Privacy Policy
This Privacy Policy explains how we collect, handle, protect, and systematically isolate data across the platform, digital applications, API endpoints, and automation services provided under the brand name DhiTantra(collectively, the "Platform").
Privacy at a Glance
- We never sell your personal data.
- Enterprise workspace data is never used for shared AI model training.
- You retain complete control and deletion rights over your uploaded documents.
1. Who We Are & Compliance Frame
1.1 The Entity: DhiTantra builds legal intelligence and execution infrastructure for citizens, students, legal professionals, and organizations in India. The Platform is operated by JNANAPRAVIDHI TECHNOLOGIES PRIVATE LIMITED ("the Company", "we", "us", or "our"), a company incorporated under the Companies Act, 2013, bearing CIN: U62011MH2026PTC470656, and having its registered office at Green Meadows, Lokhandwala, Kandivali East, Mumbai 400101.
1.2 Statutory Framework: This policy is designed to comply with applicable data protection laws in India, specifically the Digital Personal Data Protection (DPDP) Act, 2023. For the purposes of processing Personal Data under the DPDP Act, the Company acts as a Data Fiduciary, and where we process information strictly on behalf of an enterprise subscriber or corporate entity, we act as a Data Processor.
2. Information We Collect and Process
We collect and process only the information strictly necessary to safely deploy, monitor, execute, and scale our legal intelligence tools. This is categorized into:
- Account and Sign-Up Information: Your name, corporate or academic email address, telephone number, professional role, organization/firm details, and billing/GST data.
- Audio and Voice Data: Voice inputs and audio commands captured during interactions with our Multilingual AI Legal Assistant. Audio processing is handled strictly via transient memory channels to convert voice commands into structured text.
- Workspace Content and Case Artifacts: Natural language legal queries, uploaded document briefs, FIR records, land transcripts ($7/12$ extracts), contract profiles, court orders, litigation histories, witness statements, and synthetic texts generated by our automated multi-agent engines during active user sessions.
- Technical, Usage, and Telemetry Data: Internet Protocol (IP) addresses, device identifiers, browser types, interaction logs, latency metrics, and feature engagement history collected automatically to secure our computing infrastructure.
- Support Communications: Correspondence, error logs, and tickets generated when you communicate with our customer success or engineering teams.
3. Purpose of Processing (How We Use Information)
We utilize your information strictly to maintain the functional integrity of the Platform, specifically:
- To provision your private workspaces, calculate usage tiers, execute multi-agent legal processing, and drive real-time automated search, parsing, and legal drafting functions.
- To execute automated portal dispatches and facilitate connection features on behalf of the user at their explicit request.
- To detect, investigate, and mitigate systemic abuse, automated scraping, or intellectual property violations.
- To communicate essential security alerts, infrastructure modifications, system maintenance notices, and regulatory compliance updates.
- To run internal, aggregated diagnostic evaluations aimed at optimizing inference speeds and refining our custom retrieval pipelines (RAG).
4. Enterprise Isolation & AI Guardrails (Model Training Statement)
4.1 The Training Wall: The Company enforces an absolute wall regarding machine learning optimization. We do not utilize your confidential Workspace Content, proprietary case briefs, uploaded legal instruments, voice records, or structural prompt queries to train, fine-tune, or reinforce any public or multi-tenant machine learning models.
4.2 Confidentiality: All uploaded matter-related documents are treated as highly confidential enterprise data. We do not engage in the sale, monetization, or unauthorized distribution of user-provided information.
4.3 Private Architectures:For qualifying enterprise clients, corporate legal departments, and government units, we provide isolated Virtual Private Cloud (VPC) deployments or air-gapped systems where session inputs never leave your firm's designated local perimeter.
5. Authorized Third-Party Sharing and Data Intermediaries
We do not share your private data except in the following limited, legally protective contexts:
- Infrastructure Intermediaries: We route data through secure, heavily vetted cloud hosting platforms, encrypted database clusters, and enterprise API foundation model providers (such as Google Cloud Vertex AI, Azure Speech, or Groq). These providers operate under strict business associate agreements containing zero data-retention and zero model-training policies.
