Privacy Policy
1. Introduction and Definitions
CGS AI Tech LLP (“Company”, “we”, “our”, “us”), operating under the brand name Court-Kachahri, is committed to protecting the privacy, confidentiality, and security of all information entrusted to us. This Privacy Policy establishes the legal framework, principles, and procedures governing the collection, processing, storage, and use of personal data of all users, clients, legal professionals, professional partners, and third parties interacting with our platform and services.
By accessing or using Court-Kachahri, including by registering as a user, professional, or advocate, or by selecting “I Agree & Continue” on any Platform agreement, declaration, or policy, you agree to the practices described in this Privacy Policy.
1.1 Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person, including name, age, gender, photograph, identification numbers (PAN, Aadhaar, GST, CIN), contact information, financial information, device identifiers, biometric data, and behavioral patterns.
- “Sensitive Personal Data” means personal data concerning religious or political beliefs, health and medical records, sexual orientation, genetic information, criminal records, financial and payment information, and all information pertaining to legal proceedings.
- “Data Fiduciary” means the Company, which determines the purposes and means of processing personal data and is responsible for ensuring compliance with data protection obligations.
- “Data Principal” means any natural person to whom personal data relates, including clients, legal professionals, professional partners, opposing counsel, and parties to legal proceedings.
- “Data Processor” means any entity that processes personal data on behalf of the Data Fiduciary pursuant to a written Data Processing Agreement.
- “Processing” means any operation performed on personal data, including collection, storage, retrieval, use, analysis, transmission, deletion, and destruction, whether automated or not.
2. Who This Policy Applies To
This Privacy Policy applies to: Citizens and General Users; Advocates and Legal Professionals; Chartered Accountants, Company Secretaries, Tax Professionals, and other Service Providers; Startups, Companies, LLPs, MSMEs, and Organizations; Law Students, Interns, and Mentors; Visitors to the Platform; and all employees, contractors, and service providers of the Company.
3. Legal Framework and Regulatory Compliance
This Privacy Policy is established and administered in strict compliance with:
- Digital Personal Data Protection Act, 2023 (DPDP Act) & DPDP Rules, 2025: Primary statutory framework governing personal data processing in India. The Company complies with rights of Data Principals (Sections 8–12), obligations of Data Fiduciaries (Sections 6–7), and Data Protection Board requirements (Sections 14–16).
- Information Technology Act, 2000: Compliance with Sections 43, 65–75, and 72 covering intermediary liability, unauthorized access, and confidentiality.
- IT (Intermediary Guidelines) Rules, 2021: Adherence to transparency, user grievance redressal, and sensitive data handling.
- Bharatiya Nyaya Sanhita, 2023: Ensuring data relating to criminal proceedings is handled in accordance with statutory safeguards and principles of justice.
- Bar Council of India Rules & Advocates Act, 1961: All legal professionals remain bound by BCI standards of conduct, attorney-client privilege, and statutory confidentiality.
4. Information We Collect
4.1 Account & Legal Professional Information
We collect Full Name, Email Address, Mobile Number, Profile Photograph, Username, and Login Credentials. For advocates and legal professionals, we collect Enrollment Number, Bar Council Details, Practice Areas, Qualifications, Experience, Office Address, and Verification Documents. As authorized under the Advocate Declaration, verification may include cross-checking credentials with the Bar Council of India and State Bar Councils.
4.2 Professional Partners & Startup Information
For Chartered Accountants, Company Secretaries, IP Consultants, GST Consultants, and Business Advisors, we collect licensing and registration details verified with ICAI, ICSI, ICMAI, GSTN, and MCA. For startups, MSMEs, and organizations, we collect Entity Name, CIN, LLPIN, GST, PAN, Incorporation Documents, and Corporate Governance Records to provide legal support and compliance management.
