Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how LawyersNearMe ("we", "us", "our") collects, uses, stores, shares and protects your personal data (“Personal Information”) when you access or use the LawyersNearMe website, mobile application, or any associated service (collectively, the “Platform”). It also explains your rights as a Data Principal under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and our obligations as a Data Fiduciary.
This policy is issued in compliance with the DPDP Act 2023, the Information Technology Act 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
If you do not agree with this Privacy Policy, please do not use the Platform. By accessing or using the Platform you are deemed to have read, understood and accepted this Privacy Policy and to have consented to the collection, processing, storage and sharing of your Personal Information as described below.
For information specifically about cookies, see our Cookie notice. For terms governing your use of the platform, see our Terms of Service.
1. Who we are
LawyersNearMe is operated by [ADVOCATE REVIEW: insert registered legal entity name, address, CIN, GSTIN] We are a technology company that operates a self-listing information directory. We are not a law firm, we do not provide legal advice or representation, and we do not solicit work, promote, market, recommend, rank for consideration, or otherwise advertise any advocate. The role of the Platform with respect to advocates is described in Section 7 of our Terms of Service; this Privacy Policy covers only how we handle Personal Information. . We act as the Data Fiduciary for the personal data described in this policy.
2. What personal data we collect
2.1 If you are a consumer (someone looking for a lawyer)
- • Name, email and mobile number (provided at signup)
- • Authentication data: hashed password, password-reset tokens, one-time passwords (OTPs) sent to your registered email or mobile, session tokens, and where you sign in with a third-party identity provider (e.g., Google), the identifier returned by that provider
- • Preferred language and accessibility preferences (used for translation of in-app strings)
- • State / location (optional; used to narrow lawyer matches)
- • Description of your legal issue (the free-text query you submit when using the “Analyze your issue” flow)
- • Connection metadata when you reach out to a lawyer (timestamp, lawyer matched, the issue context you chose to share)
- • Technical data: Internet Protocol (IP) address, browser type, device type, operating system, referring URL, time-zone, anonymous session ID, page-view events (see Cookie notice)
2.2 If you are a lawyer (advocate signing up for a profile)
- • Name, email, mobile number, date of birth, gender, professional bio, photograph
- • Bar Council registration details: bar council name, enrolment number, enrolment date, expiry date
- • Selected specialisations and high-court / court affiliations
- • Authentication data: hashed password, password-reset tokens, one-time passwords (OTPs) sent to your registered email or mobile, session tokens, and where you sign in with a third-party identity provider, the identifier returned by that provider
- • Identity verification documents uploaded by you for our verification team to review — including, without limitation, your enrolment certificate, Bar Council ID, government-issued photo identification (e.g., PAN, masked Aadhaar, Driving Licence, Voter ID, Passport), and (if a law-firm registration) firm-level constitutional documents (e.g., partnership deed, incorporation certificate, GST registration)
- • Payment data: processed by our payment provider — we receive only the transaction status, masked instrument identifier (e.g., last four digits) and method type. We do not store full card numbers, CVVs, net-banking credentials, or UPI credentials on our servers
- • Bank account details (account holder name, account number, IFSC) collected only if and when you become eligible for payouts (e.g., for refunds), and stored in encrypted form
- • Connection history with consumers (who reached out, when, what issue context they shared)
- • Performance / quality metrics: rating, response time, completed connections, complaints history (used only internally for fair ranking and platform integrity)
2.3 Sensitive Personal Information
The IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 define certain categories of information as “sensitive” — for example, biometric records, health and medical records, passwords, financial account details such as cards and bank credentials, and information about a person's religion, caste, race, sexual orientation, or political beliefs.
We deliberately keep our collection of these categories narrow. We will only handle:
- • the masked payment-instrument details described in Section 2.2, because payments are an unavoidable part of running a paid advocate listing; and
- • the identity-verification documents you choose to upload when registering as a lawyer (Section 2.2), because the Bar Council verification step depends on them.
Nothing else in the sensitive bucket is required for the Platform to function, and we ask you not to volunteer such information in the free-text fields, queries or uploads available on the Platform unless it is genuinely material to the legal issue you want help with.
If, on your own initiative, you do share such information (for instance by typing details of a medical condition into a query about a medical-negligence dispute), you authorise us to process it solely to provide the Services you have asked for, and the rest of this Policy — on security, retention, sharing and deletion — applies to it.
