DRAFTARD
Draftard
Privacy Policy Security Terms of Service

Contents

  1. Who We Are
  2. Scope
  3. Data We Collect
  4. Legal Basis
  5. How We Use Data
  6. Third-Party Processors
  7. International Transfers
  8. Data Retention
  9. Your Rights
  10. Cookies & Storage
  11. Children
  12. Security
  13. Grievance Officer
  14. Changes
  15. Contact

Privacy Policy

Effective date: 14 August 2026  ·  Last updated: 14 August 2026

This policy is governed by the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules). By using Draftard, you confirm that you have read and understood this policy.

1. Who We Are

[COMPANY NAME] ("Draftard", "we", "us", or "our") operates the platform accessible at draftard.com and its platform subdomain. We act as the Data Fiduciary as defined under the DPDPA, 2023.

Registered office: No.21 CHB Colony Street No.1, Vellore Road, Tiruchengode, Tamil Nadu, India.

Contact: supportmatriq@gmail.com

2. Scope

This policy applies to all personal data processed by Draftard in connection with:

  • Registration and management of firm accounts on our platform;
  • Use of our AI-powered legal tools (document drafting, translation, legal research);
  • Billing, wallet top-ups, and subscription management;
  • Customer support and communications.

It does not apply to third-party websites linked from our platform. We are not responsible for their privacy practices.

3. Data We Collect

3.1 Account & Identity Data

  • Full name, email address, and bcrypt-hashed password;
  • Firm name, firm identifier, and user role (Owner, Admin, Member);
  • Mobile number (where provided for OTP or contact).

3.2 Document & Content Data

  • Legal documents, case descriptions, or queries submitted to our AI tools for processing;
  • Generated drafts, translations, and research results returned to you;
  • Important: Document content is processed in real time and is not stored permanently on our servers beyond your active session and document history records in your account.

3.3 Usage & Technical Data

  • IP address, browser type, operating system, and referring URL;
  • Pages visited, features used, timestamps, and session identifiers;
  • Error logs and performance data for debugging purposes.

3.4 Billing & Financial Data

  • Wallet balance, transaction history, and plan tier;
  • Razorpay payment link identifiers and subscription IDs;
  • We do not store card numbers, CVV, UPI IDs, or bank account details. All payment instrument data is handled exclusively by Razorpay and is subject to Razorpay's PCI-DSS-compliant infrastructure.

3.5 Communications Data

  • Emails sent to and received from you (support, billing alerts, OTP, account notifications).

4. Legal Basis for Processing

Under the DPDPA, 2023, we process your personal data on the following grounds:

Processing ActivityLegal Basis
Account registration and authenticationConsent; Contract performance
AI tool processing of submitted documentsConsent; Contract performance
Billing, payments, and subscriptionsContract performance; Legal obligation
Service notifications and alertsLegitimate interest; Contract performance
Security monitoring and fraud preventionLegitimate interest; Legal obligation
Product analytics and improvementLegitimate interest

Where we rely on consent, you may withdraw it at any time by contacting us. Withdrawal does not affect the lawfulness of processing already carried out.

5. How We Use Your Data

We use the data collected to:

  • Create and maintain your firm account and authenticate your users;
  • Deliver AI-powered document drafting, legal translation, and legal research services;
  • Process payments, manage wallet credits, and handle subscriptions via Razorpay;
  • Send transactional emails (OTP, payment receipts, billing alerts, plan change notifications);
  • Detect, prevent, and respond to fraud, abuse, and security incidents;
  • Comply with applicable Indian laws, court orders, and regulatory requirements;
  • Improve platform performance, features, and reliability;
  • Respond to support requests and resolve disputes.

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

6. Third-Party Sub-Processors

We engage the following sub-processors to deliver our services. Each has been assessed for adequate data protection standards:

Sub-ProcessorPurposeData SharedLocation
Anthropic, PBC AI language model inference (Claude API) Document content and prompts submitted for AI processing United States
Razorpay Software Pvt Ltd Payment processing, subscription mandates Billing amount, payment link metadata; no card/UPI data India
Supabase Inc Cloud database hosting All structured account, billing, and history data India (ap-south-1 / Mumbai)
Render Inc Application server hosting Application logs, session data, in-memory processing United States (Oregon)
Google LLC (Gmail / SMTP) Transactional email delivery Recipient email address and email content United States

We require all sub-processors to implement appropriate technical and organisational security measures and to process data only on our documented instructions.

Anthropic specifically: When you submit a document or query to our AI tools, that content is transmitted to Anthropic's API. Anthropic's Privacy Policy and API usage terms apply to that processing. By using our AI tools, you consent to this transfer. Do not submit personally identifiable information about third parties, privileged communications, or classified content unless you have the necessary authority to do so.

7. International Data Transfers

Some of our sub-processors operate outside India. Transfers to Anthropic (USA), Render (USA), and Google (USA) take place under standard contractual protections and the sub-processors' respective privacy frameworks.

Your structured account and transaction data is stored on Supabase's Mumbai (India) region and does not leave India in the ordinary course of operations.

To the extent required by the DPDPA, we ensure that cross-border transfers occur only to countries, or under conditions, approved by the Central Government of India.

8. Data Retention

Data CategoryRetention Period
Account and firm data (active)Duration of account + 90 days after closure
Document generation historyDuration of account + 90 days after closure
Payment and billing records8 years (statutory requirement under Indian tax law)
Assistant conversations and linked attachments7 days from thread creation; warning email sent approximately 24 hours before deletion
Security and access logs90 days rolling
Support correspondence3 years from last interaction
Data after account deletionAnonymised or deleted within 30 days, except where retention is required by law

9. Your Rights Under the DPDPA, 2023

As a Data Principal under the DPDPA, you have the following rights:

  • Right to Information: Know what personal data we hold about you and how it is processed.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to lawful retention obligations.
  • Right to Grievance Redressal: File a grievance with our Grievance Officer (see Section 13) and receive a response within the timelines prescribed under the DPDPA.
  • Right to Nominate: Nominate an individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, email our Grievance Officer at supportmatriq@gmail.com with the subject line "DPDPA Rights Request". We will acknowledge within 3 business days and respond within 30 days.

If you are dissatisfied with our response, you may approach the Data Protection Board of India once it is constituted under the DPDPA.

10. Cookies & Browser Storage

We use the following cookies and browser storage mechanisms:

NameTypePurposeDuration
ls_sessionSession cookie (HTTP-only, Secure)Server-side session identifier; no session data travels in the cookie itself30 days or browser close
ls-themeCookie / localStorageStores your light/dark mode preference1 year

We do not use third-party advertising cookies or tracking pixels.

11. Children's Data

Our platform is intended solely for law firms, advocates, and legal professionals. It is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has registered an account, we will delete the account and associated data promptly.

12. Security Measures

We implement industry-standard technical and organisational security measures as required under the IT (SPDI) Rules, 2011. For a detailed description of our security practices, please review our Security Policy.

13. Grievance Officer

In accordance with the DPDPA, 2023, and the Information Technology Act, 2000, a Grievance Officer has been designated:

Grievance Officer — Draftard
[COMPANY NAME]
No.21 CHB Colony Street No.1, Vellore Road, Tiruchengode, Tamil Nadu
Email: supportmatriq@gmail.com
Response time: Within 30 days of receipt of grievance

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 15 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

The version history of this document is available on request.

15. Contact Us

For any privacy-related queries not addressed above:

Email: supportmatriq@gmail.com
Platform: draftard.com

Security Policy → Terms of Service →