Bolt — Instant, Verified, Immutable Consent | Qila CMP
Built for India's DPDP Act

Every consent, captured instantly. Verified forever.

Bolt captures explicit, verified customer consent over RCS and WhatsApp — and locks it into a tamper-proof record that no one can quietly edit later.

Multi-factor verified identity Tamper-proof audit trail DPDPA ready
Why this matters now

Data privacy failures are getting more expensive, more regulated, and harder to hide.

$4.44M
Avg. breach cost globally (2025)
₹19.5 Cr
Avg. breach cost in India (2024)
144
Countries with a data privacy law
79%
Of the world's population now covered by one
Up to ₹250 Cr — max DPDPA penalty per breach 241 days — average time to detect and contain a breach 53% — of breaches target customer personal data 20% — of breaches now involve shadow AI
India spotlight

DPDPA is converging on one expectation: provable consent

India's Digital Personal Data Protection Act doesn't just ask for consent — it asks you to be able to prove, on demand, that someone actually said yes. Most organisations aren't ready for that bar yet.

IN

India — DPDPA, 2023

  • Average breach cost hit ₹19.5 Cr in 2024
  • Only 16% of consumers are aware of their data rights
  • Penalties run up to ₹250 Cr (~$30M) per breach
  • 80% of organisations expect compliance challenges
  • Full enforcement lands by May 2027
What is Bolt

A consent capture layer that lives inside the chats people already open

Bolt is a consent capture product built on Qila CMP. It collects verified, immutable customer consent over RCS and WhatsApp, so every message you send afterward has a legal record standing behind it — not a checkbox someone half-remembers ticking.

  • No app to install — consent is captured inside RCS and WhatsApp
  • Every "yes" is tied to a verified individual, not just a phone number
  • The record can't be quietly edited after the fact
01

User receives message

A rich RCS or WhatsApp message asks for consent to communicate.

02

User gives consent

One tap on "Yes, I agree" — a clear, frictionless opt-in.

03

Consent captured & stored

The record is secured immediately, giving you a verifiable audit trail for compliance.

Why Bolt

Built to hold up when someone asks for proof

Compliance isn't the sale — but it's the moment Bolt earns its keep.

Instant consent capture

Verified consent is recorded in real time, in a flow people can complete in one tap.

Verified identity

Multi-factor authentication ties every consent to a real, confirmed individual.

Immutable audit trail

Tamper-proof records give you a complete, unalterable history of every consent event.

Global compliance

Built to meet DPDPA, CCPA, HIPAA and other regulatory requirements worldwide.

DPDPA field guide

What changes for your marketing channels

India's Digital Personal Data Protection Act draws a sharp line by channel and by purpose. Here's the short version.

What you can do

Email

Send marketing emails with explicit, purpose-specific consent obtained upfront.

SMS / calls

Contact opted-in users who are not on the DND registry, with separate TCCCPR consent.

WhatsApp / chat

Message users who have actively opted in on that specific channel.

Push notifications

Send app push messages where in-app consent was freely given and specific.

Retargeting ads

Run personalised ads using zero-party or anonymised data with clear consent.

What you cannot do

Email

Use data collected for service or support to send unsolicited promotional emails.

SMS / calls

Contact DND-registered users even if DPDPA consent was obtained — both consents are required.

WhatsApp / chat

Send promotional blasts using phone numbers collected for other purposes.

Bundled consent

Bundle marketing consent with service sign-up — each purpose needs its own consent.

Data broking

Purchase or sell personal data for advertising without fresh, explicit consent.

Consent must be Free, Specific, Informed, Unconditional, Unambiguous and Withdrawable. Non-compliance carries penalties of up to ₹250 Cr.
Case study

Preparing for India's DPDP Act — with no direct line to the customer

The scenario

A major apparel brand sells exclusively through agents and retail distributors. It has no direct relationship with the end consumer and relies entirely on third-party channels for communications, marketing and promotions.

The challenge

Once the DPDP Act takes full effect in 2027, the brand loses the ability to message customers without verified, explicit consent — and without direct access to buyers, collecting that consent looks nearly impossible.

The solution: Bolt

Deployed before the Act comes into force, Bolt lets the brand proactively collect verified consent from end customers over RCS and WhatsApp — even through its distributor and agent network. By the time DPDPA is enforced, a compliant consent base already exists.

  • Consent collected at the point of sale, via agents
  • Immutable proof of consent, ready for audit
  • Zero disruption when the Act is enforced
Get in touch

Start building your verified consent base — before you need it.

Talk to us about deploying Bolt across your RCS and WhatsApp channels, and see a live consent capture in a working demo.