Compliance

Your data stays in India

Built for Indian enterprises and global businesses that need genuine data sovereignty, regional isolation and regulatory alignment — all from our own Noida region.

Sovereign India data residency

All customer data is stored and processed exclusively in our own Noida region. We own the metal — there is no cross-border replication and no foreign jurisdiction. Your data physically stays in India.

DPDP Act aligned

Our architecture supports the requirements of India's Digital Personal Data Protection Act (DPDP, 2023): data-fiduciary obligations, purpose limitation and data residency are built in, not bolted on.

GDPR ready

For customers handling EU personal data, our isolated VPC architecture and strict residency controls support GDPR obligations, with no cross-border transfer by default.

SOC 2 Type II — in progress

We are actively working toward SOC 2 Type II certification under AICPA standards, targeted for 2026. Access management, change control and audit logging are designed to meet those requirements.

HIPAA-aligned architecture

Dedicated enterprise clusters can be configured to support HIPAA-aligned workloads. A Business Associate Agreement (BAA) is available on request. DataDack does not currently hold HIPAA certification as a covered entity.

Compliance, answered

Is DataDack Cloud compliant with India's DPDP Act?
DataDack Cloud is architected to support India's Digital Personal Data Protection Act (DPDP, 2023). All data is stored and processed within India in our sovereign Noida region, with purpose limitation and data-residency obligations built in. Application-level obligations such as consent and retention remain yours as the data fiduciary.
Does DataDack store data outside of India?
No. All compute and storage run on our own bare-metal infrastructure in the Noida (India) region. There is no cross-border replication — your data physically stays within Indian borders.
Is DataDack Cloud SOC 2 certified?
DataDack Cloud is actively working toward SOC 2 Type II certification under AICPA standards, targeted for 2026. Enterprise customers can request current security posture documentation by contacting contact@datadack.cloud.

Need documentation for procurement or a vendor security review? Email contact@datadack.cloud. This page is general information about our compliance posture and is not legal advice.