Legal Document

DPDP Compliance

Our commitments under India's Digital Personal Data Protection Act, 2023 — explained plainly, without legalese.

Last updated: 21 June 2026

§ Overview

India's Digital Personal Data Protection Act, 2023 (DPDP Act) is a landmark privacy law that gives Indian individuals — called Data Principals — rights over their personal data, and places obligations on organisations that process that data — called Data Fiduciaries and Data Processors.

Veloqit Bloom is a B2B SaaS product for Indian salon owners. This page explains:

  • How we act as a Data Fiduciary for salon owner data.
  • How we act as a Data Processor for salon customer data on the salon's behalf.
  • The 5 core DPDP obligations and how we meet each one.
  • The practical steps for customers and salon owners to exercise their data rights.
This page is a plain-language summary. For the full legal details, please read our Privacy Policy.

§ Our Roles Explained

Data Fiduciary

For salon owners

When you (a salon owner) create an account, we collect your name, email, phone, GSTIN, and billing information. We decide the purpose of this processing — to provide the service and comply with law. So we are your Data Fiduciary, and you are our Data Principal.

Data Processor

For salon customers

When salon owners add their customers' names and phone numbers to Bloom, the salon owner is the Data Fiduciary for those customers. We process that data only on the salon's instructions. The salon owner must obtain valid consent from their customers.

§ The 5 Core DPDP Obligations

The DPDP Act places five principal categories of obligations on Data Fiduciaries. Here is how Bloom fulfils each:

1

Notice & Consent

The Obligation

Before collecting personal data, provide a clear notice explaining what data is collected, why, and for how long. Processing must be based on free, specific, informed, and unambiguous consent.

How We Comply

During signup, we present this Privacy Policy and obtain explicit consent. We explain each category of data and its purpose. For WhatsApp messaging, salons must ensure customers have consented to receive messages. Consent records are stored with timestamps.

2

Data Quality & Minimisation

The Obligation

Only collect personal data that is adequate, relevant, and necessary for the stated purpose. Ensure data is accurate and kept up to date.

How We Comply

We collect only the fields necessary to operate the salon management functions. Salon owners can correct customer records at any time. We do not collect sensitive personal data (e.g., biometrics, health data) unless explicitly required for a feature.

3

Purpose Limitation & Storage Limitation

The Obligation

Use personal data only for the purpose for which it was collected. Do not retain data longer than necessary.

How We Comply

Data is processed only for the purposes stated in our Privacy Policy. Retention periods are defined per data category (see Privacy Policy §10). After account closure, non-billing data is deleted within 30 days; financial records are retained 7 years per GST law.

4

Security Safeguards

The Obligation

Implement appropriate technical and organisational measures to protect personal data from unauthorised access, use, disclosure, alteration, or destruction.

How We Comply

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Row-level security in Supabase prevents cross-salon data access. MFA is available for owner accounts. Error monitoring via Sentry. Access to production data is restricted to authorised Veloqit engineers.

5

Accountability & Grievance Redressal

The Obligation

Maintain records of processing activities, appoint a Grievance Officer, and establish a mechanism for Data Principals to raise and resolve complaints.

How We Comply

We have appointed a Grievance Officer (see below). We respond to all grievances within 30 days. We maintain processing activity records. Sub-processors are contractually bound to equivalent data protection standards.

§ Salon Customer: How to Request Data Deletion

If you are a salon customer (i.e., you visited or booked at a salon that uses Veloqit Bloom), your personal data is held by your salon. Veloqit processes it only as a Data Processor on the salon's behalf.

To exercise your data rights:

1

Contact your salon first

In the first instance, contact the salon directly and ask them to delete or correct your records from their Veloqit Bloom account. As the Data Fiduciary for your data, the salon is responsible for honouring your request.

2

Opt out of WhatsApp messages immediately

Send STOP to any WhatsApp message you receive from Bloom. Your number will be opted out within 24 hours and you will receive no further messages from that salon's Bloom account.

3

Escalate to Veloqit if unresolved

If the salon does not respond to your deletion or correction request within 15 days, you may email us at dpdp@veloqit.com with the salon's name and your request. We will facilitate the deletion in our role as Data Processor.

