VakeelOS Privacy Policy

Effective date: 10 July 2026 Privacy contact: support@vakeelos.com

This policy explains how VakeelOS handles personal data. It should be read with the Terms of Service and Acceptable Use Policy.

1. Our role and your firm's role

For the account and professional information of advocates and staff who use VakeelOS, the VakeelOS operator acts as Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

For client, case, contact, document, invoice, and other matter information that a firm places in its workspace, the firm decides why and how that data is used. The firm is the Data Fiduciary and VakeelOS acts as its Data Processor to provide and secure the service. Firms are responsible for having authority to process their clients' and other third parties' data, providing required notices, and assigning appropriate member access.

2. Data we handle

Account and professional information

  • name, verified email address or phone number, avatar, and authentication IDs;
  • firm, role, professional profile, bar-enrolment details, and roster preferences;
  • subscription, consent choices, notification preferences, and support requests.

Firm-controlled practice data

  • cases, CNR and case numbers, courts, parties, contacts, hearing dates, cause lists, case notes, and court orders;
  • documents and generated drafts;
  • tasks, comments, time entries, invoices, payment records, and related metadata.

Legal files can contain sensitive information chosen by the firm. VakeelOS does not require users to add information that is unnecessary for the selected feature.

AI and court-integration data

  • drafting instructions, draft content, legal-research questions, retrieved passages, citations, and document-analysis inputs;
  • court identifiers, advocate names or codes, case numbers, public-portal URLs, CAPTCHA images, and public results needed to perform a requested sync.

Private firm content is not used to train general-purpose AI models.

Technical and security data

  • selected security-relevant change logs, usage and quota counters, IP-derived rate-limit keys, and authentication/session metadata;
  • error and performance telemetry such as route names, stack traces, user or firm identifiers, browser details, and file identifiers. Error context can contain information present in an unexpected failure, so telemetry is access-restricted and should not be treated as an India-only data flow.

3. Why we use data

We process data to:

  • authenticate users and provide the workspace;
  • store, search, export, and manage firm records;
  • synchronize court, cause-list, roster, and order information;
  • generate requested drafts, research, comparisons, and document analyses;
  • send notifications selected by a user and communications necessary to operate the account;
  • process subscriptions and payment links, enforce plan limits, prevent abuse, troubleshoot failures, and secure the service; and
  • comply with lawful requests and applicable record-keeping duties.

Core processing is necessary to provide the service requested by the account or firm. Separate controls are provided for optional marketing, WhatsApp delivery, and cross-border AI fallback where applicable. Operational email preferences do not themselves authorize WhatsApp: WhatsApp delivery also requires the user's separate WhatsApp consent.

4. Where data is stored and processed

Primary PostgreSQL records and uploaded files are stored in Microsoft Azure's Central India region. This is a primary-storage commitment, not a claim that every service operation stays in India. Authentication, notifications, background-job orchestration, telemetry, payment processing, court access, and AI inference can involve other providers and regions.

| Provider | Purpose | Data that may be shared | Location note | | ----------------------- | -------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | Microsoft Azure | App compute, PostgreSQL, Blob Storage, AI and embeddings | Workspace data, files, prompts, retrieved text | Primary database, files, and app runtime are configured in Central India. AI routing depends on the deployed region and SKU and may be cross-border. | | Clerk | Authentication | Name, email, phone, auth and session identifiers | Clerk-managed processing may occur outside India. | | Razorpay | Subscription and payment-link processing | Amount, contact and provider transaction metadata | Payment processing is handled under Razorpay's applicable India services and terms. | | Resend | Transactional and reminder email | Recipient, subject, and email body | Resend-managed processing may occur outside India. | | Meta WhatsApp Cloud API | User-enabled WhatsApp notifications | Phone number and approved message-template fields | Meta processing may occur outside India unless the deployed account has an applicable local-storage configuration. | | Inngest | Background-job orchestration | User, firm, case and document IDs; some workflows also carry case numbers, advocate names or codes, court URLs, and job results | Inngest-managed event and run data may be processed outside India. | | Sentry | Error and performance telemetry | Technical context described in section 2 | Sentry-managed processing may occur outside India. Session replay is not enabled. | | Discord | Sanitized operational alerting | Ticket identifiers, category/priority, and redacted system-health summaries; ticket text, reporter details, case numbers, and attachments are excluded in production | Discord-managed processing may occur outside India. Full support content is available only in the authenticated admin and configured support inbox. | | Upstash | Rate limits, counters, and transient caches | Hashed or direct keys, counters, and cached AI results | Processing region depends on the Redis database configured for the deployment. | | 2captcha | Backup court CAPTCHA solving | CAPTCHA image and challenge metadata | Used only when configured; provider processing may occur outside India. | | Public court portals | Court sync and verification | Case/CNR, advocate or court search inputs | Controlled by the relevant public authority and its portal. |

Direct non-Azure AI fallback is disabled by default in production code and must be explicitly enabled by the operator. Enabling it creates an additional cross-border flow and does not override a user's applicable consent choice.

5. Sharing

We share data with the providers above only as needed to provide, support, secure, or bill for the service; with firm members according to workspace permissions; or where disclosure is required by law. We do not sell personal data or client files.

6. Retention

  • Account and firm data remains while the account or workspace is active, unless the firm deletes it or a valid erasure request applies.
  • AI research query logs are scheduled for deletion after 90 days.
  • Unlinked scraped court and roster records are subject to scheduled retention windows; records incorporated into a matter may remain with that matter.
  • Financial records can be retained in anonymized form where a statutory books-and-records obligation applies.
  • Security logs, provider events, backups, and telemetry follow operational and provider retention settings and may persist for a limited period after primary deletion.
  • Downloadable account exports use time-limited links. Users should store an export securely and delete local copies when no longer needed.

7. Security

VakeelOS uses TLS in transit, tenant and role checks in application code, signature verification for supported webhooks, short-lived file-access URLs, and restricted production credentials. These controls reduce risk but no online service can promise absolute security or end-to-end encryption for every data flow. Users must protect their account, devices, downloaded files, and invitations.

8. Your choices and rights

Depending on your role and applicable law, you may:

  • view and correct profile information;
  • control available email and WhatsApp preferences;
  • request an account-data export (the scope of firm-controlled data depends on your role and the firm's instructions);
  • withdraw an optional consent without affecting unrelated core processing;
  • request correction, erasure, or grievance redressal; and
  • nominate another person to exercise applicable rights in the event of death or incapacity.

Account-erasure requests use a 30-day restoration window. A sole-member closure and a member leaving a multi-member firm have different effects because the firm may need to retain its own matters and financial records. Contact support@vakeelos.com if the in-product controls do not cover your request.

9. Children

VakeelOS is intended for adults using a professional legal workspace. Users must confirm that they are at least 18 years old. The service is not directed to children, but legal files may concern minors where a firm has a lawful professional reason to process that information. In that situation the firm remains responsible for the purpose, authority, access, and safeguards for the matter data.

10. Changes and contact

We may update this policy as the product, providers, or legal requirements change. The effective date above will be updated and material changes will be communicated through an appropriate service channel.

Privacy, export, erasure, or grievance questions may be sent to support@vakeelos.com.

Privacy Policy | VakeelOS