- User-Driven Collaboration & Dispatches: We transmit workspace content to other users strictly at your direction (e.g., sharing a matter bundle within your firm's domain or executing a direct portal dispatch to a regulatory system).
- Legal and Regulatory Mandates: We may disclose your data if required to do so by a valid legal order, judicial decree, warrant, or statutory requirement issued by a competent regulatory authority or law enforcement agency within the jurisdiction of India.
- Cross-Border Transfer & Cloud Processing: To deliver high-performance legal inference speeds, the Platform utilizes secure cloud computing nodes and data centers. You explicitly consent to the secure transfer and processing of your technical data across these protected infrastructure environments, provided that our strict data isolation, zero model-training, and zero-retention policies remain fully enforced.
6. Technical Security and Data Infrastructure
We implement rigorous administrative, logical, and physical security measures to safeguard your legal workflows:
- Encryption Architecture: Data is encrypted continuously while in transit using Transport Layer Security (TLS 1.3) and while at rest across our clusters using Advanced Encryption Standard with a 256-bit key length (AES-256).
- Identity Controls: System access relies on strict role-based access control (RBAC), multi-factor authentication protocols, and least-privilege production access configurations.
- User Responsibility: While we maintain strict platform safeguards, you remain entirely responsible for the protection, stewardship, and secrecy of your individual account passwords and authentication tokens.
7. Retention and Structured Erasure
7.1 Retention Span: We store your personal information and account metrics for as long as your subscription is active, or as required to fulfill the business operations defined in Section 3, or to comply with statutory accounting and tax regulations.
7.2 Erasure Autonomy: You maintain full ownership over your data. Upon your request for account deletion or individual workspace purging, the corresponding documents are immediately flagged for erasure and completely purged from all live application nodes, indexing blocks, and transient caching layers within twenty-four (24) hours, unless preservation is mandated by law.
8. Your Statutory Rights under Indian Law
In complete alignment with the DPDP Act, 2023, users within India possess explicit statutory rights regarding their personal data, including:
- Right to Access and Summary: The right to review a summary of the personal data currently being processed by us and the identities of third-party processors with whom it has been shared.
- Right to Correction and Erasure: The right to correct inaccuracies, update outdated records, or complete missing attributes, alongside the right to demand erasure of personal data that is no longer necessary for the purpose it was collected.
- Right to Grievance Redressal: The right to register an official complaint with our internal Grievance Officer regarding any perceived data handling issue before escalating to external regulatory bodies.
- Right to Multilingual Consent: The right to access consent notices and privacy summaries in English as well as the languages specified in the Eighth Schedule to the Constitution of India, ensuring transparent processing for all users.
- Right to Nomination: Under Section 14 of the DPDP Act, you possess the right to nominate any other individual to exercise your data rights in the event of death or physical/mental incapacity.
- Consent Management & Withdrawal: You may review, manage, or withdraw your consent at any time. Withdrawal does not affect the legality of processing performed prior to the withdrawal.
9. Age Constraints & Academic Onboarding
Outside of specific student workspace modules provisioned under educational institutional licenses (such as university deployment for LexArena), the Platform is engineered for legal professionals, corporate entities, and adult citizens. We do not knowingly collect or process personal data belonging to unsupervised minors under the age of eighteen (18) years.
10. Modifications to this Policy
We reserve the right to revise, restructure, or update this Privacy Policy to mirror advancements in our infrastructure security or shifting legal interpretations. We will communicate material changes directly inside the platform workspace or via your registered corporate email address prior to the deployment of the modified policy.
11. Grievance Officer and Contact Infrastructure
In compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details of the Grievance Officer are provided below:
- Name: Mr. Anuj Mishra
- Designation: Grievance Officer / Data Protection Officer
- Entity: JNANAPRAVIDHI TECHNOLOGIES PRIVATE LIMITED
- Registered Address: Green Meadows, Lokhandwala, Kandivali East, Mumbai 400101
- Email: privacy@dhitantra.ai
We are committed to acknowledging your grievance within 24 hours and resolving it within 15 days of receipt.