3. Why we collect this data (purposes)
- • Matching: connect consumers with lawyers appropriate to their issue, state, and specialisation
- • Verification: confirm a lawyer is genuinely enrolled with a State Bar Council before listing them publicly
- • Account management: authentication, profile updates, password recovery
- • Payment processing: activate paid lawyer subscriptions and issue receipts
- • Service improvement (with consent): aggregate analytics on which legal issues are most searched, in what states
- • Fraud prevention: detect duplicate enrolments, forged documents, abusive behaviour
- • Legal compliance: respond to lawful requests from courts, regulators, or law enforcement
4. Legal basis (under the DPDP Act)
We process your personal data on the following grounds:
- • Your consent (DPDP Act Section 6) — given when you create an account, accept this policy, or accept analytics cookies
- • Performance of a contract — fulfilling our Terms of Service with you
- • Legal obligation — responding to court orders, tax filings, regulator requests
- • Certain legitimate uses (DPDP Act Section 7) — fraud prevention, statutory compliance
5. Who we share your data with
We share data only with the parties listed below, and only the minimum necessary in each case. Each Data Processor we engage is contractually required to process your information only in accordance with our instructions, to maintain confidentiality, and to implement appropriate technical and organisational safeguards as required by the DPDP Act and the IT Rules 2011.
- • Payment gateway / processor ([ADVOCATE REVIEW: name once production agreement is signed — expected: Razorpay Software Private Limited or equivalent RBI- regulated payment aggregator]) — to receive subscription payments from lawyers and to process refunds. The processor receives the masked instrument identifier and your billing details
- • Email delivery provider ([ADVOCATE REVIEW: name once finalised — expected: Amazon SES, SendGrid, or equivalent]) — to send verification, OTP, notification and transactional emails. The provider receives your email address and the message payload
- • SMS / mobile OTP provider ([ADVOCATE REVIEW: name once finalised — expected: MSG91, Twilio, Gupshup, or equivalent]) — to send OTPs and transactional SMS. The provider receives your mobile number and the message payload
- • Cloud hosting and infrastructure provider ([ADVOCATE REVIEW: Hetzner Online GmbH currently; once an India-region migration is decided, replace with that provider name]) — for storing and processing your data on secure servers. All data is encrypted in transit (TLS 1.2+) and at rest. See Section 11 for the data-residency disclosure.
- • Sign-in identity providers— if you choose to sign in via a third-party identity provider (e.g., Google), the provider authenticates you and returns a stable identifier and your email address to us. Your use of the identity provider is governed by that provider's own privacy policy
- • Lawyers on the Platform— when you, as a consumer, reach out via the Connect flow, the lawyer sees the information you chose to share at that point (typically your name, contact, and the issue context). Lawyers are bound by these Terms of Service to use such information only to respond to your enquiry and not for unsolicited marketing
- • Monitoring and error-reporting ([ADVOCATE REVIEW: Sentry Inc. or equivalent — PII is scrubbed from error payloads before they leave our servers]) — to detect, diagnose and resolve technical issues with the Platform
- • AI-assisted document verification — only for lawyers/advocates, when you upload a Bar Council enrolment certificate during signup or re-verification, we send the certificate image to Anthropic PBC (Anthropic Privacy Policy) to perform structured information extraction (OCR) using Claude. Anthropic may retain the document and the extraction result for up to 30 daysfor trust-and-safety review under their organisation-default retention setting. Anthropic does not use this content to train its models unless we separately opt in (we have not). We do not send any other category of personal data to Anthropic. Consumers' data is not shared with Anthropic at all. [ADVOCATE REVIEW: confirm Anthropic disclosure language is sufficient under DPDP Section 6 (cross-border transfer) and BCI Rule 36/37 (advocate-data confidentiality). Consider enabling Anthropic Zero Data Retention via Anthropic support to remove the 30-day retention window entirely and revise this paragraph accordingly]
- • Government authorities, courts and regulators — when required by lawful order or notice under Indian law, including under the Code of Criminal Procedure, the Income Tax Act, the GST law, the DPDP Act, or as required to defend our legal rights
- • Successor entity— in the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding, your information may be transferred to the successor entity. We will use reasonable efforts to notify you in advance of such a transfer where required by law
We do not sell, rent or trade your personal data, share it with advertisers, or use it to deliver targeted advertising on third-party platforms.
