home / Privacy Policy
We ask for your documents, your contact details and sometimes information about your family. This policy explains what we do with that information, how we protect it, and what rights you
have.
We collect only what a task actually requires. Usually that is your contact details, the details of the task, and the documents needed for it.
We use that information to do the work you have asked for, to report back to you, to invoice you, and to meet our legal obligations. Nothing else.
We do not sell your data. We do not use it for advertising. We share it only with the people a task requires, such as the Authority we are lodging with or the advocate you have instructed.
You can ask what we hold, ask us to correct it, ask us to erase it, and withdraw your consent. Contact our Grievance Officer.
1.1 This policy applies to personal data we collect from visitors to our website, from persons who enquire about our services, and from clients in the course of an Engagement.
1.2 For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act) we are the Data
Fiduciary in respect of that personal data, and you are the Data Principal.
1.3 This policy should be read together with our Terms and Conditions.
2.1 Information you provide to us:
● name, telephone number, email address, and the city and country you are contacting us
from;
● details of the task, and of the property, person or matter it concerns;
● identity documents where a government or legal process requires them, which may include
Aadhaar, PAN, passport, OCI card or voter identity card;
● property documents, including sale deeds, Khata extracts, encumbrance certificates, tax
receipts, survey records and approvals;
● Authorisation documents, including any power of attorney or authorisation letter;
● where you
engage us for care coordination, limited health related information concerning the person cared
for;
● payment and remittance details.
2.2 Information collected automatically when you use our website: pages visited, approximate
location derived from IP address, device and browser information, and referral source. This is
collected through analytics as described in clause 11.
3.1 Identity documents, financial information and health related information constitute sensitive
personal data or information under the Information Technology (Reasonable Security Practices
and Procedures and Sensitive Personal Data or Information) Rules, 2011.
3.2 We collect such data only where a specific task requires it, only with your consent, and only to
the extent required for that task.
3.3 We do not require you to provide Aadhaar or any other identity document except where the
process being undertaken on your behalf requires it, and we will tell you why it is required before
requesting it.
4.1 We process personal data only for the following purposes:
● to respond to your enquiry and prepare a written scope and quote;
● to perform the Engagement you have instructed;
● to make applications to and collect documents from an Authority on your behalf, where
authorised;
● to coordinate with advocates, medical practitioners, contractors, couriers and
other third parties approved by you;
● to send you updates, photographs, receipts, reports and closing summaries;
● to raise invoices, receive payment and maintain accounting records;
● to comply with legal, tax and regulatory obligations in India, and to respond to lawful requests
from an Authority or a court.
4.2 We do not sell personal data, we do not use it for advertising or profiling, and we do not disclose it
for any purpose outside those listed in clause 4.1.
5.1 Our lawful basis for processing is your consent, given when you enquire or instruct us, and, where applicable, the performance of our agreement with you and compliance with law.
5.2 Consent is sought in clear and plain language, and identifies the personal data concerned and the
purpose for which it is required.
5.3 You may withdraw your consent at any time. Withdrawal is as easy as giving consent, and is
made by written notice to our Grievance Officer.
5.4 Withdrawal of consent during an Engagement may prevent us from completing it. We will
inform you clearly if that is the case before acting on the withdrawal. Withdrawal does not affect
the lawfulness of processing carried out before it.
5.5 Withdrawal of consent does not release you from any liability for fees or Disbursements already
incurred.
6.1 We disclose personal data only where the task requires it, and only to:
● Authorities, where an application or request is being made on your behalf;
● advocates and other professionals you have instructed or approved;
● hospitals, clinics and medical practitioners, where you have engaged us for care
coordination;
● contractors, tenants, builders and service providers relevant to your
property;
● couriers and document handling services, where documents are being
despatched;
● our accountant, auditor or legal adviser, bound by professional
confidentiality;
● any person to whom disclosure is required by law or by an order of a court or competent
Authority.
6.2 We require any third party engaged by us to process personal data only on our
instructions and to maintain security measures appropriate to the data.
7.1 We store personal data in India.
7.2 Personal data is transferred outside India only where you are located outside India and we are
sending information to you, or where a task specifically requires such a transfer and you have
approved it.
7.3 Any such transfer is made in accordance with section 16 of the DPDP Act and any restriction
notified by the Central Government.
8.1 We retain task records, correspondence and evidence for the duration of the Engagement and
thereafter for the period required by Indian tax, accounting and record keeping law.
8.2 Original documents belonging to you are returned, couriered or handed over on completion in
accordance with clause 13 of the Terms. We retain originals beyond completion only on your written
instruction.
8.3 When personal data is no longer required for the purpose for which it was collected, and
no legal obligation requires its retention, we erase it.
9.1 We follow reasonable security practices and procedures as required under section 43A of the
Information Technology Act, 2000 and the rules made thereunder, and take reasonable safeguards
as required under section 8 of the DPDP Act.
9.2 In practice this includes:
● access restricted to the persons working on your task;
● physical documents held in locked storage;
● digital records held on password protected devices and accounts;
● encrypted messaging used for document exchange where available;
● a written record of documents received and returned;
● third parties given only the information their part of the task requires.
9.3 No system is entirely secure. We do not warrant absolute security, and transmission of
information to us over the internet is at your own risk.
10.1 Under the DPDP Act you have the right to:
● obtain a summary of the personal data we hold about you and the processing activities undertaken;
● obtain the identities of other Data Fiduciaries and Data Processors with whom your data has
been shared, and the categories of data shared;
● require correction, completion or updating of inaccurate or misleading personal data;
●
require erasure of personal data no longer necessary for the purpose for which it was
collected, subject to our legal retention obligations;
● nominate another individual to exercise these rights on your behalf in the event of your
death or incapacity;
● readily available means of grievance redressal, as set out in clause 13.
10.2 We respond to a request under clause 10.1 within 30 days of receipt, and may require
verification of your identity before doing so.
10.3 You are responsible for the accuracy of the information you give us, and for not impersonating
any other person or suppressing material information when exercising these rights.
11.1 Our website uses essential cookies necessary for it to function, and analytics cookies
which help us understand which pages are read.
11.2 We do not use advertising cookies, retargeting pixels or third party marketing trackers.
11.3 Non essential cookies are set only after you consent through the notice displayed on your first
visit. You may refuse or withdraw that consent, and you may block cookies through your browser.
The website functions either way.
12.1 Our services are not directed at children and we do not knowingly collect personal data from a
person under 18 years of age.
12.2 Where a task concerns a person under 18, we act only on the instructions of a parent or lawful
guardian, and we process that child’s personal data only with verifiable consent from that parent or
guardian in accordance with section 9 of the DPDP Act.
12.3 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
13.1 Where a personal data breach occurs, we will notify the Data Protection Board of India and each
affected Data Principal in the manner and within the time prescribed under the DPDP Act and the
rules made under it.
13.2 Our notice to you will describe the nature of the breach, its likely consequences, the measures
taken, and the steps you may take to protect your interests.
14.1 Our website may contain links to third party websites. This policy does not apply to them, and
we are not responsible for their content or their handling of personal data.
15.1 If you have a concern about how your personal data has been handled, contact our
Grievance Officer using the details in Schedule A.
15.2 We acknowledge every grievance within 48 hours of receipt and resolve it within 30 days.
15.3 If you are not satisfied with our response, you may make a complaint to the Data Protection
Board of India in accordance with the DPDP Act.
16.1 We may update this policy. The date at the head of this document records when it was last updated.
16.2 Where a change materially affects how we handle your personal data, we will notify you
directly using the contact details we hold for you.