DPDP Compliance
Our commitments under India's Digital Personal Data Protection Act, 2023 — explained plainly, without legalese.
Last updated: 21 June 2026
§ Overview
India's Digital Personal Data Protection Act, 2023 (DPDP Act) is a landmark privacy law that gives Indian individuals — called Data Principals — rights over their personal data, and places obligations on organisations that process that data — called Data Fiduciaries and Data Processors.
Veloqit Bloom is a B2B SaaS product for Indian salon owners. This page explains:
- How we act as a Data Fiduciary for salon owner data.
- How we act as a Data Processor for salon customer data on the salon's behalf.
- The 5 core DPDP obligations and how we meet each one.
- The practical steps for customers and salon owners to exercise their data rights.
§ Our Roles Explained
Data Fiduciary
For salon ownersWhen you (a salon owner) create an account, we collect your name, email, phone, GSTIN, and billing information. We decide the purpose of this processing — to provide the service and comply with law. So we are your Data Fiduciary, and you are our Data Principal.
Data Processor
For salon customersWhen salon owners add their customers' names and phone numbers to Bloom, the salon owner is the Data Fiduciary for those customers. We process that data only on the salon's instructions. The salon owner must obtain valid consent from their customers.
§ The 5 Core DPDP Obligations
The DPDP Act places five principal categories of obligations on Data Fiduciaries. Here is how Bloom fulfils each:
Notice & Consent
The Obligation
Before collecting personal data, provide a clear notice explaining what data is collected, why, and for how long. Processing must be based on free, specific, informed, and unambiguous consent.
How We Comply
During signup, we present this Privacy Policy and obtain explicit consent. We explain each category of data and its purpose. For WhatsApp messaging, salons must ensure customers have consented to receive messages. Consent records are stored with timestamps.
Data Quality & Minimisation
The Obligation
Only collect personal data that is adequate, relevant, and necessary for the stated purpose. Ensure data is accurate and kept up to date.
How We Comply
We collect only the fields necessary to operate the salon management functions. Salon owners can correct customer records at any time. We do not collect sensitive personal data (e.g., biometrics, health data) unless explicitly required for a feature.
Purpose Limitation & Storage Limitation
The Obligation
Use personal data only for the purpose for which it was collected. Do not retain data longer than necessary.
How We Comply
Data is processed only for the purposes stated in our Privacy Policy. Retention periods are defined per data category (see Privacy Policy §10). After account closure, non-billing data is deleted within 30 days; financial records are retained 7 years per GST law.
Security Safeguards
The Obligation
Implement appropriate technical and organisational measures to protect personal data from unauthorised access, use, disclosure, alteration, or destruction.
How We Comply
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Row-level security in Supabase prevents cross-salon data access. MFA is available for owner accounts. Error monitoring via Sentry. Access to production data is restricted to authorised Veloqit engineers.
Accountability & Grievance Redressal
The Obligation
Maintain records of processing activities, appoint a Grievance Officer, and establish a mechanism for Data Principals to raise and resolve complaints.
How We Comply
We have appointed a Grievance Officer (see below). We respond to all grievances within 30 days. We maintain processing activity records. Sub-processors are contractually bound to equivalent data protection standards.
§ Salon Customer: How to Request Data Deletion
If you are a salon customer (i.e., you visited or booked at a salon that uses Veloqit Bloom), your personal data is held by your salon. Veloqit processes it only as a Data Processor on the salon's behalf.
To exercise your data rights:
Contact your salon first
In the first instance, contact the salon directly and ask them to delete or correct your records from their Veloqit Bloom account. As the Data Fiduciary for your data, the salon is responsible for honouring your request.
Opt out of WhatsApp messages immediately
Send STOP to any WhatsApp message you receive from Bloom. Your number will be opted out within 24 hours and you will receive no further messages from that salon's Bloom account.
Escalate to Veloqit if unresolved
If the salon does not respond to your deletion or correction request within 15 days, you may email us at dpdp@veloqit.com with the salon's name and your request. We will facilitate the deletion in our role as Data Processor.
Escalate to the Data Protection Board
If your grievance remains unresolved, you may file a complaint with the Data Protection Board of India through the portal notified by the Central Government under the DPDP Act 2023.
