Settings → Privacy & Data Rights
Privacy & Data Rights
One place to see what data we hold, exercise your rights under the DPDP Act, and raise a grievance. Closes the s.11 access, s.13 grievance and “readily-available means” (Rule 14) findings.
Right to access · s.11
Summary of your personal data
A summary of the personal data we process, what we do with it, and who we’ve shared it with.
Exercise your rights
Raise a grievance or data request · s.13
Tell us what you need
Developer & backend spec
- Access summary (s.11). Generate from live data: categories + purposes from your processing register, recipients from the current sub-processor list, and the user’s consent records. Offer a machine-readable export (JSON) and a PDF.
- Identity verification. Verify the requester (logged-in session or registered-email + OTP) before fulfilling access/erasure to prevent unauthorised disclosure.
- Grievance workflow. On submit: create a ticket, write to the grievance register + audit ledger, email an acknowledgement within 24h, start a 30-day SLA timer, and route to the Grievance Officer. Surface status to the user.
- Wire the quick links to the real routes (Data & Backup, Business identity, Privacy & AI, Nominee) and the cookie banner’s
LLConsent.open(). - Policy alignment. Update Privacy Policy s.12 to point here: “Exercise your rights at Settings → Privacy & Data Rights.” This hub satisfies Rule 14’s “readily-available means.”