Compliance

DPDP Act 2023 Compliance

Flinterra is built from the ground up to comply with India's Digital Personal Data Protection Act, 2023. This page outlines our compliance framework and data protection practices.

Flinterra's privacy-by-design architecture ensures that student data, institutional data, and personal information are handled in full compliance with the DPDP Act 2023. Below is how we address each key requirement.

Data Localisation

All student and institutional data is stored exclusively on Indian cloud servers — AWS Mumbai region and Microsoft Azure India regions. No data is transferred outside India without explicit consent and DPDP-compliant cross-border transfer provisions.

Compliant

Explicit Consent Framework

Flinterra operates on an explicit, informed, and freely-given consent model. Parents provide consent for student data. Institutions consent for institutional data. Consent is granular (per data category), revocable at any time, and documented with timestamped records.

Compliant

Data Minimisation

We collect only the minimum data necessary to deliver our services. Raw student activity data is never accessed by Flinterra — our zero-knowledge architecture generates insights without ever seeing individual actions.

Compliant

Purpose Limitation

Data is used only for the specific purpose for which consent was obtained — providing AI governance, policy implementation, reporting, and platform services. Data is never repurposed without fresh consent.

Compliant

Data Security

Encryption at rest (AES-256) and in transit (TLS 1.3). Access controls, multi-factor authentication, regular security audits, and employee training. ISO 27001 certification roadmap in progress.

Compliant

Data Retention & Erasure

Data retained only as long as necessary for the purpose collected. Institutional data retained for service duration plus 12 months. Upon request or termination, data is securely deleted within 30 days. Anonymised aggregate data may be retained for analytics.

Compliant

Data Principal Rights

Flinterra fully supports data principal rights under DPDP Act: right to access, right to correction, right to erasure, right to withdraw consent, and right to grievance redressal. Requests are acknowledged within 24 hours and resolved within 30 days.

Compliant

Grievance Redressal

A designated Grievance Officer handles all data-related complaints. Email: grievance@flinterra.in. Complaints are acknowledged within 24 hours and resolved within the statutory 30-day period.

Compliant

Data Sharing & Third-Party Processing

Flinterra does not sell personal data. Third-party data processing (cloud infrastructure, analytics) is governed by strict data processing agreements that mandate DPDP Act compliance. Each processor is vetted and audited.

Compliant

Privacy by Design

Flinterra's platform architecture embeds privacy at every layer — zero-knowledge reporting, federated data processing, consent-first workflows, and data localisation. Privacy is not a feature; it is the foundation.

Compliant

Additional Information

For a complete understanding of how Flinterra handles your data, please also review our Privacy Policy and Terms of Service. For specific compliance questions, contact us at dpo@flinterra.in.

Flinterra Private Limited · Surat, Gujarat, India · DPDP Act 2023 Compliant

← Back to Home  ·  Privacy Policy  ·  Terms of Service  ·  Contact