4.3 AI Service, Consultation & Consent Records
When users interact with AI tools, we process prompts, queries, and uploaded drafts solely for providing AI functionality and improving quality. When a user or professional selects “I Agree & Continue”, the Company records the identity, specific document version accepted, timestamp, and IP address as documentary proof of informed consent under the DPDP Act, 2023.
4.4 Financial, Revenue-Share, and Payout Information
In connection with our 70:30 Revenue-Sharing Model, we process service values, invoice details, Platform Fee computations, bank account details, and GST/TDS deduction records as required under the Companies Act, 2013 and Income Tax Act, 1961.
5. Legal Basis for Processing
The Company processes personal data on the following legal bases:
- Consent: Explicit, informed, and voluntary consent obtained prior to processing, withdrawable at any time.
- Performance of Contract: Processing necessary to enter binding agreements, deliver legal/professional services, and disburse revenue-share payouts.
- Compliance with Legal Obligations: Court orders, RBI/SEBI/MCA regulatory requirements, KYC/AML obligations, and tax/audit rules.
- Legitimate Interests: Platform security, fraud prevention, credential verification, and service improvement.
- Professional Privilege: Personal data relating to legal proceedings is processed in accordance with attorney-client privilege and work product doctrine under Indian law.
6. How We Use Information
We use information for: account creation and management; verifying advocates and Professional Partners; connecting users with legal experts; managing case files and online chambers; delivering AI drafting tools; maintaining community safety; customer support and grievance resolution; billing, invoicing, and revenue-share computation; and marketing (subject to opt-in consent).
7. Lawyer-Client Confidentiality
8. Community Safety & Professional Compliance
We review community activity, public posts, and reports to enforce guidelines, prevent harassment, and maintain platform integrity. Advocates and Professional Partners are expected to comply with the Advocates Act, 1961, BCI Rules, and governing body codes (ICAI, ICSI, ICMAI). We process data necessary to verify and maintain such compliance.
10. Data Sharing and Disclosure
Court-Kachahri does not sell personal information. We share data only with: advocates and professionals providing requested services; authorized organization representatives; service providers and cloud infrastructure partners (AWS, Google Cloud, Razorpay, Instamojo) bound by legally binding Data Processing Agreements (DPAs); and judicial/regulatory authorities (CBI, ED, Income Tax, RBI, SEBI) when required by valid legal writs or directives.
Where a claim or proceeding is raised against a professional in connection with Platform services, relevant registration and consultation records may be shared to investigate, defend, or settle the claim without waiving attorney-client privilege except as legally required.
11. Company and Startup Data Confidentiality
Company and startup data uploaded to Court-Kachahri shall be treated as strictly confidential. Access is restricted to authorized representatives of the organization, assigned legal teams, and authorized operational personnel. Confidentiality obligations survive termination of services.
12. Data Retention Schedule
| Data Category | Retention Period |
|---|---|
| Account Information | Duration of active account + 5 years post-closure (for tax and audit) |
| Litigation Data and Case Files | Duration of proceedings + 10 years after final judgment or dismissal |
| Financial, Revenue-Share & Payout Records | 7 years as mandated by the Companies Act, 2013 and Income Tax Act, 1961 |
| Communication Records | 3 years, extended for litigated matters until final disposition |
| Agreement Acceptance & Consent Records | Duration of account + 7 years post-closure, for consent proof & disputes |
| AI Interaction & Community Data | Duration of service + reasonable period for quality improvement |
| Technical and Analytics Data | 2 years from date of collection |
13. Data Deletion
Users may request deletion upon permanent account closure or via written deletion requests. Upon expiration of retention periods, personal data is securely destroyed or irreversibly anonymized. Deletion may be deferred where required for legal compliance, active disputes, security investigations, or indemnification defense.
14. Rights of Data Principals under DPDP Act, 2023
Subject to applicable law, Data Principals have the following statutory rights:
- Right to Know (Section 11): Request information regarding personal data held, processing purposes, recipients, and source within 30 calendar days.
