Compliance & Data Protection

DPDP-ready by construction — consent capture, a consent ledger, retention with automatic anonymization, DSAR handling and an audit trail. Not a policy document: working controls.

Six controls, built into the product

Most vendors say "DPDP-ready" and mean a privacy page. These are the actual features that make the data lawful to hold.

Consent capture & e-signature

Explicit, informed consent recorded at check-in with a purpose notice — signed digitally, stored against the visit.

Consent ledger

Every consent event, version and withdrawal in one searchable ledger — the record a regulator asks for.

Retention & auto-anonymization

Set a retention window per site; a nightly compliance job redacts name, email, phone and photo on visits that age out.

DSAR request handling

Log, track and fulfil data-subject access, correction and erasure requests with deadlines and an outcome trail.

Anonymization log

A tamper-evident record of what was anonymized, when and under which policy — proof the purge actually ran.

Full audit trail

Who accessed, changed or exported personal data, with actor, time and action — exportable for audit.

Retention that enforces itself

Storage limitation is the DPDP requirement paper registers fail hardest — books sit in cupboards for years. Set a retention window once and the system purges on schedule, with proof.

Per-site retention window
Choose how long checked-out visit data is kept (365 days by default).
Nightly compliance job
Ages out records automatically — no one has to remember to delete.
Redaction, not deletion
Personal fields (name, email, phone, photo) are redacted; the operational record stays for audit continuity.
Anonymization log
Every run recorded — what, when, under which policy.

Consent you can evidence

Under the DPDP Act, visitor data generally needs a consent-based footing with a clear purpose notice. A signature scrawled to get past the gate is not that. This is.

Purpose notice at check-in
Visitors see what is collected and why before anything is stored.
Digital e-signature
Consent signed and timestamped, with the exact consent-text version.
Withdrawal recorded
Consent withdrawals are captured in the same ledger.
Searchable ledger
Find every consent event for a person in seconds.

Individual rights, on a deadline

When someone asks what you hold about them — or asks you to erase it — a bound register cannot answer. A DSAR workflow can, on time, with evidence.

Request intake & tracking
Log access, correction and erasure requests with due dates.
Locate every record
Find all data for a person across visits, consents and logs.
Outcome trail
Record what was disclosed, corrected or erased, and when.
Audit-ready export
Produce the evidence pack if a regulator asks.

Compliance as a by-product of running the gate properly

Run visitors, contractors and material through manmov'e and the DPDP artifacts write themselves — consented records, enforced retention, a DSAR trail and a full audit log — instead of a separate compliance project you dread.

DPDP Act 2023Configurable data regionPrivate / on-premise hostingRole-based accessEncrypted transport

Product capabilities described here support your compliance program; they are not legal advice. Consult your legal or compliance team for obligations specific to your organization.

Frequently asked questions

How does manmov'e help with DPDP Act compliance?

The DPDP Act 2023 requires informed consent, purpose limitation, storage limitation, security safeguards and the ability to honour individual rights. manmov'e captures consent digitally at check-in, limits data to the visit purpose, auto-anonymizes records after a configurable retention window, logs every access, and gives you a workflow to fulfil data-subject requests — the controls a paper register can never provide.

What does the nightly anonymization job actually do?

Visits checked out longer ago than your retention window are anonymized automatically: visitor name, email, phone and photo are redacted, while the non-personal visit record (date, host, purpose) is kept for operational and audit continuity. Every run is written to the anonymization log.

What is a DSAR and how is it handled?

A Data Subject Access Request is an individual asking what personal data you hold, or asking you to correct or erase it. manmov'e logs each request, tracks it against a deadline, lets you locate every record for that person, and records the outcome — so you can respond on time with evidence.

Is consent really captured, or just a checkbox?

Consent is presented with a clear purpose notice and captured with a digital signature, timestamp and consent-text version. Withdrawals are recorded too. The ledger shows exactly what each person agreed to and when.

Where is the data stored?

Data region is configurable per deployment (India by default). Private and on-premise hosting are available for enterprises with data-residency requirements.

Does this cover employees and contractors as well as visitors?

Yes. Retention, audit and access controls apply across visitor, workforce and material records. Employee data follows your HR retention policy; visitor data — the higher-obligation case under DPDP — follows the consent-based flow.

See the compliance controls working

Book a 30-minute demo of consent capture, retention, DSAR handling and the audit trail on a live system.

No commitment. We'll call you within 24 business hours to confirm your preferred time.

Make 'DPDP-ready' mean something.

See consent, retention and DSAR handling running — not described — in one demo.