Privacy Policy

Last updated: August 2026

1. Introduction

CaseFiles ("we", "our", or "us"), operated from Mumbai, Maharashtra, India, is committed to protecting your privacy and personal data. This Privacy Policy describes how we collect, use, store, disclose, and safeguard your information when you use our legal practice management platform (the "Service").

This policy is formulated in compliance with the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other applicable Indian data protection laws. By using the Service, you consent to the practices described herein.

2. Information We Collect

We collect the following categories of data to provide and improve the Service:

2.1 Personal Information

  • Full name, email address, phone number
  • Professional details: Bar Council enrollment number, chamber address, practice areas
  • Account credentials (hashed passwords, two-factor authentication data)
  • Profile photograph (if uploaded)

2.2 Financial Information

  • Billing address and GST details
  • Payment transaction records (processed via Razorpay; we do not store card numbers or CVV)
  • Invoice and fee note records

2.3 Case Data

  • Case details: case numbers, party names, court names, judge names, hearing dates
  • Case notes, internal memos, and legal research
  • Client communications and correspondence

2.4 Documents and Files

  • Uploaded documents: pleadings, contracts, evidence, court orders
  • Scanned images and OCR-processed text
  • Documents generated through the AI Legal Assistant

2.5 Automatically Collected Information

  • Device type, operating system, browser type and version
  • IP address, approximate geolocation (city-level)
  • Usage data: pages visited, features used, session duration, click patterns
  • Log data: error reports, performance metrics

3. Advocate-Client Privilege and Confidentiality

We recognize the sanctity of advocate-client privilege under the Indian Evidence Act, 1872 (Section 126) and the Advocates Act, 1961. Your case data, client communications, and legal documents are treated as strictly confidential.

  • We do not access, review, or use your case data or client communications for any purpose other than providing the Service.
  • Our employees and contractors are bound by strict confidentiality obligations and do not have access to your data unless necessary for technical support, and only with your explicit authorization.
  • We will not disclose case data to any third party except as required by a valid court order, legal process, or as expressly directed by you.
  • AI-assisted features process data algorithmically; no human reviews the content of your documents or case files unless you explicitly request support assistance.

4. Legal Basis for Processing

Under the IT Act and SPDI Rules, we process your data based on:

  • Consent: You provide explicit consent when creating an account and uploading data.
  • Contractual necessity: Processing is necessary to perform our obligations under the Terms of Service.
  • Legal obligation: Processing is required to comply with applicable Indian laws, court orders, or regulatory requirements.
  • Legitimate interest: Processing is necessary for fraud prevention, security, and service improvement, balanced against your privacy rights.

5. How We Use Your Information

We use the collected data to:

  • Provide, maintain, and improve the Service
  • Process subscription payments and generate invoices
  • Send service-related communications (account alerts, billing notices, security notifications)
  • Respond to support requests and resolve technical issues
  • Generate anonymized, aggregated analytics to improve the Service
  • Power AI-assisted features (legal draft generation, case analysis) based solely on data you provide
  • Comply with legal obligations and respond to lawful requests from Indian authorities
  • Detect and prevent fraud, abuse, and security incidents

6. Data Storage and Security

In compliance with Rule 8 of the SPDI Rules (Reasonable Security Practices), we implement the following security measures:

6.1 Infrastructure

  • All primary data is stored on Supabase servers located in India (AWS Mumbai region, ap-south-1).
  • Documents and media files are stored on Cloudinary with India-based CDN nodes.
  • We do not transfer your data outside India for storage purposes (see Section 11 on Cross-Border Transfer).

6.2 Encryption

  • Data at rest: AES-256 encryption
  • Data in transit: TLS 1.3 (HTTPS) encryption for all communications
  • Database-level encryption for sensitive fields
  • End-to-end encryption for document uploads

6.3 Access Controls

  • Role-based access control (RBAC) within the platform
  • Multi-factor authentication (MFA) support
  • Session management with automatic timeout
  • Audit logging of all data access and modifications
  • Annual third-party security audits and penetration testing

7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

7.1 Service Providers

We engage trusted third-party processors who operate under strict Data Processing Agreements (DPAs) with confidentiality and security obligations:

  • Supabase: Database hosting, authentication, and real-time subscriptions
  • Razorpay: Payment processing (Razorpay is PCI DSS Level 1 compliant; we do not store payment card data)
  • Cloudinary: Document and media file storage, image optimization, and delivery
  • OpenAI: AI-powered features (legal draft generation, case analysis). Data sent to OpenAI is processed under API agreements that prohibit training on your data. No case data is used to train AI models.