4

Escalate to the Data Protection Board

If your grievance remains unresolved, you may file a complaint with the Data Protection Board of India through the portal notified by the Central Government under the DPDP Act 2023.

Response commitment: We will acknowledge all customer data requests within 2 business days and complete them within 7 business days.

§ Salon Owners: Exporting & Deleting Your Data

As a salon owner (our direct Data Principal), you have the following data control options within Veloqit Bloom:

Data Export

  • Go to Settings > Data Export to download all your data in CSV format (customers, appointments, invoices, staff).
  • Individual invoices can be downloaded as PDFs from the Billing section.
  • Export is available at any time during an active subscription and for 30 days after cancellation.

Data Correction

  • You can correct your business name, address, GSTIN, contact details, and payment information from Settings > Business Profile at any time.
  • Staff and customer records can be edited directly from within the app.

Account & Data Deletion

1

Request account deletion

Go to Settings > Account > Delete Account and confirm the deletion request. You will receive an email confirmation within 24 hours.

2

30-day grace period

After deletion is requested, your account enters a 30-day grace period. Your data is accessible but no new charges are applied. You may export your data during this period or cancel the deletion request.

3

Permanent deletion

After 30 days, all personal data is permanently deleted from our systems, except financial records (invoices, payment receipts) which are retained for 7 years as required by the GST Act and Income Tax Act.

Once the 30-day grace period expires and deletion is complete, data cannot be recovered. Please export anything you need before the deadline.

§ Bloom is Not Directed at Children

Veloqit Bloom is a B2B professional service designed exclusively for adult salon operators and their adult customers. We do not knowingly collect, use, or process personal data of individuals under 18 years of age.

The DPDP Act 2023 imposes additional obligations on Data Fiduciaries who knowingly process children's data (Section 9). Veloqit's service:

  • Does not allow registration by individuals under 18.
  • Does not display targeted advertising.
  • Does not enable profiling of children.
  • Does not include social features designed to attract minors.

If we discover that personal data of a minor has been processed without parental consent, we will delete it promptly and notify the relevant salon owner. Salon owners are responsible for ensuring compliance when entering customer data involving minors.

§ Cross-Border Data Transfers

The DPDP Act 2023 empowers the Central Government to restrict cross-border transfer of personal data to certain countries. We are committed to complying with all such restrictions as and when they are notified.

Currently, data processed by some of our sub-processors (Supabase, Anthropic, Vercel, Resend, Sentry) may be stored or processed in the United States. We ensure:

  • Contractual safeguards with all sub-processors (DPAs/SCCs).
  • Processing limited to the minimum data necessary for each function.
  • Sub-processors are SOC 2 Type II certified or equivalent where available.

Razorpay processes all payment data within India in compliance with RBI Payment Aggregator guidelines.

§ Grievance Officer

We have appointed a Grievance Officer as required by Section 13 of the DPDP Act 2023 and Rule 5 of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:

Name: Shubham Jiotode

Designation: Data Protection & Grievance Officer

Email: grievance@veloqit.com

DPDP Requests: dpdp@veloqit.com

Address: Veloqit Technologies Private Limited, FLAT NO 102, BUILDING C, DREAM AAWAS PANJARI FARM, Bori (Nagpur), Nagpur, Nagpur- 441108, Maharashtra, India

Response Timeline Commitment

Acknowledgement

2 business days

Data access requests

7 business days

Correction requests

7 business days

Erasure requests

7 business days

WhatsApp opt-out

24 hours

General grievances

30 days

Security incidents

72 hours notice

DPB escalations

As prescribed by law

§ Data Protection Board of India

If your complaint is not resolved by our Grievance Officer within 30 days, you have the right to escalate to the Data Protection Board of India — the statutory authority established under Section 18 of the DPDP Act 2023.

The Data Protection Board of India (DPBI) has the power to:

  • Investigate complaints from Data Principals.
  • Issue directions to Data Fiduciaries and Data Processors.
  • Impose financial penalties for non-compliance.
The Board's complaint portal and contact details will be published by the Ministry of Electronics and Information Technology (MeitY) upon the Board's constitution. We will update this page with the portal link once available.

We are committed to co-operating fully with the Data Protection Board of India in any investigation or proceeding.