Ninebloomninebloom
Warm desert landscape — editorial compliance backdrop

The DPDP Act is live.
Your data compliance is not.

The Digital Personal Data Protection Act applies to every organisation that handles personal data in India.
Penalties reach ₹250 crore. We make you compliant in 15 minutes — no legal team, no IT department, no paperwork.

Get Compliant — Free AssessmentSee How It Works — 2 Min Video

Full enforcement: 13 May 2027 · Maximum penalty: ₹250 crore · Board operational since Nov 2025 · Setup 15 minutes · No lock-in

Schools
HOSPITALS
Startups
Ninebloom
DPDP Ready
WHAT IS THE DPDP ACT

India now has
a data protection law.

The Digital Personal Data Protection Act, 2023 — Rules notified Nov 2025. If you collect customer names, patient records, student files, phone numbers — you are a Data Fiduciary with legal duties.

DOB Age gate · Parent/Adult OTP verified

DOB Age gate &
verified consent

Every form starts with DOB. Under 18 routes to parent flow (phone OTP via SMS/WhatsApp); 18+ routes to direct adult email OTP. Privacy notices auto-generated with per-purpose toggles in 7+ languages.

CONSENT LEDGER — 7 YR
  • Hash-chain #08492 — valid
  • Purpose: Admission / KYC
  • Withdrawal link — active

Immutable ledger &
one-tap withdrawal

Hash-chained, timestamped, IP and device logged with 7-year retention. One-tap withdrawal per purpose embedded in every notice and receipt. Withdrawing consent is as easy as giving it.

90dVaultDSR
Grievance SLA countdown ACTIVE

Principal Vault &
90-day grievance

OTP login where users see their data, correct, or delete without tickets. Full grievance intake system with automated 90-day SLA countdown timer and escalation alerts before Board complaints.

BREACH & RETENTION

72h timer + 48h delete alert

Hash-chained
AUDIT PACK

One-click Board PDF

72h Breach, retention &
Board audit pack

Armed 72-hour timer with Board templates. Automated retention engine with 48h pre-deletion notices and deletion certs. One-click Board-ready PDF audit pack export.

PENALTIES · MAXIMUM
Failing to protect children's data (no verifiable parental consent)₹200 crore
Failing security safeguards₹250 crore
Failing to report a breach₹200 crore
Full table + timeline →
WINDOW IS SHRINKING
11 Aug 2023Act passed
14 Nov 2025Rules notified. Data Protection Board operational
13 Nov 2026Consent Manager framework goes live
13 May 2027Full enforcement. All penalties active. No grace period.
HOW THE ACT HITS YOUR INDUSTRY

Three industries.
Three different emergencies.

Pick the one that looks like you. Each has a different ₹200Cr trap.
Hover to preview — click for full deep dive.

Review /Parent consent — Education
NON-COMPLIANCE CHECKLIST
Admission forms with a checkbox instead of verified parent consent
Student photos posted on Facebook, school website, WhatsApp groups — no per-use consent
Student data shared with EdTech vendors, bus operators, photographers — no contracts
Old student records sitting on staff laptops and Google Drives for years
WHAT WE DO
OTP VERIFIEDSmart admission formParent OTP before submit
WHATSAPPRetro-consent 72%Resend to remaining
SHARED CORE · INDUSTRY WORKFLOWS

Education vs Startups: What Changes

The 13-feature core (DOB Age gate, Hash-chained ledger, Principal Vault, 72h breach timer, Board audit pack) is built once and shared. The difference is in verification channels, form complexity, and child-data penalty thresholds.

AspectEducational Institutions (Lead GTM)Startups & SMBs
Primary flowChild (parent OTP via phone)Adult (email OTP)
Primary channelWhatsApp forms with SMS fallbackWebsite embed + REST API
Killer featureRetro-consent campaigns for existing studentsTracker scanner + B2B compliance report link
Form count7 pre-built templates1–3 pre-built templates
Vault usersParents (non-technical, phone-first, multilingual)Users (technical, email-first, English)
Sales motionWhatsApp outreach to institutions, 15-min setupSelf-serve signup + developer docs
Language priorityRegional languages critical (English + 6 languages)English-first (English + Hindi)
Data sensitivityChildren's data — ₹200 crore penalty regimeUser data — standard obligations
Explore 7 Education Templates & Roadmap →Explore Startup Widget, API & Scanner →
Pricing

Priced for what you
actually are

Not what enterprises pay. All plans include vault, grievance, breach, scanner, audit & dashboard. No lock-in. Enterprise 5,000+ → custom volume.

Starter

₹2,500

per month

Small coaching, clinic, early startup — up to 200 records, then ₹3/record. Consent, OTP, ledger, vault, breach, audit.

