
Privacy Policy
How we collect, use, protect, and respect your data — and your clients' data.
- Who We Are
- Scope of This Policy
- Information We Collect
- How We Collect Information
- Legal Basis for Processing
- How We Use Your Information
- AI Tools & Data Processing
- Sharing & Disclosure of Information
- International Data Transfers
- Data Retention & Deletion
- Security of Your Data
- Cookies & Tracking Technologies
- Children's Privacy
- Your Rights Under Indian Law
- Client Data — Advocate's Obligations
- Data Breach Response
- Third-Party Links & Services
- Changes to This Policy
- Grievance Redressal & Contact
1.Who We Are
Subroutine Labs LLP ("CaseClarity", "Company", "we", "us", or "our") is a limited liability partnership registered under the Limited Liability Partnership Act, 2008, with its registered office at 005 A-Wing, Silicon Valley, Alviso Tower, Powai, Mumbai, Maharashtra 400076, India (LLPIN: ACZ-7784).
We operate the CaseClarity platform — an AI-assisted legal technology system for Indian advocates, law firms, and corporate legal teams — accessible at caseclarity.in and via associated mobile and desktop applications (collectively, the "Platform").
For the purpose of applicable data protection law, including the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), CaseClarity is the Data Fiduciary / Body Corporate in respect of personal data processed on the Platform.
2.Scope of This Policy
This Privacy Policy ("Policy") explains how we collect, receive, use, store, process, transfer, protect, and disclose personal data and other information when you:
- Visit or browse the Platform;
- Register for a Free or Paid account;
- Use any feature of the Platform, including AI Tools, case management, drafting, research, or hearing tracking;
- Upload or submit documents, evidence, or client data; or
- Contact us for support, billing, or any other purpose.
This Policy applies to all users of the Platform: individual advocates, law firm staff, Firm Admins, in-house legal counsels, and any other authorised users.
This Policy is incorporated into and must be read alongside our Terms and Conditions. In the event of conflict, the Terms and Conditions shall prevail for commercial matters; this Policy shall prevail for data protection matters.
3.Information We Collect
3.1 Account & Registration Information
| Category | Data Elements | Sensitivity |
|---|---|---|
| Identity | Full name, email address, mobile number, designation, Bar Enrolment number | Personal Data |
| Firm Profile | Firm name, firm registration number, address, city, state, PIN code, firm contact email & phone | Business Data |
| Authentication | Hashed password, session tokens, device identifiers, last login timestamp | Security Data |
| Profile & Preferences | Avatar, language preference, notification preferences, theme settings | Personal Data |
| Subscription | Plan type, billing cycle, subscription start & end dates, payment status | Financial Data |
3.2 Client Data (Uploaded by Advocates)
| Category | Data Elements | Basis for Collection |
|---|---|---|
| Client Identity | First name, last name, father's name, date of birth, gender, marital status | Client intake (advocate-entered) |
| Contact Details | Mobile number, email address, residential address, city, state, PIN code | Client intake |
| Identification Documents | Aadhaar number (encrypted), PAN number (encrypted) | KYC & legal filings — SPDI |
| Financial Information | Occupation, annual income range, employer name | Legal aid eligibility & case context |
| Emergency Contact | Emergency contact name, relationship, mobile number | Client welfare & urgent communications |
| Case & Legal Data | Case number, case type, court, case status, assigned advocate, legal documents, case notes, chronology of events | Case management & drafting services |
| Evidence & Documents | Uploaded files (PDF, DOCX, images), file metadata, OCR-extracted text, evidence timelines, document categories & tags | Evidence management & AI analysis |
| Hearing Records (Roznama) | Hearing dates, judge names, court stage, courtroom number, order summaries, judicial directions, next hearing dates | Hearing tracking module |
| Drafts & Legal Documents | AI-generated and advocate-edited legal drafts, version history, track-change records, client review comments | Drafting & collaboration module |
| Health / Medical Data | If uploaded as evidence in relevant cases (e.g., personal injury, compensation) | Advocate-uploaded evidence — SPDI |
3.3 Usage & Technical Data
| Category | Data Elements |
|---|---|
| Device & Browser | IP address, browser type and version, operating system, device type, screen resolution, user agent string |
| Log Data | Pages visited, features used, timestamps, clickstream data, error logs, API call logs (without sensitive content) |
| Performance Data | Page load times, API response times, session duration, crash reports |
| Analytics | Anonymised, aggregated usage patterns collected via third-party analytics tools. Replay masking is enabled by default — no document content or PII appears in session replays. |
3.4 Payment Data
Payment information (card details, UPI IDs, bank account details) is processed exclusively by our third-party payment processor. CaseClarity does not store, access, or process raw payment credentials. We receive only a transaction reference ID and payment status. The payment processor's privacy policy governs the handling of your payment data.
