Data discovery and DSAR,
for the data nobody remembers.
Discovery and classification across your stores, a map of how personal data actually crosses borders, and a rights workflow that runs on the statutory clock rather than on whoever remembers the inbox.
What it does
- Discovery and classification across data stores
- Cross-border data-flow mapping with residencies named
- DSAR workflow with statutory SLAs and due dates
- Breach simulator and notification drafts
A right you cannot exercise is not a right
DPDP section 11 gives the Data Principal access to a summary of their personal data and the processing done on it; sections 12 and 13 add correction and erasure. GDPR Articles 15 to 17 ask comparable questions. All of them are unanswerable if you cannot say where the data is.
Which is why discovery comes before the request workflow, not after it. A DSAR process sitting on an unmapped estate produces a confident reply that is incomplete, and an incomplete reply is the version a regulator reads.
Erasure is instruction, not access
Your personal data lives in your databases. We deliberately do not reach into them and delete rows: doing so would make us a processor of your data and hand a third party destructive access to your production systems. Neither is something you should want from a compliance vendor.
So the model is attestation, not execution. A withdrawal, an expiry or an elapsed retention period raises a dated obligation naming the purpose, the principal and the deadline; the person who owns that store carries it out and records the outcome. An outcome of retained under law is refused unless the law relied on is named, because “we kept it” without a citation is the answer that fails an inspection.
Rehearse the breach before you have one
Breach notification clocks are short and start at awareness, not at conclusion of the investigation. The first time a team drafts that notification should not be while the clock is running.
The simulator runs the scenario against your real data map, so the draft names the actual stores, categories and residencies involved, and the gaps it exposes (an unmapped store, an unnamed owner, a residency nobody had recorded) surface on a day when finding them costs nothing.
Where this sits
This is one engine of eleven on a single control graph, which is why a result produced here reaches every framework that asks for it instead of being gathered again under another heading. The platform overview shows the other ten, and coverage lists the regimes they answer.
Related reading: the DPDP Act guide and the DPIA template.
The things people ask us
Do you delete data from our databases?
No, deliberately. Reaching into your stores to delete rows would make us a processor of your data and give a third party destructive access to your production systems. We raise the dated obligation and record the attested outcome; your data owner performs the deletion.
What happens when someone withdraws consent?
A dated erasure obligation is raised naming the purpose, the principal and the deadline, and the relay tells the processors you already shared that data with. Withdrawal has to be as easy as consent was under DPDP section 6(4), and it has to propagate, not just stop your own processing.
Can we record that data was kept lawfully?
Yes, but not vaguely. An outcome of retained under law is refused unless the specific law is named. An unexplained retention is exactly what an inspection will ask about, so the field makes you answer it in advance.
How is personal data classified?
By discovery across your stores rather than by a form somebody fills in, with sensitivity recorded as a class (financial, health, biometric, identifier or children's data) because those attract heavier scrutiny and a heavier breach consequence.
What does the breach simulator produce?
A notification draft built against your real data map, naming the stores, categories and residencies actually involved, plus the gaps the scenario exposed. Running it on a quiet day is considerably cheaper than discovering those gaps during the notification window.
Your next audit could be a link.
Thirty minutes. We connect one cloud account live and show you real evidence landing in the ledger before the call ends.