7.2 Legal Requirements

We may disclose your data if required by:

  • A valid court order or subpoena issued under Indian law
  • A direction from a competent government authority under the IT Act
  • A request from law enforcement agencies for investigation of cyber incidents under Section 69 of the IT Act

7.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide 30 days' prior notice and ensure the successor entity honors this Privacy Policy.

8. Data Retention and Deletion

We retain your data in accordance with the following policy:

  • Active accounts: Data is retained for as long as your account is active and the Service is being used.
  • Account deletion: Upon account deletion request, all personal data, case data, and documents are permanently deleted from our active systems within 30 days. Backup copies are purged within 90 days.
  • Legal retention: Where retention is required by applicable Indian law (e.g., under the Companies Act, 2013 or Income Tax Act, 1961), we retain the minimum necessary data for the legally mandated period.
  • Anonymized data: Aggregated, anonymized data that cannot identify you may be retained indefinitely for analytics and service improvement.
  • Financial records: Transaction records are retained for 7 years as required under Indian tax laws.

9. Your Rights Under Indian Law

Under the IT Act and SPDI Rules, you have the following rights:

  • Right to Access (Rule 5): You may request a copy of all personal data we hold about you. We will respond within 30 days.
  • Right to Correction: You may request correction of inaccurate or incomplete personal data.
  • Right to Withdraw Consent: You may withdraw consent for data processing at any time. Where processing is based solely on consent, we will cease processing your data upon withdrawal.
  • Right to Grievance Redressal: You may file a complaint with our Grievance Officer if you are dissatisfied with our data handling practices (see Section 14).
  • Right to Data Portability: You may request your data in a commonly used, machine-readable format (CSV/JSON) for transfer to another service provider.

To exercise any of these rights, please contact us at privacy@casefiles.in.

10. Cookies Policy

We use cookies and similar tracking technologies to enhance your experience. Cookies are small data files stored on your device.

10.1 Types of Cookies

  • Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Functional Cookies: Remember your preferences (language, theme, layout settings) to provide a personalized experience.
  • Analytics Cookies: Help us understand usage patterns (pages visited, features used, errors encountered) so we can improve the Service. We use privacy-respecting analytics that do not track individual users across websites.

10.2 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies may impair the functionality of the Service. Disabling functional or analytics cookies will not affect core functionality.

11. Cross-Border Data Transfer

Our primary data infrastructure is located in India. However, certain service providers may process limited data in jurisdictions outside India:

  • OpenAI API: AI processing requests may be routed through OpenAI's servers located in the United States. This data is processed under API agreements that strictly prohibit the use of your data for model training.
  • Email delivery: Transactional and service emails may be routed through servers located outside India.

Where data transfer outside India occurs, we ensure adequate protection through contractual safeguards, encryption, and compliance with applicable data transfer provisions under Indian law. We do not transfer Sensitive Personal Data or Information outside India except where necessary for performance of a contract and with appropriate security measures in place.

12. Children's Privacy

The Service is designed for legal professionals and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take immediate steps to delete such information. If you believe a child has provided us with personal data, please contact us immediately at privacy@casefiles.in.

13. Data Breach Notification

In the event of a data breach involving Sensitive Personal Data or Information, we will:

  • Notify affected users within 72 hours of becoming aware of the breach, in compliance with Rule 6 of the SPDI Rules.
  • Notify the Indian Computer Emergency Response Team (CERT-In) as required under the IT Act and the Information Technology (Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013.
  • Provide details of the breach, the data affected, and the remedial measures taken.
  • Take immediate steps to contain the breach, secure affected systems, and prevent recurrence.

14. Grievance Officer

In accordance with the IT Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the name and contact details of our Grievance Officer are provided below. You may contact the Grievance Officer for any complaints regarding the processing of your personal data, or for exercising any of your rights under this policy:

Grievance Officer

CaseFiles

Mumbai, Maharashtra, India

Email: privacy@casefiles.in

The Grievance Officer will acknowledge your complaint within 24 hours and endeavor to resolve it within 30 days from the date of receipt.

15. Third-Party Links

The Service may contain links to third-party websites or services (e.g., court websites, legal databases). We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.

16. Changes to This Policy

We reserve the right to modify this Privacy Policy at any time. Material changes will be notified to you via email or a prominent notice on the Service at least 30 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy. The "Last updated" date at the top of this page indicates when this policy was last revised.

17. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

CaseFiles Privacy Team

Mumbai, Maharashtra, India

Email: privacy@casefiles.in