Privacy Policy
Effective date: 07/03/2026
Last updated: 07/03/2026
1. Introduction
This Privacy Policy (“Policy”) describes how Lawsathi Hub (“LawSathi,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use:
- Our website at https://lawsathi.in
- Our web application at https://app.lawsathi.in
- Our native Android application (LawSathi, package name
com.lawsathi.app) - Related support, sales, and communication channels
LawSathi is a legal practice management platform for lawyers, law firms, and legal teams in India. Because the Service processes confidential legal matter data and sensitive personal information about your clients, we design our practices with data protection and the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”) in mind.
By registering for, accessing, or using LawSathi, you acknowledge that you have read this Policy. Where consent is required under applicable law, we will obtain it separately (for example, at registration or when enabling optional features).
2. Roles and Responsibilities
2.1 LawSathi as Data Fiduciary
For account, billing, platform security, and operational data relating to registered users (lawyers and firm staff), LawSathi generally acts as a Data Fiduciary.
2.2 You as Data Fiduciary for Client Data
When you upload or enter information about your clients, cases, documents, invoices, and communications, you are typically the Data Fiduciary (or authorized processor on behalf of your firm) for that information. LawSathi processes such data on your instructions to provide the Service.
You are responsible for:
- Having a lawful basis to collect and upload client data into LawSathi
- Providing any required notices and obtaining consents from your clients
- Using AI-generated outputs only after professional review
- Configuring team access and sharing appropriately
If you believe we process personal data about you only as someone else’s client (not as a LawSathi user), please contact the law firm that uses LawSathi, or us at support@lawsathi.in.
3. Information We Collect
3.1 Account and Profile Information
When you create or manage an account, we may collect:
- Full name
- Email address
- Phone number (used for verification and notifications)
- Password (stored in hashed form; not readable by us)
- Professional role and team membership
- Profile preferences and notification settings
- If you sign in with Google: your Google account identifier, name, email, and profile picture URL
3.2 Authentication and Security Data
To protect accounts, we may collect and process:
- One-time passwords (OTP) sent via email or WhatsApp
- Multi-factor authentication (MFA) settings; MFA secrets are stored using field-level encryption
- Login timestamps and session records
- Login attempt logs (including email, success/failure, method, browser/device type, and a hashed form of IP address — we do not store raw IP addresses in login audit logs)
- Device information for active sessions and mobile push delivery
3.3 Practice and Client Data (User-Provided)
Depending on how you use LawSathi, you may store:
Client information, such as:
- Name, contact details, addresses
- Date of birth or incorporation
- Government identifiers (e.g., PAN, Aadhaar, CIN, registration numbers)
- Gender, occupation, nationality, jurisdiction
- Communication preferences and notes
Case and matter information, such as:
- Court details, case numbers, parties, advocates, hearing dates
- Case documents, orders, judgments, drafts, and workspace content
- Tasks, calendar events, billing records, and invoices
Documents and files you upload, create, or export through the platform.
You control what you enter. Please do not upload data you are not authorized to process.
3.4 Payment and Subscription Information
Subscription and billing are processed through Razorpay. We receive:
- Subscription status, plan type, trial dates
- Transaction references and payment status from Razorpay webhooks
We do not store full payment card numbers. Card and banking details are handled by Razorpay under their own privacy policy.
3.5 AI and Research Features
When you use AI features (including Case Insights, Research Sathi, argument generation, contract review, document chat, and related tools), we process:
- Your prompts and queries
- Case metadata and document content you attach or select for analysis
- Generated outputs, citations, and workflow state
To provide these features, content may be transmitted to multiple frontier AI models and providers (see Section 6).
3.6 Court and Public Legal Data
When you use eCourt sync, causelist features, or similar integrations, we may fetch and store publicly available court records and related metadata (e.g., case status, orders, listings) from official or public sources to display within your workspace.
