Section 01
Overview
- 1.1This Privacy Policy describes how Legal Dictum collects, uses, stores and protects personal data when you use legaldictum.in, and serves as the notice contemplated by the Digital Personal Data Protection Act, 2023 ("DPDP Act") read with the Digital Personal Data Protection Rules, 2025.
- 1.2This policy is additionally informed by the Information Technology Act, 2000 and rules made under it, to the extent they continue to apply.
- 1.3By signing in and using the platform, you give your consent to the processing of your personal data for the purposes described in this policy. Consent is given by a clear affirmative action — creating an account and continuing to use the platform. If you do not consent, you must not sign in or use the platform.
- 1.4You may withdraw your consent at any time, as easily as it was given, as described in Section 11. Withdrawal does not affect the lawfulness of processing done before withdrawal.
- 1.5This policy should be read alongside our Terms and Conditions, which govern your use of the platform.
Section 02
Who We Are
- 2.1Legal Dictum is an online legal education platform based in India, operating at legaldictum.in. For the purposes of the DPDP Act, Legal Dictum is the Data Fiduciary for the personal data described in this policy, and you are the Data Principal.
- 2.2For privacy-related queries and to exercise any right under this policy, contact us through the Contact page at legaldictum.in/static/contact.html → Raise a Grievance, or write to support@legaldictum.in.
Section 03
Personal Data We Process
- 3.1We collect only the data necessary to provide our services. The following is an itemised description of the personal data we process:
| Personal data | When collected | Purpose |
|---|---|---|
| Name | From your sign-in provider (currently Google) when you create an account | To identify and personalise your account |
| Email address | From your sign-in provider when you create an account | Account identification, sign-in, essential communications |
| Plan status and validity | On plan purchase | To determine your content access rights |
| Daily usage records (credits and peeks used) | Each time content is opened on a free account | To operate the daily free allowance |
| Content access history | Each time content is accessed | To enable repeat access, "continue where you left off" and your history |
| Test attempt records (answers, scores, timing) | On test start, submission or abandonment | To score attempts and show results and history |
| States of interest | Optionally added by you in My Space | To show state-focused portals and relevant content |
| Payment transaction records (plan, amount, payment reference) | On purchase, from our payment provider | To activate plans, process transactions and resolve disputes |
| Phone number | Only if you choose to provide it (e.g. on the Contact page) | To reach you about your request, if provided |
We do not store payment card details, UPI credentials, bank account numbers or CVVs. Payment processing is handled by our payment service provider (currently Razorpay). We receive only a transaction confirmation and reference.
- 3.2Voluntarily provided information: If you provide additional information through the Contact page or any other platform feature (such as a phone number or the text of a message), it is personal data you provide voluntarily for the purpose of that request, and may be used to respond to and act on the request. You may ask for its removal at any time through the Contact page.
- 3.3We do not knowingly collect any sensitive categories of data, and we ask that you do not include such data in messages to us.
Section 04
Purposes of Processing
- 4.1Providing the service: Name, email and plan status are used to authenticate you and determine your content access rights. This is the service your consent enables: access to study pages, tests, daily features and your personal history.
- 4.2Daily allowance and access management: Usage records and content access history are used to operate the free daily allowance and manage repeat access.
- 4.3Test history: Attempt records, scores and answers are stored to score your attempts and display results and history.
- 4.4Personalisation: States of interest are used to display relevant portals and content.
- 4.5Account security: Session records may be used to limit the number of devices signed in to one account.
- 4.6Communications: Your email may be used for essential account notifications (sign-in, plan activation and expiry, payment confirmations) and, where offered, optional updates and offers which you may opt out of at any time (see Section 14).
- 4.7Legal compliance: We may use or disclose your data to comply with applicable Indian law, court orders or lawful requests from government authorities. Such processing is a legitimate use under the DPDP Act and does not require separate consent.
- 4.8We do not use your personal data for any purpose beyond what is described in this policy without your consent.
Section 05
Consent and Legal Basis
- 5.1Our primary legal basis for processing is your consent, given when you create an account and confirmed by the notice shown to you at sign-up. Your consent covers the personal data and purposes itemised in Sections 3 and 4.
- 5.2Certain processing rests on legitimate uses recognised by the DPDP Act, including: data you voluntarily provide for a specified purpose (such as a message on the Contact page), compliance with law and judicial orders, and responding to legal obligations.
