Legal
Privacy Policy & Legal Disclaimer
Effective date: 24 May 2026 · Bindals Law Chambers, New Delhi
Applies to: www.bindalslawchambers.com and portal.bindalslawchambers.com
Bar Council of India Compliance Notice
As per Bar Council of India Rules, advocates are not permitted to solicit work or advertise. This Website and Portal are published solely for informational and practice-management purposes. The information on this Website does not constitute legal advice, nor does accessing it create an attorney-client relationship.
1. Overview and Scope
This Privacy Policy and Legal Disclaimer ("Policy") is published by Bindals Law Chambers, a law firm registered with the Bar Council of Delhi and regulated by the Bar Council of India, with principal offices at E-13/29, Innov8 Harsha Bhawan, 4th Floor, Connaught Place, New Delhi - 110001 (the "Firm", "we", "us", or "our").
This Policy applies to all personal data collected through: (a) our public website at www.bindalslawchambers.com (the "Website"); and (b) our password-protected Client Portal and Lawyer Portal accessible at portal.bindalslawchambers.com (the "Portal"). Where a provision applies only to one of these platforms, it is expressly stated.
This Policy does not apply to information collected by the Firm in the course of a retainer or attorney-client relationship except to the extent that such information is processed through the Portal, which is governed by the provisions of this Policy in addition to engagement-specific confidentiality obligations and professional conduct rules.
By accessing the Website or registering for the Portal, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree, please discontinue use of the Website and Portal immediately.
2. Bar Council of India Disclaimer
As required by the Bar Council of India Rules on Standards of Professional Conduct and Etiquette (Schedule III), the following notice applies to this Website and Portal:
This Website and Portal are maintained solely for informational and practice-management purposes and do not constitute advertising, solicitation, or an invitation to create an attorney-client relationship. The information contained herein is not legal advice and should not be relied upon as such. No action should be taken or omitted on the basis of information on this Website without first obtaining specific legal advice from a qualified advocate.
The Firm does not solicit work or advertise through this Website in a manner prohibited under the Advocates Act, 1961 or the Bar Council of India Rules. Publication of the Firm's areas of practice and credentials is permitted under the Rules solely for the purpose of enabling persons to make an informed decision about engaging the Firm.
Transmission of information to the Firm through this Website or by email does not create an attorney-client relationship. Such a relationship arises only upon execution of a formal engagement letter and acceptance by the Firm.
The Firm makes no representations about the accuracy, completeness, or currency of any legal information published on this Website. Laws and judicial interpretations change frequently; readers should seek current professional advice before acting.
3. Information Collected — Website
Through the public Website, we collect the following categories of personal data:
a) Information you voluntarily provide
- Contact details: name, email address, telephone number
- Organisational information: name of organisation or employer
- Matter information: type of legal matter and brief description as submitted through the inquiry form
- Consultation details: preferred dates, time zone, and pre-consultation notes submitted through our booking platform (Cal.com)
- Correspondence: content of emails, letters, or messages sent to the Firm
b) Information collected automatically
- Technical data: IP address, browser type and version, operating system, referring URL, pages visited, and timestamps
- Cookie data: as described in Section 9 below
We do not collect sensitive personal data as defined under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including passwords, financial information, health data, or biometric data — through the public Website contact and booking forms.