3.7 Communications
If you enable notifications, we process:
- Email addresses and phone numbers for delivery
- Message delivery status
- Your preferences for hearing reminders, deadlines, daily digests, billing alerts, and trial or subscription notices
3.8 Mobile App Data
On the Android app, we may collect:
- Firebase Cloud Messaging (FCM) device tokens for push notifications
- Biometric authentication is handled by your device’s operating system. LawSathi does not receive or store your fingerprint or face data; biometrics are used locally on your device to unlock an existing session.
3.9 Technical and Usage Data
We automatically collect limited technical information, such as:
- Browser type, app version, and device type
- Error and performance logs (via monitoring tools configured to minimize personal data)
- API usage related to security, rate limiting, and service reliability
We do not use third-party advertising trackers.
3.10 Cookies and Local Storage
On the web app, we use:
- Essential cookies/local storage for authentication tokens, session state, and user preferences required to operate the Service
- Capacitor Preferences (on mobile) for session persistence
We do not use cookies for third-party advertising.
4. How We Use Personal Data
We use personal data for the following purposes:
| Purpose | Examples |
|---|---|
| Provide the Service | Account creation, case/client management, document storage, search, collaboration |
| AI-assisted legal workflows | Insights, research, drafting, contract review, precedent analysis |
| Court connectivity | eCourt lookup, causelist ingestion, hearing tracking |
| Communications | OTP verification, reminders, digests, billing notices, support |
| Billing | Subscriptions, trials, invoices, payment status |
| Security | Authentication, MFA, fraud prevention, login throttling, access control |
| Compliance | Responding to lawful requests, enforcing terms, audit logs |
| Improvement | Debugging, reliability monitoring, feature development (with data minimization) |
| Product communications (with consent where required) | Product updates, onboarding, and service-related announcements |
We process personal data only where permitted under applicable law, including on the basis of your consent, performance of a contract (providing the Service you subscribed to), compliance with legal obligations, and legitimate uses recognized under the DPDP Act.
5. AI Processing — Important Notice
LawSathi includes AI features that analyze legal content you provide. Please note:
- AI output is assistive only. It does not constitute legal advice. You must independently review all AI-generated content before relying on it or sharing it with clients or courts.
- Your content may be sent to AI providers. To generate responses, we may transmit prompts, case context, and document excerpts to multiple frontier AI models and providers.
- We take steps to limit unnecessary data sharing, but you should not submit data you are not authorized to share with subprocessors.
- You control usage by choosing which cases, documents, and features to use.
6. Third-Party Service Providers
We use trusted third parties to operate LawSathi. These providers process data only as needed to perform services for us and are contractually required to protect it.
| Category | Purpose |
|---|---|
| Cloud hosting & storage | Application hosting, file and document storage |
| Database & search infrastructure | Application data, indexing, and retrieval |
| AI services | AI-assisted insights, research, drafting, and analysis via multiple frontier AI models and providers |
| Payments | Subscriptions and payments (Razorpay) |
| Transactional and service-related email | |
| OTP, reminders, and notifications you enable | |
| Push notifications | Android push alerts (Firebase Cloud Messaging) |
| Authentication | Sign-in with Google |
| Error monitoring | Application stability (configured to avoid sending unnecessary personal data by default) |
| Document tooling | In-browser document editing and PDF viewing |
Third-party privacy policies govern their direct collection of data (e.g., when you pay via Razorpay or sign in with Google).
7. How We Share Personal Data
We do not sell your personal data.
We may share personal data:
- Within your team/workspace — according to roles and permissions you or your firm configure
- With your clients — if you use client portal or sharing features you initiate
- With service providers — as described in Section 6
- For legal reasons — if required by law, court order, or government authority, or to protect rights, safety, and security
- Business transfers — in connection with a merger, acquisition, or asset sale, with notice where required
8. International Data Transfers
Some of our infrastructure and subprocessors may process data outside India (for example, cloud regions or AI service endpoints). Where personal data is transferred internationally, we implement appropriate safeguards consistent with applicable law, including contractual protections and data minimization.
9. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.
| Data type | Retention approach |
|---|---|
| Active account data | Retained while your account is active |
| Deleted accounts | Soft-deleted with recovery period; permanently deleted after applicable retention window |
| Documents in trash | Recoverable for a limited period, then permanently deleted |
| Security logs | Retained for a limited period for fraud prevention and audit |
| Billing records | Retained as required for tax and accounting laws |
| Backups | May persist for a limited period in encrypted backups before rotation |
You may request earlier deletion subject to legal and contractual obligations (see Section 11).
10. Security
We implement technical and organizational measures designed to protect personal data, including:
- Encryption in transit (HTTPS/TLS)
- Encrypted storage for sensitive fields (e.g., MFA secrets)
- Role-based and resource-level access controls
- Team data isolation
- Session management with expiry and revocation
- Login rate limiting and audit logging
- Secure file upload controls
- Automated backups and soft-delete recovery
No system is completely secure. You are responsible for safeguarding your credentials, enabling MFA where available, and managing team access appropriately.
11. Your Rights and Choices
Subject to applicable law (including the DPDP Act), you may have the right to:
- Access personal data we hold about you
- Correct inaccurate or incomplete data
- Erase personal data (subject to legal retention requirements)
- Withdraw consent for processing that relies on consent (without affecting prior lawful processing)
- Nominate another individual to exercise your rights in the event of death or incapacity
- Grievance redressal through our Grievance Officer
How to exercise your rights
Email support@lawsathi.in with:
- Your registered email address
- A clear description of your request
- Proof of identity where reasonably required
We will respond within timelines prescribed under applicable law.
Account and notification controls
You can update profile details, notification preferences (email, WhatsApp, push, digest), and MFA settings within the app. You may uninstall the Android app or revoke push permissions at any time through device settings.
Data export
You may request an export of your account data by contacting support@lawsathi.in. Export availability may depend on your plan and the format of stored content.
12. Children’s Privacy
LawSathi is intended for legal professionals and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
13. Service Communications
We may send product announcements, onboarding tips, or important service updates by email or WhatsApp. You can opt out of non-essential communications through:
- Unsubscribe links in emails (where provided)
- Notification preferences in your account settings
- Contacting support@lawsathi.in
Transactional messages (OTP, security alerts, hearing reminders you enabled, billing notices) may still be sent as part of the Service.
14. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will notify you by email, in-app notice, or a prominent notice on our website. The “Last updated” date at the top will reflect the latest version. Continued use after changes constitutes acceptance where permitted by law.
15. Grievance Officer (India)
In accordance with the DPDP Act, the Grievance Officer for LawSathi is:
Name: Henil Chopada
Email: grievance@lawsathi.in
Address: Office 825, KBC, Yogi Chowk Rd, Yogi Chowk Ground, Mahalaxmi Society, Nana Varachha, Surat, Gujarat 395011
We will endeavour to resolve grievances within 30 days of receipt, or within the period required by applicable law.
16. Contact Us
LawSathi / Lawsathi Hub
Website: https://lawsathi.in
Support: support@lawsathi.in
Sales: sales@lawsathi.in
Registered address: Office 825, KBC, Yogi Chowk Rd, Yogi Chowk Ground, Mahalaxmi Society, Nana Varachha, Surat, Gujarat 395011
Appendix A — Summary of Data Categories (Quick Reference)
| Category | Collected? | Shared with third parties? |
|---|---|---|
| Account credentials | Yes | No (except Google OAuth if used) |
| Client PII (PAN, Aadhaar, etc.) | If you enter it | Only subprocessors needed to run the Service |
| Case documents | Yes | AI providers when you use AI features |
| Payment card data | No (handled by Razorpay) | Razorpay only |
| Biometric data | No (device-local only) | No |
| Push device tokens | Yes (Android) | Google Firebase |
| Raw IP addresses | Not in login audit logs | May appear in server/infrastructure logs |