window in case the decision is reversed. When the window lapses, the job clears the tenant's wrapped encryption key before the cascade delete — so even a database dump taken months earlier now holds only ciphertext nobody can unwrap.
FAQ
Frequently asked questions
What does the DPDP module actually help me do?
It gives you the operational plumbing for privacy work — data-subject requests, a breach register, and consent records — inside your tenant. It supports operating in line with the DPDP Act 2023 aligned and GDPR & DPDPA aligned posture; it is tooling, not a certification.
What is the 72-hour clock on a breach incident?
Every security-incident record is stamped with a deadline 72 hours after discovery and moves through open, investigating, authority-notified and resolved. It tracks the notification window and flags it — it does not file anything with an authority on your behalf.
What types of data-subject request are supported?
Access, correction, erasure and portability. Each has its own status workflow and a default 30-day SLA, and the record shows a breach flag automatically once the due date passes while still open.
How does crypto-erasure differ from just deleting rows?
Sensitive tenant fields are encrypted with a per-tenant key. Erasure clears that wrapped key first and then deletes the organization, so encrypted values in any retained backup become unrecoverable rather than merely marked deleted.
Can an accidental erasure be undone?
There is a grace window — 90 days by default — before permanent erasure runs, and reinstating the organization inside that window cancels the schedule. Once the key is cleared and the delete runs, it is final.
Do you keep proof of consent to policies?
Yes. Each acceptance stores the document type, the exact version accepted, the IP address and the timestamp, so you can show what a specific user agreed to and when.
Where can I read how Infronest itself handles personal data?
Our own practices are published in the privacy policy, and the Security Trust Center describes the platform's security posture. The compliance module is the tooling we give your team for the same obligations.
Data-subject requests with 30-day SLAs, a breach register with a 72-hour clock, consent evidence and crypto-erasure — operational records you can put in front of a DPO, not promises.