Know what your firm knows — instantly

Discover what your firm can achieve when every lawyer has instant access to your full institutional knowledge.

Book a live demo

See eCourt sync, AI Workspaces, and pricing on a walkthrough with our team.

Book a live demo

Or start your free trial — no card required

Privacy Policy

Effective date: 07/03/2026
Last updated: 07/03/2026

1. Introduction

This Privacy Policy (“Policy”) describes how Lawsathi Hub (“LawSathi,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use:

LawSathi is a legal practice management platform for lawyers, law firms, and legal teams in India. Because the Service processes confidential legal matter data and sensitive personal information about your clients, we design our practices with data protection and the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”) in mind.

By registering for, accessing, or using LawSathi, you acknowledge that you have read this Policy. Where consent is required under applicable law, we will obtain it separately (for example, at registration or when enabling optional features).

2. Roles and Responsibilities

2.1 LawSathi as Data Fiduciary

For account, billing, platform security, and operational data relating to registered users (lawyers and firm staff), LawSathi generally acts as a Data Fiduciary.

2.2 You as Data Fiduciary for Client Data

When you upload or enter information about your clients, cases, documents, invoices, and communications, you are typically the Data Fiduciary (or authorized processor on behalf of your firm) for that information. LawSathi processes such data on your instructions to provide the Service.

You are responsible for:

  • Having a lawful basis to collect and upload client data into LawSathi
  • Providing any required notices and obtaining consents from your clients
  • Using AI-generated outputs only after professional review
  • Configuring team access and sharing appropriately

If you believe we process personal data about you only as someone else’s client (not as a LawSathi user), please contact the law firm that uses LawSathi, or us at support@lawsathi.in.

3. Information We Collect

3.1 Account and Profile Information

When you create or manage an account, we may collect:

  • Full name
  • Email address
  • Phone number (used for verification and notifications)
  • Password (stored in hashed form; not readable by us)
  • Professional role and team membership
  • Profile preferences and notification settings
  • If you sign in with Google: your Google account identifier, name, email, and profile picture URL

3.2 Authentication and Security Data

To protect accounts, we may collect and process:

  • One-time passwords (OTP) sent via email or WhatsApp
  • Multi-factor authentication (MFA) settings; MFA secrets are stored using field-level encryption
  • Login timestamps and session records
  • Login attempt logs (including email, success/failure, method, browser/device type, and a hashed form of IP address — we do not store raw IP addresses in login audit logs)
  • Device information for active sessions and mobile push delivery

3.3 Practice and Client Data (User-Provided)

Depending on how you use LawSathi, you may store:

Client information, such as:

  • Name, contact details, addresses
  • Date of birth or incorporation
  • Government identifiers (e.g., PAN, Aadhaar, CIN, registration numbers)
  • Gender, occupation, nationality, jurisdiction
  • Communication preferences and notes

Case and matter information, such as:

  • Court details, case numbers, parties, advocates, hearing dates
  • Case documents, orders, judgments, drafts, and workspace content
  • Tasks, calendar events, billing records, and invoices

Documents and files you upload, create, or export through the platform.

You control what you enter. Please do not upload data you are not authorized to process.

3.4 Payment and Subscription Information

Subscription and billing are processed through Razorpay. We receive:

  • Subscription status, plan type, trial dates
  • Transaction references and payment status from Razorpay webhooks

We do not store full payment card numbers. Card and banking details are handled by Razorpay under their own privacy policy.

3.5 AI and Research Features

When you use AI features (including Case Insights, Research Sathi, argument generation, contract review, document chat, and related tools), we process:

  • Your prompts and queries
  • Case metadata and document content you attach or select for analysis
  • Generated outputs, citations, and workflow state

To provide these features, content may be transmitted to multiple frontier AI models and providers (see Section 6).

3.6 Court and Public Legal Data

When you use eCourt sync, causelist features, or similar integrations, we may fetch and store publicly available court records and related metadata (e.g., case status, orders, listings) from official or public sources to display within your workspace.

