Sign out of ClariCase?

You’ll need to sign in again to access your account and case information.

Data Protection Policy

How ClariCase protects legal and personal information.

This policy sets out the controls, responsibilities and safeguards used to handle user data, legal documents and platform records.

Policy Section

1. Purpose

ClariCase handles personal information, legal documents, case records, billing records and communication history. This Data Protection Policy explains how such information should be collected, accessed, stored, used, shared, retained and protected.

This Policy supports the Privacy Policy and Consent Policy and is intended to reduce legal, operational, financial, security and reputational risk.

Policy Section

2. Data Protection Principles

ClariCase follows these principles: purpose limitation, data minimization, lawful processing, access limitation, confidentiality, integrity, accountability, retention control, user transparency and security by design.

Data should be collected only for defined purposes, accessed only by authorized persons, used only for service delivery or lawful purposes and retained only as needed.

Policy Section

3. Categories of Protected Data

Protected data may include personal details, identity information, contact details, legal case facts, criminal matter details, family information, property records, business records, court documents, notices, orders, evidence, billing records, payment status, communication logs, consent records, account data, device data, IP addresses and support notes.

Certain information may be sensitive because it relates to legal disputes, criminal allegations, family matters, financial exposure, identity documents, health issues, children, property, business conflicts or confidential communications.

Policy Section

4. Roles and Responsibilities

ClariCase management is responsible for establishing data protection practices, approving access policies and ensuring operational accountability.

Employees, Relationship Managers, coordinators, contractors and vendors must access information only where necessary for their role.

Independent lawyers are responsible for professional confidentiality and data handling obligations related to matters they accept.

Users are responsible for providing accurate data, sharing documents lawfully and protecting their account credentials.

Policy Section

5. Access Control

Access to data should be role-based and limited to persons who need it for onboarding, coordination, lawyer matching, document organization, billing, support, security or compliance.

Administrative access should be restricted, monitored and periodically reviewed.

Access should be removed or modified when a staff member changes role, leaves ClariCase, a vendor contract ends or access is no longer required.

Policy Section

6. Document Handling

Documents should be uploaded through approved channels wherever possible. Sensitive documents should not be requested through unsecured or public channels unless operationally unavoidable and consented to by the user.

Documents should be categorized, indexed and linked to the correct case or user profile. Staff should avoid unnecessary downloads, local copies, screenshots or forwarding.

Where documents are shared with independent lawyers or service providers, sharing should be limited to what is necessary for the relevant purpose.

Policy Section

7. Security Measures

ClariCase may implement reasonable security measures such as secure hosting, HTTPS, role-based access, password controls, OTP verification, encryption where appropriate, audit logs, backups, device controls, staff confidentiality obligations, vendor confidentiality terms and incident response procedures.

Security measures should be reviewed periodically and updated based on risk, business scale, legal requirements and technical feasibility.

Policy Section

8. Authentication and Credentials

Users and staff should use strong passwords, protect OTPs and keep devices secure.

Credentials must not be shared. Staff must not request user passwords, payment OTPs, UPI PINs or banking credentials.

Suspicious login activity, lost devices or suspected unauthorized access must be reported promptly.

Policy Section

9. Data Sharing Controls

Data may be shared with independent lawyers, coordinators, support staff, payment processors, cloud vendors, communication vendors, auditors, advisors, authorities or other service providers only where required for service delivery, legal compliance, security, billing or dispute resolution.

Before sharing sensitive information, the purpose and recipient should be verified where feasible.

Bulk export or transfer of data should be restricted and logged.

Policy Section

10. Retention and Deletion

Data should be retained only as long as required for service delivery, billing, legal compliance, tax obligations, audit, dispute resolution, security, fraud prevention and operational needs.

Deletion requests should be assessed against retention obligations, legal holds, outstanding payments, active disputes, backup schedules and technical feasibility.

Backups may retain data for a limited period even after deletion from active systems.

Policy Section

11. Incident Response

A data incident may include unauthorized access, accidental disclosure, lost device, wrong recipient sharing, malware, credential compromise, vendor breach, data corruption or suspected security threat.

ClariCase should investigate incidents, contain risk, preserve logs, assess impact, notify stakeholders where required by law, document corrective action and improve controls.

Users and staff must promptly report suspected incidents to [Insert security email].

Policy Section

12. Vendor Management

Vendors that handle data should be selected with regard to reliability, confidentiality, security practices and business need.

Where feasible, vendor agreements should include confidentiality, data protection, access limitation, breach notification, retention and deletion obligations.

Critical vendors should be reviewed periodically.

Policy Section

13. Training and Confidentiality

Staff, coordinators and contractors with access to user information should receive practical guidance on confidentiality, document handling, phishing risk, secure communication and escalation of incidents.

Confidentiality obligations should continue after termination of employment or engagement.

Policy Section

14. Audit Logs and Monitoring

ClariCase may maintain logs for login activity, document access, uploads, downloads, updates, communication events, payment records and administrative actions.

Logs may be used for security, audit, compliance, dispute resolution and service quality.

Policy Section

15. Data Protection by Design

New platform features, integrations, automation workflows, dashboards, templates or add-ons should consider privacy, consent, access, retention and security requirements at the design stage.

Only data necessary for the feature should be collected or shown.

Policy Section

16. User Responsibilities

Users should upload only relevant documents, avoid public sharing of sensitive information, keep contact details updated, protect account credentials and report unauthorized access promptly.

Users should ensure they have authority to share documents and information relating to other persons or entities.

Policy Section

17. Review and Updates

This Policy should be reviewed periodically and updated based on changes in law, platform architecture, business model, vendors, risk profile and operational experience.

Legal Policy Center

Review the connected ClariCase policies.

This page should be read together with the Terms of Use, Privacy Policy, Refund Policy, Disclaimer, Data Protection Policy, Consent Policy and Grievance Contact page.