DPDP Compliance

Our compliance posture, plainly.

Digital Personal Data Protection Act, 2023 Last reviewed: May 12, 2026

India's Digital Personal Data Protection Act ("DPDP Act") sets out how companies must handle the personal data of people in India, especially the data of children. As a service used by parents and children, we treat DPDP not as a checklist but as the floor.

This page is a one-page summary of where we stand. It is a companion to our full Privacy Policy, which remains the authoritative document.

§ 4 · Lawful processing

Consent-based, narrow purpose.

We collect only what's needed to analyse a child's schoolwork for their parent. No data is processed for an unrelated purpose without fresh consent.

✓ In place
§ 6 · Notice & consent

Plain-language consent at sign-up.

The Graddly app shows a short, readable consent screen before any account creation, explaining what we collect and why. Consent can be withdrawn from Profile at any time.

✓ In place
§ 9 · Children's data

Parental consent, no profiling.

Accounts are held by parents/guardians ≥ 18. By adding a child profile, the parent provides verifiable consent on the child's behalf. We do not profile children for advertising, and we show no ads.

✓ In place
§ 8(7) · Data retention

Photos auto-delete after 90 days.

Original photos are deleted within 90 days of upload. Only the text analysis is retained, so you can look back at past weeks. You can delete everything via Profile → Delete account.

✓ In place
§ 8(4) · Security safeguards

Encryption at rest & in transit.

Photos live in Cloudflare R2 with short-lived signed URLs (15-min expiry). Data in transit is TLS 1.3. Database access is restricted by least-privilege roles.

✓ In place
§ 11 · Rights of data principals

Access, correction, erasure.

Email hello@graddly.com to access, correct, or erase data; we respond within 7 working days. Most actions are also self-serve in the app.

✓ In place
§ 8(6) · Breach notification

Notification within 72 hours.

In the unlikely event of a personal data breach, we will notify affected users and the Data Protection Board of India within 72 hours of discovery.

✓ Policy in place
§ 13 · Data Protection Officer

Reachable, named contact.

Our Data Protection Officer is reachable at hello@graddly.com. For the registered postal address, see our Contact page.

✓ In place

Questions or complaints?

Write to hello@graddly.com. If you're not satisfied with our response, you may also contact the Data Protection Board of India.