Consent you can prove
Compliance you can ship

Complyt handles your business' privacy compliance from end to end. Consent, cookies, user requests, and audit-ready records, without the manual work.

“Why Complyt?”

Privacy compliance shouldn't mean weeks of lawyer calls and consultant meetings. The law doesn't just require consent, it requires you to prove it. Complyt turns that legal burden into software, so your team can stay compliant without slowing down. The DPDP Act puts the burden of proving consent on you, not your user. A policy PDF can't carry that burden. A tamper-evident ledger can.

The DPDP Act, in a minute

2026
JUL
 
THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023
IN BRIEF

The DPDP Act requires businesses to handle personal data lawfully, securely, and transparently. It requires strong processes for consent, security, and data governance. Non-compliance can lead to heavy penalties and loss of customer trust.

Consent before you collect — per purpose
Withdrawal as easy as consent
A grievance channel — the law starts the clock
Breaches reported — to users too
The burden of proving it all is yours — s.6(10)

The platform

What your users see is only the surface. Complyt quietly handles the complexity behind privacy compliance, giving your business everything it needs to stay compliant as you grow.

yourstore.in
We use cookies. Choose what you share.
AcceptManage
#0141a41f→9f2e#01429f2e→c7d1#0143c7d1→5b8a

Consent ledger

A tamper-evident record of every consent — history that can't be quietly edited.

history that can testify →
CRMEMAILANALYTICSADScomplyt

Integrations

Every tool in your stack, kept true to what each user actually agreed.

state, synced everywhere →
Consent banner

Per-purpose, plain-language consent — collected the way the Act wants it.

Webhooks

consent.withdrawn reaches your backend the moment it happens.

Notice versions

New notice, fresh consent — provable years later.

v1 ✓ consentedv2 consent required
Withdrawal

One click per purpose — exactly as easy as giving consent.

Cookie manager

Non-essential scripts wait for consent — withdraw, and the gate closes.

Grievance portal

Complaints land in your queue with the 30-day clock already running.

We can't leak what we never see.

We never see who your users are — by architecture, not policy. Complyt proves consent without ever holding an identity.

WHAT WE HOLD
proof of consent✓ audit-ready
Enough to satisfy an auditor. Not enough to identify anyone.
WHAT WE NEVER HOLD
priya@example.com✗ stays with you
Names, emails, phone numbers — your users' identities stay yours, always.

That isn't a policy promise. It's how Complyt is built — to the same standard the DPDP Rules set for the people they trust with consent.

CONSENT  ·  WITHDRAWAL  ·  COOKIES  ·  GRIEVANCE  ·  LEDGER  ·  NOTICE VERSIONS  ·  WEBHOOKS  ·  INTEGRATIONS  ·  EVIDENCE  ·  DPDPA  ·  CONSENT  ·  WITHDRAWAL  ·  COOKIES  ·  GRIEVANCE  ·  LEDGER  ·  NOTICE VERSIONS  ·  WEBHOOKS  ·  INTEGRATIONS  ·  EVIDENCE  ·  DPDPA  ·  

Ships like code.

Because it is code. One script tag on the front end — the SDK is open source, yours to read — one identify() after login, webhooks on the back. Your site changes nothing else.

01Paste the tag. Banner, cookie gating and grievance portal go live.
02Call identify() after login. We never learn who — only that consent exists.
03Subscribe webhooks. Signed consent events, like any other event stream.
SDK · OPEN SOURCE
WEBHOOKS · PRO
index.html
<!-- consent · cookies · grievance · withdrawal -->
<script
  src="https://cdn.complyt.in/sdk.js"
  data-key="cmp_live_9f2e"
  data-modules="consent,cookies,grievance">
</script>
<script>
  Complyt.identify(user.id) // we never see the raw ID
</script>
// that's the whole integration.
banner live · consent logged · you're covered
zero dependencies · plays nice with any stack · fails safe by default

An afternoon, hour by hour

No consultants, no committees. One developer, one afternoon.

1:00 pm

Connect

Workspace, domains, purposes. Self-serve — no call with us required.

1:30 pm

Paste the tag

The banner is live, and the ledger records event #1.

2:15 pm

Wire webhooks

A test withdrawal reaches your backend, signed, before the chai's done.

4:00 pm

Audit-ready

Export the evidence: every event, chained and verifiable — generated as you went.

Penalties under the DPDP Act
reach ₹250 crore.

Your defence is evidence.

Does DPDP apply to you?

If you collect, store or process the personal data of people in India — yes. Whatever the industry.

E-COMMERCE
E-commerce & D2C
Consent has to travel with every checkout, address book and remarketing pixel.
FINTECH
Fintech & BFSI
KYC files and credit data sit in the Act's highest-penalty tier.
HEALTH
Health & pharma
Records and prescriptions need consent you can prove years later.
SAAS
SaaS & platforms
You process customers' data on their behalf — their obligations arrive in your contracts.
EDTECH
EdTech
Many users are minors — verifiable guardian consent is the Act's hardest ask.
TRAVEL
Travel & hospitality
IDs and itineraries cross hotels, airlines and agents — every hop needs a basis.
MEDIA
Media & adtech
Behavioural profiles and third-party cookies are exactly what the Act polices.
RETAIL
Retail & services
Loyalty programmes and CRMs hold personal data by the lakh.
Handling Indians' personal data? Then yes — it applies.See where you stand

Built for startups outgrowing their paperwork.

You're shipping weekly and signing bigger customers. DPDPA shouldn't be the thing that slows either down.

vendor security review — Q7
Are you DPDPA-compliant?YES ✓

Founders

Answer yes — with evidence attached, not a policy PDF. Close the deals that ask the question, without hiring for it.

<script src="cdn.complyt.in/sdk.js">
// consent live · 0 config

Developers

One tag, honest docs, webhooks like any other event stream. Compliance that reads like a good API, not a government circular.

09:41  consent.givenusr_2f4
10:03  consent.withdrawnusr_88a
10:17  grievance.resolved#1042

Legal & ops

Every consent tied to a notice version. Every grievance on a running clock. Audit-ready is the resting state, not the fire drill.

Built on trust? Prove it.

When the Board — or your biggest customer — asks "show me consent for this purpose, over this period", the answer is a download. Every event, its notice version, its proof of integrity — verifiable at export, not asserted.

Complyt Founders

"Compliance shouldn't take longer than the feature that caused it. We're engineers, so we built the DPDPA tool we wanted to buy — one script tag, receipts for everything. India-first, because this deadline is ours too."

— founders, complyt · under the guidance of IIMA Ventures

Questions, answered

An afternoon well spent.

Bring a developer and your stack. Leave with consent, withdrawal, grievances and cookies running — and a ledger already keeping receipts.

Book a demo
dpdpa-checklist.md
Notice & consent banner
Consent withdrawal flow
Grievance officer portal
Cookie gating
Tamper-evident audit ledger
Evidence export

Talk to us.

Send a message and we'll get back to you to set up a demo.

hello@complyt.in
Bangalore, India