3.5 Communications Data
If you contact us via email, support tickets, or in-app messaging, we retain the content of that communication and your contact details to respond to your query and for quality assurance. Client review portals record document view activities and feedback submitted by your clients through secure, password-protected links.
4.How We Collect Information
4.1 Directly from You
Most information is collected directly from you when you:
- Register and create an account;
- Add clients, cases, evidence, or documents to the Platform;
- Complete Smart Q&A sessions or interact with AI Tools;
- Subscribe to a plan, make a payment, or update billing details;
- Contact our support team; or
- Respond to surveys or provide feedback.
4.2 Automatically
Technical and usage data is collected automatically when you use the Platform through server logs, cookies, and lightweight analytics tools. See Section 12 for details on cookies.
4.3 From Third Parties
We may receive information from:
- Authentication providers (if you use Google or other SSO login, we receive your name and email address);
- Payment gateways (transaction confirmations and billing status only);
- Public court information sources (planned) (we may, in future, link publicly available court cause list data or legal act information to your case records).
5.Legal Basis for Processing
Under the DPDP Act, 2023, and applicable Indian law, we process personal data on the following legal grounds:
| Processing Activity | Legal Basis |
|---|---|
| Account registration and delivery of Platform services | Consent (explicit clickwrap) & Contractual necessity |
| Processing subscription payments and billing | Contractual necessity & Legal obligation (GST, accounting) |
| Processing client personal data uploaded by advocates | Consent obtained by the advocate from their client; CaseClarity acts as Data Processor on the advocate's instructions |
| AI-assisted drafting & analysis (using your data as input) | Consent (at account registration & feature use) & Contractual necessity |
| Analytics and platform improvement | Legitimate interest (anonymised & aggregated data only); Consent for identifiable usage tracking |
| Security monitoring, fraud prevention, abuse detection | Legitimate interest & Legal obligation |
| Compliance with court orders, government directions, or legal process | Legal obligation |
| Processing sensitive personal data (Aadhaar, PAN, health data) | Explicit consent of the Data Principal; advocate's professional obligation to hold such data |
6.How We Use Your Information
6.1 To Provide and Improve the Platform
- Creating and managing your account and firm profile;
- Delivering all Platform features including case management, AI drafting, hearing tracking, and client portals;
- Generating and storing AI-assisted legal documents tied to your cases;
- Maintaining version control, audit trails, and change tracking on drafts;
- Sending you service-related emails (account verification, subscription confirmations, hearing reminders, draft review notifications).
6.2 Billing and Subscription Management
- Processing subscriptions, renewals, and payment confirmations;
- Issuing GST-compliant invoices;
- Managing plan upgrades, downgrades, and cancellations;
- Recovering outstanding dues (where necessary).
6.3 Security and Fraud Prevention
- Detecting and preventing unauthorised access, account takeovers, and abuse;
- Monitoring for unusual activity patterns that may indicate breach or misuse;
- Enforcing rate limits and security controls;
- Maintaining administrative and payment-related activity logs for compliance and forensic purposes.
6.4 Platform Analytics and Improvement
- Understanding how the Platform is used (anonymised & aggregated data only);
- Identifying and fixing bugs, performance issues, and usability problems;
- Prioritising feature development based on aggregated usage patterns;
- Running A/B tests on UI features using anonymised cohort data.
6.5 Legal and Compliance Obligations
- Complying with applicable Indian law, including the IT Act, DPDP Act, GST Act, and Prevention of Money Laundering Act;
- Responding to valid legal process (court orders, government directions, regulatory inquiries);
- Defending against legal claims;
- Maintaining statutory records as required.
6.6 What We Do NOT Do With Your Data
- We never sell your personal data or your clients' data to any third party.
- We do not use your case content, client data, or legal documents for advertising or marketing purposes.
- We do not use identifiable User Data or client data to train AI models without your explicit, separate written consent.
- We do not share your data with government bodies or law enforcement except as compelled by valid legal process.
- We do not profile your clients or use their data for purposes beyond providing the Platform services you have subscribed to.
7.AI Tools & Data Processing
7.1 How AI Tools Use Your Data
When you use AI-powered features (Smart Q&A, Draft Generation, Legal Analysis, and Evidence Analysis), the following may be transmitted to our AI model providers:
- Your case queries, factual context, and Q&A responses;
- Uploaded evidence documents (after OCR text extraction);
- Draft text for AI evaluation or revision.
