At Jagriq, protecting your data — and the data of the clients you serve — is central to everything we build. This policy explains what we collect, why, how we keep it safe, and the rights and controls you have.
Jagriq is a legal-technology platform operated by Deephash Technologies Pvt. Ltd.. In this policy, "Jagriq", "we", "us" and "our" refer to Deephash Technologies Pvt. Ltd., the Data Fiduciary for the personal data described here. We process personal data in line with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules.
Effective 2026-07-04. Last updated 2026-07-04.
1. Who this covers, and our role
This policy applies to visitors to our website, individuals who use Jagriq, and the client, matter and document data our users manage on the platform.
If you use Jagriq as a firm or organisation: when you use Jagriq to work on your own clients' matters, your firm is the Data Fiduciary for that client data and Jagriq acts as your Data Processor — we process it only on your instructions and under our agreement with you. A Data Processing Addendum is available on request. You decide who in your organisation can access what (see Section 5).
This notice is written in English; we will provide it in Hindi or another language on request.
2. What we collect
We collect only what we need to run the service for you, in three ways: directly from you (when you sign up, add details, upload content or contact us); automatically (usage and device data as you use the platform); and from your organisation (where a firm gives you access to its Jagriq workspace).
Account & identity — your name, email, and (for mobile sign-in) phone number; your verification status and multi-factor authentication settings; and, if you sign in with Google or Apple, the identifier they provide. Your password is held by our identity provider and is never stored on Jagriq's own servers.
Professional details (advocates) — where you choose to add them: bar enrolment number, bar council and state, year of enrolment, Advocate-on-Record number, chamber address, languages and practice areas.
Billing details — billing name and address, state, PIN code and GSTIN where applicable. Payments are handled by our payment partner; we keep the transaction reference, amount and method, and never store your full card number, CVV or banking credentials.
Content you provide — documents you upload (such as judgments, petitions, agreements and notices), matter and case information, party details, your queries, and data we derive from your content to power features (for example extracted text, summaries and search indexes). Some fields you enter may include sensitive personal data, which we protect with additional safeguards.
Communications — where you connect an email, WhatsApp or messaging account, the messages, attachments and counterparty details within your matters, and the authorisation you grant. Credentials for connected accounts are stored encrypted and never shown to us in plain text.
Usage & device data — IP address, device and browser details, and interaction and session logs, used for security, reliability and improving the service.
Enquiries — when you contact us, request a demo or fill in a form, the name, email, phone, organisation and message you submit.
3. How we use your data, and our lawful basis
We use your data to provide and operate Jagriq; to keep it secure and prevent fraud and abuse; to provide support; to meet our legal and regulatory obligations; and — with your consent — to send you product or marketing communications, which you can opt out of at any time using the unsubscribe link in any such message or by emailing us. Under the DPDP Act we rely on your consent, on the Act's legitimate uses, and on our contractual and legal obligations as our lawful bases.
4. AI features and our no-training promise
Jagriq uses artificial intelligence to power research, drafting, document intelligence and related features. We do not use your documents, matter data, client data or queries to train or improve any AI model — ours or a third party's. The AI providers we work with are bound by contract to the same commitment and to strict confidentiality. AI output is decision-support and should always be verified by a qualified professional before use. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing — a qualified person is always responsible for the outcome.
5. How we keep your data safe
Security and confidentiality are core to a platform built for legal work, so we are specific about how we protect your data:
- Isolation between organisations — every organisation's data is logically separated from every other's. Access is scoped to your organisation and checked on every request, so one customer can never see another's data.
- Ethical walls within your firm — you can restrict a sensitive matter to a named team. Anyone outside that wall — including firm administrators — cannot see it, and the wall applies right down to the underlying files.
- Encryption — your data is encrypted in transit (TLS) and at rest using managed keys. On Enterprise plans, your organisation can have a dedicated encryption key.
- Access-controlled storage — documents are stored under a dedicated per-organisation path and are served only through short-lived, access-checked links — never public URLs.
- Audit trail — sensitive actions are recorded in an immutable audit log, so access can be reviewed.
- Need-to-know staff access — our team does not access your matter content except where you ask us to help you, under audited controls; ethical walls apply to our staff too.
- Recognised standards — our security programme is designed around recognised information-security standards, including the principles of ISO/IEC 27001, and the reasonable-security-practices requirements of Indian law.
- Data residency & transfers — your data is hosted and stored in India (Amazon Web Services, Mumbai region). Where a feature relies on a specialist AI provider, that processing is carried out under strict contractual confidentiality and no-training terms, and confidential matter content is routed to in-region processing where available. Where any personal data is processed outside India, we ensure it is protected by contractual safeguards giving a comparable level of protection, consistent with applicable law.
