Capture
The trackers running on your website are detected and inventoried so you can see what is actually firing.
The Product
DPDPA.support is a self-configuring DPDP Act 2023 compliance platform, with each site kept fully separate and secure. It captures consent with proof, gates trackers until consent, gives your data principals real self-service, honours access and erasure under the Act, and hands your DPO a working console. Every capability below maps to something the platform actually does today.
Runs on your own site · Fully isolated · Your data stays yours
Consent ledger
Every consent decision is captured per purpose and written to a secure, tamper-evident system of record. Consent events sync automatically and cryptographically verified, and every event is stored in an append-only audit trail you can query. When the Data Protection Board or an auditor asks, the answer is a record, not a recollection.
Cookie & tracker gating
DPDPA.support captures the cookies and trackers present on your site and actually gates them at the source. Analytics and advertising tags do not fire until consent is given, the trackers are gated at the source, not merely hidden behind a banner. Provisioning enforces gating for new tenants, and the setup surface gives you a tracker report with one-click enforcement.
The trackers running on your website are detected and inventoried so you can see what is actually firing.
Analytics and advertising categories are gated, blocked until the data principal consents.
Gating is auto-applied at provisioning and re-runnable from the setup surface without creating duplicates.
My Data self-service
At a tenant-branded My Data surface, members are auto-resolved from their login, no email is ever typed in. An OTP step-up confirms identity to that inbox before sensitive actions, sessions are scoped per site and securely signed so one site's session is invalid everywhere else, and consent is exposed as per-purpose toggles, both grouped and individual, with accept-all and decline-all.
access & portability
A access and portability request produces a structured DPDP-AccessReport/1.0 JSON document, the data principal's consent ledger, their grievances, and the fan-out across the surfaces where their data lives. Principals can pull it themselves through the self-service Download My Data action, and the same data underpins portability filing.
erasure & legal-hold
This is the honest, lawful version of erasure. Under erasure, DPDPA.support stops all processing the moment a request is honoured. But records are not physically destroyed on the spot: the Act's the Act lets a fiduciary retain data under a legal hold, and physical deletion happens only when the retention clock expires. Freezing, not silently deleting, is what keeps you compliant on both sides of the obligation.
Consents are withdrawn, marketing consent is revoked, email subscriptions are unsubscribed, and marketing labels are stripped.
The member record is deleted so a fresh signup starts clean, while the contact record is frozen rather than deleted, preserving the lawful retention record.
Data is retained under a documented legal hold (on the order of years, per the applicable retention rule), frozen, not actively processed.
A daily retention sweep physically deletes records only once their retention period has elapsed.
Why freeze, not purge? A purge-on-request that destroyed retained records would breach the retention obligation. DPDPA.support stops processing immediately and handles physical deletion automatically at the right time.
DPO console
DPDPA.support provisions a DPO surface where grievances, corrections, and portability requests are filed and resolved in one place, including a respond-and-action flow that lets the DPO reply to the data principal and choose what happens next. It is a console, not a shared spreadsheet.
Receive, respond to, and action grievances raised by data principals, with the response delivered back to the principal.
Correction and portability filings are tracked alongside access and erasure so nothing falls through the cracks.
Find any data principal and see their consent and request history drawn from the system of record.
Data discovery & RoPA
A data inventory step (“List Apps and Storage”) walks the apps and storage attached to your website so you can see where personal data actually sits across surfaces, contacts, members, orders, bookings, forms, inbox, invoices, loyalty, reviews and more. That inventory is the foundation for a Record of Processing Activities your DPO can stand behind.
Inventory the apps and storage connected to your website to surface where personal data resides.
Organise discovered data by the surfaces and processing purposes it belongs to.
Build toward a Record of Processing Activities grounded in your real data inventory.
Intelligence tier
For fiduciaries who want more depth, the Intelligence tier is a bring-your-own-key capability: you supply your own key so analysis runs on your terms, your data stays under your control rather than being handed to someone else's model. It sits on top of the compliance core; the consent, rights, erasure and DPO capabilities above stand entirely on their own without it.
Governance & audit
Governance runs through the whole platform. Every consent event is persisted to an append-only, tamper-evident audit trail you can query. Each site is fully isolated with its own securely-stored keys and policy, and sessions are scoped per site, isolation is enforced by default. Operated by CynorSense Solutions Pvt. Ltd., Hyderabad.
Every consent event is persisted append-only as tamper-evident evidence.
Each site's keys and policy are stored securely and kept fully separate from every other site.
securely signed sessions are bound to a tenant; one site's session is invalid elsewhere.
Tenant isolation is enforced by default, the safe default when anything is uncertain.
DPDPA.support is the fiduciary's own consent management and compliance platform. It is not a Board-registered Consent Manager.
Install from dpdpa.support, answer two questions during onboarding, your fiduciary legal name and your DPO email, and your tenant is provisioned. Not sure where to start? Begin with the by-need view.