Consent you can prove, in the language it was given
India's Digital Personal Data Protection Act asks for a notice, a clear consent, a way to withdraw, rights of access and erasure, a grievance route, and a guardian for children. HostMyForms builds each of these into the form itself, and keeps a receipt you could hand to a regulator.
What the Act asks, and what the product does
Each row names an obligation in plain words and the built behaviour that answers it. Where the product does not yet cover a point, the row says so.
| What the Act asks | What HostMyForms does | Status |
|---|---|---|
| Give a notice that says what data is collected and why, in a language the person understands | Per-purpose consent notices, versioned and never edited once published, in English and the 22 Eighth Schedule languages. A notice is complete in a language or left out, never half translated. | Built |
| Take consent that is free, specific, informed, and unambiguous | Purposes are consented to one by one. Required purposes are marked; optional ones are off until switched on. The exact notice version and content hash shown are recorded. | Built |
| Make withdrawal as easy as giving consent | A private rights link after submission lets a respondent withdraw any purpose without an account. Withdrawing a required purpose applies the campaign's rule: anonymize or delete. | Built |
| Keep a record you can show | Every grant and withdrawal writes a receipt: notice version, content hash, language, purposes changed, time. Receipts chain per person by an HMAC over the previous receipt, so a missing or altered record shows. | Built |
| Honour access, correction, and erasure | Respondents see, download, or erase their response from their rights link. Account holders export everything as JSON and delete their account after a seven-day window. A request register with a 90-day due date tracks every request. | Built |
| Publish a grievance contact and respond in time | Every workspace publishes a grievance contact. Respondents write to it from their rights page, and the message lands in the workspace's request register. | Built |
| Get a parent's or guardian's consent for a child | A campaign that may include children asks for an age declaration. For a minor, a parent or guardian verifies an email and consents, and the guardian's consent is linked to the response. | Built |
| Re-ask when the terms change | When a required platform notice changes, every signed-in request, API tokens and MCP included, is refused until the person accepts it, signs out, or chooses to leave. | Built |
| Erase data once the purpose is served | Deletion and withdrawal are built. Automatic erasure at the end of a retention period is on the roadmap; today it is a scheduled export and delete. | Coming |
| Notify a breach | A breach register and notification workflow are not built. Keep this in your own incident process for now. | Coming |
Receipts that prove what was shown
Every grant and withdrawal writes a receipt: which notice version and content hash was displayed, in which language, which purposes changed, and when. Receipts chain per person through an HMAC over the previous receipt, so a missing or altered record shows. Published notice versions are never edited.
Who is the fiduciary, and who is the processor
Your workspace is the data fiduciary for the people who answer your forms. HostMyForms is its data processor: it stores and processes on your instruction, routes every respondent request to your inbox, and never decides one for you. The platform's own account holders, the people who run workspaces, are the platform's data principals, and the same rights pages serve them.
Twenty-three languages, one receipt
A respondent in Odisha reads the notice in Odia, a respondent in Chennai in Tamil. Both receipts name the language shown. If a translation is missing, the form says so instead of silently showing English.
What this page is not
These are engineering decisions, documented in the open. They are not legal advice. Notice texts, grievance deadlines, retention periods, and the approach to children's consent need review by your counsel, and the DPDP Rules bring obligations in over time. Semantic search, if you turn it on, sends answer text to Voyage AI in the United States under zero-day retention, and your notice should say so.
Questions people ask
Can we use our own notice text?
Yes. A workspace writes its own purposes and notice text per campaign, in any of the supported languages. Published versions are frozen; changing the text creates a new version and, for required purposes, asks for consent again.
What does a respondent see after submitting?
A private link, sent by email for identified respondents or shown on screen for anonymous ones. It opens a page with their answers and consents, where they can withdraw a purpose, download their response, erase it, or write to your grievance contact.
Are receipts kept after a deletion?
Yes. Deletion scrubs personal details but keeps consent records, receipts, and the audit log under the now-anonymous id, as proof the fiduciary must retain.
Does this make us compliant?
It gives you the mechanics: notices, consent, receipts, rights, grievances, guardians. Compliance also depends on your notice text, your retention policy, and your processes. Book a walkthrough and bring your counsel's questions.
Collect with consent from the first response
Publish your respondent notice, set a grievance contact, and every campaign inherits it.