Last updated: 04 August 2026 · Effective from: 1 May 2025
This Privacy Policy ("Policy") describes how LexWiser ("we", "us", "our"), acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023, collects, processes, stores, shares, and protects the personal data of its clients, prospective clients, and website visitors ("you", "Data Principal").
This Policy is prepared and published in compliance with:
By using our website lexwiser.in, submitting our contact form, communicating with us on WhatsApp or email, or engaging our legal services, you acknowledge that you have read and understood this Policy.
Under Section 2(i) of the DPDP Act, a "Data Fiduciary" is any person who alone or in conjunction with others determines the purpose and means of processing of personal data. LexWiser is the Data Fiduciary for all personal data collected through this website and in connection with our legal services.
Where we engage third-party service providers (e.g. web hosting, payment gateways) who process data on our instructions, those providers act as "Data Processors" under Section 2(k) of the DPDP Act. We remain responsible for ensuring they handle your data in accordance with this Policy and applicable law.
The DPDP Act requires every Data Fiduciary to provide a clear, standalone notice to the Data Principal before or at the time of collecting personal data. This section constitutes that notice.
Data Fiduciary: LexWiser, B-171, Mahatma Hansraj Marg, Block B, Lok Vihar, Pitampura, Delhi – 110034
Personal data to be processed: Name, email address, mobile number, WhatsApp number, nature of legal query, documents shared with us, and any other information you voluntarily provide
Purpose of processing: To respond to your legal enquiry, provide legal services you engage us for, communicate with you about your matter, process your payment, comply with legal obligations, and improve our services
Basis of processing: Your consent (given by submitting our contact form, messaging us on WhatsApp, or emailing us), contract performance, and our legal obligations
How to withdraw consent: Email hello@lexwiser.in with the subject line "Withdraw Consent" at any time. Withdrawal will not affect the lawfulness of processing before withdrawal
How to raise a complaint: Contact our Grievance Officer (Section 23 of this Policy) or approach the Data Protection Board of India (Section 24)
This notice is written in plain English. If you require this notice in Hindi or any other Scheduled language, please contact us at hello@lexwiser.in and we will provide it.
4.1 How We Obtain Consent
Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional and unambiguous, and must be signified by a clear affirmative action. We obtain consent through the following affirmative acts:
We do not treat silence, inactivity, pre-ticked boxes, or continuing to browse our website as consent to process your personal data.
4.2 Granularity and Specificity of Consent
Your consent is sought separately for each distinct purpose. Consent given for one purpose does not authorise us to process your data for a different purpose. For example:
4.3 Withdrawing Your Consent
You may withdraw your consent at any time and it must be as easy to withdraw as it was to give, per Section 6(4) of the DPDP Act. To withdraw consent:
4.4 Consent for Sensitive Personal Data
Where we process Sensitive Personal Data or Information ("SPDI") as defined under the SPDI Rules 2011 (such as financial information, health records, or information relating to criminal proceedings), we obtain your explicit written consent before collection. This consent is obtained separately from general consent and specifies the exact category of SPDI being collected and the specific purpose.
Section 7 of the DPDP Act permits processing of personal data for certain "Legitimate Uses" without requiring consent. We rely on these in the following situations:
| Legitimate Use (Sec 7) | How It Applies to LexWiser |
|---|---|
| Sec 7(a): State Function and Legal Obligation | Disclosure of data to courts, tribunals, IP offices, GST authorities, MCA, FIU-IND as required by law, court order, or summons |
| Sec 7(b): Compliance with Law | Processing KYC and anti-money-laundering data under applicable Indian AML legislation; maintaining accounting records under the Income Tax Act; maintaining client files under Bar Council Rules |
| Sec 7(c): Medical Emergency | Processing health-related data shared in the context of a legal matter involving a medical emergency (e.g. personal injury, insurance claims) |
| Sec 7(d): Employment Purposes | Processing data of our own staff or associates for employment-related purposes |
| Sec 7(f): Public Interest and Research | Any anonymised and aggregated data used for legal research or sector-level analysis. No individual is identifiable from such data. |
We do not rely on legitimate use as a blanket override to avoid obtaining consent. Legitimate use is invoked only where the specific statutory condition is genuinely met.