This data is transmitted to third-party AI service providers under data processing agreements.
7.2 AI Provider Data Obligations
Our agreements with AI providers require them to:
- Not use your data to train their AI models without your separate explicit consent;
- Process your data only for the purpose of generating the requested output;
- Maintain appropriate security and confidentiality standards;
- Not retain your input data beyond the processing session, except as required by their own legal obligations.
7.3 Citation Warnings
AI-generated drafts and analysis may contain citations to case law or statutory provisions. All AI-generated citations carry a visual warning badge and must be independently verified. We do not guarantee the accuracy of any citation.
7.4 Anonymised AI Training (Future)
We may, in the future, seek to use anonymised, de-identified, and aggregated legal drafting patterns to improve our own proprietary AI models. Before implementing any such programme, we will:
- Obtain explicit, opt-in consent from users;
- Ensure all data is irreversibly anonymised; and
- Publish an updated Privacy Policy with full disclosure.
8.Sharing & Disclosure of Information
8.1 We Share Only When Necessary
We do not sell, rent, or trade your personal data. We may share your information only in the following circumstances:
8.2 Service Providers & Technology Partners
| Category | Examples | Data Shared | Purpose |
|---|---|---|---|
| Cloud Infrastructure | Our cloud hosting infrastructure | All Platform data (encrypted) | Hosting, database, storage |
| Third-party AI service providers | Enterprise AI model APIs | Case queries, document text (as inputs) | AI-assisted legal drafting and analysis |
| Payment Processing | Our third-party payment processor | Billing name, email, subscription amount | Payment processing |
| Analytics | Third-party analytics tools | Anonymised usage events (no PII in event properties) | Product analytics (replay masking ON) |
| Email / Notifications | Transactional email provider | Email address, notification content | Service & account emails |
| Security Monitoring | Security audit services | Log data, IP addresses (anonymised) | Threat detection & incident response |
All service providers are bound by data processing agreements that prohibit them from using your data for their own purposes, require adequate security measures, and restrict sub-processing without our approval.
8.3 Within Your Firm
If you are a Staff user or Advocate under a Firm Admin account, your Firm Admin has administrative access to your account data, assigned cases, drafts, and activity logs within that firm's scope. This is necessary for firm-level case management and access control. Users who are Firm Admins are responsible for ensuring their staff understand this access.
8.4 Client Review Portals
When you generate a secure client review link for a draft, your client will be able to access that draft, view its contents, and submit feedback. Access is controlled by the time-limited, password-protected URL you generate. We log the client's access activities (IP address, timestamp, time spent) for your audit trail. The client does not get an account on CaseClarity.
8.5 Legal Process & Regulatory Compliance
We may disclose information if we believe disclosure is required or permitted by law, including:
- In response to a valid court order, summons, warrant, or subpoena;
- To comply with a direction from a government or regulatory authority;
- To protect the rights, safety, or property of the Company, its users, or the public;
- To investigate, prevent, or take action against suspected fraud, security threats, or illegal activity.
Where legally permitted, we will notify you before disclosing your data in response to legal process.
8.6 Business Transfers
If the Company undergoes a merger, acquisition, restructuring, or sale of assets, your data may be transferred as part of that transaction, subject to the acquirer assuming the obligations of this Policy. We will notify you via email and an in-Platform notice at least 30 days before any such transfer that materially changes how your data is handled.
8.7 Aggregate & Anonymised Data
We may share aggregated, anonymised, and de-identified statistical data (e.g., "X% of advocates use the drafting module for civil matters") with partners, investors, or in public reports. Such data cannot identify any individual user or their clients.
9.International Data Transfers
CaseClarity's primary infrastructure is hosted in India. However, some of our third-party service providers — including AI model providers and cloud services — may process data in data centres outside India (e.g., USA, EU).
When transferring data internationally, we rely on:
- Data Processing Agreements with standard contractual protections;
- Provider assurances of equivalent data protection standards;
- Industry-standard encryption in transit and at rest.
By using the Platform, you consent to such transfers to the extent necessary to provide the AI and infrastructure services. If data localisation becomes mandatory under the DPDP Act or any other Indian law, we will update our practices accordingly.
10.Data Retention & Deletion
10.1 Retention During Subscription
We retain all User Data and client data uploaded to the Platform for the full duration of your active subscription period.
10.2 Post-Cancellation Grace Period
Upon cancellation or expiry of your subscription, we retain your data for 30 days to allow you to export your data. During this period, the Platform remains accessible in read-only mode for data retrieval. After 30 days, all User Data and client data will be permanently and irreversibly deleted from our production systems.
