LEGAL

Data Protection

The technical and organisational measures that keep your legal information confidential.

Last updated 1 January 2026

1. Access control

Every request to the database is evaluated against row-level security policies bound to the signed-in user. Customers can reach only their own records; legal professionals can reach only matters assigned to them; organisation administrators can reach only their organisation's records.

2. Document storage

Documents are held in private storage that is not publicly reachable. Access is granted per file, per user, and is checked on every download. Documents are shared with a legal professional only when you choose to share them with your matter.

3. Audit logging

Sensitive actions, such as document access, matter assignment, role changes and subscription changes, are recorded in an append-only audit log that cannot be edited or deleted by platform users.

4. Roles and least privilege

Staff and professional access is granted on the principle of least privilege, through named roles rather than shared accounts, and is removed when no longer required.

5. Data residency and processors

Platform data is hosted with reputable infrastructure providers under contractual confidentiality and security obligations. Processors are used only where necessary to operate the service, such as hosting, email and payment processing.

6. Incident response

If a security incident affects your personal information, we will investigate, contain and notify affected users and the relevant authorities as required by applicable Indian law.

7. Reporting a vulnerability

If you believe you have found a security issue, write to security@sagaveil.in. Please do not test against other customers' data.