6.1 Data You Provide Directly
6.2 Data Collected Automatically
We do not collect any data not listed above. We do not collect biometric data, social media data, or political/religious affiliation data.
Under the DPDP Act, personal data must be processed only for a lawful purpose for which consent has been given or which constitutes a Legitimate Use. The table below sets out every purpose for which we process your data:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Respond to your legal enquiry and provide a quote | Identity, Contact, Matter | Consent (Sec 6) |
| Deliver legal services you have engaged us for | Identity, Contact, Matter, Financial | Contract (Sec 7) |
| Send updates on your ongoing legal matter | Identity, Contact | Contract (Sec 7) |
| Process payment for services rendered | Financial | Contract (Sec 7) |
| Issue invoices and maintain accounting records | Identity, Financial | Legal obligation: Income Tax Act, GST law |
| KYC / AML compliance | Identity, SPDI | Legal obligation: applicable Indian AML legislation (Sec 7) |
| File documents with courts, tribunals, IP Office, MCA, GST authority | Identity, Matter | Legal obligation and contract (Sec 7) |
| Comply with court orders or summons | Any relevant data | Legal obligation (Sec 7) |
| Send service-related notifications (e.g. trademark hearing reminders) | Contact | Consent / Contract |
| Respond to your grievances and complaints | Identity, Contact, Communication | Legal obligation (Sec 13 DPDP) |
| Maintain professional records as required by Bar Council Rules | Matter | Legal obligation: BCI Rules |
| Website improvement through analytics and security monitoring | Technical, Usage, Cookie | Legitimate interest (Sec 7) |
| Prevent fraud or unauthorised access | Technical | Legitimate interest (Sec 7) |
We will never process your data for a purpose other than those listed above without first obtaining fresh, specific consent from you.
Under Section 8(3) of the DPDP Act, a Data Fiduciary must ensure that personal data processed is complete, accurate, and consistent with the purpose of processing. Under Section 8(4), personal data must be collected only to the extent necessary for the specified purpose ("data minimisation").
We implement data minimisation and quality as follows:
Section 8(5) of the DPDP Act requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. We implement the following:
A "personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data (Section 2(s), DPDP Act).
Our obligations in the event of a breach:
Under Section 8(7) of the DPDP Act, a Data Fiduciary must erase personal data as soon as it is reasonable to assume that the specified purpose is no longer being served, and retention is not required for compliance with any law.
| Data Category | Retention Period | Statutory Basis |
|---|---|---|
| Enquiry data (no client engagement) | 12 months from enquiry date | Sec 8(7) DPDP Act. Purpose is served once the query is resolved. |
| Active client matter files | Duration of engagement plus 7 years after closure | Limitation Act 1963; Bar Council of India Rules |
| Financial and payment records | 8 years from date of transaction | Sec 44AA Income Tax Act; GST records rule |
| KYC and AML records | 5 years from end of business relationship | Applicable Indian AML rules |
| Court and tribunal filings and orders | Permanently (matter-specific) | Bar Council Rules; potential future proceedings |
| Website server logs | 90 days | Security monitoring. Auto-deleted at 90 days. |
| Cookie data | Session cookies: on browser close. Persistent: up to 12 months. | Sec 8(7) DPDP Act. Deleted at end of purpose. |
| WhatsApp and email communications | Duration of matter plus 7 years | Matter continuity; potential dispute resolution |
| Withdrawn-consent data | Deleted within 30 days of withdrawal request | Sec 6(4) and Sec 8(7) DPDP Act |
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with you. We conduct periodic data audits to ensure timely deletion.
