DataSurity

Data Principal Rights Portal

Every rights request, verified, fulfilled and proven.

One portal for access, correction, erasure, nomination and grievances, in your brand and on your domain. Each request is verified, routed to the right owners, closed with evidence and answered well inside the time the law allows.

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction

Every request in. Every answer on record.

People raise requests wherever they meet you. Each one ends as a verified, evidenced answer.

  • Your website
  • Your app
  • Email
  • Branch and call centre
  • Consent preference centre
  • Grievance channel
DataSurity Rights Portal
  • Identity verified
  • Every system holding the person's data
  • Tickets to data owners
  • Replies from your domain
  • Closure certificate
  • Board-ready export
Built on the Act

90 days is the ceiling, not the target

  • 90 days

    The most the Rules allow. Your published timeline becomes the clock, and settings can't exceed the law

  • 7 · 3 · 1

    Days' warning before a clock runs out, so the DPO hears before the person does

  • 1 certificate

    For every closed request, with every step behind it on record

How it works

Five steps from request to proof

Features

What the rights portal does for you

01

Erasure that respects retention law

Not every record can be erased on request. PMLA, RBI and SEBI rules often require keeping data for years. Here a system can decline erasure with its legal citation. The request closes as partly fulfilled, and the person is told what stays, why, and until when. That's what Section 12(3) asks for.

02

A process nobody can weaken

The steps are fixed by the Act. Automation can be switched on or off at each step, but identity checks can't be removed, and no setting can promise slower than the law allows. The process your auditor reviews is the process that runs.

03

Your brand, your domain

The person wrote to you, so you answer. The portal runs on your domain, in your colours. Every reply goes out from your sending domain, carrying your Data Protection Officer's contact. DataSurity's name appears nowhere the person looks.

04

One queue for everyone who acts

Data owners get one list: rights requests to fulfil and consent withdrawals to carry out, from every module. They close each with evidence. The DPO sees every clock, every overdue item and every exemption waiting for approval.

What the Act asks, and how the Rights Portal answers

Every request type maps to a section of the Act, and nothing in the product goes beyond it.

Section
  • s.11

    A summary of the person's data, how it's used, and everyone it's shared with

    Access requests assembled from every system and recipient, with the consent history

  • s.12

    Correction, completion, updating and erasure

    Tickets to each system's owner, closed with evidence

  • s.12(3)

    Erasure unless the law requires retention

    Exemptions with legal citations, and a partly fulfilled outcome explained to the person

  • s.13

    Grievances answered within the published time, before any complaint to the Board

    Grievance threads with clocks, escalation and the Board line on closure

  • s.14

    Nominating someone to act on death or incapacity

    Nomination requests recorded against the person

  • s.8(9), s.8(10)

    Published contact and a working grievance mechanism

    DPO contact on the portal and every reply

  • s.6(4)

    Withdrawal as easy as giving consent

    Withdrawals on the same portal, carried out through the Consent module

  • s.9

    Children's rights exercised by a parent or guardian

    Requests about children flagged and routed for guardian handling

Deploy it your way

Built for regulated Indian enterprises: your data stays where your policies say it must.

  • 01

    SaaS, hosted in India

    Managed by SARC AI on infrastructure in Indian data centres.

  • 02

    Private cloud

    Runs in your own cloud account, under your keys and access policies.

  • 03

    On-premises

    Installed in your data centre. Scanners read in place, and nothing leaves your network.

Connects to

  • PostgreSQL
  • MySQL
  • Oracle Database
  • Microsoft SQL Server
  • MongoDB
  • MariaDB
  • IDIBM Db2
  • SAP HANA
  • Snowflake
  • Amazon Redshift
  • Google BigQuery
  • Databricks
  • Teradata
  • Amazon DynamoDB
  • Azure SQL
  • Apache Cassandra
  • Redis
  • Elasticsearch
  • Couchbase
  • ClickHouse
  • Apache Hive
  • Apache Kafka
  • SQLite
  • Neo4j

Connectors are enabled during onboarding. Logos belong to their owners and indicate compatibility, not endorsement.

Certified

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

Frequently asked questions

How long do we have to respond?

The Rules allow up to 90 days for rights requests and grievances. You publish your own timeline, and that becomes the clock on every request. DataSurity won't let a setting exceed what the law allows, and warns the DPO seven, three and one day before any clock runs out.

Which rights does the DPDP Act give?

Access to a summary of your data, how it's used and who it's shared with. Correction, completion, updating and erasure. A grievance channel. And nomination of someone to act for you. Data portability is a GDPR right and isn't in the DPDP Act, so we don't sell it as one.

How do you verify the person asking?

By an OTP to an email address or mobile number you already hold for them. Nothing is shown or changed before that. Their identifiers are stored as one-way fingerprints, and any time a staff member reveals a person's details, the reveal is logged.

What if the law requires us to keep the data?

The system owner marks it exempt and picks the legal citation, such as PMLA or an RBI retention rule. The DPO approves. The request closes as partly fulfilled, and the person is told what was erased, what stays, why, and until when.

When can a person complain to the Data Protection Board?

Only after using your grievance channel and not getting a resolution within your published time. That makes your grievance process the front line. A logged, timed, answered grievance is the best protection against a complaint reaching the Board at all.

Will our customers see DataSurity's name?

No. The portal runs on your domain and in your brand. Replies go from your own sending domain, signed with your DPO's contact. The person deals with you from start to finish.

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

Knowledge resources

Send one test request. Watch it close.