Information We Collect

We collect only the information necessary to provide and improve AdvoHQ's services. This falls into two broad categories: information you provide directly, and information generated automatically through your use of the platform.

We do not collect payment card details directly — any billing is handled by third-party processors who are independently PCI-DSS compliant.

How We Use Your Data

We process your data only for legitimate, specified purposes. We do not sell your data, and we do not use case content for advertising.

  • Providing and maintaining your AdvoHQ account and case library.
  • Powering AI-assisted features such as case summarisation, brief drafting, and legal research queries.
  • Sending essential transactional communications (login OTPs, security alerts, court date reminders).
  • Diagnosing bugs, preventing fraud, and improving platform security.
  • Complying with lawful obligations under Indian law, including the IT Act 2000 and applicable Bar Council regulations.
  • Generating aggregate, anonymised analytics to understand feature usage — your personal identity is never associated with these reports.

Data Sharing & Disclosure

We share your information in the following limited circumstances only:

  • AI Service Providers: Case prompts you submit are forwarded to our AI API provider (currently DeepSeek) for processing. DeepSeek's data-use policy applies. We do not send client names or identifying information unless you explicitly include them in your prompt.
  • Infrastructure Providers: Hosting, database, and CDN services that process data on our behalf under data-processing agreements.
  • Legal Obligation: When required by a court order, statutory authority, or applicable Indian law, we may disclose data after verifying the request's legality.
  • Business Transfers: In the event of a merger, acquisition, or restructuring, your data may transfer to the successor entity, who will be bound by equivalent privacy obligations.

Important: We will never voluntarily share your case data with opposing counsel, third parties, or law enforcement without a valid legal order. Advocate–client privilege considerations guide every disclosure decision.

Data Storage & Security

Your data is stored on servers located in India or within jurisdictions offering equivalent data-protection standards. We implement the following safeguards:

  • Passwords are never stored in plain text — they are hashed using industry-standard bcrypt with high cost factors.
  • All data in transit is encrypted via TLS 1.2 or higher.
  • Database access is restricted by role and requires authenticated credentials.
  • Two-factor authentication (2FA) is available for all accounts and strongly recommended.
  • Regular security audits and dependency vulnerability scans are conducted.
  • JWT session tokens are short-lived and invalidated on logout.

Despite our best efforts, no system is entirely immune to risk. If you suspect unauthorised access to your account, contact us immediately at contact@advohq.in.

Data Retention

We retain your data only as long as necessary for the purpose it was collected, or as required by law. Specific retention periods:

  • Account and case data: Retained for the duration of your active account, plus 90 days after deletion to allow for reinstatement requests.
  • Server access logs: Retained for 12 months for security and fraud-prevention purposes.
  • AI session data: Not persisted server-side beyond the active session (unless saved by you).
  • Billing records: Retained for 7 years in accordance with Indian accounting and tax regulations.

After applicable retention periods, data is permanently deleted or anonymised in a manner that prevents re-identification.

Cookies & Local Storage

AdvoHQ uses browser localStorage and session tokens rather than traditional tracking cookies. Here is what we store client-side:

  • Auth token (localStorage): A JWT used to authenticate your session. It is cleared on logout.
  • User preferences: Theme, sidebar state, and UI settings — no personal data.
  • Case cache (localStorage): A local snapshot of your case data to enable faster loading. It is encrypted at rest where supported by your browser.

We do not use third-party tracking cookies, advertising pixels, or cross-site tracking technologies. You can clear all locally stored data at any time via your browser's developer tools or the Settings → Clear Data option within AdvoHQ.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the "Last revised" date at the top of this page.
  • For significant changes, we will notify registered users by email at least 14 days before the change takes effect.
  • Your continued use of AdvoHQ after the effective date constitutes acceptance of the revised policy.
  • If you disagree with a material change, you may close your account before it takes effect and request data erasure.

We encourage you to review this policy periodically. Prior versions are available on request.