Privacy, the Indian way.
India got a privacy law that reads differently from every other one — consent-first, purpose-bound, multilingual by right, with penalties that reach ₹250 crore. Sammati was built for that statute specifically, by people who would rather build the boring, auditable thing than the demo-friendly one.
Most consent tools were built for a cookie banner.
The DPDP Act does not ask whether you showed a banner. It asks whether you can produce, for a named data principal, the notice they were served, in the language they were served it, at the moment they agreed — and prove that record has not been edited since.
Almost every tool on the market answers the first question well and the last one not at all. That gap is not a feature request. It is the whole obligation. So the ledger came first here, and the interface came after: a hash-chained artifact store, a versioned notice library, and a rights workflow with statutory clocks, before a single dashboard was drawn.
The result is a platform that is unglamorous in exactly the right places. When a regulator, an auditor, or a plaintiff asks what happened, the answer is a record, not a recollection.
Four positions we don't trade away
Consent is a legal record, not a log line
Every artifact is immutable once written and chained: each ledger entry hashes its own canonical JSON together with the hash before it. Break one row and the chain says so. That is the difference between a consent you can show a regulator and a row in a database that you assert is true.
Your data stays where you decide
Sammati runs as SaaS or entirely inside your own cloud account (BYOC), from the same codebase, under the same licence. Regulated buyers should not have to choose between a product that works and a deployment their board will sign off on.
A notice a person can actually read
The DPDP Act gives the data principal the right to a notice in any of the Eighth Schedule languages. We treat that as an engineering requirement, not a translation backlog — 22 languages, versioned, with the served version pinned to the artifact.
Built for the Indian statute, not adapted to it
This is not a GDPR product with an India mode. Purpose limitation, verifiable parental consent, Consent Manager registration, the rights timelines, breach reporting — all modelled from the DPDP Act and its Rules, with our partner law firm reviewing the content that ends up in front of a data principal.
Sammati is an Arborworld product
The platform is built and operated by Arborworld India Private Limited, an Indian company based in Bangalore. Contracts, invoices and support all sit with that entity — there is no offshore holding structure between you and the people who write the code.
- Legal entity
- Arborworld India Private Limited
- Based in
- Bangalore, Karnataka, India
- Product
- Sammati — DPDP consent & privacy platform
- Data residency
- India (SaaS), or your own account (BYOC)
- Governing law
- India · courts at Bangalore
- General enquiries
- [email protected]
See whether any of this is true.
Run the free DPDP self-assessment against your own setup, or read the platform page and hold it to the claims above.
Building a practice around DPDP instead? See the partner programme.