We do not sell, rent, or trade your personal data to any third party. We do not share your data with advertisers, marketing agencies, or data brokers.
We may share your personal data in the following limited and controlled circumstances:
13.1 With Your Express Consent
Where you have given explicit consent, for example by instructing us to share documents with a co-counsel, forensic expert, chartered accountant, or any other professional engaged on your behalf.
13.2 For Performance of Your Legal Matter
13.3 Legal and Regulatory Obligations
13.4 Data Processors (Service Providers)
All our Data Processors are contractually bound to: (a) process data only on our written instructions; (b) maintain appropriate security measures; (c) not sub-process without our authorisation; and (d) delete or return data upon termination of services.
Section 16 of the DPDP Act empowers the Central Government to restrict transfer of personal data to certain countries or territories. Our cross-border data flows are as follows:
We do not transfer your substantive legal matter data (case files, strategy, or confidential documents) to any overseas server or jurisdiction, except where required by the nature of your specific legal matter (for example, an international trademark filing).
As and when the Central Government notifies countries to which cross-border transfers are restricted under the DPDP Act, we will review and update our data transfer practices to remain compliant.
WhatsApp is our primary channel for client updates and document sharing. By messaging us on WhatsApp or providing your WhatsApp number in our contact form, you consent to receiving communications from us via WhatsApp.
Our website uses cookies to function properly and to improve your experience. Under the DPDP Act, where cookies collect personal data, appropriate notice and consent are required.
| Cookie Type | Purpose | Duration | Consent Required? |
|---|---|---|---|
| Strictly Necessary | Website functionality: session management and security | Session (deleted on browser close) | No. Essential for site operation. |
| Analytics | Understand how visitors use the site (anonymised) | Up to 12 months | Yes. Opt-out available. |
| Preference | Remember your settings and preferences | Up to 12 months | Yes. You can decline. |
To manage or disable cookies, adjust your browser settings. Note: disabling strictly necessary cookies may cause parts of the site to stop functioning. You may also opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.
Sections 11–14 of the DPDP Act confer the following rights on every Data Principal:
You have the right to obtain from us: (a) confirmation of whether we are processing your personal data; (b) a summary of the personal data being processed; and (c) the identities of all Data Fiduciaries and Data Processors with whom your data has been shared, along with the categories of data shared. We will respond within 30 days.
You have the right to: (a) correct inaccurate or misleading personal data; (b) complete incomplete personal data; and (c) have your personal data erased where it is no longer required for the purpose for which it was collected, or where consent has been withdrawn. Erasure may be declined where retention is required by applicable law (e.g. Indian AML legislation, Bar Council Rules). In such cases, we will inform you of the reason. We will respond within 30 days.
You have the right to have any grievance relating to the processing of your personal data addressed by our Grievance Officer within the timeframes set out in Section 23. If you are not satisfied, you may escalate to the Data Protection Board of India (see Section 24).
You have the right to nominate any other individual who shall exercise your rights under the DPDP Act in the event of your death or incapacity. To register a nominee, please email us at hello@lexwiser.in with the details of your nominee and their relationship to you.
You may withdraw consent at any time by emailing hello@lexwiser.in with subject "Withdraw Consent". Withdrawal is as easy as giving consent. We will process your withdrawal within 15 days. Withdrawal does not affect lawfulness of prior processing.
How to exercise your rights: Send a written request to hello@lexwiser.in clearly identifying yourself and specifying the right you wish to exercise. We may ask for proof of identity before actioning your request to protect against fraudulent requests.
The DPDP Act is the first Indian privacy law that imposes duties on Data Principals (individuals) in addition to rights. Section 15 requires every Data Principal to:
Violation of Section 15 duties may attract civil penalties under Section 25 of the DPDP Act, up to ₹10,000 per violation as determined by the Data Protection Board. As your legal counsel, we also draw your attention to the fact that providing false information in the context of legal proceedings may constitute an offence under the Indian Penal Code and other applicable laws.
