Data Processing Agreement
A plain-language summary of how we process personal data on your behalf. The signed agreement is available on request.
Last updated 5 October 2026
01Who does what
When you use ConsentArc, you are the Data Fiduciary for the personal data of your users, and DPDPA Shield Technologies Private Limited is your Data Processor. We process that data only to provide the service and only on your documented instructions.
02What we process
- Cookie consent and DPDPA consent records, including the notice version and purposes.
- Withdrawals and the tasks created from them.
- Data principal rights requests, including the contact details used for OTP verification.
- Breach incident records you log, such as affected systems and data categories.
03Where it's stored
All consent, rights and breach records are stored in India, in AWS Mumbai (ap-south-1).
04How it's protected
- Consent, withdrawal and rights records are stored with a SHA-256 hash in write-once storage, so they can't be edited or backdated.
- Rights requests are identity-checked with a one-time password before any data is shared.
- Tabletop drills run separately and never touch live records.
05Sub-processors
We use Amazon Web Services (Mumbai region) to host the service. The full list of sub-processors is available on request, and we will tell you before we add a new one.
06If something goes wrong
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and give you the information you need to meet your own obligations to CERT-In and the Data Protection Board.
07When the subscription ends
All consent and compliance data belongs to you. You can export it as CSV or JSON for 30 days after termination. After that window we delete it, unless the law requires us to keep it.
08Get the signed DPA
Email hello@consentarc.com with your company name and we will send the agreement for signature. For how we handle data on our own website, see our Privacy Policy.