10.3 Backup Retention
Encrypted backup copies may persist in our disaster recovery systems for up to 90 days after deletion from production systems, after which they are also purged. Backup data is not accessible for operational purposes and is retained solely for disaster recovery.
10.4 Audit Logs
Anonymised activity log entries (recording administrative and payment-related actions, without sensitive content) may be retained for up to 3 years for security, fraud prevention, and legal compliance purposes.
10.5 Billing Records
Transaction records, invoices, and GST-related financial data are retained for 8 years as required under the GST Act, 2017, and applicable Indian law.
10.6 Deletion Requests
You may request deletion of your data at any time (see Section 14). We will action deletion requests within 30 days, subject to our retention obligations under applicable law. We will confirm deletion in writing.
10.7 Sensitive Data (Aadhaar & PAN)
Aadhaar and PAN numbers are encrypted, and access is restricted to specific authorised legal functions.
11.Security of Your Data
11.1 Technical Safeguards
We implement industry-standard technical security measures, including:
- Encryption in transit: All data transferred between your browser/app and our servers is protected using industry-standard encryption;
- Encryption at rest: Database records and stored files are protected using industry-standard encryption;
- Sensitive identifiers: Aadhaar and PAN numbers are encrypted, with access restricted to authorised legal functions;
- Authentication: Secure authentication and session management via our access-control systems;
- Role-Based Access Control (RBAC): Strict permission-based access ensuring users can only access data within their authorised scope;
- Tenant Isolation: Access-control policies ensuring firm data is isolated between tenants;
- Activity Logging: We log administrative and payment-related actions, and are expanding activity logging across the Platform;
- Penetration Testing: We conduct periodic security assessments of the Platform.
11.2 Organisational Safeguards
- Access to production systems is restricted to authorised engineers on a need-to-know basis;
- All employees with data access are bound by confidentiality obligations;
- Security incident response procedures are maintained and tested;
- Third-party service providers are vetted for security standards before onboarding.
11.3 User Responsibility
Security is a shared responsibility. You are responsible for maintaining the security of your login credentials, choosing strong passwords, and logging out of shared devices. Do not share your credentials with unauthorised individuals. Report suspected security incidents immediately to security@caseclarity.in.
11.4 Limitations
No security system is impenetrable. Despite our best efforts, we cannot guarantee that unauthorised third parties will never be able to defeat our security measures. We are not responsible for security incidents caused by your failure to maintain credential security, attacks on third-party infrastructure outside our control, or vulnerabilities in client-side software (browser, OS).
12.Cookies & Tracking Technologies
12.1 What We Use
| Type | Name / Provider | Purpose | Duration |
|---|---|---|---|
| Essential | Sign-in token (browser localStorage) | Authentication — maintains your logged-in session | Until logout |
| Functional | user_data (browser localStorage) | Stores user profile & role for UI rendering | Until logout |
| Analytics | Third-party analytics tools (ph_* cookies) | Anonymised product analytics — autocapture OFF; no PII in events; session replay with full text masking enabled | 1 year |
| Performance | Internal performance monitoring | Page load times, API performance metrics | Session |
12.2 What We Do Not Use
- We do not use advertising cookies or third-party tracking pixels;
- We do not use cross-site tracking;
- We do not sell or share cookie data with advertising networks.
12.3 Managing Cookies
Essential cookies cannot be disabled as they are required for the Platform to function. You may disable analytics cookies via your browser settings. Note that disabling certain cookies may impair Platform functionality. For full cookie details, see our Cookie Policy.
13.Children's Privacy
The Platform is intended solely for use by adults (18 years and above) in a professional legal capacity. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.
In the context of legal cases involving minors (e.g., child custody, juvenile matters), any data about minors that is uploaded by an advocate is processed solely for the purpose of that specific legal matter, with the utmost sensitivity and confidentiality, and is never used for any other purpose.
14.Your Rights Under Indian Law
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), and the IT (SPDI) Rules, 2011, you have the following rights as a Data Principal:
Right to Access
Request a summary of personal data we hold about you and how it is being processed.
Right to Correction
Request correction or updating of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data when no longer necessary for the purpose of processing or when consent is withdrawn.
Right to Data Portability
Request a machine-readable export of your personal data and case data in a structured format (JSON / CSV / DOCX).
Right to Withdraw Consent
Withdraw consent for processing at any time. Note: withdrawal may affect your ability to use certain Platform features.
Right to Grievance Redressal
Lodge a complaint with our Grievance Officer and, if unresolved, with the Data Protection Board of India under the DPDP Act.
