Reference

DPDP Act 2023 — Our Posture

Section-by-section, how we meet each obligation. Not aspirational — every link goes to a live page or operational process.

The Digital Personal Data Protection Act 2023 is the foundational law governing how organisations in India handle personal data. Below is how Maitro meets each material obligation. If something here is wrong or out of date, email our Grievance Officer and we'll fix it (it's not for marketing — it's a working spec).

SectionTopicOur posture
§5Lawful processingEvery data category has a named lawful basis (see /legal/privacy section 1).
§6ConsentConsent requirements and withdrawal path are documented at /trust/consent. Wire the live consent ledger before production.
§7Legitimate use without consentListed only when a data category uses legitimate_use or another permitted basis in the venture config.
§8(2)Notice of purposeThe privacy page lists purpose, basis, retention, and sharing for each configured data category.
§8(6)Reasonable securitySecurity controls are published at /trust/breach from venture config. Do not claim a control until it is live.
§9Children (under 18)Verified guardian consent flow — see /trust/under-18.
§10Significant Data FiduciarySee /trust/dpo for DPO appointment and DPIA cadence.
§11Notice / Privacy PolicyPlain-language privacy policy at /legal/privacy. Updates notified 7 days in advance.
§13Grievance OfficerNamed officer with email, SLA, and escalation tree at /legal/grievance.
§14Data Subject RightsRights request form surfaces live at /trust/dsr. The consuming app must implement the API endpoint before production.
§17(2)Cross-border restrictionsIndia-only by default. Any cross-border transfer requires new consent + listed in privacy policy.

What we don't do (yet)

  • Annual DPIA publication — add only after the venture has a reviewed DPIA publication process
  • External audit attestation — add only after a signed audit report or regulator-facing attestation exists

How to challenge our posture

If you believe Maitro is not meeting any obligation listed above, email the Grievance Officer at privacy@maitro.tech with the section number and your evidence. We will respond within 7 days. Reasoned disagreement is welcome.

Last reviewed: 2026-05-26

Grievance Officer (per DPDP §13)

Bhaskar Anand, Director, Talpro India Private Limited

Email: privacy@maitro.tech

Acknowledgement SLA: 7 days · Resolution SLA: 30 days

Maitro uses only strictly necessary session cookies and privacy-first, cookieless analytics. No advertising cookies are set. See our Cookie Policy.