The DPDP Act is live. Fines reach ₹250 Cr, and every day matters.Run a free check
ABOUT US

Privacy, the Indian way.

India got a privacy law that reads differently from every other one — consent-first, purpose-bound, multilingual by right, with penalties that reach ₹250 crore. Sammati was built for that statute specifically, by people who would rather build the boring, auditable thing than the demo-friendly one.

WHY WE EXIST

Most consent tools were built for a cookie banner.

The DPDP Act does not ask whether you showed a banner. It asks whether you can produce, for a named data principal, the notice they were served, in the language they were served it, at the moment they agreed — and prove that record has not been edited since.

Almost every tool on the market answers the first question well and the last one not at all. That gap is not a feature request. It is the whole obligation. So the ledger came first here, and the interface came after: a hash-chained artifact store, a versioned notice library, and a rights workflow with statutory clocks, before a single dashboard was drawn.

The result is a platform that is unglamorous in exactly the right places. When a regulator, an auditor, or a plaintiff asks what happened, the answer is a record, not a recollection.

What we hold

Four positions we don't trade away

Consent is a legal record, not a log line

Every artifact is immutable once written and chained: each ledger entry hashes its own canonical JSON together with the hash before it. Break one row and the chain says so. That is the difference between a consent you can show a regulator and a row in a database that you assert is true.

Your data stays where you decide

Sammati runs as SaaS or entirely inside your own cloud account (BYOC), from the same codebase, under the same licence. Regulated buyers should not have to choose between a product that works and a deployment their board will sign off on.

A notice a person can actually read

The DPDP Act gives the data principal the right to a notice in any of the Eighth Schedule languages. We treat that as an engineering requirement, not a translation backlog — 22 languages, versioned, with the served version pinned to the artifact.

Built for the Indian statute, not adapted to it

This is not a GDPR product with an India mode. Purpose limitation, verifiable parental consent, Consent Manager registration, the rights timelines, breach reporting — all modelled from the DPDP Act and its Rules, with our partner law firm reviewing the content that ends up in front of a data principal.

THE COMPANY

Sammati is an Arborworld product

The platform is built and operated by Arborworld India Private Limited, an Indian company based in Bangalore. Contracts, invoices and support all sit with that entity — there is no offshore holding structure between you and the people who write the code.

Legal entity
Arborworld India Private Limited
Based in
Bangalore, Karnataka, India
Product
Sammati — DPDP consent & privacy platform
Data residency
India (SaaS), or your own account (BYOC)
Governing law
India · courts at Bangalore
General enquiries
[email protected]
Where to next

See whether any of this is true.

Run the free DPDP self-assessment against your own setup, or read the platform page and hold it to the claims above.

Building a practice around DPDP instead? See the partner programme.