§ Salon Owners: Exporting & Deleting Your Data
As a salon owner (our direct Data Principal), you have the following data control options within Veloqit Bloom:
Data Export
- Go to Settings > Data Export to download all your data in CSV format (customers, appointments, invoices, staff).
- Individual invoices can be downloaded as PDFs from the Billing section.
- Export is available at any time during an active subscription and for 30 days after cancellation.
Data Correction
- You can correct your business name, address, GSTIN, contact details, and payment information from Settings > Business Profile at any time.
- Staff and customer records can be edited directly from within the app.
Account & Data Deletion
Request account deletion
Go to Settings > Account > Delete Account and confirm the deletion request. You will receive an email confirmation within 24 hours.
30-day grace period
After deletion is requested, your account enters a 30-day grace period. Your data is accessible but no new charges are applied. You may export your data during this period or cancel the deletion request.
Permanent deletion
After 30 days, all personal data is permanently deleted from our systems, except financial records (invoices, payment receipts) which are retained for 7 years as required by the GST Act and Income Tax Act.
§ Consent Management
For Salon Owners
When you create a Veloqit Bloom account, you provide explicit consent to our Privacy Policy and Terms. You can withdraw consent at any time by deleting your account (see above). Withdrawal does not affect prior processing.
For Salon Customers (WhatsApp Opt-Out)
Salon customers who receive WhatsApp messages via Bloom can opt out at any time:
- Reply STOP to any Bloom WhatsApp message.
- Your number is added to the opt-out list within 24 hours.
- You will receive a confirmation message and no further automated messages from that salon's Bloom number.
- To re-subscribe, reply START or ask the salon to re-enable messaging for your number.
Consent Records
We maintain timestamped records of all consent actions (sign-up consent, WhatsApp opt-in/opt-out) for audit purposes. These records are retained for the duration of the account plus 3 years.
§ Bloom is Not Directed at Children
Veloqit Bloom is a B2B professional service designed exclusively for adult salon operators and their adult customers. We do not knowingly collect, use, or process personal data of individuals under 18 years of age.
The DPDP Act 2023 imposes additional obligations on Data Fiduciaries who knowingly process children's data (Section 9). Veloqit's service:
- Does not allow registration by individuals under 18.
- Does not display targeted advertising.
- Does not enable profiling of children.
- Does not include social features designed to attract minors.
If we discover that personal data of a minor has been processed without parental consent, we will delete it promptly and notify the relevant salon owner. Salon owners are responsible for ensuring compliance when entering customer data involving minors.
§ Cross-Border Data Transfers
The DPDP Act 2023 empowers the Central Government to restrict cross-border transfer of personal data to certain countries. We are committed to complying with all such restrictions as and when they are notified.
Currently, data processed by some of our sub-processors (Supabase, Anthropic, Vercel, Resend, Sentry) may be stored or processed in the United States. We ensure:
- Contractual safeguards with all sub-processors (DPAs/SCCs).
- Processing limited to the minimum data necessary for each function.
- Sub-processors are SOC 2 Type II certified or equivalent where available.
Razorpay processes all payment data within India in compliance with RBI Payment Aggregator guidelines.
§ Grievance Officer
We have appointed a Grievance Officer as required by Section 13 of the DPDP Act 2023 and Rule 5 of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
Name: Shubham Jiotode
Designation: Data Protection & Grievance Officer
Email: grievance@veloqit.com
DPDP Requests: dpdp@veloqit.com
Address: Veloqit Technologies Private Limited, FLAT NO 102, BUILDING C, DREAM AAWAS PANJARI FARM, Bori (Nagpur), Nagpur, Nagpur- 441108, Maharashtra, India
Response Timeline Commitment
Acknowledgement
2 business days
Data access requests
7 business days
Correction requests
7 business days
Erasure requests
7 business days
WhatsApp opt-out
24 hours
General grievances
30 days
Security incidents
72 hours notice
DPB escalations
As prescribed by law
§ Data Protection Board of India
If your complaint is not resolved by our Grievance Officer within 30 days, you have the right to escalate to the Data Protection Board of India — the statutory authority established under Section 18 of the DPDP Act 2023.
The Data Protection Board of India (DPBI) has the power to:
- Investigate complaints from Data Principals.
- Issue directions to Data Fiduciaries and Data Processors.
- Impose financial penalties for non-compliance.
We are committed to co-operating fully with the Data Protection Board of India in any investigation or proceeding.