  • Consent capture & OTP verify
  • Hash-chained ledger
  • Principal Vault (OTP)
  • Grievance + breach (72h)
  • Tracker scanner
  • Audit pack — one click
Start free
Standard

₹4,000

per month

Growing school/hospital/startup — up to 1,000 records, then ₹2.50/record. Retro-campaigns + vendor register.

  • Everything in Starter
  • Up to 1,000 records
  • Retro-consent WhatsApp
  • Vendor register & templates
  • Priority breach support
  • Multi-user access
Start free

All plans: consent capture, OTP, ledger, Vault, grievance, breach manager, tracker scanner, audit pack, dashboard. Enterprise custom for 5,000+ — volume pricing.

HOW IT WORKS

From signup to compliant.
Without the back-and-forth.

Connect → Campaign → Compliant. WhatsApp link, embed or API — whatever you use today.

Warm desert landscape surrounding Ninebloom workspace
Ninebloom
COMPLIANCE

Consent ledger

All recordsVerifiedPending
P
Parent OTPVerified
P
PatientVerified
U
User VaultVerified
V
Vendor AContracted
V
Vendor BContracted
T
Tracker scan3 flagged
01 — 5 minConnect forms

Replace or embed consent layer. Notice from actual fields. Per-purpose consent. OTP at submit.

02 — 5 minSend campaigns

One WhatsApp/SMS/email link for existing data. Track 72% verified, resend to remainder.

03 — ongoingYou're compliant

Ledger hash-chained, vault self-serve, breach timer armed, audit pack one click.

Security built for teams where data accountability is non-negotiable.

See full security documentation
Certified and compliant

Audited annually against security, availability and confidentiality criteria. Compliant with EU data protection and US healthcare privacy standards.

Private LLM gateway

PII and sensitive data are stripped before anything reaches an LLM provider. Documents are never sent for ingestion or training — only anonymized chunks.

Zero data retention

No retention on the provider side, no training on your data. You control retention periods for messages and media to meet policy.

Audit and conversation logs

A full trail of what the AI agent said, what it decided, and why. Data Subject Requests can be fulfilled without dependency on Ninebloom.

Prompt integrity and sandboxing

User inputs are sandboxed away from system prompts. Out-of-scope inputs never reach the model; topics and phrases can be blocked outright.

MCP server

Helpdesk operations exposed as MCP tools — connect internal systems without custom integration. Works with Claude Code, Claude Desktop, and Cursor.

Data minimization

Purpose-limited collection enforced at form level. Extra fields flagged before consent, never stored silently.

Verifiable parental consent

Every child record requires OTP-verified parent identity with DigiLocker optional. Proof retained, hash-chained for years.

One-click Board audit pack

Hash-chained ledger, vault logs and breach reports exported in one click. Ready for inquiry, no spreadsheet scramble.

FAQ

Questions
answered.

Straight answers. No legal jargon.

Chat with us

No — and anyone claiming a "DPDP certified" badge is misleading you. The Government of India does not issue certifications under the Act. What we provide is the operational compliance the Act demands: consent records, rights handling, breach readiness, and audit evidence. That is what the Board accepts.

Yes. The Act applies by data, not by size. A coaching centre with 100 students is a Data Fiduciary. A clinic with 50 patients is a Data Fiduciary. The penalties don't scale down with your revenue.

That's the retro-consent campaign — our core feature. You send one link to everyone whose data you hold. They verify and consent via OTP. You track coverage until you're done. Existing data is where most risk sits, because the Board can ask about data you collected years ago.

Before processing any child's data (under 18), you must verify the parent is who they claim — via OTP to their phone, DigiLocker, or government ID. The consent is then recorded with proof. A checkbox or a signature on a form is not verifiable.

The Board can initiate an inquiry from a single complaint. If you cannot produce consent records, penalties apply — ₹200 crore for children's data violations, ₹250 crore for security failures. The Act places the burden of proof on you.

Only if the government designates you a Significant Data Fiduciary — which applies to large platforms, not small institutions. Below that threshold, you need the capabilities (consent records, grievance handling, breach readiness) but not the full-time officer. That's what we are.

A policy page is a document. Compliance is a system. The Act demands consent records with proof, rights request handling with deadlines, breach reporting within 72 hours, and retention management. None of that lives in a policy PDF. That's what our platform runs.

Integrations

Connect your workflow.
Ninebloom meets you there.

WhatsApp, Tally, GA4, Meta Pixel and 60+ more. Ninebloom scans trackers,
logs vendors, and keeps consent in sync — right where your team already works.

Desert lake at sunset — final compliance call

One complaint can start an inquiry.
One click can prove you're ready.

Get your free compliance assessment. Five minutes. No card.

Start Free AssessmentBook a 10-Minute Demo