- 5.3You may withdraw consent at any time, with ease comparable to the ease with which it was given — see Section 11. On withdrawal, we stop the processing that rested on your consent within a reasonable time, unless retention or processing is required or permitted by law. Withdrawing consent for processing that is necessary to run your account means the account can no longer be provided, and is treated as a request to close and delete the account.
- 5.4Consequences of withdrawal (such as loss of access, history and any unexpired plan duration) are borne by you, as provided by the DPDP Act.
Section 06
Anonymised and Aggregated Data
- 6.1Legal Dictum reserves the right to use anonymised, aggregated, non-personally identifiable data derived from user activity on the platform for any purpose, including but not limited to analytics, platform improvement, research and commercial purposes.
- 6.2Anonymised data cannot be used to identify any individual user and is not personal data under the DPDP Act. This right exists indefinitely and is not affected by account deletion or opt-out requests.
- 6.3Examples include: aggregate test performance statistics, most-accessed content categories, usage patterns by portal — none of which can identify you individually.
Section 07
Third Party Service Providers
- 7.1Legal Dictum uses third-party service providers — as Data Processors where they process personal data on our behalf — for authentication, data storage and hosting, payment processing and other platform functions. Providers currently include our database and authentication provider, our payment provider (Razorpay) and our web host. Providers may change from time to time.
- 7.2As part of normal platform operations, certain data (such as name, email, transaction details and usage information) is transmitted to these providers as necessary for the service to function, under their respective terms.
- 7.3We do not sell or rent your personal data, and we do not share it with any third party for that third party's marketing purposes.
- 7.4We may disclose your data if required by applicable Indian law, court order, regulatory authority or lawful government request.
- 7.5To the fullest extent permitted by applicable law, Legal Dictum is not liable for any independent act or omission of a third-party provider outside our instructions. Users are encouraged to review the privacy policies of third-party services they interact with through the platform (for example, Google when signing in, and Razorpay when paying).
Section 08
Storage, Security and Breach Notification
- 8.1Your data is stored with our cloud database provider, which implements industry-standard security practices including encryption at rest and in transit.
- 8.2Access to the database is restricted through row-level security and server-side access checks, so that users can only access their own data. Client applications have no direct write access to sensitive tables.
- 8.3All data transmission is encrypted via HTTPS.
- 8.4We take reasonable security safeguards, as required by the DPDP Act, to prevent personal data breach. However, no system is completely secure, and to the fullest extent permitted by applicable law, Legal Dictum shall not be liable for unauthorised access that occurs despite reasonable safeguards.
- 8.5Breach notification: In the event of a personal data breach, Legal Dictum will notify affected users and the Data Protection Board of India in the manner and within the timelines prescribed under the DPDP Act and the DPDP Rules, 2025.
Section 09
Cookies and Local Storage
- 9.1Legal Dictum uses browser-based storage technologies including localStorage and sessionStorage to maintain your sign-in session and platform preferences.
- 9.2localStorage is used to store your authentication session (so you remain signed in between visits), reading preferences (such as text size and night mode), and a record that you have seen the sign-up notice.
- 9.3The platform is an installable web app. Pages you open may be cached on your own device so they remain readable offline. This cache stays on your device and can be cleared through your browser settings.
- 9.4These storage technologies are essential for the platform to function. They are not used for advertising or cross-site tracking.
- 9.5You may clear this storage through your browser settings at any time. Doing so will sign you out of the platform.
Section 10
Retention and Erasure
- 10.1Account data (name, email, states of interest, plan status): retained while your account exists, and erased when account deletion is completed.
- 10.2Operational records (content access history, daily usage, test attempts): retained for as long as reasonably necessary to run the service and your history, and may be pruned from time to time in the ordinary course.
- 10.3Payment transaction records: retained as required by applicable financial, tax and accounting laws in India, including after account deletion, to the extent the law requires.
- 10.4When the purpose of processing is no longer being served and retention is not required by law, personal data is erased in accordance with the DPDP Act.
- 10.5Legal Dictum reserves the right to retain anonymised or aggregated data derived from any of the above indefinitely (see Section 6).
