NYAYA
Privacy Policy
Version 1.1 · Effective date: 12 October 2026
Who we are
Nyaya is a legal research and practice-management service for Indian advocates, offered on the Legal World website (legalworld.site) and in the Nyaya mobile app. Nyaya is currently operated by Vinit Khandal, an individual, based in Jaipur, Rajasthan, India (“we”, “us”). For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the data fiduciary for your account data.
Nyaya may later be operated by a company. If that happens we will update this policy and tell you before the change takes effect.
What we collect and why
Reading public court records and laws does not need an account. When you sign in or use the private workspace, we handle the following.
- Google sign-in: your Google account identifier, your email address (only if Google has verified it), your name, and the time Google last confirmed your sign-in. We use these to create and protect your account. We never receive your Google password and do not ask for access to Gmail, Drive or Google Calendar.
- Account details: account status, interface language, an early-access group (used to switch on new features), when the account was created, last signed in and finished setup, and which Terms and Privacy Policy versions you accepted.
- Setup answers: your role, type of practice, state, courts, practice areas and chamber name. They decide what Nyaya shows first. We deliberately do not ask for phone numbers or bar enrolment numbers.
- Practice records you enter: matters, client and opposite-party names, client phone numbers and emails, hearings and court details, tasks, notes, client-update drafts, fee entries and receipts, registers, contacts, team knowledge, research briefs, imported spreadsheets and small private files (PDF, PNG, JPEG). We keep these to run your workspace.
- Team and sharing: the emails and roles of colleagues you invite, client-portal links you create and private calendar-feed links. For links we keep only a scrambled (hashed) form of the secret part.
- Research: saved cases, folders, notes on passages, saved searches and watchlists. Searches you run are processed to show results; we do not keep a history of your search terms, although public search responses may be cached briefly by our hosting provider.
- Suggestions to the public library: the record you propose, your sources, reasons and reviewers’ notes. Reviewers can see your email. Only approved content is published, without your email.
- Security records: sessions, a log of administrative actions (which account did what, and when), and short-lived request counters used to stop abuse. Counters for visitors who are not signed in use a hash of the network address made with a secret key, never the address itself.
- Technical data: our servers report only timings and the serving location in responses, and our error logs record only the type of error, never your content. Our hosting provider processes network addresses and request details to deliver and protect the service.
Legal basis
We process your account and workspace data on the basis of your consent, which you give by signing in and accepting these documents, and which you can withdraw by deleting your account. Withdrawing consent does not affect processing already done.
Where the DPDP Act allows processing for certain legitimate uses — for example to comply with a law or court order, or to respond to a threat to safety — we may rely on those uses. Optional usage analytics runs only while it is switched on in your browser.
Your clients’ data
When you record information about your clients, opposite parties or other people in your workspace, you (or your firm) decide why and how it is used, so you are the data fiduciary for it. Nyaya stores and processes it only on your instructions, to provide the service — we act as your data processor.
You are responsible for having a lawful basis, such as your client’s consent, for entering their details, sharing a client-portal link, sending them updates and contacting them on WhatsApp, and for answering their requests about their data. We will help you do so, for example through export and deletion.
A workspace is visible only to its owner and colleagues who accepted an invitation, according to their role. Public-library reviewers and administrators get no special access to private workspaces.
WhatsApp, calls and calendars
The “open WhatsApp” buttons open WhatsApp on your own device with a message filled in; you choose whether to send it. Nyaya does not send the message and does not see it. Call buttons open your phone’s dialler. WhatsApp is run by Meta under its own terms and privacy policy.
Nyaya can also send WhatsApp messages itself through Meta’s WhatsApp Business Platform, from one Nyaya number on behalf of the advocate. This is switched off until we configure it and turn it on for your account. When it is on: an approved client update is sent only when an advocate presses Send, and hearing reminders only for matters where an advocate turned them on — and in both cases only to a client number with consent recorded. Clients can reply STOP at any time.
- Consent records keep the client’s full WhatsApp number, whether consent was given or withdrawn, how (recorded by the advocate, or the client replied START or STOP), by whom and when.
- The message log keeps only a one-way hash of the number made with a secret key (HMAC-SHA-256), the template, delivery status and times — not the text of messages sent, which already lives on the approved update.
- Client replies are attached to a workspace only when they answer Nyaya’s own recent conversation with that number; their text is kept up to 2,000 characters, and photos or documents are not downloaded. Messages from unknown senders keep no text and are deleted after 30 days.
- If you turn on the evening digest of tomorrow’s hearings, we keep your own WhatsApp number for it until you turn it off or reply STOP.
