Why Binary AIQ

Built for the obligation you were actually given.

Most privacy tooling is either a spreadsheet template, a GRC bolt-on or an EU-first platform retrofitted to India. Binary AIQ is authored to the DPDP Act, operated in-country and produced by practitioners.

Positioning

What Binary AIQ is — and what it is not.

Binary AIQ is
  • An operating system for DPDP obligations — record, notice, consent, rights, retention, incident and evidence in one attested surface.
  • A record of processing that composes from your inventory and updates when the inventory changes.
  • A publishable, versioned Privacy Notice — with a signed hash the regulator can reconcile against what the data principal actually saw.
  • A consent ledger with granular purposes, lawful basis and withdrawal — every event timestamped and attributable.
  • A grievance workflow that meets the Section 13 timeline, with the officer named and the closure receipt exportable.
Binary AIQ is not
  • A cookie-consent banner sold as a privacy programme. Consent is one artifact of many; the record and the rights response matter more.
  • A generic GRC platform with a DPDP module clipped in. Every workflow here is authored to the Act and reviewed by counsel.
  • A US or EU tool with the region label changed. Data residency is Mumbai. Templates cite Indian sections. The grievance officer field is not optional.
  • A generator. Nothing is auto-published. Every artifact is a draft until an accountable owner attests it.
Substantive differences

What actually changes when you run on Binary AIQ.

One record, many audiences.

The processing activity, the notice section, the consent purpose, the retention schedule and the DPA clause all derive from the same underlying record. Change the lawful basis in one place and every downstream artifact updates for review — not silently, but with a diff and an owner sign-off.

Evidence is produced, not gathered.

A notice publish, a consent capture, a DSR verification, a retention deletion, an incident notification — each writes an attested record with actor, timestamp, IP and lineage. When the DPB asks, you produce a query, not a folder search.

Scope-limited access, by default.

A department-scoped member sees their department and its parent business unit — not the whole organisation. Impersonation writes a session record. Every read is attributable. This is how a listed group actually operates.

In-country residency, deployment choice.

Primary data residency is Mumbai. Where the customer needs it, Binary AIQ runs single-tenant or inside the customer VPC on AWS, Azure or GCP. Keys and network boundary stay with the customer.

Comparison

Where Binary AIQ sits relative to the alternatives.

Spreadsheets & shared drives
Cheapest to start, impossible to defend at scale. No lineage, no attestation, no scope limits.
Cookie-consent tools
Solve one artifact (consent) but leave record, rights, retention, incident and evidence unaddressed.
Generic GRC platforms
Broad, shallow. DPDP module is a checklist wrapped around generic workflows — the actual privacy work still happens outside.
EU-first privacy platforms
Well-built, but authored to the GDPR. Section numbers, timelines and role definitions do not map cleanly to the DPDP Act.
Binary AIQ
Authored to the DPDP Act. Records, notices, consent, rights, retention, incident and evidence in one attested surface. Operated in-country by practitioners.