Flinterra is built from the ground up to comply with India's Digital Personal Data Protection Act, 2023. This page outlines our compliance framework and data protection practices.
Flinterra's privacy-by-design architecture ensures that student data, institutional data, and personal information are handled in full compliance with the DPDP Act 2023. Below is how we address each key requirement.
All student and institutional data is stored exclusively on Indian cloud servers — AWS Mumbai region and Microsoft Azure India regions. No data is transferred outside India without explicit consent and DPDP-compliant cross-border transfer provisions.
CompliantFlinterra operates on an explicit, informed, and freely-given consent model. Parents provide consent for student data. Institutions consent for institutional data. Consent is granular (per data category), revocable at any time, and documented with timestamped records.
CompliantWe collect only the minimum data necessary to deliver our services. Raw student activity data is never accessed by Flinterra — our zero-knowledge architecture generates insights without ever seeing individual actions.
CompliantData is used only for the specific purpose for which consent was obtained — providing AI governance, policy implementation, reporting, and platform services. Data is never repurposed without fresh consent.
CompliantEncryption at rest (AES-256) and in transit (TLS 1.3). Access controls, multi-factor authentication, regular security audits, and employee training. ISO 27001 certification roadmap in progress.
CompliantData retained only as long as necessary for the purpose collected. Institutional data retained for service duration plus 12 months. Upon request or termination, data is securely deleted within 30 days. Anonymised aggregate data may be retained for analytics.
CompliantFlinterra fully supports data principal rights under DPDP Act: right to access, right to correction, right to erasure, right to withdraw consent, and right to grievance redressal. Requests are acknowledged within 24 hours and resolved within 30 days.
CompliantA designated Grievance Officer handles all data-related complaints. Email: grievance@flinterra.in. Complaints are acknowledged within 24 hours and resolved within the statutory 30-day period.
CompliantFlinterra does not sell personal data. Third-party data processing (cloud infrastructure, analytics) is governed by strict data processing agreements that mandate DPDP Act compliance. Each processor is vetted and audited.
CompliantFlinterra's platform architecture embeds privacy at every layer — zero-knowledge reporting, federated data processing, consent-first workflows, and data localisation. Privacy is not a feature; it is the foundation.
CompliantFor a complete understanding of how Flinterra handles your data, please also review our Privacy Policy and Terms of Service. For specific compliance questions, contact us at dpo@flinterra.in.
Flinterra Private Limited · Surat, Gujarat, India · DPDP Act 2023 Compliant