DPDP Compliance Notice

Effective date: March 31, 2026

This notice describes Kootami’s data governance commitments aligned to the Digital Personal Data Protection Act, 2023 (India) and applicable subordinate rules. It should be read with ourPrivacy PolicyandTerms and Conditions.

1. Regulatory Applicability

Kootami supports organizations operating in India and globally. DPDP obligations apply to digital personal data processed in scope of the Act and related legal requirements.

2. Data Fiduciary and Processor Context

In tenant-managed workflows, organizations may act as data fiduciaries while Kootami operates platform infrastructure as a service provider/processor. For platform-level security and operational functions, Kootami may act as data fiduciary.

3. Notice and Consent Practices

  • Clear purpose statements are presented in major collection workflows.
  • Consent-dependent flows can be configured by tenant organizations.
  • Consent withdrawal requests are handled subject to legal exceptions.

4. Purpose Limitation and Data Minimization

Kootami is designed to process data needed for membership operations, event participation, governance workflows, and security administration. Unnecessary processing is restricted through role and workflow controls.

5. Data Principal Rights

Subject to law and context, data principals may request:

  • Access to personal data summaries.
  • Correction, completion, and update of inaccurate data.
  • Erasure where retention is no longer lawful or required.
  • Withdrawal of consent for consent-based processing.
  • Grievance registration and resolution tracking.
  • Nomination rights, where applicable.

6. Children’s Data Safeguards

Where processing involves children, Kootami and tenant organizations are expected to implement age-appropriate controls, including authorization and consent requirements as applicable by law.

7. Security Safeguards

  • Authentication and authorization controls.
  • Secure data transmission and operational logging.
  • Incident detection and response practices.
  • Tenant isolation and restricted internal access pathways.

8. Breach and Incident Handling

Kootami maintains incident response procedures to investigate, contain, and remediate security events. Notifications are handled in accordance with legal obligations and risk assessment outcomes.

9. Data Retention and Deletion

Retention is governed by operational need, tenant policy, audit requirements, and legal obligations. Deletion or anonymization is applied when data is no longer lawfully required.

10. Cross-Border Processing

Cross-border processing, where required, is controlled through governance, contractual safeguards, and platform security mechanisms aligned to applicable legal requirements.

11. Grievance and Contact