DOB Age gate &
verified consent
Every form starts with DOB. Under 18 routes to parent flow (phone OTP via SMS/WhatsApp); 18+ routes to direct adult email OTP. Privacy notices auto-generated with per-purpose toggles in 7+ languages.

The Digital Personal Data Protection Act applies to every organisation that handles personal data in India.
Penalties reach ₹250 crore. We make you compliant in 15 minutes — no legal team, no IT department, no paperwork.
Full enforcement: 13 May 2027 · Maximum penalty: ₹250 crore · Board operational since Nov 2025 · Setup 15 minutes · No lock-in
The Digital Personal Data Protection Act, 2023 — Rules notified Nov 2025. If you collect customer names, patient records, student files, phone numbers — you are a Data Fiduciary with legal duties.
Every form starts with DOB. Under 18 routes to parent flow (phone OTP via SMS/WhatsApp); 18+ routes to direct adult email OTP. Privacy notices auto-generated with per-purpose toggles in 7+ languages.
Hash-chained, timestamped, IP and device logged with 7-year retention. One-tap withdrawal per purpose embedded in every notice and receipt. Withdrawing consent is as easy as giving it.
OTP login where users see their data, correct, or delete without tickets. Full grievance intake system with automated 90-day SLA countdown timer and escalation alerts before Board complaints.
72h timer + 48h delete alert
One-click Board PDF
Armed 72-hour timer with Board templates. Automated retention engine with 48h pre-deletion notices and deletion certs. One-click Board-ready PDF audit pack export.
Pick the one that looks like you. Each has a different ₹200Cr trap.
Hover to preview — click for full deep dive.
The 13-feature core (DOB Age gate, Hash-chained ledger, Principal Vault, 72h breach timer, Board audit pack) is built once and shared. The difference is in verification channels, form complexity, and child-data penalty thresholds.
| Aspect | Educational Institutions (Lead GTM) | Startups & SMBs |
|---|---|---|
| Primary flow | Child (parent OTP via phone) | Adult (email OTP) |
| Primary channel | WhatsApp forms with SMS fallback | Website embed + REST API |
| Killer feature | Retro-consent campaigns for existing students | Tracker scanner + B2B compliance report link |
| Form count | 7 pre-built templates | 1–3 pre-built templates |
| Vault users | Parents (non-technical, phone-first, multilingual) | Users (technical, email-first, English) |
| Sales motion | WhatsApp outreach to institutions, 15-min setup | Self-serve signup + developer docs |
| Language priority | Regional languages critical (English + 6 languages) | English-first (English + Hindi) |
| Data sensitivity | Children's data — ₹200 crore penalty regime | User data — standard obligations |
Not what enterprises pay. All plans include vault, grievance, breach, scanner, audit & dashboard. No lock-in. Enterprise 5,000+ → custom volume.
per month
Small coaching, clinic, early startup — up to 200 records, then ₹3/record. Consent, OTP, ledger, vault, breach, audit.
per month
Growing school/hospital/startup — up to 1,000 records, then ₹2.50/record. Retro-campaigns + vendor register.

per month
Large school / multi-clinic / scaling startup — up to 5,000 records, then ₹2/record. Photo workflows, retention engine.
All plans: consent capture, OTP, ledger, Vault, grievance, breach manager, tracker scanner, audit pack, dashboard. Enterprise custom for 5,000+ — volume pricing.
Connect → Campaign → Compliant. WhatsApp link, embed or API — whatever you use today.

Replace or embed consent layer. Notice from actual fields. Per-purpose consent. OTP at submit.
One WhatsApp/SMS/email link for existing data. Track 72% verified, resend to remainder.
Ledger hash-chained, vault self-serve, breach timer armed, audit pack one click.
Audited annually against security, availability and confidentiality criteria. Compliant with EU data protection and US healthcare privacy standards.
PII and sensitive data are stripped before anything reaches an LLM provider. Documents are never sent for ingestion or training — only anonymized chunks.
No retention on the provider side, no training on your data. You control retention periods for messages and media to meet policy.
A full trail of what the AI agent said, what it decided, and why. Data Subject Requests can be fulfilled without dependency on Ninebloom.
User inputs are sandboxed away from system prompts. Out-of-scope inputs never reach the model; topics and phrases can be blocked outright.
Helpdesk operations exposed as MCP tools — connect internal systems without custom integration. Works with Claude Code, Claude Desktop, and Cursor.
Purpose-limited collection enforced at form level. Extra fields flagged before consent, never stored silently.
Every child record requires OTP-verified parent identity with DigiLocker optional. Proof retained, hash-chained for years.
Hash-chained ledger, vault logs and breach reports exported in one click. Ready for inquiry, no spreadsheet scramble.
No — and anyone claiming a "DPDP certified" badge is misleading you. The Government of India does not issue certifications under the Act. What we provide is the operational compliance the Act demands: consent records, rights handling, breach readiness, and audit evidence. That is what the Board accepts.
Yes. The Act applies by data, not by size. A coaching centre with 100 students is a Data Fiduciary. A clinic with 50 patients is a Data Fiduciary. The penalties don't scale down with your revenue.
That's the retro-consent campaign — our core feature. You send one link to everyone whose data you hold. They verify and consent via OTP. You track coverage until you're done. Existing data is where most risk sits, because the Board can ask about data you collected years ago.
Before processing any child's data (under 18), you must verify the parent is who they claim — via OTP to their phone, DigiLocker, or government ID. The consent is then recorded with proof. A checkbox or a signature on a form is not verifiable.
The Board can initiate an inquiry from a single complaint. If you cannot produce consent records, penalties apply — ₹200 crore for children's data violations, ₹250 crore for security failures. The Act places the burden of proof on you.
Only if the government designates you a Significant Data Fiduciary — which applies to large platforms, not small institutions. Below that threshold, you need the capabilities (consent records, grievance handling, breach readiness) but not the full-time officer. That's what we are.
A policy page is a document. Compliance is a system. The Act demands consent records with proof, rights request handling with deadlines, breach reporting within 72 hours, and retention management. None of that lives in a policy PDF. That's what our platform runs.
WhatsApp, Tally, GA4, Meta Pixel and 60+ more. Ninebloom scans trackers,
logs vendors, and keeps consent in sync — right where your team already works.

Get your free compliance assessment. Five minutes. No card.