India's Digital Personal Data Protection Act, 2023 ("DPDP Act") shapes both how we build Niyam and how we run FlickerBytes. This page sets out both. It is a statement of how we operate, not legal advice.
How we handle your data
For the personal data you give us, FlickerBytes is a Data Fiduciary. We meet the Act's core obligations as follows:
- Notice and lawful basis. We tell you what we collect and why, and we process only on your consent under section 6 or, where you have voluntarily given us your data for a specified purpose such as answering your enquiry, under section 7(a). We do not rely on a general "legitimate interests" basis, because the DPDP Act does not provide one.
- Consent you can withdraw. Consent on our website is collected through Niyam's own consent widget, and can be reviewed, changed or withdrawn at any time from the same widget - as easily as it was given.
- Data Principal rights. You can obtain a summary of our processing, have your data corrected or erased, withdraw consent, nominate someone to act for you, and raise a grievance. You may also complain directly to the Data Protection Board of India.
- Security. We apply reasonable safeguards, set out on our Security & Trust page, where we are also explicit about which certifications we hold and which we are still working toward.
- Breach response. We maintain an incident-response process and will notify the Data Protection Board and affected Data Principals in the form and within the timeframes the Act and its Rules require.
- Retention and erasure. We erase personal data when consent is withdrawn or the purpose is served, unless the law requires us to keep it.
The detail, including our processors, transfers and retention periods, is in our Privacy Policy.
How we help you comply
Niyam operationalises the DPDP Act for your organisation: discovery of personal data, consent capture and preference management, Data Principal rights requests, breach records, vendor governance and audit-ready evidence, with DPO support available as a service.
- Not sure whether the DPDP Act applies to you? Take the check.
- Want your posture measured? Start a free gap analysis.
- Prefer a working list? Use the readiness checklist.
What we do not claim
We think it matters that a compliance vendor is precise about its own status:
- We are not a registered Consent Manager under section 6(7) of the DPDP Act. Niyam provides consent management as a product capability; that is a different thing from the registered statutory role.
- We do not hold ISO 27001 or SOC 2 certification today. Both are in progress, and our Security & Trust page says exactly where we are.
- Using Niyam does not by itself make an organisation compliant. It gives you the system of record, the workflows and the evidence; the obligations remain yours.
Grievances
For any data-protection question, rights request or grievance, contact Richa Goyal at Compliance1@flickerbytes.com or +91 96723 70157.