Section 9 of the DPDP Act imposes specific obligations on Data Fiduciaries when processing personal data of children (persons under 18 years of age).
19.1 Verifiable Parental Consent
Before processing any personal data of a child, we are required under Section 9(1) to obtain verifiable consent of the parent or lawful guardian of the child. We will not knowingly collect personal data from any child without such consent.
19.2 No Tracking or Behavioural Monitoring of Children
Under Section 9(3), a Data Fiduciary must not undertake tracking or behavioural monitoring of children or targeted advertising directed at children. We do not engage in any such activities. Our website contains no advertising and we do not use profiling cookies.
19.3 Minors as Parties to Legal Matters
Where a minor is a party to a legal matter (e.g. a child's custody matter, a minor's property dispute, or a case involving a juvenile), we:
19.4 If You Believe a Child's Data Has Been Submitted
If you believe a child under 18 has submitted personal data to us without parental consent, please contact us immediately at hello@lexwiser.in. We will investigate and delete the data promptly.
Over and above this Privacy Policy, all information shared with us in the context of a legal engagement is protected by:
Attorney-client privilege belongs to you as the client, not to us. We will:
Please note: privilege does not apply where you seek our assistance in carrying out a crime or fraud. In such circumstances, we are obligated to decline instructions and, where required by law, to report to the appropriate authority.
Our website may link to government portals (MCA21, IP India, GST Portal, Income Tax e-filing), WhatsApp, and other third-party services. Once you leave lexwiser.in, this Privacy Policy does not apply. We encourage you to read the privacy policies of any third-party website you visit. We are not responsible for their content or privacy practices.
We may update this Policy to reflect changes in the law (including rules notified under the DPDP Act), our practices, or our services. The "Last Updated" date at the top of this page always reflects the most recent revision.
For material changes, particularly changes that expand how we use your data or reduce your rights, we will notify you by displaying a prominent notice on our website and by emailing you if you are an existing client, at least 15 days before the change takes effect.
Your continued use of our services after notification of a material change constitutes acceptance of the revised Policy. If you do not accept the revised Policy, you may withdraw consent and discontinue using our services.
Rule 5(9) of the SPDI Rules 2011 and Section 13 of the DPDP Act require every Data Fiduciary to designate a Grievance Officer. Our designated Grievance Officer is:
| Designation | Grievance Officer, LexWiser |
| hello@lexwiser.in | |
| Address | B-171, Mahatma Hansraj Marg, Block B, Lok Vihar, Pitampura, Delhi – 110034 |
| Hours | Monday to Saturday, 10:00 AM – 7:00 PM IST |
Process for raising a grievance:
The DPDP Act establishes the Data Protection Board of India ("DPB") as an independent adjudicatory body with powers to investigate complaints, issue directions, and impose financial penalties on Data Fiduciaries.
You may approach the Data Protection Board if:
Penalties under the DPDP Act (Schedule):
| Violation | Maximum Penalty |
|---|---|
| Failure to implement reasonable security safeguards (Sec 8(5)) | Up to ₹250 crore |
| Failure to notify DPB of a data breach (Sec 8(6)) | Up to ₹200 crore |
| Failure to fulfil obligations for children's data (Sec 9) | Up to ₹200 crore |
| Breach of any other DPDP Act obligation | Up to ₹50 crore |
| Data Principal duties violation (Sec 15) | Up to ₹10,000 |
Note: The Data Protection Board is yet to be formally constituted as of the date of this Policy. Once operational, complaints may be filed through the mechanism prescribed by the Central Government.
For any questions about this Privacy Policy or how we handle your data:
This Privacy Policy is governed by the laws of India. Any disputes arising under or in connection with this Policy shall be subject to the jurisdiction of the courts in Delhi, India, and to the authority of the Data Protection Board of India under the DPDP Act, 2023.
© 2026 LexWiser. All rights reserved. This Policy was last reviewed on 04 August 2026.