Meta processes these messages as our processor, on servers that may be outside India. Message text is never sent to analytics. All of this is part of your workspace: it is included in your export; a matter’s messages and reminder settings are removed with the matter, and everything is removed with the workspace.
If you subscribe to a private calendar link in Google Calendar, Apple Calendar or another app, that app fetches your hearing details from Nyaya and keeps them under its own policy. Choose the “minimal” detail level to leave client names out, and revoke the link at any time.
Optional usage analytics
Limited usage analytics is on by default. It tells us which features are used so we can improve Nyaya. Turn it off at any time with Usage analytics in the page footer or under More; every feature keeps working. Browser “Do Not Track” and “Global Privacy Control” signals switch it off automatically.
Only fixed categories are sent — such as which screen was opened, the language, a coarse device type, whether you are signed in, and broad result or timing buckets. Search terms, legal text, names, emails, phone numbers, matter or workspace identifiers and full web addresses are never sent. Events go through our server, which removes your network address before passing them to PostHog in the United States.
A random identifier, not linked to your account, is kept in your browser for up to 30 days to count returning visits. Turning analytics off deletes it. PostHog keeps events for up to one year; events already sent are not deleted by turning analytics off.
How long we keep data
- Account, setup answers and personal research: until you delete your account.
- Workspace records: until the workspace owner deletes them or the workspace. Lowering a plan never deletes data.
- Sign-in sessions: at most seven days, and they end after three days without use. Sign-in step records: minutes.
- Abuse-prevention counters: most expire within an hour and a few daily allowances within a day; expired counters are deleted within a day.
- Log of administrative actions: one year, after which entries are deleted.
- Client-portal links: active for at most 30 days, and you can withdraw them earlier. Seven days after a link expires or is withdrawn, it is deleted together with its copy of the shared updates and the client’s acknowledgement.
- Calendar links: until you revoke them. A link that no calendar app has used for 90 days is turned off automatically; we note at most once a day when a calendar app last used it.
- Published public-library records and their review history are kept as part of the public record; your identity is removed from them when you delete your account.
- Recovery backups: our database provider keeps point-in-time recovery history for up to 30 days, so deleted data can remain in it until that period ends.
- Analytics events at PostHog: up to one year.
How we protect data
- All connections use HTTPS encryption. Session cookies cannot be read by page scripts and are sent only over secure connections.
- Session, portal and calendar secrets are stored only as one-way hashes, so a copy of our database does not reveal them.
- Every private request checks your workspace role. Exporting your data, transferring a workspace or deleting your account requires a Google sign-in within the last ten minutes.
- Requests from other websites are refused, request rates are limited, and suspended accounts are signed out everywhere.
No system is perfectly secure. Uploaded files are not scanned for malware, and the service can technically read workspace content in order to deliver it. Keep your devices locked, and protect any file you download or print. If a personal data breach affects you, we will inform you and the Data Protection Board of India as the law requires.
Your rights
Under the DPDP Act you can:
- get a summary of your personal data and how it is processed, and the identities of those we have shared it with;
- have inaccurate or incomplete data corrected or completed, and have it updated;
- have your data erased, unless we must keep it to comply with a law;
- withdraw your consent at any time;
- nominate another person to exercise these rights if you die or become unable to do so; and
- have your grievances addressed by us, and then complain to the Data Protection Board of India.
How to use your rights
Most of this is self-service in your profile: download your data, correct your setup answers and workspace records, sign out on all devices, transfer or delete a workspace, and delete your account. Your name and email come from Google and update when you next sign in.
Deleting your account removes your identity, sessions, setup answers, personal research and unpublished suggestions. Hand over or delete the workspaces you own first. Records you added to someone else’s workspace stay with that workspace, without your identity, and published public records stay public without your name or email.
For anything else — including a summary of your data, nominating someone, or a request from a client about data an advocate holds in Nyaya — write to vinit224488@gmail.com. We may need to confirm your identity first. A client’s request is passed to the advocate responsible for that workspace.
Children
Nyaya is not meant for anyone under 18, and we do not knowingly process children’s personal data or track or target children. If you believe a child has created an account, write to us and we will delete it.
Grievance officer
Grievance officer: Vinit Khandal, Jaipur, Rajasthan, India. Email: vinit224488@gmail.com.
We acknowledge grievances promptly and respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Changes to this policy
We will update this policy when Nyaya’s data handling changes. For important changes we will tell you in the app, and signed-in users will be asked to review the new version before continuing. The version number and effective date are shown at the top.
Contact
Questions about this policy or your data: vinit224488@gmail.com. Post: Vinit Khandal, Jaipur, Rajasthan, India.