4. Information Collected — Client Portal
The Portal is a password-protected platform used by the Firm's clients and lawyers to manage ongoing legal matters. The following categories of personal data are collected and processed through the Portal:
a) Account and identity data
- Registration credentials: full name, email address, mobile number, and a password (stored as a one-way bcrypt hash; the plaintext password is never retained)
- Client profile: address (line 1, line 2, city, state, PIN), identity document type, organisation name where applicable
- KYC status and consent records
b) Matter and case data
- Case/matter details: matter reference, title, type, court, CNR number, case number, filing date, state code, and status
- Hearing records: hearing dates, purposes, court room, judge name, next date, previous date — shared with clients at the Firm's discretion
- Internal notes: lawyer-authored notes associated with matters (not disclosed to clients)
c) Documents
- Uploaded files: documents uploaded by lawyers or clients (PDF, Word, Excel, image, or plain text), stored in Cloudflare R2 object storage
- Document metadata: filename, file type, file size, upload timestamp, uploader identity, and document category
- Virus scan result: a SHA-256 cryptographic hash of each uploaded file is transmitted to VirusTotal (Google LLC) to check against known malware signatures; the file itself is not transmitted
- Visibility controls: lawyers control whether each document is shared with the client
d) Privileged case facts submissions
- Clients may submit privileged case facts (factual narratives for legal use) through the Portal
- These submissions are encrypted at rest using AES-256 encryption with a dedicated key (PRIVILEGED_CONTENT_KEY) before storage in the database
- Submissions are accessible only to authorised lawyers; access is recorded in an append-only audit log
- Reviewer notes added by lawyers to case facts submissions are internal and are never disclosed to clients
e) Billing and financial data
- Invoice records: invoice number, status, line items, amounts, GST components, due dates, and payment history
- Payment records: payment method, transaction reference, and payment date
- No card numbers, bank account numbers, or UPI credentials are collected or stored by the Firm or the Portal; payment processing is handled entirely by third-party payment gateways outside the Portal
f) Session and technical data
- Session tokens: JSON Web Tokens (JWT) stored as httpOnly, Secure cookies; session tokens are signed and expire automatically
- Audit logs: an append-only record of significant events including login, case facts access, and document downloads, recording actor type, actor ID, action, resource type, resource ID, and timestamp
- Technical metadata: IP address, browser information, and timestamps associated with Portal activity
5. Purposes of Processing
We use personal data collected through the Website and Portal for the following purposes:
Website purposes
- Responding to inquiries and assessing whether the Firm is in a position to assist with a matter
- Scheduling and managing consultation appointments
- Performing conflict-of-interest checks before accepting instructions
- Communicating with prospective clients regarding the Firm's services
- Operating, maintaining, and improving this Website
Portal purposes
- Managing ongoing client-lawyer engagements, including matter records, hearings, documents, and billing
- Enabling clients to access case information, upload documents, submit privileged case facts, and view invoices
- Enabling lawyers to manage all aspects of client matters within the Portal
- Sending transactional notifications: document published alerts, hearing reminders, password reset emails, and invoice notifications
- Maintaining audit trails for regulatory compliance and privilege protection
- Detecting and preventing security threats through virus scanning of uploaded files
Common purposes
- Complying with applicable legal and regulatory obligations, including record-keeping requirements under Bar Council rules
- Establishing, exercising, or defending legal claims
- Internal administration and business continuity
We do not sell, rent, or trade your personal data to third parties for commercial or marketing purposes.
6. Legal Basis for Processing
The processing of your personal data is based on one or more of the following grounds under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000:
- Consent: where you have voluntarily provided your information by completing the contact form, booking a consultation, registering for the Portal, or communicating with us
- Performance of a contract: where processing is necessary to deliver legal services under an engagement letter or to maintain the Portal for the benefit of registered clients
- Legitimate interests: to operate the Firm's practice, conduct conflict checks, maintain client and matter records, communicate about legal services, and ensure the security of the Portal — where such interests are not overridden by your fundamental rights
- Compliance with law: where processing is necessary to comply with a legal obligation applicable to the Firm, including obligations under the Advocates Act, Bar Council rules, or orders of a competent court
7. Disclosure of Your Information
We do not disclose your personal data to third parties except in the following circumstances:
- Platform infrastructure providers: third-party technology providers who host and operate the Website and Portal under appropriate data processing terms (see Section 8 for a full list)
- Professional advisers: other advocates, barristers, or experts retained in connection with a matter, and regulatory or court bodies as required in the course of legal proceedings
- Legal compliance: where required by law, court order, or lawful request by a governmental authority in India
- Conflict checks: limited matter information may be shared with other counsel for the sole purpose of conducting a conflict-of-interest check
- Business transfers: in the event of restructuring or dissolution of the Firm, data may transfer to a successor practice under equivalent confidentiality obligations
- With your consent: for any other purpose to which you have expressly consented
Lawyers registered on the Portal access client and matter data only in the context of their authorised role. Client data is never accessible across unrelated matters or to other clients.
8. Third-Party Services and Platform Infrastructure
The Website and Portal rely on the following third-party services. Each processes data under its own privacy policy. We have listed the data each service receives and the purpose for which it is used:
Hosting and Deployment
- Vercel Inc. (vercel.com) — hosts and serves both the Website and the Portal globally via its edge network. All web traffic, including uploaded files during transit, passes through Vercel's infrastructure. Vercel is incorporated in the United States; data may be processed in multiple global regions. Subject to Vercel's Privacy Policy.
Database
- Neon Inc. (neon.tech) — provides the cloud-hosted PostgreSQL database that stores all Portal data, including client profiles, matter records, hearing data, invoice records, encrypted case fact submissions, document metadata, session tokens, and audit logs. Neon servers may be located outside India. Subject to Neon's Privacy Policy.
