The DPDP Act, 2023 — intent, and one gap left visible.
Caretech AI makes no claim of compliance with the DPDP Act. This page states what Caretech AI intends to support under the Act, and then names the one statutory item that is missing rather than writing around it.
Where the Act may apply
For users, clients, employees, patients, caregivers, or partners located in India, Caretech AI may be subject to the Digital Personal Data Protection Act, 2023, depending on the nature of processing and service delivery.
Whether Caretech AI would be a data fiduciary or a data processor in a given arrangement is not settled here. That determination follows from who decides the purpose and means of processing, and it belongs in an agreement.
Practices Caretech AI intends to support
Caretech AI intends to support responsible data practices involving:
- Purpose-based personal data processing
- Consent or other lawful grounds where applicable
- Reasonable security safeguards
- Data principal rights support where applicable
- Data retention management
- Data processor and fiduciary role clarity
- Cross-border data transfer awareness where applicable
Each of these becomes a commitment when it is written into an agreement, and not before. Grievance response is not on the list, for the reason set out below.
The designation, and where enquiries go meanwhile
The DPDP Act requires a data fiduciary to publish the contact details of a designated Grievance Officer. Caretech AI has not yet made that designation.
Until it is made, this page makes no claim about grievance handling.
Data protection enquiries in the meantime go to compliance@caretechai.com. That address is not a grievance route under the Act and is not offered as one.
What customers and partners are responsible for
Customers and partners are responsible for ensuring that notices, consents, data collection practices, and end-user communications are appropriate for their specific use case and jurisdiction.
Nothing on this site states where data physically resides. No India data residency or in-country hosting is claimed, and no diagram implies a residency boundary that does not exist.
Ask us who the officer will be.
If your organization processes personal data in India, the designation above is a reasonable thing to require before work begins.