6. How long we keep your data (retention)
| Category | Retention |
|---|---|
| Account record (consumer or lawyer) | For as long as your account is active. On deletion request, anonymised within [ADVOCATE REVIEW: 30 / 60 / 90 days] unless we are required to retain it for legal or financial audit purposes. |
| Lawyer verification documents | Retained for the duration of the lawyer's active listing plus [ADVOCATE REVIEW: 1 / 3 / 7 years] for audit-trail purposes |
| Payment / billing records | 8 years (per Income Tax Act 1961 / GST law retention requirements) |
| Connection / message history | Retained for the duration of your account; anonymised on deletion request |
| Anonymous analytics events | Aggregated indefinitely; raw event rows retained for [ADVOCATE REVIEW: 12 / 24 months] |
| Consent log | Retained for the lifetime of your account (required as evidence of consent under DPDP Act) |
7. Your rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights with respect to your Personal Information:
- • Right to information— a summary of the categories of Personal Information we process about you, the purposes of processing, and the third parties with whom we share it
- • Right to access— request a copy of the Personal Information we hold about you
- • Right to correction, completion and updating — request that we correct inaccurate or incomplete data
- • Right to erasure— request that we delete your Personal Information, subject to (a) lawful retention requirements (e.g. tax records, audit trails), and (b) our legitimate need to retain data necessary to defend ongoing or anticipated legal claims
- • Right to data portability— receive a copy of your Personal Information in a structured, commonly used, machine-readable format, where technically feasible
- • Right to grievance redressal— raise a complaint with our Grievance Officer (see Section 8) and, if not resolved to your satisfaction, escalate to the Data Protection Board of India
- • Right to nominate— nominate another individual to exercise your rights on your behalf in the event of your death or incapacity
- • Right to withdraw consent— at any time, by writing to our Grievance Officer (Section 8) or by using the in-product controls. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. [ADVOCATE REVIEW: confirm effect on active lawyer subscriptions — current draft: where withdrawal would prevent us from providing the Services you paid for, we may terminate the service and process a pro-rata refund per the Refund Policy]
You may exercise any of the rights above by writing to our Grievance Officer using the contact details in Section 8. We may verify your identity before responding to a request, and we will respond within the timeframes prescribed by the DPDP Act and the IT Rules 2021. Some rights may not be available in all circumstances — for example, we may not be able to delete data that we are required by law to retain, or that is necessary to defend ongoing legal claims.
8. Grievance Officer
In compliance with the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer is:
Name: [ADVOCATE REVIEW: appoint a named individual]
Email: [ADVOCATE REVIEW: grievance@lawyersnearme.in or equivalent]
Postal address: [ADVOCATE REVIEW: registered office address]
Response time: we will acknowledge your complaint within 24 hours and resolve it within 15 days, as required by IT Rules 2021.
9. Children
LawyersNearMe is intended for individuals aged 18 and above. We do not knowingly collect personal data of children. If you believe we have inadvertently collected data of a child, please contact our Grievance Officer and we will delete it.
10. Security
We implement technical, administrative and organisational measures to protect your Personal Information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:
- • Encryption of data in transit using Transport Layer Security (TLS 1.2 or higher) for all communications between your device and our servers
- • Encrypted storage of passwords using industry-standard cryptographic hashing (bcrypt) with per-account salt
- • Role-based access controls limiting employee access to Personal Information to those with a need-to-know
- • Network-level firewalls, intrusion detection, and continuous monitoring of our hosting infrastructure
- • Encrypted storage of bank account details and other sensitive categories at rest
- • Periodic internal review of data collection, storage and processing practices, and of physical security measures, to guard against unauthorised access to systems
Despite these measures, no system of electronic storage or transmission can be guaranteed to be completely secure. By using the Platform you acknowledge that you provide your Personal Information at your own risk and that we cannot warrant absolute security in the face of unforeseen events or evolving threats.
11. Personal data breach notification
In the event we discover a personal data breach that is likely to result in adverse impact to you, we will notify you and the Data Protection Board of India of such breach in the manner and within the timeframes prescribed by the DPDP Act and rules made thereunder. The notice will describe, to the extent then known, the nature of the breach, the categories of information affected, the likely consequences, and the mitigation measures we have taken or intend to take.
12. Cross-border transfers and data residency
We endeavour to host and process Personal Information on infrastructure located in India. [ADVOCATE REVIEW: as of the date of this policy, our primary production servers are with Hetzner Online GmbH, which operates data centres in Germany — this is a cross-border transfer that should be either (a) disclosed honestly here, or (b) migrated to an India-region provider before launch. The DPDP Act permits transfer to countries not specifically restricted by the Central Government; we should monitor the negative-list notifications and update this policy accordingly]
Where Personal Information is transferred outside India, we ensure that the recipient is bound by contractual obligations to maintain confidentiality and security standards consistent with this Privacy Policy and applicable Indian law.
13. Changes to this policy
If we make material changes to this Privacy Policy, we will re-prompt for consent on your next visit. Non-material changes (typos, link updates, clarifying examples) will be reflected in the “Last updated” date above without re-prompting.