LEGAL
Data Protection
The technical and organisational measures that keep your legal information confidential.
Last updated 1 January 2026
1. Access control
Every request to the database is evaluated against row-level security policies bound to the signed-in user. Customers can reach only their own records; legal professionals can reach only matters assigned to them; organisation administrators can reach only their organisation's records.
2. Document storage
Documents are held in private storage that is not publicly reachable. Access is granted per file, per user, and is checked on every download. Documents are shared with a legal professional only when you choose to share them with your matter.
3. Audit logging
Sensitive actions, such as document access, matter assignment, role changes and subscription changes, are recorded in an append-only audit log that cannot be edited or deleted by platform users.
4. Roles and least privilege
Staff and professional access is granted on the principle of least privilege, through named roles rather than shared accounts, and is removed when no longer required.
5. Data residency and processors
Platform data is hosted with reputable infrastructure providers under contractual confidentiality and security obligations. Processors are used only where necessary to operate the service, such as hosting, email and payment processing.
6. Incident response
If a security incident affects your personal information, we will investigate, contain and notify affected users and the relevant authorities as required by applicable Indian law.
7. Reporting a vulnerability
If you believe you have found a security issue, write to security@sagaveil.in. Please do not test against other customers' data.