India segmentation and packaging
The beachhead is mid-market fintech/NBFC/payment and SaaS/IT services organisations that need DPDP readiness, can sponsor integrations faster than a large bank, and benefit from self-hosting or India-region options. A regulated bank design partner anchors assurance and sector depth but should not be the only route to product learning.
Segment priority
Section titled “Segment priority”| Segment | Urgency/risk | Complexity/sales | Entry offer |
|---|---|---|---|
| fintech/NBFC/payments mid-market | high data/regulator/vendor exposure | medium-high; 3–9 months | 90-day finance readiness + two integrations |
| SaaS/IT services exporters | processor/Fiduciary dual role, customer pressure | medium; 2–6 months | processor plane + evidence/exit |
| large banks/insurers | highest scrutiny/scale | very high; 9–18 months | design partnership/dedicated deployment |
| healthcare/pharma networks | sensitive/complex chains | high; 6–12 months | one workflow/record-class pilot |
| manufacturing groups | workforce/IoT/global support | medium-high | employee + connected-product inventory |
| SMEs | broad need/low staff and ACV | low direct, partner-led | MSP managed privacy operations |
Buyer map
Section titled “Buyer map”Economic buyer: CIO/CISO/chief risk or compliance. Champion: DPO/privacy/legal operations. Technical buyer: architecture/platform/security. Users: privacy ops, data/system owners, incident, vendor risk, support. Blockers: counsel wary of claims, procurement worried about open source, engineering resisting connectors, business concerned about conversion friction.
Packages
Section titled “Packages”Community: public core, English docs, synthetic demo, API, basic Docker/Kubernetes and community support.
Enterprise self-hosted: SSO/SCIM, advanced policy/approval, KMS/HSM/WORM, signed enterprise connectors, sector packs, LTS and support.
Managed India cloud: enterprise capabilities plus operation, backup, upgrades and SLO.
Implementation: discovery, migration, integrations, workflow/tabletop and training.
Partner SME: multi-customer operations boundary, templates, assisted support and monthly evidence; customer data remains isolated.
Pricing
Section titled “Pricing”Recommended base: annual platform by deployment/support tier + included legal entities and connector capacity; add transparent entity bands, premium connector/sector packs and managed event-volume capacity at high scale.
Avoid per rights request, grievance, withdrawal, incident, deletion or affected Principal. Those metrics punish legal/safe behaviour. Employee/Data Principal/MAU pricing can be unpredictable and discourage inventory; use it only as a high-scale capacity band with generous inclusion. Publish what counts as connector, entity and environment.
Competitive landscape
Section titled “Competitive landscape”The July 2026 scan shows:
- global privacy management suites (for example OneTrust and Securiti) spanning inventory, rights, consent and governance;
- privacy engineering/data-discovery products (for example Privado) closer to code/data flows;
- India-focused consent/privacy vendors (for example Consentin, OneConsent and Consent Server);
- GRC/ITSM tools adapted through workflow;
- law firms, audit firms and system integrators using templates/custom builds.
These are category and vendor-stated capability observations, not verified performance, compliance or price comparisons. No public price is invented. Diligence must test India legal semantics, commencement labels, statutory CM claims, self-hosting, PII flow, connector evidence, accessibility, sector overlays, export and support access.
Differentiation
Section titled “Differentiation”- primary-source, effective-date legal configuration;
- three profiles with statutory CM separation;
- control plane that minimises PII and runs customer-side agents;
- distributed failure/reconciliation and honest evidence;
- open core, self-hosting and clean exit;
- deep India sector conflict maps rather than generic GDPR recoding.
Positioning
Section titled “Positioning”“Open privacy operations and evidence infrastructure for India.” Never “guaranteed compliance,” “Board approved,” or “registered Consent Manager” without verified status. A readiness assessment is dated and scoped; it is not certification.