6. When we share data, and our sub-processors
We never sell your personal data. We share it only:
- with service providers (sub-processors) who help us run the platform under contracts requiring confidentiality, security and no independent use of your data. Our principal sub-processors are Amazon Web Services (cloud hosting, identity, and email/SMS delivery — in India), our payment gateway for payments, Twilio and WhatsApp/Meta for messaging, Sarvam AI for Indic translation, and enterprise AI providers (Microsoft Azure OpenAI and AWS Bedrock, running in Indian regions) that power our AI features under no-training terms;
- with services you choose to connect (such as your email or calendar), acting on your authorisation;
- where required by law or in response to a lawful request from a competent authority; and
- with your consent, or as needed to complete something you ask us to do.
Our Sub-processors are published on a dedicated page, which we keep current.
7. How long we keep your data, and erasure
We keep personal data for as long as we need it to provide the service and to meet our legal, accounting and regulatory obligations. As a guide: account and profile data is kept while your account is active; matter and client data is kept for as long as your organisation instructs; and security and processing logs are kept for a limited period (typically up to 12 months) for audit and compliance. When data is no longer needed, we delete it or irreversibly de-identify it.
You can ask us to erase your personal data; on a verified request we will delete it — including your documents and matter content — within 30 days, except where we are required or permitted by law to retain it (for example under a legal hold). Data held under a retention or legal-hold obligation is deleted once that obligation ends.
8. Your rights under the DPDP Act
You have the right to:
- access a summary of the personal data we hold about you and how we use it;
- correct, complete or update inaccurate or incomplete data;
- erase your personal data, subject to Section 7;
- nominate someone to exercise your rights in the event of death or incapacity;
- withdraw consent at any time — as easily as you gave it, including through a registered Consent Manager where available (this does not affect processing already carried out); and
- raise a grievance and, if unresolved, complain to the Data Protection Board of India (Section 9).
To exercise any of these, email support@jagriq.com or use our data rights request form. We may need to verify your identity first. If your data is managed by a firm using Jagriq, we will direct your request to that firm as the Data Fiduciary.
Your responsibilities: The DPDP Act also asks you to provide accurate and genuine information, to exercise your rights honestly, and not to impersonate anyone or raise false or frivolous grievances.
9. Grievance redressal
If you have any concern about how we handle your personal data, contact our Grievance Officer:
Arpan Manna, Grievance Officer — Deephash Technologies Pvt. Ltd. Email: support@jagriq.com · Phone: +91 91471 43399 Blue Lotus, 5th Floor, AG 347, Krishnapur, Kolkata, West Bengal 700102, India
We will acknowledge your grievance within 7 days and work to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India. See our Grievance Redressal Policy for the full process.
10. If a data breach happens
If a personal-data breach occurs, we will act without undue delay to contain and remediate it, and will notify affected individuals and the Data Protection Board of India within the timelines prescribed under the DPDP Act and its rules.
11. Children's data
Jagriq is intended for users aged 18 and over, and we do not knowingly collect children's personal data. We do not track, profile, or serve targeted advertising to children. Where a child's data appears within a user's matter, we process it on that user's instructions and rely on them to obtain any consent required by law, including verifiable parental consent.
12. Cookies and analytics
We use cookies and browser storage as described in our Cookie Policy. We do not use them for advertising or to track you across other websites.
13. De-identified and aggregated data
We may produce aggregated or de-identified statistics that cannot identify you (for example, overall feature usage) to operate, secure and improve the platform. This information is not personal data.
14. Users outside India
Jagriq is built for India and your data is stored in India. If you access Jagriq from another region, additional rights may apply:
- European Economic Area / United Kingdom (GDPR): you also have rights to data portability, to restrict or object to processing, and not to be subject to decisions based solely on automated processing that produce legal effects. Our lawful bases are consent, contract, legal obligation and legitimate interests, and any international transfer is protected by appropriate safeguards.
- California (CCPA/CPRA): you have rights to know, access, correct and delete your personal information and to opt out of its "sale" or "sharing" — we do not sell or share personal information — and we will not discriminate against you for exercising your rights.
To exercise any of these, contact support@jagriq.com.
15. Changes to this policy
We may update this policy from time to time. We will post material changes on this page with a revised "last updated" date, and notify you where required.
16. Contact us
Deephash Technologies Pvt. Ltd. (operating Jagriq) Blue Lotus, 5th Floor, AG 347, Krishnapur, Kolkata, West Bengal 700102, India CIN: U62013WB2025PTC282180 · GSTIN: 19AALCD9642D1ZD General: support@jagriq.com · Privacy & rights: support@jagriq.com · Phone: +91 91471 43399