Guest data, on-device by design
Where Cformly stands on the DPDP Act 2023 — and the features in the app today that back it up.
The posture, in four points
- Passports and visas are read by open-source OCR running entirely on the phone. No third-party AI, no cloud OCR — and no document image is ever uploaded to any server, including ours.
- Guest records, photos, and extracted fields live only in an encrypted on-device database (SQLCipher; the key stays in the phone's keystore, hardware-backed where available).
- Filing happens in the hotel's own browser: the extension fills the portal form in the host's logged-in session, and a person solves the CAPTCHA, attaches the photo, and submits. Cformly never submits anything.
- Your rights are built in: export or delete everything from Settings at any time — access, correction, and erasure as the DPDP Act 2023 lays out.
Where the DPDP Act stands
The DPDP Act 2023 has commenced only in part: most substantive duties for data fiduciaries, and most operational rules, are scheduled to commence on 13 May 2027. Cformly is built to those requirements today — on-device processing, purpose-limited data, consent artifacts. These are stated practices, not certifications.
Proof you can check today
- Consent receipt export — Settings → Data & Privacy exports exactly what was consented to and when: the data-practice scope lines, a timestamp, and the app version. Ready to share with a guest or an auditor.
- Readiness templates — a hotel retention-policy template and a DPIA template, written around how Cformly actually processes data, ship alongside the product.
- Guest privacy badge — a printable reception card that tells guests in plain words what happens to their passport details.