14.1 How to Exercise Your Rights
Submit a request to our Grievance Officer at privacy@caseclarity.in with:
- Your registered email address and account ID;
- The right you wish to exercise and specific information requested;
- Proof of identity (to prevent fraudulent data requests).
We will acknowledge your request within 48 hours and act upon it within 30 days. Where we cannot fulfill a request (e.g., deletion of data subject to legal hold), we will explain the reason.
14.2 Withdrawal of Consent
You may withdraw your consent to data processing at any time by submitting a request or cancelling your subscription. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. If consent is withdrawn for processing essential to service delivery, we may not be able to continue providing the Platform to you.
14.3 Data Protection Board
If you are not satisfied with our response to your data protection concern, you have the right to lodge a complaint with the Data Protection Board of India when such Board becomes operational under the DPDP Act, 2023.
15.Client Data — Advocate's Obligations
15.1 Your Responsibility for Client Consent
By uploading any client data to the Platform, you represent and warrant that:
- You have obtained your client's free, specific, informed, and unambiguous consent to process their personal data using a third-party technology platform;
- Your client is aware that an AI-assisted platform will process their case documents, identity details, and communications;
- You have informed your client about the nature of AI processing, including potential for AI errors, in compliance with your professional duties;
- Where your client's data includes Sensitive Personal Data (Aadhaar, PAN, medical records), you have obtained explicit, written consent;
- You have a lawful basis for retaining and processing your client's data on the Platform throughout the duration of your mandate and thereafter as required by the Advocates Act and Bar Council rules.
15.2 Professional Privilege
We acknowledge that case strategies, legal advice, and lawyer-client communications uploaded to the Platform may be protected by legal professional privilege. CaseClarity's staff do not access the content of your case files or client data except:
- In the course of automated processing for service delivery (AI model API calls);
- When you specifically request technical support that requires data access (with your explicit permission);
- Where access is compelled by valid legal process.
We do not waive and will not act in a manner inconsistent with the preservation of legal professional privilege.
15.3 Data Localisation for Client Files
All client case data uploaded to the Platform is stored in databases hosted in India. AI processing may involve temporary transmission to non-Indian AI model providers (see Section 7), but generated outputs are stored in India.
15.4 Client's Right of Access
If your client exercises data rights under the DPDP Act directly with CaseClarity, we will refer the client to you (as their Data Fiduciary / advocate) and notify you. We will only respond directly to client erasure or access requests for data we hold independently of your instructions (e.g., client review portal access logs).
16.Data Breach Response
16.1 Detection & Containment
We maintain a Security Incident Response Plan. Upon detecting a data security incident, we will immediately:
- Isolate and contain the breach;
- Assess the nature and scope of data affected;
- Engage our security team and, where necessary, external forensic specialists;
- Preserve evidence for investigation.
16.2 Notification
In the event of a personal data breach that is likely to result in a risk to your rights or interests:
- We will notify affected users by email within 72 hours of becoming aware of the breach (or as required under applicable law);
- The notification will describe: the nature of data affected, approximate number of individuals affected, likely consequences, and steps we have taken;
- We will report the breach to the Data Protection Board of India and any other relevant authority as required by law;
- We will provide periodic updates as our investigation proceeds.
16.3 Remediation
Following a breach, we will implement remediation measures, review and strengthen security controls, and offer affected users guidance on protective steps they should take.
17.Third-Party Links & Services
The Platform may contain links to third-party websites, public court portals, legal databases, or partner services. This Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party service you access through the Platform.
CaseClarity is not responsible for the privacy practices, content, or security of third-party websites or services. Links to third-party services do not constitute our endorsement of their privacy standards.
18.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or Platform features. When we make material changes, we will:
- Update the "Effective Date" at the top of this page;
- Send a notice to your registered email address at least 15 days before the change takes effect;
- Display a prominent in-Platform banner notifying you of the update;
- Where required by law (e.g., changes to how we process Sensitive Personal Data), seek fresh consent.
Your continued use of the Platform after the effective date of any change constitutes acceptance of the revised Policy. If you do not accept a material change, you must stop using the Platform and may request deletion of your data.
Previous versions of this Policy are archived and available on request at privacy@caseclarity.in.
19.Grievance Redressal & Contact
Contact Our Privacy & Data Protection Team
If you are not satisfied with our response to your privacy grievance, you may escalate your complaint to the Data Protection Board of India once it becomes operational under the DPDP Act, 2023. You may also approach a Consumer Disputes Redressal Commission under the Consumer Protection Act, 2019, for applicable matters.