Privacy Policy
At VidhiMeet, privacy and legal confidentiality are foundational obligations. As a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data with strict adherence to purpose limitation, data minimization, and field-level encryption. This Privacy Policy outlines how your personal data, consultation metadata, and legal documents are gathered, processed, secured, and purged.
1. Information Collected & Mandatory Age Verification (DPDP Act §9)
To operate a compliant legal marketplace, we collect the following categories of data:
- Profile & Verification Data: User full name, email address, date of birth (stored to verify DPDP §9 18+ legal capacity), and password hash. Advocate profiles store Bar Council enrollment numbers, practice addresses, Aadhaar numbers, and verified bank account/UPI details.
- Consultation & Case Artifacts: Intake form responses, appointment schedules, encrypted chat transcripts, document drafting proposals, and uploaded case PDFs/DOCX files.
- Automated Telemetry & Network Logs: IP address, user-agent details, and video room connection durations (used solely for dispute resolution and security rate-limiting).
2. Field-Level AES-256 Encryption at Rest
Unlike standard web directories, sensitive PII and financial records in VidhiMeet are protected by **field-level encryption at rest** using Fernet AES-256 keys (`EncryptedString` database decorator):
- Encrypted Advocate Credentials: Aadhaar numbers, practice addresses, bar license URLs, and mobile numbers are stored in encrypted format in the database engine.
- Encrypted Financial Records: Advocate bank account numbers and IFSC codes are encrypted at rest and masked in UI displays (`••••••••1234`).
- Case Document Vault: Uploaded draft documents and intake attachments are stored in private encrypted storage accessible only via short-lived, signed URLs.
3. Consent Management & Data Principal Rights (DPDP Act 2023)
Under the DPDP Act 2023, clients and legal professionals retain full authority over their personal data as Data Principals:
- Explicit Consent Logging: Account creation and consultation bookings log explicit consent timestamps tied to specific policy versions (`v1.0`).
- Right to Access & Correction: Users can inspect and update profile details, bank details, and consultation records via their portal dashboard.
- Right to Erasure & Consent Withdrawal: You may withdraw consent or request complete erasure of your platform data by contacting our Data Protection Officer. Upon request, automated purge routines (`data_retention_purge.py`) sanitize your account records while preserving statutory tax/escrow audit logs.
4. Forensic Timestamps & Automated Data Retention Purge
In accordance with CERT-In cybersecurity directives and tax retention guidelines:
- NTP Timestamp Verification: Consent logs, audit trails, and dispute records are timestamped using NTP-synchronized UTC/IST clocks (`ntp_time.py`) to prevent forensic alteration.
- Automated Retention Schedule: Revoked refresh tokens, expired session keys, and withdrawn consent data are automatically purged on a scheduled basis.
5. Designated Data Protection Officer (DPO) & Incident Notification
In compliance with DPDP Act rules and CERT-In mandates, VidhiMeet maintains a dedicated Data Protection Officer desk. In the unlikely event of a security incident affecting personal data, impacted Data Principals and the Data Protection Board of India will be notified within statutory timelines (72 hours).
6. Contact Data Protection Officer
To exercise your data rights, request data erasure, or log a privacy complaint, reach our DPO desk at dpo@vidhimeet.in or privacy@vidhimeet.in.