A withdrawal reaches nobody
The customer clicks "withdraw". Your CRM, ad tools and partners keep processing, because nobody told them.
Promiz is built around one question: can you prove a lawful basis for every record you hold? Map each DPDP obligation to a working control - and export the evidence the day you're asked for it.
Consent comes in from each channel. Every change goes out at once as a signed webhook, so your tools act only on what the customer allowed.
Signed - verify each message with your signing secret.
Retried - failed sends retry, then wait for your review.
Logged - inspect, resend or test any delivery.
Events you can subscribe to
Connect any tool that accepts webhooks or calls an API. Promiz does not ship pre-built app connectors today.
Many tools stop at the banner. The legal risk sits in the four steps that follow.
The customer clicks "withdraw". Your CRM, ad tools and partners keep processing, because nobody told them.
Retention periods live in a policy PDF. Nothing counts down, and nobody can show when data was deleted.
Access, correction and erasure requests arrive by email, with no deadline and no record of the reply.
Penalties under the DPDP Act can reach ₹250 crore. The Board will look for proof, not policies.
See how Promiz closes the gap→Six modules share one record, so every choice ties back to a notice, a purpose and a deadline.
No-code notices for your website, forms and email.
Find what runs on your site and file it under the right purpose.
A permanent, chained record of every grant, change and withdrawal.
A branded self-service site and a request queue for your team.
Deadlines for stopping processing and for erasing data.
Log, track and report a breach against the clock.
Write the binding consent text once. Promiz fingerprints it and stores it with every consent, so you can always show what a person agreed to.
Records are never edited or deleted. Each change is a new entry, linked to the one before it. Any tampering shows at once.
"Stop using it" and "delete it" are different duties under the Act. Promiz keeps them apart, so data you must keep by law is never erased by mistake.
| Task | Purpose | Due | Status |
|---|---|---|---|
| Stop processing W-2041 | Marketing email | 17 Sep | Confirmed by CRM |
| Stop processing W-2042 | Usage analytics | 18 Sep | Awaiting |
| Stop processing W-2037 | Partner offers | 15 Sep | Overdue |
| Erase data E-0913 | Loan enquiry | 20 Sep | 48h notice sent |
| Erase data E-0907 | KYC records | - | Legal hold |
A branded site with your logo and colours. Customers sign in with a one-time code, manage every consent and raise requests. Your team works one queue with a clock on each request.
Raise a request
Log the breach, its severity and who is affected. Record your investigation and fixes. Promiz builds the structured Rule 7 report from what you recorded.
Follow one customer from the first notice to a closed task. On the left is what the customer sees. On the right is what your team sees.
हर उद्देश्य के लिए अपनी पसंद चुनें। आप कभी भी सहमति वापस ले सकते हैं।
शिकायत अधिकारी: privacy@sample.example
| Purpose | Legal basis | Retention |
|---|---|---|
| Account opening | Legal obligation | As required by law |
| Marketing email | Consent | Until withdrawal |
| Usage analytics | Consent | 12 months |
One choice per purpose. Required purposes are marked. Nothing is ticked for them. Your team publishes the notice once, with a legal basis and retention for each purpose.
Add your website or product, its domains, branding and keys.
Pick the mode, write the text and add purposes.
Publish in the languages your customers read.
Add the script, connect forms or call the API.
One script shows the banner and blocks tags until their purpose is allowed.
Consent on sign-up, contact and KYC forms, with optional email or SMS OTP.
Raise requests and check consent before processing, by API or Python SDK.
Branch or call-centre staff send a single-use email link. Unanswered links expire.
Each sector has its own data, regulators and hard cases. Promiz handles them with the same record, rules and queues.
Consent across branches, apps and call centres, while RBI rules keep some records for years.
Borrower data flows to partners and collection agents, so every withdrawal must reach them.
Agents collect health and family details offline, often with no proof of what was shown.
Care data must stay available, while research and marketing need their own consent.
New pixels and marketing tools appear on the site every week.
Many learners are under 18, so guardian consent and tracking limits apply.
Guest and booking data moves between hotels, agents and loyalty programmes.
Your product and your customers’ users both need clear consent and fast request handling.
Promiz works for any Data Fiduciary that collects personal data in digital form.
The DPDP Rules, 2025 were notified on 13 November 2025. Here is where things stand, and how Promiz covers each duty.
Confirm the dates that apply to you with your legal team. Check whether the proposed Significant Data Fiduciary date has been notified.
Versioned notices in 23 languages, with shown-notice snapshots
A separate choice per purpose; required and optional handled apart
One-click withdrawal in the banner and the privacy portal
A stop-processing task per withdrawal, with overdue alerts
Per-purpose retention, legal holds, 48-hour notice and confirmed deletion
Self-service portal and a request queue with deadlines
Breach log, 72-hour countdown and a structured report
Guardian verified as an adult through DigiLocker; child-restriction flags
Recorded for the organisation and applied per purpose
Most DPDP tools now say “22 languages” and “built for India”. These questions show the real difference.
Promiz opens a stop-processing task with a deadline and records who confirmed it.
Only your system can close an erasure task. Promiz never marks a deletion it did not receive.
Yes. Each record keeps the notice version, a text fingerprint and a snapshot.
Staff send a single-use email link. Unanswered requests expire.
Mark the purpose with a legal-obligation basis. A withdrawal stops use and never triggers erasure.
Through DigiLocker. The verified reference is stored with the consent.
Yes. Every change saves a new version. Old records always keep the version the customer saw.
From the first click to the last webhook.
For consent given before the Act started, the Act asks you to send a notice as soon as reasonably practicable. Ask your legal team whether you also need fresh consent. Promiz can send consent requests by email link.
No. Promiz is software that you, the Data Fiduciary, use to run your own consent and rights processes. A Consent Manager is a separate role registered with the Data Protection Board.
If a cookie identifies or profiles a person, treat it as personal data. The website script blocks each tag until its purpose is allowed and records the choice.
English and the 22 languages of the Eighth Schedule. Translate by hand or with background auto-translation. Customers can switch language inside the notice.
By signed webhook, sent at once. Failed deliveries are retried, then held for review. Your system confirms back to Promiz to close the task.
No. Promiz supports your compliance programme. Your legal team decides purposes, legal bases and retention periods.
A 30-minute session on your own use case.