Data protection

How Aadhrix approaches India's Digital Personal Data Protection Act, 2023.

This page describes what this platform actually does under the DPDP Act, 2023, and where its Rules currently stand — plainly, and without claiming a certification that does not exist. It is an engineering position, not legal advice; see the disclaimer at the end.

Where the law currently stands

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, with a staggered, three-phase commencement set by the Ministry of Electronics and IT itself:

  1. 14 November 2025 — only the procedural and administrative provisions took effect (definitions, and the Data Protection Board's own constitution and procedure). Nothing here yet requires consent managers, breach notification, or data-principal-rights machinery.
  2. 14 November 2026 — the registration and oversight framework for Consent Managers (Rule 4) takes effect; only an India-incorporated entity meeting the Rules' own financial and fiduciary conditions may register to operate as one.
  3. 14 May 2027 — the core data-protection obligations and rights become effective: consent, purpose limitation, breach notification, and data-principal rights, eighteen months after notification.

Aadhrix is in that first phase today: none of the Act's substantive obligations are yet legally in force. That does not make the practices on this page optional — they are followed as good practice ahead of that date, not because a deadline requires them yet.

What counts as your personal data here

Your name, mobile number, email address (where collected), and the case data you enter or upload. One thing worth being precise about: the internal record of which source backed which sentence of an answer or draft — kept permanently, for accountability — does not identify you by name on its own. It carries an account reference with no guaranteed live row behind it, plus the text and source it points to, nothing more.

Retention, by data class

Login & auth activity

90 days, then automatically removed.

Anonymous conversations

Removed by a time-boxed cleanup job, not kept indefinitely.

A matter's own records

Hearings, documents, drafts, fee entries — kept for as long as the account exists. Deleted only when the account is erased.

The evidence ledger

Which source backed which sentence — permanent, and cannot be edited, by design.

Owner-action audit trail

Permanent, append-only, internal to Aadhrix — it exists to hold Aadhrix accountable, not as a record about you.

Session tokens

Revoked when you sign out, and deleted along with your account on erasure.

There is no single blanket retention policy across every table — the categories above are the honest inventory, not a rounded-off simplification.

Your rights as a data principal, today

Access & portability

You can request a complete export of every record tied to your account.

Correction

Most of your own profile details are already correctable directly inside the product, under Settings.

Erasure

A real, irreversible deletion of your account and its data — not a deactivation. Available directly inside the product today, as “Relinquish My Account” under Settings (or your Profile page, for a citizen account).

Access/portability and correction are still handled by writing to hello@aadhrix.com rather than a self-service button — a real, disclosed gap, not smoothed over. See our grievance page for how a request like this is handled.

Consent

Every account starts with an explicit consent checkbox at signup, not pre-ticked for you. Setting up a separate Advocate Workspace — a distinct step that submits your real Bar enrolment number and State Bar Council for review — asks for its own explicit consent again at that point, rather than silently relying on whatever the original signup already covered.

Breach detection and notification

There is no automated breach-detection tooling, and no tested breach-notification runbook, in place today. This is a real gap we are naming rather than glossing over. If that changes, or if the law requires it of us once Phase 3 above takes effect, we will notify affected users and, where required, the Data Protection Board of India.

Grievances

For a data protection concern specifically, or any other complaint about the platform, see our Grievance Officer page for how to reach us and what to expect.

This page is an engineering description, not legal advice. It describes what this codebase does today, and should not be relied on as a compliance opinion. See also our security page and Privacy Policy.

← Back to Aadhrix