Privacy Policy

Privacy Policy

CaseDocker Document Reference: "CDA/Privacy Policy/Ver 2.0/Effective 2026-07-27"

Privacy Policy for the CaseDocker platform at https://www.casedocker.com

Version 2.0 — effective 27 July 2026

This Privacy Policy explains how Coingeit Technologies Private Limited (CIN U72300UP2013PTC059652), registered at 1403, ATS Greens 2, Sector 50, Noida, Uttar Pradesh, India, which owns and operates the CaseDocker platform ("CaseDocker", "we", "us" or "our"), collects, uses, shares, secures and retains personal data. It applies to the Website, the CaseDocker platform, and our related applications and services (together, the "Services").

This policy forms part of our Terms of Service , which define the capitalised terms used here. If this policy is not acceptable to you, please stop using the Services.

1. Our role, and the two kinds of data we handle

The Digital Personal Data Protection Act, 2023 ("DPDP Act") calls the organisation that decides why and how personal data is processed a Data Fiduciary, and the individual the data is about a Data Principal. Our role depends on which of two categories the data falls into.

1.1. Account and website data — we are the Data Fiduciary. This is data about you as our customer or visitor: your registration details, billing details, support correspondence and how you use the Services. We decide why and how it is processed, and this policy describes that processing in full.

1.2. Customer Content — we are a processor acting for you. This is the material you put into the platform: contracts, case files, notices, documents and the personal data of your own clients, employees and counterparties contained in them. You decide why and how that data is processed. We process it only to provide the Services to you, on your instructions, under clause 14 of the Terms of Service .

1.3. If you are an individual whose personal data appears inside a customer's account — for example, because a law firm using CaseDocker holds your file — we have no direct relationship with you. Please contact that firm, which is the Data Fiduciary for your data. If you contact us instead, we will refer your request to them and support them in answering it.

2. Personal data we collect

2.1. Data you give us

Registration data: name, email address, mobile number, organisation name and role.

Billing data: billing address, GSTIN, and invoice records. We do not collect or store card numbers, UPI IDs, net banking credentials or wallet details — see section 6.

Authentication data: your password, held only as a salted hash, and any multi-factor authentication settings.

Support and enquiry data: the content of messages you send us, demo requests and newsletter sign-ups.

Recruitment data: information in a job application, where you make one.

Customer Content: the documents and data you upload or generate, handled under section 1.2.

2.2. Data collected automatically

Technical data: IP address, browser type and language, device and operating system, referring URL, time zone, pages and files accessed, and errors generated.

Usage data: sign-in times, session duration, features used, and volume of data and storage used.

Security data: authentication events, access logs and audit trails, kept to detect and investigate unauthorised access.

IP addresses and device identifiers are personal data. We treat them as such.

2.3. Data about other people that you give us

If you give us another person's personal data — for example when referring a colleague, adding an Authorised User, or uploading a document containing a third party's details — you confirm that you are entitled to do so and that any notice or consent required by law has been given or obtained. We do not use third-party personal data you provide for our own marketing. Anyone can ask to be removed from our communications by using the unsubscribe link in any message or writing to [email protected] .

3. Why we process personal data, and on what basis

Under the DPDP Act we process personal data either with your consent or for a "legitimate use" permitted by the Act, such as a purpose for which you have voluntarily provided your data. Where other laws apply to you, the equivalent lawful bases are contract performance, legitimate interests, legal obligation and consent.

3.1. To provide the Services — creating and administering your account, authenticating you, enabling platform features, storing and processing Customer Content, and providing support. Basis: performance of our contract with you.

3.2. To take payment — processing subscriptions, issuing invoices, and meeting tax and accounting obligations. Basis: contract and legal obligation.

3.3. To operate and secure the platform — monitoring availability and performance, preventing and investigating fraud, abuse and unauthorised access, and maintaining audit trails. Basis: legitimate use and legal obligation.

3.4. To send service communications — notifications about your account, subscription expiry and renewal, security alerts, maintenance windows and changes to these policies. These are not marketing and you cannot opt out of them while you hold an account. Basis: contract.

3.5. To improve the Services — analysing aggregated usage patterns and performance to fix problems and prioritise development. Basis: legitimate use.

3.6. To market to you — newsletters, product announcements, event invitations and offers. You can opt out at any time, and every marketing message carries an unsubscribe link. Basis: consent.

3.7. To meet legal obligations and defend claims — responding to lawful requests from courts, regulators and law enforcement, and establishing or defending legal claims. Basis: legal obligation and legitimate use.

If we ever want to use your personal data for a materially different purpose, we will tell you and, where the law requires it, ask for your consent first.