3.7 Communications

If you enable notifications, we process:

  • Email addresses and phone numbers for delivery
  • Message delivery status
  • Your preferences for hearing reminders, deadlines, daily digests, billing alerts, and trial or subscription notices

3.8 Mobile App Data

On the Android app, we may collect:

  • Firebase Cloud Messaging (FCM) device tokens for push notifications
  • Biometric authentication is handled by your device’s operating system. LawSathi does not receive or store your fingerprint or face data; biometrics are used locally on your device to unlock an existing session.

3.9 Technical and Usage Data

We automatically collect limited technical information, such as:

  • Browser type, app version, and device type
  • Error and performance logs (via monitoring tools configured to minimize personal data)
  • API usage related to security, rate limiting, and service reliability

We do not use third-party advertising trackers.

3.10 Cookies and Local Storage

On the web app, we use:

  • Essential cookies/local storage for authentication tokens, session state, and user preferences required to operate the Service
  • Capacitor Preferences (on mobile) for session persistence

We do not use cookies for third-party advertising.

4. How We Use Personal Data

We use personal data for the following purposes:

PurposeExamples
Provide the ServiceAccount creation, case/client management, document storage, search, collaboration
AI-assisted legal workflowsInsights, research, drafting, contract review, precedent analysis
Court connectivityeCourt lookup, causelist ingestion, hearing tracking
CommunicationsOTP verification, reminders, digests, billing notices, support
BillingSubscriptions, trials, invoices, payment status
SecurityAuthentication, MFA, fraud prevention, login throttling, access control
ComplianceResponding to lawful requests, enforcing terms, audit logs
ImprovementDebugging, reliability monitoring, feature development (with data minimization)
Product communications (with consent where required)Product updates, onboarding, and service-related announcements

We process personal data only where permitted under applicable law, including on the basis of your consent, performance of a contract (providing the Service you subscribed to), compliance with legal obligations, and legitimate uses recognized under the DPDP Act.

5. AI Processing — Important Notice

LawSathi includes AI features that analyze legal content you provide. Please note:

  1. AI output is assistive only. It does not constitute legal advice. You must independently review all AI-generated content before relying on it or sharing it with clients or courts.
  2. Your content may be sent to AI providers. To generate responses, we may transmit prompts, case context, and document excerpts to multiple frontier AI models and providers.
  3. We take steps to limit unnecessary data sharing, but you should not submit data you are not authorized to share with subprocessors.
  4. You control usage by choosing which cases, documents, and features to use.

6. Third-Party Service Providers

We use trusted third parties to operate LawSathi. These providers process data only as needed to perform services for us and are contractually required to protect it.

CategoryPurpose
Cloud hosting & storageApplication hosting, file and document storage
Database & search infrastructureApplication data, indexing, and retrieval
AI servicesAI-assisted insights, research, drafting, and analysis via multiple frontier AI models and providers
PaymentsSubscriptions and payments (Razorpay)
EmailTransactional and service-related email
WhatsAppOTP, reminders, and notifications you enable
Push notificationsAndroid push alerts (Firebase Cloud Messaging)
AuthenticationSign-in with Google
Error monitoringApplication stability (configured to avoid sending unnecessary personal data by default)
Document toolingIn-browser document editing and PDF viewing

Third-party privacy policies govern their direct collection of data (e.g., when you pay via Razorpay or sign in with Google).

7. How We Share Personal Data

We do not sell your personal data.

We may share personal data:

  1. Within your team/workspace — according to roles and permissions you or your firm configure
  2. With your clients — if you use client portal or sharing features you initiate
  3. With service providers — as described in Section 6
  4. For legal reasons — if required by law, court order, or government authority, or to protect rights, safety, and security
  5. Business transfers — in connection with a merger, acquisition, or asset sale, with notice where required

8. International Data Transfers

Some of our infrastructure and subprocessors may process data outside India (for example, cloud regions or AI service endpoints). Where personal data is transferred internationally, we implement appropriate safeguards consistent with applicable law, including contractual protections and data minimization.