Document Storage
- Cloudflare Inc. — R2 Object Storage (cloudflare.com) is used to store documents uploaded through the Portal. Files are stored at rest in Cloudflare's global network. Access to stored files is controlled via time-limited pre-signed URLs generated on demand; files are never publicly accessible by default. Subject to Cloudflare's Privacy Policy.
Transactional Email
- Resend Inc. (resend.com) — used to send transactional emails from the Portal, including document published notifications, hearing date reminders, password reset links, matter linked confirmations, and invoice notifications. Resend receives the recipient's email address, name, and the content of the notification. Resend is incorporated in the United States. Subject to Resend's Privacy Policy.
Malware Detection
- VirusTotal (Google LLC, virustotal.com) — when a document is uploaded to the Portal, a SHA-256 cryptographic hash of the file is transmitted to VirusTotal's API to check whether the file is known to contain malware. The file itself, its name, and its contents are never transmitted to VirusTotal — only the hash. VirusTotal is operated by Google LLC and is subject to Google's Privacy Policy. Files whose hashes are unknown to VirusTotal are treated as clean without further submission.
Source Code Version Control
- GitHub Inc. (github.com) — the source code of the Website and Portal is stored in a private repository on GitHub. No client personal data, document contents, or database credentials are stored in the repository. Subject to GitHub's Privacy Policy.
Website-only services
- Formspree Inc. (formspree.io) — processes contact form submissions on the Website. Data is transmitted to Formspree's servers and forwarded to the Firm's email. Formspree is incorporated in the United States.
- Cal.com (cal.com) — processes consultation booking requests submitted through the Website. Subject to Cal.com's Privacy Policy.
- Google LLC — Google Maps is embedded on the Website and is subject to Google's Privacy Policy.
We recommend reviewing the respective privacy policies of these services before submitting information. The Firm is not responsible for the independent data practices of third-party providers beyond the contractual and technical controls we implement.
10. Data Retention
We retain personal data for as long as necessary for the purposes described in this Policy, or as required by applicable law and professional conduct rules.
Website inquiry data
- Inquiry data from prospective clients who do not proceed to a formal engagement is retained for three years from the date of the inquiry, after which it is securely deleted or anonymised.
Portal data
- Active Portal accounts: retained for the duration of the client-Firm engagement and for a minimum of six years following the conclusion of all matters, in accordance with applicable limitation periods under Indian law
- Uploaded documents: soft-deleted documents (marked isDeleted) are retained for 30 days before permanent deletion from R2 storage; permanently deleted documents cannot be recovered
- Case fact submissions: retained for six years following the conclusion of the relevant matter
- Audit logs: retained indefinitely as they constitute an append-only compliance record
- Session tokens: expire at logout or after the configured session lifetime and are not retained thereafter
- Invoice and billing records: retained for eight years in accordance with applicable accounting and tax laws
You may request deletion of your personal data at any time (see Section 11), subject to the Firm's legal obligations to retain records.
11. Your Rights
Under the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal:
- Right to access: to obtain confirmation of whether we process your personal data and a summary of the data we hold
- Right to correction: to have inaccurate or incomplete personal data corrected — Portal users may update their profile directly through the Portal settings page
- Right to erasure: to have your personal data erased where it is no longer necessary for the purposes for which it was collected, subject to overriding legal obligations (including retention of audit logs and billing records)
- Right to withdraw consent: to withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing
- Right to grievance redressal: to have grievances regarding our data processing practices addressed in a timely manner
- Right to nominate: to nominate a person to exercise your rights in the event of your death or incapacity
To exercise any of these rights, please contact our Grievance Officer as detailed in Section 12. We will acknowledge your request within 48 hours and endeavour to resolve it within 30 days.
You also have the right to lodge a complaint with the Data Protection Board of India once constituted under the DPDP Act, 2023.
12. Grievance Officer
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the Firm has designated the following Grievance Officer for data protection matters:
Name: Anurag Bindal Firm: Bindals Law Chambers Address: E-13/29, Innov8 Harsha Bhawan, 4th Floor, Connaught Place, New Delhi - 110001 Email: info@bindalslawchambers.com Working hours: Monday to Saturday, 10:00 AM – 6:00 PM IST
Grievances may be submitted by email or in writing. We will respond to all grievances within 30 days of receipt.
13. Data Security
We implement the following technical and organisational measures to protect personal data:
In transit
- All communications between your browser and the Website or Portal are encrypted using TLS 1.2 or higher (HTTPS). HTTP connections are redirected to HTTPS.
- Documents are transmitted to Cloudflare R2 over encrypted connections; download links are time-limited pre-signed URLs that expire automatically.