4. Artificial intelligence and CDGenie

The Services include AI features — CDGenie — that summarise, extract, classify, draft and answer questions about your documents.

4.1. We do not use Customer Content to train, fine-tune or improve generally available machine learning models, whether ours or a third party's.

4.2. Where an AI feature is delivered using a third-party model provider, your content is sent to that provider only to generate the response you asked for. We contract with those providers on terms that prohibit training on your content and require deletion after processing. See section 8 for the functions our service providers perform.

4.3. AI output can be wrong. It is not legal advice and must be verified by a qualified person before it is relied on. See clause 10 of the Terms of Service .

4.4. We do not use AI to make decisions about you that produce legal effects without human involvement.

5. Cookies and similar technologies

We use cookies, local storage, tags and similar technologies. Some are necessary for the Services to work; others are used only with your consent.

Strictly necessary — sign-in, session management, security, load balancing and remembering your cookie choices. These cannot be switched off. The "Remember me" option stores a persistent cookie so you do not have to sign in on each visit; if you block cookies you will not be able to use the signed-in areas of the platform.

Analytics — measuring how the Website and platform are used so we can improve them. We use third-party analytics providers, including Google Analytics, for this.

Functional — remembering your preferences and settings.

Marketing — measuring the effectiveness of our campaigns, where used.

You can control cookies through your browser settings, which also allow you to delete cookies and local storage objects already set. Blocking non-necessary cookies will not stop you using the Services. Third-party widgets described in section 9 may also set cookies.

6. Payments

Card, UPI, net banking and wallet payments are handled by third-party payment gateways. When you pay, we pass the gateway your email address, phone number and the transaction amount. Everything else you enter — card number, UPI ID, net banking or wallet credentials — goes directly to the gateway and is never captured or stored by us. Your use of a gateway is governed by that provider's own privacy policy, which you should read. We retain the transaction reference, amount, date and status for accounting and tax purposes.

7. Who we share personal data with

We do not sell personal data. We do not share Customer Content with anyone for their own purposes. We share personal data only in these circumstances:

7.1. Subprocessors. Service providers who process data on our behalf, under written contracts that limit them to our instructions and impose confidentiality and security obligations. The functions they perform are described in section 8.

7.2. Your own organisation. Where you use the Services under an organisational subscription, your administrators can access your account activity and the Customer Content within it.

7.3. Legal and regulatory requirements. Where we are required to disclose by law, or by a binding order of a court, tribunal or authority of competent jurisdiction. Where we are legally permitted to do so, we will tell you before disclosing Customer Content and give you a reasonable opportunity to challenge the request. We publish no data voluntarily to law enforcement beyond what a valid legal process requires, except where we believe in good faith that disclosure is necessary to prevent imminent serious harm to a person.

7.4. Professional advisers. Our auditors, lawyers, insurers and bankers, where necessary and under a duty of confidence.

7.5. Corporate transactions. If we are involved in a merger, acquisition, restructuring or sale of assets, personal data may transfer to the counterparty, subject to this policy continuing to apply. We will notify you by email or a prominent notice on the Website before your data becomes subject to a different privacy policy.

7.6. Aggregated information. We may share aggregated, de-identified statistics that cannot reasonably be used to identify you or any individual.

8. Our service providers

We engage service providers to carry out functions on our behalf. They act only on our instructions, under written contracts that impose confidentiality and security obligations, and may not use the data for their own purposes. The functions they perform are:

• cloud hosting, storage and backup of the platform;

• artificial intelligence and machine learning processing for the CDGenie features, under the restrictions in section 4;

• payment processing, as described in section 6;

• delivery of transactional and marketing email;

• product analytics and website measurement;

• customer support and ticketing.

Customers who need the identity of the specific providers engaged for their account — for example to complete their own record of processing activities, or to agree a data processing agreement — can request the current list by writing to [email protected] .

9. Third-party links and widgets

The Website carries links to third-party sites and social sharing widgets, including LinkedIn, X (formerly Twitter) and Facebook. These widgets can see your IP address and the page you are on, and may set their own cookies — that is personal data, and their handling of it is governed by their own privacy policies, not this one. We do not control third-party sites and are not responsible for their privacy practices. Please read their policies before giving them your information.

10. International transfers

We primarily store and process personal data in India. Some service providers described in section 8 may process data outside India, in which case the transfer is made in accordance with section 16 of the DPDP Act and any restrictions notified by the Central Government. Where personal data protected by the laws of another jurisdiction is transferred, we put appropriate safeguards in place, including standard contractual clauses where required. Customers who need a data processing agreement or standard contractual clauses can request our current form at [email protected] .

