Ronin Works helps Indian businesses get DPDP-ready and keep their data clean enough to stay that way — as a consulting programme, and increasingly as software you can run yourself. Here's everything we do.
The full compliance programme, delivered before the 13 May 2027 deadline. We turn the Act's obligations into working processes and leave you audit-ready.
Map every system, sheet, inbox and vendor holding personal data — the inventory everything else depends on.
Plain-language privacy notices and consent flows that meet the free/specific/informed/withdrawable standard.
A published grievance officer and a tracked process for access, correction and erasure within the 90-day cap.
Detect, contain, and notify affected users and the Data Protection Board within 72 hours.
Data-processing agreements with every vendor, plus retention schedules honouring the 1-year log-retention rule.
The documentation trail that proves compliance if the Board — or an enterprise customer — ever asks.
We're a data-quality studio first — which is why we're unusually good at the hardest part of DPDP: finding and cleaning the data itself. Clean data is compliant data.
Clean, de-dupe and refresh Salesforce, HubSpot, Zoho and the rest so every team trusts every record.
Match, merge and purge duplicates across systems into one clean master per customer.
Phones, addresses, names and dates reformatted to one consistent standard, ready to sort and analyse.
Close the gaps — missing contacts and firmographics appended from fresh, verified sources.
Every record cross-checked; dead emails and invalid numbers flagged, corrected or retired.
Scrub, map and de-dupe before data lands in a new platform — never carry old mess forward.
The compliance work we do by hand, increasingly available as tools — starting with consent.
DPDP-compliant consent collection for MSMEs. One script tag adds a consent banner to your website; every decision is logged, timestamped and provable, with a consent-check API for your other systems.
Personal data removal for individuals. Saaph finds where your personal data is exposed across the open web and gets it removed under the DPDP Act — then keeps watch.
We're building the consent suite in the order MSMEs actually need it. Register interest on the Ronin Consent page to get each as it ships.
Collection + append-only audit log + consent-check API. Cookie and analytics consent from the same widget.
Verifiable parental consent for under-18 users under Rule 10, via DigiLocker's age-token route — as an API.
Access/correction/erasure requests tracked against the 90-day clock, with templated responses and an audit trail.
A wizard that produces a compliant, versioned notice in plain language and Indian languages.
Track purpose-end and retention periods; automate deletion tasks with the 1-year log floor built in.
A monthly report — consent stats, pending requests, retention actions — software plus a human review.
Take the free 2-minute DPDP Readiness Scorecard, or tell us about your business and we'll come back with where your gaps are.
Take the free check →