The DPDP Act is live. Fines reach ₹250 Cr, and every day matters.Run a free check
SAAS & TECHNOLOGY

You are a processor for them and a fiduciary for you.

Your customers' data makes you their processor. Your own signups, trials, support tickets and marketing make you a Data Fiduciary in your own right. Most technology companies handle the first because a customer asked, and discover the second during a deal.

Built for: B2B SaaS, platforms, developer tools, marketplaces and technology startups selling into India.

WHAT MAKES THIS SECTOR DIFFERENT

The pressure points, specifically

01

The DPA request arrives mid-deal

The first time most SaaS companies think seriously about DPDP is when an enterprise buyer sends a data processing agreement and a security questionnaire. Answering it in the deal cycle costs weeks; having the answer costs days.

02

Two hats, one codebase

The obligations you carry as a processor for customer data are different from the ones you carry as a fiduciary for your own leads and users. Conflating them produces a privacy notice that is wrong about both.

03

Sub-processors are your liability

Every analytics tool, error tracker, support platform and model API in your stack is a sub-processor your customer is entitled to know about. A published list is table stakes; knowing it is complete is the hard part.

04

Consent belongs in the product, not beside it

If your platform collects on behalf of customers, they will eventually need to prove those consents. Building that yourself is a quarter of engineering time you would rather spend on the product.

WHAT SAMMATI DOES

The parts that matter here

  • Consent as an API, not a screen

    A server-side consent API with typed schemas, bulk ingestion and a sub-200ms p95, so consent capture fits inside your existing signup and onboarding flows rather than interrupting them with someone else's UI.

  • Embed it in your own product

    A hosted portal you can white-label, a mobile SDK, and a consent banner. If your customers carry the obligation and your product is where it has to be met, you can serve that without building a consent platform of your own.

  • Your own sub-processor register, maintained

    A vendor register with assessments and a portal where each sub-processor answers for itself, so the list you publish is one you can defend rather than one you assembled from memory.

  • The evidence enterprise buyers ask for

    A hash-chained consent ledger, per-tenant isolation enforced in the database, and an audit trail. These are the answers to the questions on the security questionnaire, produced from the system rather than written into a document.

  • Deploy in your cloud or ours

    SaaS or entirely inside your own cloud account from the same codebase, which matters when your own customers ask where consent data for their end users is going to sit.

QUESTIONS WE GET ASKED

SaaS & technology and the DPDP Act

General information about the DPDP Act, 2023, not legal advice. For a position specific to your organisation, talk to us or read the deep dive: DPDP Compliance for SaaS Companies and Startups in India.

Where to start

Find out where you actually stand.

The free self-assessment takes a few minutes and gives you a written position on your own setup, not a generic checklist.