1. Lawyer-Client Privilege Protection

Vakilat.io recognizes the absolute sanctity of attorney-client privilege in India (Section 126 of the Evidence Act/Section 132 of BSA). We do not use your private documents, client data, or chat queries to train our foundation AI models. Your proprietary data remains isolated in your firm's tenant environment workspace.

2. Data Collection and Usage

When you register for Vakilat, we collect your name, email, Bar Council State, and practice details. This information is used strictly to provision your workspace, authenticate you, and tailor the AI's jurisdictional context to your region.

3. Data Storage & Residency

All user data, case files, and generated drafts are stored securely on servers physically located within the Republic of India to comply with local data sovereignty regulations. We utilize enterprise-grade AES-256 encryption at rest and TLS 1.3 in transit.

4. Third-Party Subprocessors

To provide advanced AI capabilities, we may utilize secure API endpoints from third-party LLM providers. In all such data agreements, strict Zero Data Retention (ZDR) clauses are enforced, ensuring that third-party AI labs delete your prompt data immediately upon returning the result.

5. Compliance with DPDPA, 2023

Vakilat complies fully with the Digital Personal Data Protection Act, 2023. You have the right to access, correct, or erase your personal data at any time via the platform settings.