# Promiz > Promiz is a consent and privacy management platform for India's Digital Personal Data Protection (DPDP) Act 2023 and DPDP Rules 2025, built by Pentafox Technologies (SOC 2 Type II, ISO 27001:2022). It lets a Data Fiduciary collect consent in 23 languages, keep tamper-evident consent records, and close every withdrawal, erasure, rights request and breach notice on time. Promiz is software run by the Data Fiduciary. It is not a registered Consent Manager and it does not give legal advice. ## Pages - [Home](https://promiz.in/): What Promiz does, the DPDP timeline, readiness check and buyer FAQ. - [Solutions](https://promiz.in/solutions/): The six modules - notices, cookie scanner, consent records, privacy portal, obligations and retention, breach management. - [About us](https://promiz.in/about/): Who builds Promiz, the Pentafox Technologies background, security posture and how to reach the team. - [Industries](https://promiz.in/industries/): How DPDP duties land in BFSI, healthcare, e-commerce, education, SaaS and other sectors, and what Promiz covers in each. - [DPDP guide](https://promiz.in/dpdp-guide/): Plain-language guide to the DPDP Act 2023 and DPDP Rules 2025 - key dates, duties, penalties and what to do first. - [Resources](https://promiz.in/resources/): Anonymised, illustrative deployment scenarios (not named customers), plus research notes and blog posts on DPDP duties, penalties and key dates. - [Scenarios](https://promiz.in/resources/scenarios/): Three illustrative DPDP deployments in lending, insurance and ed-tech - the problem, the modules set up, and what changed. - [Research](https://promiz.in/resources/research/): Notes mapping DPDP duties and penalty bands to the controls that satisfy them. - [Blog](https://promiz.in/resources/blog/): Practical posts on what to do, in what order, before the DPDP Rules apply in full on 13 May 2027. - [Book a demo](https://promiz.in/demo/): 30-minute live demo on your own purposes and data. ## Modules - Consent notices: stand-alone, itemised, plain-language notices in English plus the 22 Eighth Schedule languages; per-purpose opt-in, no pre-ticked boxes. - Cookie scanner: finds tags and cookies on your sites, blocks each until its purpose is allowed, records the choice. - Consent records: chained, tamper-evident record per purpose - notice text, version, timestamp, method - exportable as evidence. - Privacy portal and rights requests: access, correction, erasure, nomination and grievance requests with deadlines tracked. - Obligations and retention: withdrawal and erasure queues pushed to downstream systems by signed webhook, legal holds, 48-hour notice before erasure. - Breach management: intake, assessment, and Data Protection Board and Data Principal notification within 72 hours. ## Key DPDP dates - 13 November 2025: DPDP Rules, 2025 notified; Data Protection Board set up. - 13 November 2026: Consent Manager provisions start (an earlier date for Significant Data Fiduciaries has been proposed). - 13 May 2027: notice, consent, rights, security, breach and erasure duties apply in full. - Penalties: up to ₹250 crore per instance for the most serious failures. Confirm specifics with your legal team. ## Contact - Demo and sales: https://promiz.in/demo/ - Company: Pentafox Technologies, Coimbatore and Chennai, India - https://pentafox.in/ - LinkedIn: https://www.linkedin.com/company/pentafox-tech/