Section 11
Your Rights as a Data Principal
- 11.1Right to access: You may request a summary of the personal data we hold about you and of the processing activities undertaken. Identity verification may be required before we comply.
- 11.2Right to correction, completion and updating: You may update your states of interest directly from My Space. For other corrections (for example, a changed email), contact us through the Grievance process.
- 11.3Right to erasure: You may request erasure of your personal data. Erasure will be carried out unless retention is necessary for the specified purpose or required by law (see Section 10.3).
- 11.4Withdrawal of consent / account deletion: You may withdraw consent and request deletion of your account and associated personal data through the Delete Account option on our Contact page at legaldictum.in/static/contact.html. Requests are processed manually and may take up to 15 days. Deletion is permanent and irreversible — any remaining plan duration, content access history and test history will be permanently lost, and no refund will be issued for unused plan time, save as mandatory law requires.
- 11.5Right of grievance redressal: You may raise a grievance about any act or omission regarding your personal data through the Contact page → Raise a Grievance. We will endeavour to resolve privacy grievances within 15 days.
- 11.6Right to nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity, by writing to us through the Grievance process with the nominee's details.
- 11.7Complaint to the Data Protection Board: If you are not satisfied with our response after exhausting the grievance process, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act.
- 11.8Legal Dictum may decline requests that are manifestly unfounded, excessive, repetitive or technically impracticable, and will state its reasons where it does so.
Section 12
Your Duties as a Data Principal
- 12.1Under the DPDP Act, you must not impersonate another person, suppress material information, or register a false or frivolous grievance or complaint.
- 12.2When exercising the right to correction or erasure, you must furnish only information that is verifiably authentic.
Section 13
Minors
- 13.1Legal Dictum is intended exclusively for users who are 18 years of age or older. We do not offer accounts to children as defined by the DPDP Act.
- 13.2We do not knowingly collect personal data from persons under 18. By registering, you represent and warrant that you are at least 18 years old.
- 13.3If we become aware that a user under 18 has registered, we will terminate that account and erase the associated data.
- 13.4If you believe a minor has registered, please notify us immediately through the Contact page.
Section 14
Communications
- 14.1We may send essential account communications including sign-in notifications, plan activation and expiry notices, payment confirmations and important platform or policy updates. These are necessary for the service and cannot be opted out of while you hold an account.
- 14.2Where we offer optional updates or offers by email, you may opt out at any time by contacting us through the Contact page or by using the unsubscribe link in any such email. Opting out does not affect essential account communications.
- 14.3If you have voluntarily provided a phone number, we may use it to reach you about your request. You may ask us to remove it at any time.
Section 15
Changes to This Policy
- 15.1Legal Dictum may update this Privacy Policy at any time. The updated version will be posted on this page with a revised date.
- 15.2For significant changes that materially affect your rights, we will endeavour to notify registered users. It remains your responsibility to review this policy periodically.
- 15.3Continued use of the platform after any change is posted constitutes your acceptance of the updated policy. Where a change requires fresh consent under the DPDP Act, we will seek it.
Section 16
Grievance Officer and Contact
- 16.1In accordance with the Information Technology Act 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and the Digital Personal Data Protection Act 2023, Legal Dictum has designated a Grievance Officer to address privacy-related complaints and questions about your personal data.
- 16.2Grievance Officer: Legal Dictum
Contact: legaldictum.in/static/contact.html → Raise a Grievance, or support@legaldictum.in - 16.3Legal Dictum will endeavour to resolve all privacy complaints within 15 days of receipt.
- 16.4For data access or correction requests, use the Raise a Grievance option. For account deletion, use the Delete Account option on the Contact page. Identity verification may be required before processing any request.
- 16.5If you remain unsatisfied after our grievance process, you may complain to the Data Protection Board of India as provided by the DPDP Act.
- 16.6This Privacy Policy is governed by the laws of India. Any disputes relating to this policy shall follow the dispute resolution process in our Terms and Conditions — mandatory internal grievance, followed by mediation at the Patna High Court Mediation Centre or SAMA, followed by the exclusive jurisdiction of the courts at Patna, Bihar, India — without prejudice to your rights under the DPDP Act.
Summary: We collect only what we need to run your account. We use it only as described. We do not sell it. You can access it, correct it, withdraw consent and have it erased. We hold anonymised aggregated data indefinitely for platform improvement.
