DPDPA compliance
How Meta16Labs handles personal data under India’s Digital Personal Data Protection Act.
Role and scope
Meta16Labs operates as a Data Processor on behalf of client institutions, which remain the Data Fiduciary. Processing is limited to the purposes set out in the governing agreement.
Consent
Consent is captured at the point of collection with a clear, specific purpose notice, is recorded with a timestamp and version, and can be withdrawn through the same interface that captured it.
Purpose limitation
Personal data is processed only for the purpose consented to. Secondary use requires fresh consent or a lawful exemption, and is blocked at the platform level by default.
Data minimisation
Collection is scoped to the fields the workflow requires. Optional fields are marked as such and are never a precondition of service.
Security safeguards
Encryption in transit and at rest, role-based access control, segregated environments, and a complete audit trail on every read and write of personal data.
Retention and erasure
Retention periods are configured per data category and jurisdiction. Erasure requests are actioned within statutory timelines and propagated to backups on their next cycle.
Breach notification
Security incidents affecting personal data are reported to the Data Fiduciary without undue delay, with scope, affected categories and remediation steps.
Grievance redressal
Data principals may raise a grievance through the client institution or directly to us. Every grievance carries an owner, an SLA clock and a written outcome.
This page summarises our operating commitments. The governing terms are those in the executed agreement with your institution.