At rest
- Passwords are hashed using bcrypt with a work factor of 12 before storage; plaintext passwords are never stored or logged
- Privileged case fact submissions are encrypted using AES-256 encryption with a dedicated encryption key before storage in the database
- Database credentials, API keys, and encryption keys are stored as encrypted environment variables in Vercel and are never committed to source code
Access controls
- Role-based access: clients, lawyers, and administrators access only the data their role permits; client data is scoped to the authenticated client's own matters
- Session management: authenticated sessions use signed, httpOnly, Secure JWTs; sessions expire automatically and are invalidated on logout
- Audit logging: an append-only audit log records access to privileged data, including case fact submissions
File safety
- Every uploaded document is checked against the VirusTotal malware database by hash before it is made available for download
- Files flagged as infected are quarantined and cannot be published to clients or downloaded
No method of transmission over the Internet is completely secure. We cannot guarantee absolute security and are not responsible for breaches that are beyond our reasonable control. In the event of a personal data breach likely to result in risk to you, we will notify you as required by applicable law.
14. Cross-Border Data Transfers
The following third-party services that we use may process your personal data outside India:
- Vercel Inc. — United States and global edge network (Website and Portal hosting)
- Neon Inc. — United States (Portal database)
- Cloudflare Inc. — Global network (Portal document storage)
- Resend Inc. — United States (transactional email)
- Google LLC / VirusTotal — United States (malware hash lookup)
- Formspree Inc. — United States (Website contact forms)
- Cal.com — as per Cal.com's data processing terms (Website booking)
By submitting information through the Website or registering for the Portal, you acknowledge and consent to the transfer of your personal data to these countries and regions for the purposes described in this Policy.
We take reasonable steps to ensure that any such transfers comply with applicable data protection law and that the receiving party provides an adequate level of protection, including through contractual data processing agreements where applicable.
15. Children
The Website and Portal are not directed at, and do not knowingly collect personal data from, persons under 18 years of age. Minors should not submit personal data or register for the Portal without the consent and supervision of a parent or legal guardian.
If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete such data promptly.
16. External Links
The Website and Portal may contain hyperlinks to third-party websites, including court portals, regulatory bodies, and legal databases. The Firm is not responsible for the content or privacy practices of those websites and this Policy does not apply to them. We recommend reviewing the privacy policy of any third-party site you visit.
17. Intellectual Property
All content on this Website — including text, graphics, logos, articles, and design — is the property of Bindals Law Chambers or its content contributors and is protected under the Copyright Act, 1957 and applicable intellectual property laws of India.
You may not reproduce, distribute, modify, or commercially exploit any content from this Website without the Firm's prior written consent. Limited copying for personal, non-commercial use is permitted with appropriate attribution.
The Insights articles published on this Website are general commentary on legal developments and do not constitute legal advice.
The Portal, including its code, design, and features, is proprietary software of the Firm. Clients are granted a limited, non-transferable, non-sublicensable licence to access and use the Portal solely for the purposes of their legal engagement with the Firm.
18. Limitation of Liability
To the fullest extent permitted by law, the Firm, its partners, associates, and employees exclude all liability for any loss or damage — direct, indirect, incidental, consequential, or punitive — arising from:
- Reliance on any information published on this Website
- Inability to access or use this Website or the Portal
- Unauthorised access to or alteration of your data by third parties
- Service interruptions, outages, or errors in third-party platforms (including Vercel, Neon, Cloudflare, or Resend)
- Any content or conduct of any third party on or linked from this Website or the Portal
- Errors or omissions in document scan results provided by VirusTotal
Nothing in this Policy limits liability that cannot be excluded by law, including liability for fraud or wilful misconduct.
19. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, applicable law, or the services we use. The revised Policy will be published with an updated effective date at www.bindalslawchambers.com/privacy and is also accessible from the Portal footer. Where changes are material, we will take reasonable steps to notify you — including by email to registered Portal users. Continued use of the Website or Portal after the revised Policy takes effect constitutes acceptance of the revised terms.
20. Governing Law and Jurisdiction
This Policy is governed by the laws of the Republic of India, including the Information Technology Act, 2000, the Information Technology (Amendment) Act, 2008, and the Digital Personal Data Protection Act, 2023. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at New Delhi.
21. Contact
For any questions or concerns about this Policy, please contact:
Bindals Law Chambers E-13/29, Innov8 Harsha Bhawan, 4th Floor, Connaught Place, New Delhi - 110001 Telephone: +91 93549 55947 Email: info@bindalslawchambers.com
© 2026 Bindals Law Chambers. All rights reserved.
Registered with the Bar Council of Delhi. Advocates regulated by the Bar Council of India.
