Legal
Privacy Policy
Last updated: August 2026 · Effective from: August 2026
Rupenet Technologies Private Limited ("Rupenet", "we", "us", "our") operates the Rupenet Legal platform. This Privacy Policy explains how we collect, use, store, share and protect your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian laws.
1. Data We Collect
1.1 Account & Identity Data
- Name, email address, phone number and professional designation
- Organisation name, GSTIN (if applicable) and billing address
- Bar Council enrolment number (for advocates)
- Login credentials (passwords are hashed and never stored in plaintext)
- Multi-factor authentication identifiers
1.2 Client & Matter Data
- Client profiles, KYC documents and engagement records uploaded by you
- Matter details, case information, hearing notes and court data you enter
- Documents, contracts, correspondence and files you upload or create
- Time entries, billing records, invoices and payment information
Important: Client and matter data belongs to you (the tenant). We process this data solely on your instructions as a Data Processor. We do not access, use or share your client data for any purpose other than providing the platform services.
1.3 AI Interaction Data
- Research queries, drafting prompts and AI tool inputs
- AI-generated outputs, citations and review decisions
- Feedback provided on AI responses (accuracy, relevance ratings)
AI Data Guarantee: Your data is never used to train AI models. PII and privileged information is redacted before any external AI model calls. Tenant data is excluded from model training by default and by design.
1.4 Usage & Technical Data
- IP address, device type, browser type and operating system
- Pages visited, features used, session duration and click patterns
- Error logs, crash reports and performance metrics
- Cookies and similar tracking technologies (see Cookie Policy below)
1.5 Payment Data
- Payment method details are processed by PCI DSS-compliant payment partners
- We store only transaction references, amounts and status — not card/bank details
- UPI IDs and payment confirmations for reconciliation purposes
2. Purpose of Data Processing
| Purpose | Legal Basis (DPDPA) |
|---|---|
| Providing platform services (CRM, matters, documents, billing) | Performance of contract |
| AI-powered research, drafting and document review | Performance of contract + Consent |
| Payment processing, invoicing and reconciliation | Performance of contract + Legal obligation |
| Account security, fraud prevention and audit logs | Legitimate use + Legal obligation |
| Product improvement, analytics and bug fixes | Legitimate use (aggregated/anonymised) |
| Regulatory compliance (GST, DPDPA, BCI rules) | Legal obligation |
| Customer support and communication | Performance of contract + Consent |
| Marketing communications (only with opt-in) | Consent |
3. Data Sharing & Third Parties
We do not sell your personal data. We share data only with:
- Payment partners: PCI DSS-compliant processors for payment collection and payouts
- AI model providers: With PII/privilege redaction applied before transmission; no training on your data
- Cloud infrastructure: India-region hosting providers with documented subprocessor agreements
- eSign partners: For digital signature execution (only data you explicitly submit for signing)
- Communication providers: Email, SMS and WhatsApp delivery partners (message content as directed by you)
- Legal/regulatory authorities: When required by law, court order or regulatory directive
A documented subprocessor register is maintained and available to enterprise customers upon request.
4. Data Storage & Security
- Encryption: TLS 1.3 in transit, AES-256 at rest; tenant-specific encryption keys available for enterprise
- Data residency: India data residency option with all primary data stored in Indian data centres
- Access control: Role-based (RBAC) and attribute-based (ABAC) access, ethical walls, MFA enforcement
- Audit trail: Immutable logs for all access, exports, AI usage, approvals and administrative actions
- Backup: RPO of 1 hour, RTO of 4 hours, tested disaster recovery procedures
- Security testing: CERT-In empanelled VAPT, SAST/DAST/SCA in CI/CD pipeline
- Tenant isolation: Strict multi-tenant isolation at database, application and network level
5. Data Retention
- Client and matter data: Retained as long as your subscription is active, configurable per tenant (default 7 years)
- Account data: Retained for the duration of the account plus 90 days after deletion request
- Billing and financial records: Retained for the period required by Indian tax and accounting laws (minimum 8 years)
- Audit logs: Retained for a minimum of 3 years or as required by applicable regulations
- AI interaction logs: Retained for 1 year for quality improvement (anonymised) unless you request earlier deletion
- Marketing data: Until consent is withdrawn
Upon account termination, we provide a data export facility. After the retention period, data is securely deleted using defensible deletion processes.
6. Your Rights (DPDPA)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access: Request confirmation of whether we process your data, and obtain a summary
- Correction: Request correction or completion of inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Withdraw consent: Withdraw consent for processing where consent is the legal basis
- Grievance redressal: Lodge complaints with our Grievance Officer or the Data Protection Board of India
- Nomination: Nominate another individual to exercise your rights in case of death or incapacity
To exercise any of these rights, contact our Data Protection Officer at privacy@rupenet.com. We will respond within 30 days.
7. Cookies & Tracking
| Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management, security | Session / 30 days |
| Functional | Preferences, language, layout settings | 1 year |
| Analytics | Usage patterns, performance monitoring | 1 year (opt-in) |
We do not use third-party advertising trackers. Analytics cookies are only set with your consent.
8. Children's Data
Rupenet Legal is designed for legal professionals, businesses and adults. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected such data, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email and an in-app notification at least 30 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
10. Grievance Officer & Contact
Data Protection / Grievance Officer
Rupenet Technologies Private Limited
Noida, Uttar Pradesh, India
Email: privacy@rupenet.com
Response time: Within 30 days of receiving a verifiable request.