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.

Data typeRetention approach
Active account dataRetained while your account is active
Deleted accountsSoft-deleted with recovery period; permanently deleted after applicable retention window
Documents in trashRecoverable for a limited period, then permanently deleted
Security logsRetained for a limited period for fraud prevention and audit
Billing recordsRetained as required for tax and accounting laws
BackupsMay persist for a limited period in encrypted backups before rotation

You may request earlier deletion subject to legal and contractual obligations (see Section 11).

10. Security

We implement technical and organizational measures designed to protect personal data, including:

  • Encryption in transit (HTTPS/TLS)
  • Encrypted storage for sensitive fields (e.g., MFA secrets)
  • Role-based and resource-level access controls
  • Team data isolation
  • Session management with expiry and revocation
  • Login rate limiting and audit logging
  • Secure file upload controls
  • Automated backups and soft-delete recovery

No system is completely secure. You are responsible for safeguarding your credentials, enabling MFA where available, and managing team access appropriately.

11. Your Rights and Choices

Subject to applicable law (including the DPDP Act), you may have the right to:

  • Access personal data we hold about you
  • Correct inaccurate or incomplete data
  • Erase personal data (subject to legal retention requirements)
  • Withdraw consent for processing that relies on consent (without affecting prior lawful processing)
  • Nominate another individual to exercise your rights in the event of death or incapacity
  • Grievance redressal through our Grievance Officer

How to exercise your rights

Email support@lawsathi.in with:

  • Your registered email address
  • A clear description of your request
  • Proof of identity where reasonably required

We will respond within timelines prescribed under applicable law.

Account and notification controls

You can update profile details, notification preferences (email, WhatsApp, push, digest), and MFA settings within the app. You may uninstall the Android app or revoke push permissions at any time through device settings.

Data export

You may request an export of your account data by contacting support@lawsathi.in. Export availability may depend on your plan and the format of stored content.

12. Children’s Privacy

LawSathi is intended for legal professionals and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

13. Service Communications

We may send product announcements, onboarding tips, or important service updates by email or WhatsApp. You can opt out of non-essential communications through:

  • Unsubscribe links in emails (where provided)
  • Notification preferences in your account settings
  • Contacting support@lawsathi.in

Transactional messages (OTP, security alerts, hearing reminders you enabled, billing notices) may still be sent as part of the Service.

14. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will notify you by email, in-app notice, or a prominent notice on our website. The “Last updated” date at the top will reflect the latest version. Continued use after changes constitutes acceptance where permitted by law.

15. Grievance Officer (India)

In accordance with the DPDP Act, the Grievance Officer for LawSathi is:

Name: Henil Chopada
Email: grievance@lawsathi.in
Address: Office 825, KBC, Yogi Chowk Rd, Yogi Chowk Ground, Mahalaxmi Society, Nana Varachha, Surat, Gujarat 395011

We will endeavour to resolve grievances within 30 days of receipt, or within the period required by applicable law.

16. Contact Us

LawSathi / Lawsathi Hub
Website: https://lawsathi.in
Support: support@lawsathi.in
Sales: sales@lawsathi.in
Registered address: Office 825, KBC, Yogi Chowk Rd, Yogi Chowk Ground, Mahalaxmi Society, Nana Varachha, Surat, Gujarat 395011

Appendix A — Summary of Data Categories (Quick Reference)

CategoryCollected?Shared with third parties?
Account credentialsYesNo (except Google OAuth if used)
Client PII (PAN, Aadhaar, etc.)If you enter itOnly subprocessors needed to run the Service
Case documentsYesAI providers when you use AI features
Payment card dataNo (handled by Razorpay)Razorpay only
Biometric dataNo (device-local only)No
Push device tokensYes (Android)Google Firebase
Raw IP addressesNot in login audit logsMay appear in server/infrastructure logs