- Right to Correction (Section 12): Request correction of inaccurate, incomplete, or outdated personal data within 30 calendar days.
- Right to Erasure (Section 12): Request erasure of personal data when no longer necessary, consent is withdrawn, or processing is unlawful.
- Right to Data Portability: Receive personal data in a structured, commonly used, machine-readable format.
- Right to Withdraw Consent (Section 6): Withdraw consent at any time without affecting prior lawful processing.
- Right to Grievance Redressal & Appeal (Section 13 & 14): Raise privacy grievances with our DPO, with the right to escalate to the Data Protection Board (DPB) of India.
15. Data Security and Protection Measures
15.1 Technical and Organizational Safeguards
We implement comprehensive security measures including: end-to-end encryption in transit using TLS 1.3+; AES-256 encryption for sensitive personal data at rest; multi-factor authentication (MFA); role-based access control (RBAC); regular penetration testing; firewalls and DDoS protection; and redundant geographically distributed backups.
15.2 Data Breach Notification (72-Hour Rule)
In the event of a data breach, the Company shall notify affected Data Principals within 72 hours of discovery, providing breach details and mitigation measures. We shall also notify the Data Protection Board as required under the DPDP Act, conduct forensic investigations, and maintain breach documentation for 5 years.
16. Artificial Intelligence and Automated Decision-Making
We employ AI and machine learning for automated document analysis, contract review, clause identification, case law research, predictive legal analytics, and drafting assistance. AI tools are provided solely for informational and assistance purposes. Processing AI interaction data does not make Court-Kachahri a party to any advice subsequently rendered by an advocate.
We maintain transparency by disclosing when AI is used, testing models for bias, and allowing users to request human review of automated decisions. Only anonymized, de-identified, and aggregated data may be used to train AI models; confidential client and litigation data shall never be used for training without explicit written consent.
17. Cookies, Tracking & Child Protection
We use cookies for session maintenance, authentication, preferences, analytics, and fraud prevention. Users may control cookies through browser settings. Our services are not directed to children under 18; any minor data collected without parental consent will be immediately deleted upon discovery.
19. International Data Transfers
We may transfer personal data outside India in limited circumstances (e.g., international cloud infrastructure or cross-border legal matters) subject to executing Standard Contractual Clauses, Data Processing Agreements, ensuring equivalent data protection standards, and obtaining explicit consent for sensitive data.
20. Grievance Redressal and Dispute Resolution
20.1 Data Protection Officer (DPO) & Complaint Filing
We have appointed an independent Data Protection Officer (DPO) to oversee compliance. Data Principals may file written complaints with the DPO detailing the alleged violation. We shall acknowledge receipt within 5 business days and respond within 30 calendar days.
20.2 Escalation to Data Protection Board
If dissatisfied with the Company’s response, or if we fail to respond within the statutory timeframe, Data Principals have the right under Section 14 of the DPDP Act to file a complaint directly with the Data Protection Board (DPB) of India.
21. Changes to Policy & Limitation of Liability
We may modify this Privacy Policy with at least 30 calendar days’ prior notice for material amendments. While we implement enterprise-grade security, no system is entirely impenetrable; we are not liable for unauthorized access resulting from user credential sharing, third-party phishing, or force majeure events.
23. Contact Us
| Channel / Role | Contact Details |
|---|---|
| Organization | CGS AI Tech LLP — Court-Kachahri |
| Data Protection Officer (DPO) | info@court-kachahri.com |
| Grievance Officer / Complaints | chandrashekhar@court-kachahri.com |
| General Support & Privacy Enquiries | info@court-kachahri.com |
| Website | www.court-kachahri.com |
24. Acknowledgment and Acceptance
By accessing or using the services provided by Court-Kachahri, including by accepting any Platform Agreement, every Data Principal acknowledges that they have read, understood, and agree to be bound by the terms and conditions of this Privacy Policy. This Privacy Policy constitutes a binding legal document between the Company and the Data Principal.