India's DPDP Act · Effective 2025

Your customers' data.
Their choice, always.

SecureConsent is India's consent and document infrastructure - built for DPDP compliance. Capture consent, securely store identity documents, and honour withdrawals. Serving across India. Hosted on MeitY-approved cloud infrastructure.

Built for DPDP Rules 2025 · Data stored in India · 72-hr breach support · MeitY-aligned

India's DPDP Act changes everything about how you handle customer data.

₹250 Crore
Maximum penalty per violation under DPDP Act 2023
72 Hours
To notify the Data Protection Board after a data breach
18 Months
Phased compliance timeline granted under DPDP Rules, 2025 for full transition

Every time a hotel collects a guest's phone number, a builder takes a homebuyer's Aadhaar, or a hospital records a patient's history - that's personal data. Under DPDP, you need explicit consent, documented proof, and a clear way for people to withdraw it. SecureConsent handles all of this automatically.

One consent backbone.
Every industry.

SecureConsent has two layers - a core consent engine that any software can plug into, and purpose-built modules for specific industries.

Core Consent API

The headless backbone. Captures consent, stores immutable audit trails, fires withdrawal webhooks to every connected system instantly.

  • REST API + SDKs (Laravel, Node, Python)
  • Tamper-proof consent receipts with SHA-256 proof hash
  • Real-time withdrawal sync - when someone says stop, everything stops
  • Sandbox environment to test without real data
  • Secure document vault - Aadhaar, PAN, and KYC papers encrypted at rest in India
  • Immutable certificate of storage + certificate of deletion for every record
  • Every fetch logged - full audit trail of who accessed what and when
  • Consent renewal workflows - extend retention when data is needed longer than planned
Join Developer Preview →

Industry Modules

Pre-built consent and document collection workflows for sectors where personal data is most sensitive.

Hotels & Hospitality
Real Estate & Builders
Hospitals & Healthcare
EdTech & Schools
Tell us about your industry →

From consent link to audit trail in seconds.

01
Step 1

You send a consent link

A builder requests PAN and Aadhaar for booking. A hotel asks for ID before check-in. The link opens a branded, DPDP-compliant consent and document request page - in the customer's language.

02
Step 2

They choose what they agree to

The customer sees exactly what data and documents are being collected and why. They can agree to some purposes, decline others, and share from their personal vault or DigiLocker. No dark patterns. No pre-checked boxes.

03
Step 3

You get proof. They keep control.

You receive a tamper-proof consent receipt and a certificate of storage. They get a personal vault to view, update, renew, or withdraw consent any time - with a full audit trail of every access.

Every sector has different rules. We know them all.

Hotels & Hospitality

Guest check-in forms, WhatsApp consent, pre-arrival data collection - all compliant. Works with IDS Next, Hotelogix, eZee.

Learn more →

Real Estate & Builders

Consent before the sales call. RERA-aligned data collection. Works with LeadSquared, Sell.do, 99acres portals.

Learn more →

Hospitals & Healthcare

Patient consent for treatment, data sharing with labs and insurers. Sensitive data handling under DPDP + DISHA guidelines.

Learn more →

EdTech & Schools

Parental consent for under-18 users. No behavioral tracking without permission. DPDP's strictest requirements - handled automatically.

Learn more →

Received a consent link from a business?

If a hotel, hospital, builder, or school sent you a link powered by SecureConsent, your data and documents are being handled under India's DPDP Act - with your rights fully intact. Store your identity documents once and share them securely with any business.

Right to know

See exactly what data and documents were collected, who accessed them, and why. Every fetch is logged.

Right to correct

Fix any incorrect information or replace expired documents in your vault, any time.

Right to withdraw

Change your mind any time. Withdraw consent or request deletion - we issue a certificate of deletion instantly.

Store once, share anywhere

Upload your Aadhaar, PAN, and documents to your personal vault once. Share with any business via a single click. DigiLocker integration coming soon.

Certificates for every action

Receive a certificate when your data is stored, accessed, or permanently deleted. Proof that the business complied.

Consent renewal

If a business needs your data longer than originally planned, they must request renewal. You choose to extend or decline.

Verify a consent record

Enter your phone number or the consent ID from your link to see exactly what consents are recorded in your name.

Your data is looked up securely. Nothing is stored during this check.

Already building something? Plug in our API.

SecureConsent's Core API is a standalone product. Embed DPDP-compliant consent and secure document handling into any existing software in hours, not months.

POST https://api.secureconsent.in/v1/consent
{
"principal_id": "user_98765",
"purposes": ["marketing_calls", "whatsapp"],
"source": "web_form",
"language": "hi"
}
→ 200 OK
{
"consent_id": "cns_a3f9c12e",
"proof_hash": "sha256:a3f9...c12e",
"granted_at": "2026-06-09T13:00:00Z"
}

Every document fetch is logged. Request a certificate of storage when a record is created and a certificate of deletion when it is purged - both cryptographically signed.

DPDP compliance isn't optional. Make it effortless.

We're building India's first vertical DPDP compliance platform for SMBs. Be the first to get access.

Launching Q3 2026. No credit card required to join the waitlist.

About SecureConsent

SecureConsent is built by Intricare Technologies - a team working on compliance infrastructure for Indian businesses navigating the DPDP Act. We are based in India, building for India.

For Real Estate · RERA-Aligned

Consent before the site visit.
Proof after the sale.

Every brochure download, site visit form, and booking advance involves personal data - Aadhaar, PAN, phone numbers, income proofs. Under DPDP, a verbal "yes" is not enough. SecureConsent gives builders and brokers verifiable consent and secure document handling for every lead.

Built for DPDP Rules 2025 · Data stored in India · RERA-aligned workflows

A builder collects more personal data than a bank - with fewer safeguards.