11. How long we keep personal data

We keep personal data only as long as necessary for the purpose it was collected for, and then delete or anonymise it.

Customer Content — for as long as your account is active. After your subscription ends you have 30 days to export it, during which we will not delete it except at your written request. We then delete it from live systems.

Backups — encrypted backup copies are overwritten in the ordinary backup cycle, normally within 90 days of deletion from live systems.

Account and billing records — for the period required by tax, company and accounting law, currently up to eight years from the end of the relevant financial year.

Security and audit logs — normally up to 12 months, longer where needed to investigate a specific incident.

Marketing data — until you withdraw consent or unsubscribe, after which we keep only a suppression record so we do not contact you again.

Enquiries and support — normally up to 24 months after the matter is closed.

We may keep data for longer where it is needed to comply with a legal obligation, to establish or defend a legal claim, or to comply with an order of a court or authority — and only for as long as that purpose requires.

12. How we protect personal data

We maintain technical, organisational and physical safeguards appropriate to the sensitivity of the data we hold, which includes privileged and confidential legal material. These include:

• encryption of data in transit using TLS 1.2 or above, and encryption of stored data and backups at rest using AES-256;

• role-based access controls, so staff can reach Customer Content only where they need it to provide support, maintain security or comply with law — such access is logged and reviewed;

• confidentiality obligations binding on our personnel that survive the end of their engagement;

• passwords stored only as salted hashes, never in plain text;

• network controls, monitoring, audit logging and periodic review of our security measures;

• physical security at the facilities where our infrastructure is hosted.

No system can be guaranteed completely secure. You are responsible for choosing a strong password, keeping your credentials confidential, managing access within your own organisation, and securing your own devices and networks.

13. Personal data breaches

If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the form and within the timeframes required by the DPDP Act and the rules made under it. Where the breach affects Customer Content, we will notify the affected customer without undue delay and give them the information they reasonably need to meet their own notification obligations. Suspected security issues can be reported to [email protected] .

14. Your rights

As a Data Principal under the DPDP Act you have the following rights in relation to personal data for which we are the Data Fiduciary:

Access — a summary of the personal data we process about you, the processing activities, and the identities of others with whom it has been shared.

Correction and completion — to have inaccurate or misleading data corrected, incomplete data completed, and data updated.

Erasure — to have your personal data erased, unless retention is required for a specified purpose or to comply with law.

Withdraw consent — where processing is based on consent, to withdraw it at any time, as easily as you gave it. Withdrawal does not affect processing already carried out.

Grievance redressal — to complain to us about how we handle your data, before approaching the Data Protection Board.

Nomination — to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

You can exercise most of these rights directly in your account settings, or by writing to [email protected] . We will respond within 30 days of verifying your identity. Changes you make in your account may take up to 48 hours to propagate across our systems. There is no charge for exercising your rights.

You are responsible for the accuracy of the data you give us, and for not making a false or frivolous complaint or impersonating another person, as the DPDP Act requires of Data Principals.

If you are not satisfied with our response, you may complain to the Data Protection Board of India. Where the data concerned sits inside a customer's account, please see section 1.3.

15. Children

The Services are intended for business and professional use and are not directed at children. We do not knowingly collect personal data of anyone under 18 years of age without verifiable consent from a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child's personal data has been provided to us, contact [email protected] and we will delete it.

16. Your choices

Marketing — unsubscribe using the link in any marketing email, change your preferences in your account, or write to us. You will still receive service communications described in section 3.4 while you hold an account.

Cookies — manage through your browser settings, as described in section 5.

Account data — view, correct and delete through your account settings.

17. Contact us, and our Grievance Officer

For any question about this policy or about how we handle personal data, contact our Data Protection Officer:

CaseDocker HelpDesk , Data Protection Officer
Coingeit Technologies Private Limited, 1403, ATS Greens 2, Sector 50, Noida, Uttar Pradesh, India
[email protected]

The same mailbox reaches our Grievance Officer, who handles formal complaints. We acknowledge complaints within 24 hours and resolve them within 15 days. Full details are in the Grievance Redressal Policy .

18. Changes to this policy

We may update this policy. The version number and effective date at the top of this page always show the current version. Where a change materially affects your rights, we will give you at least 30 days' notice by email to your registered address or by a prominent notice in the Services before it takes effect. If you do not accept the change, you may stop using the Services and close your account before the effective date. Minor changes — clarifications, corrections and changes required by law — take effect on publication.

This policy is governed by the laws of India. Disputes are handled under clause 27 of the Terms of Service , without affecting your right to complain to the Data Protection Board of India or any other competent authority.