DPDP Act 2023 Compliance
How Indescape Technologies complies with India's Digital Personal Data Protection Act, 2023 — and how we help your business comply too.
1. What is the DPDP Act 2023?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's comprehensive data privacy legislation. It establishes rights for individuals ("Data Principals") and obligations for organisations that collect and process their personal data ("Data Fiduciaries").
The Act covers any digital personal data collected about Indian residents, regardless of whether the collecting organisation is inside or outside India. For businesses using WhatsApp to communicate with Indian customers, DPDP compliance is mandatory.
2. Indescape's DPDP Compliance Measures
Indescape has built compliance with the DPDP Act into the platform from the ground up. Here is what we have implemented:
Opt-in enforcement toggle ensures businesses only message contacts who have given consent
Customers can opt out by sending STOP; reactivate with START. Automatically respected across all campaigns
Customer phone numbers, emails, and message content encrypted at field level in the database
Account holders can export all their data from Settings → Privacy & Compliance
Permanent account and data deletion available from Settings, with 30-day data retention post-request
Defined retention periods for all data categories; automatic deletion after account closure
Designated contact for DPDP-related complaints: privacy@indescape.com
HMAC-verified data deletion callback endpoint for Meta app platform compliance
3. Your Rights as a Data Principal
The DPDP Act gives you the following rights regarding personal data Indescape holds about you (as an Indescape account holder):
Right to Access
Know what personal data we hold about you and how it is being used. Request a summary via Settings or email.
Right to Correction
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data. Submit from Settings → Privacy & Compliance → Delete Account.
Right to Grievance Redressal
Lodge a complaint with our Grievance Officer if your rights have been violated. We respond within 30 days.
Right to Nominate
Nominate another person to exercise your data rights in case of death or incapacity.
Right to Withdraw Consent
Withdraw consent for optional data processing at any time, without affecting the lawfulness of prior processing.
How to exercise your rights: Log in to app.indescape.com → Settings → Privacy & Compliance, or email privacy@indescape.com. We will respond within 30 days as required by the DPDP Act.
4. How Indescape Helps Your Business Comply
If you use Indescape to communicate with your customers, you are a Data Fiduciary under the DPDP Act. Indescape provides built-in tools to help you meet your obligations:
Consent Management
- Enable the opt-in enforcement toggle to ensure you only message consented contacts
- Indescape's STOP/START keyword system automatically respects opt-out requests
- Campaign opt-out flows can be configured in the flow builder
Data Security
- All customer data stored in Indescape is field-encrypted using AES-256-GCM
- Staff login roles and permissions limit data access to authorised team members
- No customer data is shared with third parties beyond what is required to deliver the WhatsApp service
Your Responsibilities
While Indescape provides technical tools for DPDP compliance, as a Data Fiduciary you are also responsible for:
- Obtaining valid, documented consent from your customers before adding them to Indescape
- Maintaining your own Privacy Policy that discloses your use of WhatsApp Business messaging
- Responding to your customers' data rights requests (access, correction, erasure)
- Registering as a Significant Data Fiduciary with the Data Protection Board if required based on your data volume
5. Data Localisation
The DPDP Act 2023 (as currently enacted) does not impose blanket data localisation requirements for most personal data categories. Indescape stores data on cloud infrastructure in the Asia-Pacific region (Singapore / India) to minimise latency for Indian users while meeting applicable requirements.
We will update our data storage practices if additional localisation requirements are notified by the Government of India under the DPDP Act.
6. Contacting the Data Protection Board
If you are not satisfied with how Indescape has handled your data rights request or complaint, you may approach the Data Protection Board of India (DPBI) once it is constituted under Section 18 of the DPDP Act 2023. We will cooperate fully with any DPBI inquiry.
Grievance Officer — DPDP Act 2023
🏢 Indescape Technologies, India
Response within 30 days as required by the DPDP Act 2023. For general queries: hello@indescape.com