₹250 Crore
Maximum penalty for failing to protect personal data with reasonable security safeguards
72 Hours
To notify the Data Protection Board after a data breach
5+ Docs
Aadhaar, PAN, income proof, address proof, photo - collected per homebuyer on average

Every site visit form, every broker handoff, every booking advance involves Aadhaar and PAN copies. Most builders store these in WhatsApp chats, email inboxes, or unlocked drives. Under DPDP, that is a breach waiting to happen. You need explicit consent before collection, secure storage in India, and a clear deletion trail when the customer says stop.

One platform. Every touchpoint. From first enquiry to final possession.

Pre-Sales Consent

Before your sales team makes the first call, the homebuyer receives a branded consent link. They choose exactly what they agree to - calls, WhatsApp, emails, site visits - and nothing is pre-checked.

  • Consent collected before the first sales call
  • Purpose-specific: marketing calls vs. site visits vs. loan assistance
  • Automatically synced to your CRM and broker portal

Document Vault

Homebuyers upload Aadhaar, PAN, and income proofs once. You store them encrypted in India. When they withdraw consent, you issue a certificate of deletion instantly - proof for RERA, proof for the customer.

  • SHA-256 proof hash for every document uploaded
  • Certificate of storage + certificate of deletion
  • Every fetch logged - who accessed the document and when

Broker Network Control

Channel partners and brokers receive lead data through your portal - never through WhatsApp forwards. When the homebuyer withdraws consent, every broker in the chain is notified automatically.

  • Role-based access for channel partners
  • Real-time withdrawal sync to all broker CRMs
  • No more "I told the broker to stop calling" disputes

RERA & Compliance Audit

RERA authorities and state regulators can request proof of data handling. Export the full consent trail, document access logs, and deletion certificates in one click - no scrambling through folders.

  • One-click compliance export for regulator requests
  • Retention rules aligned with RERA project timelines
  • Consent renewal when project timelines extend beyond original estimate

From site visit to booking - fully compliant.

01
Enquiry

Collect consent before the first call

A homebuyer fills an enquiry form on your website or at the site office. They receive a SecureConsent link via SMS. They choose which purposes they agree to - marketing calls, WhatsApp updates, site visit scheduling. No pre-checked boxes.

02
Document collection

KYC uploaded securely, not emailed around

After the site visit, the homebuyer uploads Aadhaar, PAN, and income proof through a branded portal. Documents are encrypted at rest in India. The broker and sales team see only what they need - never the raw files unless authorized.

03
Booking & beyond

Consent renews when timelines change

The project timeline extends by 8 months. SecureConsent sends a renewal request: "We need to keep your documents for 8 months longer than originally planned." The homebuyer approves or declines. Full audit trail maintained for RERA.

Every player in the chain. Covered.

Builder & Developer

Collect consent at every stage - enquiry, site visit, booking, agreement, possession. Export full audit trails for RERA and internal compliance. Handle withdrawals without losing customer trust.

Join early access →

Broker & Channel Partner

Access lead data through a governed portal instead of WhatsApp forwards. When the customer withdraws consent, you are notified instantly. No more compliance risk from uncontrolled data sharing.

Join early access →

Property Portal

Integrate DPDP-compliant consent collection into lead forms. Pass verifiable consent records to builder partners. Reduce liability as an intermediary under the Act.

Join early access →

Homebuyer

Upload KYC documents once. Share with the builder securely. Withdraw consent any time. See exactly who accessed your data and when. Receive certificates for every action.

Verify your consent →

Received a consent link from a builder?

If a builder or broker sent you a SecureConsent link, your Aadhaar, PAN, and contact details are being handled under India's DPDP Act - with your rights fully intact.

Right to know

See exactly what data and documents were collected, who accessed them, and why. Every fetch is logged.

Right to correct

Fix any incorrect information or replace expired documents in your vault, any time.

Right to withdraw

Change your mind any time. Withdraw consent or request deletion - we issue a certificate of deletion instantly.

Store once, share anywhere

Upload your Aadhaar, PAN, and documents to your personal vault once. Share with any builder via a single click. DigiLocker integration coming soon.

Certificates for every action

Receive a certificate when your data is stored, accessed, or permanently deleted. Proof that the builder complied.

Consent renewal

If a builder needs your data longer than originally planned, they must request renewal. You choose to extend or decline.

Verify a consent record

Enter your phone number or the consent ID from your link to see exactly what consents are recorded in your name.

Your data is looked up securely. Nothing is stored during this check.

Already using Sell.do, LeadSquared, or a custom CRM?

SecureConsent's Core API plugs into your existing real estate tech stack. Embed DPDP-compliant consent and document collection into any CRM or portal in hours, not months.

POST https://api.secureconsent.in/v1/consent
{
"principal_id": "homebuyer_45291",
"purposes": ["marketing_calls", "site_visit", "kyc_documents"],
"source": "sell_do_webhook",
"language": "hi",
"rera_project_id": "RERA-GJ-2026-0041"
}
→ 200 OK
{
"consent_id": "cns_b7e2d19f",
"proof_hash": "sha256:b7e2...d19f",
"granted_at": "2026-06-10T09:30:00Z",
"document_vault_url": "https://vault.secureconsent.in/..."
}

Every document fetch is logged. Request a certificate of storage when a record is created and a certificate of deletion when it is purged - both cryptographically signed.

Don't let DPDP become your project's delay.

Join builders across India who are making consent and KYC compliance a competitive advantage - not a regulatory risk.

Launching Q3 2026. Built for Indian real estate. No credit card required.

Pricing

Pricing will be announced closer to launch. Early access users will receive founding-customer pricing.

Get Early Access

SecureConsent is currently in private preview. Tell us about your business and we'll reach out when access is available.