Privacy Notice
Brief Network IT Services Private Limited ("Adhivaktas.com", "we")
CIN U62099DC2026PTC475137 · Office: D-65, First Floor, Defence Colony, New Delhi 110024
Last updated: 8 October 2026
Notice under section 5 of the Digital Personal Data Protection Act, 2023.
1. Who this is for
Adhivaktas.com is used by advocates, and only by advocates. It is not a service for litigants, and nothing here describes a client's data. What an advocate tells another advocate about a matter is privileged; see section 5.
2. What we collect about you, and why
When you register. Your name, age, gender, Bar enrolment number, the education you state, your mobile number, your email address (where your sign-in codes are sent), and the location your browser reports at that moment. The location is kept as an audit trail against a false registration and is not used for anything else. All of it is needed to open and hold an account, which is the service you asked for.
To verify you. A photo of you holding your Bar Council ID card, taken when you register or later from your profile, and the date the card is valid until, which is how long your verification lasts. Our verification team uses it to check that you are the person on the card and that the card matches the Bar Council's record. No other advocate ever sees it, it is never used for anything else, and it is deleted 90 days after the team decides (section 7).
When you fill in your profile, if you choose to. Postal address, state of enrolment, state of practice, languages, specialisation, years in practice, past work you list, and a photograph. Your UPI ID sits with these: it is where a withdrawal of your earnings is sent. Every field in this paragraph is optional and can be emptied at any time.
When you sign in. One record per attempt, successful or not: the time, the mobile or enrolment number given, your account if we could identify it, your IP address, your browser's user-agent string, and why an attempt failed. This is how an account takeover is noticed. The one-time code itself is never stored in our database or in any log, only a hash of it, which stops working after fifteen minutes or five wrong tries. The code is emailed to you through Google (section 6), and a copy of that email stays in our sending mailbox, by which time the code in it no longer works. If the email never reaches you, our team can read the code to you on the mobile number on your account; for that, it is held in the server's memory until it expires.
When you use the service. The briefs you post, the applications you make, who was selected, what proof was filed, whether the fee was recorded as paid or refused, and every entry in your wallet: credits received, fees locked, returned and earned, and withdrawals asked for. This record is the product: an advocate's standing on Adhivaktas.com is the history of fees honoured. It is kept for as long as the account exists, because a record that could be deleted selectively would not be worth anything.
Support tickets. Read by a person, which is what a support queue is for.
Notifications, if you switch them on: the push subscription your browser creates. Turning notifications off deletes it.
How the app is used. A random per-browser identifier, which screen was opened, which control was pressed, the language and the platform. No free text you type is ever included. This is off until you switch it on, separately from the account itself, on the screen before sign-in.
3. The Bar Council of Delhi roll
We hold a lookup copy of the Bar Council of Delhi's published verification roll (103,899 entries, as published by the Bar Council as on 30 November 2025) so that an enrolment number given at sign-up can be checked against it. Most of the people in it have never used Adhivaktas.com.
What that copy is, precisely:
- Mobile numbers are stored only as a keyed hash, never in readable form. A leaked copy of the table gives up no phone number. Only the last four digits are readable, so that an operator deciding an application can tell they have the right person.
- Names, enrolment numbers, status and addresses are readable, because there is no way to judge a doubtful application without them.
- Nothing in the service lists, exports, searches or browses the roll. It is queried one identity at a time, in answer to one question: is this enrolment number on the roll, and did the Bar Council mark it in order?
- When somebody registers, the entry their enrolment number matched is copied against their account so that a person deciding a doubtful application can see what the roll says without going back to the list. That copy is held apart from the account itself and is never returned to the advocate or to anyone else through the service, because an enrolment number is public and anything answered against one is answered to whoever typed it.
If you are on that roll and want your entry removed from our copy, write to the Grievance Officer in section 9. We remove it once we have confirmed that the request comes from the person named in the entry.
4. What we never do
- No real money passes through us during the trial. The wallet holds trial credits, not money. We hold no bank account details and no card details. Before the wallet carries real money we will say here, and in the app, what that involves.
- We do not read your messages or your files. No automated process in the service touches them: not analytics, not search, not classification. A posting on the public board is read once when written and reduced to fixed labels, because the board is published to every advocate anyway. Messages and documents are not.
- We do not sell personal data, and we do not share it with advertisers.
5. Messages, files and calls
Messages between two advocates are stored, so both sides keep the record and so a dispute can be settled. Files are not stored, only the name of a file, who shared it and when.
Calls connect directly between the two devices. We do not record them and we do not keep their audio. Where two networks cannot reach each other, the encrypted media passes through a relay that cannot read it and does not retain it.
Treat all of it as you would any other channel about a client's matter.
6. Who else sees it
Only processors acting on our instructions, under contract:
| Purpose | Processor | Where the data sits |
|---|---|---|
| Hosting and database | DigitalOcean, Bengaluru (BLR1) | India |
| Database backups | DigitalOcean managed backups, same cluster and region | India |
| Delivery of the app to your browser | Cloudflare | Served from the nearest edge; Cloudflare sees your IP address and the request, not your account contents |
| One-time sign-in codes by email | Google (Google Workspace) | Google's data centres, which may be outside India |
| The platform fee | Razorpay | India |
| Error reporting | Sentry | United States |
| Uptime monitoring | Better Stack | Outside India. It requests a public health page and receives no personal data. |
Two of these may be outside India. Google carries the email with your sign-in code to your address; it holds that email, which contains the code and your email address and nothing else, wherever Google keeps Workspace mail. Sentry receives an automated report when the software fails. It is configured not to attach request bodies, headers, cookies or user identities, and a second pass in our own code removes anything that looks like a mobile number, an email address, an enrolment number or a token before the report is sent. What remains is the shape of the failure. Sentry's project is nevertheless hosted in the United States, so that report leaves India.
We disclose personal data to anyone else only when the law requires it, or to a Bar Council or court acting within its authority.
7. How long we keep it
| What | Kept for |
|---|---|
| Your account and profile | While the account exists |
| The photo of you holding your Bar Council ID | Until our team decides on your verification, then 90 days |
| The record of briefs, commitments and fees, and your wallet's entries | While the account exists, and 2 years after it closes |
| Messages and file names | While the account exists, and 2 years after it closes |
| Sign-in records | 180 days |
| Usage analytics | 365 days |
| Support tickets | 180 days |
Sign-in records and usage analytics are deleted automatically once past the periods above; the service prunes them at start-up and once a day.
After an account closes, its record and messages are kept for two years, so that either side of a past engagement can still show what was agreed, and then deleted.
8. Your rights
Under the DPDP Act you may ask us to:
- tell you what we hold about you and who we have shared it with;
- correct or complete anything inaccurate;
- erase what we no longer need, subject to section 7;
- nominate someone to exercise these rights if you die or become incapable;
- withdraw a consent you gave. Withdrawing consent to usage analytics changes nothing else. Withdrawing consent to the account itself closes the account.
Ask through Support in the app, or write to the Grievance Officer. We answer within 30 days.
9. Grievance Officer
Complaints about your personal data go to the Grievance Officer named in the Grievance Redressal Policy: Urmila, grievance@adhivaktas.com. Acknowledgement within 24 hours, resolution within 15 days, as Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires.
If you are not satisfied, you may complain to the Data Protection Board of India.
10. Changes
We will post a new version here and change the date at the top. If a change matters to you, we will say so in the app rather than leave you to notice it.