Compliance & Data Protection
DPDP-ready by construction — consent capture, a consent ledger, retention with automatic anonymization, DSAR handling and an audit trail. Not a policy document: working controls.
Six controls, built into the product
Most vendors say "DPDP-ready" and mean a privacy page. These are the actual features that make the data lawful to hold.
Consent capture & e-signature
Explicit, informed consent recorded at check-in with a purpose notice — signed digitally, stored against the visit.
Consent ledger
Every consent event, version and withdrawal in one searchable ledger — the record a regulator asks for.
Retention & auto-anonymization
Set a retention window per site; a nightly compliance job redacts name, email, phone and photo on visits that age out.
DSAR request handling
Log, track and fulfil data-subject access, correction and erasure requests with deadlines and an outcome trail.
Anonymization log
A tamper-evident record of what was anonymized, when and under which policy — proof the purge actually ran.
Full audit trail
Who accessed, changed or exported personal data, with actor, time and action — exportable for audit.
Retention that enforces itself
Storage limitation is the DPDP requirement paper registers fail hardest — books sit in cupboards for years. Set a retention window once and the system purges on schedule, with proof.
Consent you can evidence
Under the DPDP Act, visitor data generally needs a consent-based footing with a clear purpose notice. A signature scrawled to get past the gate is not that. This is.
Individual rights, on a deadline
When someone asks what you hold about them — or asks you to erase it — a bound register cannot answer. A DSAR workflow can, on time, with evidence.
Compliance as a by-product of running the gate properly
Run visitors, contractors and material through manmov'e and the DPDP artifacts write themselves — consented records, enforced retention, a DSAR trail and a full audit log — instead of a separate compliance project you dread.
Product capabilities described here support your compliance program; they are not legal advice. Consult your legal or compliance team for obligations specific to your organization.
Frequently asked questions
How does manmov'e help with DPDP Act compliance?
The DPDP Act 2023 requires informed consent, purpose limitation, storage limitation, security safeguards and the ability to honour individual rights. manmov'e captures consent digitally at check-in, limits data to the visit purpose, auto-anonymizes records after a configurable retention window, logs every access, and gives you a workflow to fulfil data-subject requests — the controls a paper register can never provide.
What does the nightly anonymization job actually do?
Visits checked out longer ago than your retention window are anonymized automatically: visitor name, email, phone and photo are redacted, while the non-personal visit record (date, host, purpose) is kept for operational and audit continuity. Every run is written to the anonymization log.
What is a DSAR and how is it handled?
A Data Subject Access Request is an individual asking what personal data you hold, or asking you to correct or erase it. manmov'e logs each request, tracks it against a deadline, lets you locate every record for that person, and records the outcome — so you can respond on time with evidence.
Is consent really captured, or just a checkbox?
Consent is presented with a clear purpose notice and captured with a digital signature, timestamp and consent-text version. Withdrawals are recorded too. The ledger shows exactly what each person agreed to and when.
Where is the data stored?
Data region is configurable per deployment (India by default). Private and on-premise hosting are available for enterprises with data-residency requirements.
Does this cover employees and contractors as well as visitors?
Yes. Retention, audit and access controls apply across visitor, workforce and material records. Employee data follows your HR retention policy; visitor data — the higher-obligation case under DPDP — follows the consent-based flow.
See the compliance controls working
Book a 30-minute demo of consent capture, retention, DSAR handling and the audit trail on a live system.
Make 'DPDP-ready' mean something.
See consent, retention and DSAR handling running — not described — in one demo.