DPDP Act Compliance
Last updated: July 20, 2026 — Version 1.0
Zero Headache is an AI Start-up operated by Alap Putatunda, from India. We comply with the Digital Personal Data Protection Act 2023 (DPDP Act) and the Digital Personal Data Protection Rules 2025, notified on November 13, 2025. The Rules take effect in phases: institutional provisions and the Data Protection Board of India began in November 2025, consent-manager provisions take effect in November 2026, and the substantive notice, consent, rights, and cross-border obligations take effect in May 2027. We are building to the full standard now and this page explains how we meet our obligations as a Data Fiduciary and Data Processor.
1. Our role
We act as a Data Fiduciary for the personal data of our clients and website visitors, because we determine the purpose and means of processing that data. We act as a Data Processor for the personal data of our clients' end customers, because we process it on the documented instructions of the client, who is the Data Fiduciary for that data.
2. Consent
We process personal data on the basis of consent or for a lawful purpose permitted by the DPDP Act. Where consent is the basis, it is free, specific, informed, and unambiguous, and the individual can withdraw it as easily as it was given. For end-customer data, the client is responsible for obtaining the necessary consent from their customers.
3. Your rights as a Data Principal
- Access: request a summary of the personal data we process about you and the processing activities.
- Correction and completion: ask us to correct inaccurate or misleading data, or complete incomplete data.
- Erasure: ask us to erase your personal data, except where retention is required by law.
- Grievance redressal: contact our grievance officer (below) if you have a complaint about how we handle your data.
- Nomination: nominate another individual to exercise your rights in the event of your death or incapacity.
4. Security and retention
We implement reasonable security safeguards, including encryption in transit and at rest, access controls, and audit logging. We retain data and traffic logs for at least one year, as required by the DPDP Rules. Personal data is retained only for as long as needed for the purpose of processing or as instructed by the client, and is then deleted or anonymized.
5. Breach notification
On becoming aware of a personal data breach, we notify the Data Protection Board of India and the affected individuals as required by the DPDP Act and Rules. The notification includes the nature of the breach, the data affected, and the remedial actions taken.
6. Cross-border transfers
The DPDP Act permits the transfer of personal data outside India unless the Central Government has restricted transfers to a specific country. As of this date, no restricted list has been notified by the Central Government, and the substantive cross-border provisions take effect in May 2027. Where we transfer personal data outside India, we do so under contractual safeguards no less protective than those required by the DPDP Act.
7. Grievance officer
Under the DPDP Rules, we have appointed a grievance officer to handle data-protection complaints. Contact: legal@zeroheadache.co, Zero Headache, Kolkata, India. We acknowledge complaints within the period required by the DPDP Rules and resolve them within 90 days, as required by Rule 9.













