Data & Privacy

How we handle your client data

You hold privileged material on behalf of your clients. You are entitled to know exactly where it sits and who can reach it. This page describes what the system actually does — not what sounds reassuring.

Last updated 28 August 2026

The short version

  • Your data is stored on a server in Mumbai. It does not leave India.
  • Passwords are hashed, and cannot be read or recovered by anyone — including us.
  • We do not sell your data, show advertising against it, or train AI models on it.
  • Only people you invite into your chambers can see your matters.
  • You can export everything, and you can ask for all of it to be deleted.
01

What we hold

Only what the app needs to run your practice. There is no analytics package, no advertising pixel, and no third-party tracker anywhere on the signed-in pages.

  • Chambers profile. Name, Bar Council enrolment number, address, phone, email, and the UPI or bank details that appear on your invoices.
  • People in your chambers. Name, email, assigned role, and a hashed password. Nothing else.
  • Clients. Name, contact details, address, type, referrers, and any notes you write.
  • Matters. Case numbers, CNR, court, hall, judge, opposing counsel, parties, status and dates.
  • Hearings. Date, time, court, hall, stage, judge, cause list number and your notes.
  • Tasks, invoices and notes. Including who created or changed each task, and when.

Task records keep an audit trail — who created a task, who moved it, who completed or removed it. Deleted tasks are retained rather than erased so that trail stays intact; only the Head of Chambers can see them.

02

Where it lives

On a dedicated server in AWS Asia Pacific (Mumbai), region ap-south-1, in a PostgreSQL 18 database. Your records are not replicated to servers outside India.

The database listens only on the server’s own loopback interface. It is not reachable from the internet at all — not with a password, not from anywhere. Only the application running on that same machine can open a connection to it.

Traffic between your browser and the application is served over HTTPS, with certificates issued by Let’s Encrypt and renewed automatically.

If Google Sheets sync is switched on

Vakeel can mirror your records into a Google Sheet you own, so they are reachable from a spreadsheet. While that is enabled, a copy of your data sits in Google’s infrastructure under your own Google account — governed by Google’s terms rather than ours, and possibly stored outside India. You control it entirely: clear the Apps Script URL under Chambers Setup → Data & Sync and nothing further is sent. Rows already in your sheet remain until you delete them.

03

Who can reach it

Access is decided on the server, on every single request. The interface hides what you cannot use, but the hiding is not the protection — the server independently refuses anything your role does not permit.

Permissions are re-read from the database on each request rather than trusted from your session token. When the Head of Chambers changes someone’s role or deactivates their account, it takes effect on their very next action — not whenever their session happens to expire.

Operational access. One administrator holds credentials to the server, for the purpose of keeping it running: applying updates, restoring from backup, and investigating faults. Your case records are not read as part of that work. The only circumstance in which anyone would open your data is a support request you have made, about a specific problem, and only for as long as it takes to resolve it.

04

How it is protected

  • Passwords. Hashed with bcrypt at cost 12. We cannot read them, recover them, or tell you what yours is — only reset it.
  • Sessions. A short-lived access token, plus a separate refresh token held in a cookie that JavaScript cannot read. That limits what a cross-site scripting flaw could steal.
  • Refresh tokens. Stored only as a SHA-256 hash and rotated on every use. A token that has already been used is rejected, so a stolen one is usable at most once.
  • Password changes. Sign out every other device immediately.
  • Invoice totals. Recomputed on the server from the line items, so an amount cannot be altered in the browser.
  • Operating system. Security updates applied automatically, without waiting for a maintenance window.

Backups. The server’s storage volume is snapshotted daily, which allows the whole machine to be rebuilt. Separate off-site database backups are being rolled out and are not yet in place. We would rather tell you that plainly than describe an arrangement that does not exist yet — if a guaranteed recovery time matters to your practice, ask us where this stands before you commit.

05

What we never do

  • Sell, rent or share your records with anyone.
  • Show advertising, or let an advertising network see your data.
  • Train machine-learning models on your client records.
  • Read your matters for any purpose other than a support request you have made.
  • Load third-party trackers or analytics scripts on the signed-in pages.

If any of this ever changes, it will be announced before it takes effect — not edited quietly into this page.

06

Getting your data out

The records are yours. You can export them at any time in a format you can open elsewhere. You should never need our permission to leave, and there is no charge for taking your data with you.

To have your account and its data deleted, write to itsvishnups@gmail.com. We will confirm the request within two working days and complete the deletion within thirty days.

Retention. When an account is closed, its data is held for 90 days and then permanently deleted. The window exists so an account closed by mistake can be recovered; daily snapshots rotate out inside the same period, so no copy outlives it. If you would rather have your records erased sooner, ask and we will do it.

Bear in mind that advocates have their own record-keeping obligations. If you need material returned rather than destroyed, export it before you close the account.

07

Your rights under the DPDP Act

India’s Digital Personal Data Protection Act, 2023 gives people whose personal data you hold the right to ask what is held about them, to have it corrected, to have it erased, and to raise a grievance. Where we process data on your behalf, we will help you answer those requests.

Grievance officer

Vishnu Prasad S — responsible for privacy grievances relating to Vakeel.
itsvishnups@gmail.com

Complaints are acknowledged within two working days and answered within thirty.

Your own obligations. Where you enter client details into Vakeel, you are the one who decided to collect them. Your duties to those clients — including under the Advocates Act and your professional conduct rules — remain yours. We are the processor; you are the decision-maker.

If something goes wrong. If we become aware of a breach affecting your data, we will tell you without undue delay and in any event within 72 hours of becoming aware of it, and notify the Data Protection Board as the Act requires. You will be told what happened, what was affected, and what to do about it.

08

What we do not claim

Security pages usually list certifications. Here is what this service has not been assessed against, so you are not left to assume:

  • No SOC 2 report.
  • No ISO 27001 certification.
  • No independent penetration test has been published.
  • No formal uptime guarantee outside a signed agreement.

The service runs on a single server. That keeps it simple and keeps your data in one jurisdiction, but it means a hardware failure affects availability until the machine is restored. If your practice needs a guaranteed recovery time, ask us before you commit — we would rather tell you now than disappoint you later.

09

Changes to this page

Material changes are announced in the app before they take effect, and the date at the top of this page is updated whenever anything here changes.

Questions about any of this, or about how your chambers’ data is handled: itsvishnups@gmail.com

This page explains how Vakeel handles data. It is not legal advice, and it does not replace your own obligations to your clients.