Ready for DPDP, GDPR — and the next one.
Most vendors added a line to their privacy policy. Learnify built the machinery: pick a regulatory profile and region, rights and notices follow — consent you can prove, rights requests you can track, retention you control, an incident process that starts with a plan, and the staff training the regulations expect, with the evidence that it happened.
Who it is for
For the person whose name goes on the compliance statement.
DPDP and GDPR both make the organisation accountable for consent, notice, rights and breach handling — and for the conduct of the people who process personal data. This is for whoever owns that sentence, in Mumbai or in Munich.
- Data Protection Officers and privacy leads — Significant Data Fiduciaries under DPDP, controllers and processors under GDPR.
- Chief Compliance and Risk Officers in BFSI, healthcare, insurance and fintech handling personal data at scale.
- HR and L&D heads who must show every employee completed DPDP awareness training — and repeats it.
- IT services and BPO firms whose enterprise clients ask for DPDP or GDPR evidence in vendor due diligence.
In the product
- Regulatory profiles
- DPDP · GDPR · global
- Consent ledger
- Append-only
- Rights request types
- 8, incl. nomination
- Data regions
- Mumbai · Frankfurt
- Retention
- You set it
What changes
Obligations that become workflows
Three things both regimes require that most organisations currently do in email and spreadsheets.
8
Rights-request types, tracked
Access, correction, erasure, grievance, portability, restriction, objection and DPDP nomination — GDPR’s rights and DPDP’s, each a request with a lifecycle and a deadline, not an inbox.
Append-only
Consent that cannot be edited
Every consent event is written once and never updated or deleted. When asked what a person agreed to and when, the answer is a record, not a recollection.
1 platform
Rights handling and staff training together
The same system that manages rights requests also runs data-protection training with annual recertification — and exports proof of both.
What you get
The data-protection toolkit, shipped.
Designed with the regulations in one hand and a compliance officer’s calendar in the other.
Regulatory profiles
Choose India DPDP, EU GDPR or global at setup. Data region, default rights, notices and retention behaviour follow the profile — and a new regulation is added as a new profile, not a new platform.
Append-only consent ledger
Consent and withdrawal events are recorded immutably with time and context. Nothing is edited after the fact; the ledger is the evidence.
Versioned privacy notices
Publish a new notice version and learners see it; earlier versions stay on record, so you can show exactly what was presented and when.
Self-service rights requests
Data principals raise access, correction, erasure, grievance, portability, restriction, objection and nomination requests themselves — you choose which are self-service — and each moves through a tracked lifecycle.
Retention you decide
Set how long learning and account data is kept. Nothing is purged until you choose a period; once you do, it happens on schedule and is logged.
Incident workflow
Personal-data incidents are recorded and worked as a process inside the platform, so notification starts from a record rather than a scramble.
Data residency by profile
India-profile tenants are provisioned in Mumbai (ap-south-1), EU-profile tenants in Frankfurt (eu-central-1), with an EU representative recorded where GDPR requires one. Self-host inside your own VPC if your policy requires it.
Data-protection training, with proof
Turn your own data-protection policy into a course with AI, assign it to every employee with annual recertification and a read-and-understood attestation, and export the evidence — the awareness obligation both regimes share.
Roll-out
From policy to posture in four steps.
A sequence that works for a first-time programme and for tightening one that already exists.
Pick the profile, publish the notice
Choose DPDP, GDPR or global; the region follows. Load your privacy notice as version one and choose which rights are self-service.
Turn the policy into training
Upload your data-protection policy; the AI drafts the modules and a source-checked quiz; you approve it.
Assign with a cycle
Every employee, annual recertification, attestation required. The platform reminds, escalates and re-locks on lapse.
Run the obligations
Rights requests arrive in a queue with deadlines. Consent accrues in the ledger. Retention runs on schedule. Evidence exports on demand.
Frequently asked
Data Protection — quick answers
Everything teams ask before starting Learnify in this category.
For learner and employee data it holds, yes — consent, notices, rights requests, retention and incidents are handled inside the platform. For personal data in your other systems, Learnify covers the training and evidence half of the obligation; it does not manage consent inside third-party applications.
Access, correction, erasure, grievance, portability, restriction, objection and nomination. You choose which of these are self-service; the rest are raised on a person’s behalf by an administrator. Every request moves through the same tracked lifecycle.
Both. The EU profile provisions your tenant in Frankfurt (eu-central-1), records an EU representative where required, and the rights toolkit already covers GDPR’s data-subject rights — access, correction, erasure, portability, restriction and objection — alongside DPDP’s grievance and nomination. Consent, notices, retention and incidents work identically under either profile.
India’s Act lets a data principal nominate another person to exercise their rights in the event of death or incapacity. It has no direct GDPR equivalent, which is why generic privacy tools often lack it. Learnify treats it as a first-class request type.
It follows your regulatory profile: India-profile tenants in AWS Mumbai (ap-south-1), EU-profile tenants in Frankfurt (eu-central-1). Enterprise customers can self-host in their own VPC or on-premise.
Yes. Assign the course with annual recertification and a read-and-understood attestation; the evidence pack lists each person’s completion, score, attestation and certificate with timestamps, and flags anyone whose validity has lapsed.
Learnify is built and operated by HabileLabs with data residency in Mumbai or Frankfurt, encrypted secrets, an audit log of administrative actions and an incident process, and we sign a data-processing agreement. We will complete your vendor due-diligence questionnaire; ask us for the current security and privacy summary.
Your next audit should take an afternoon.
Start free and watch the evidence pack export from your own workspace — or book 30 minutes with a solution architect who has sat through the inspection you are preparing for.
info@habilelabs.io
20 seats · 30 days · no card
India · North America · Europe
HabileLabs Cloud, Data & AI