AS UPDATED ON 7th June, 2025.
We respect your privacy and care about how your Personal Information is used. This Privacy Policy (the “Policy”) outlines how Accio Legal (“Firm” or ”us” or”we” or ”our”) and its affiliates collect, use, store, process, transfer, and disclose your information through our Websitehttps://acciolegal.comor any other services we offer from time to time by or in connection therewith (together referred to as the “Website”). It applies to your interactions with and usage of our Website, where we provide a digital interface for facilitating connections with legal professionals and enabling the exchange of legal knowledge and related communications (the“Services”). By reviewing this Policy, you will gain a comprehensive understanding of your privacy rights and choices.
Your access to or utilisation of our Website and/or Services operated by the Firm linked to this Policy implies your agreement to be governed by this Policy. By providing us with your Personal Information, you expressly consent to the use and disclosure of your Personal Information as outlined in this Policy. This Policy, along with the Terms of Use, the Disclaimer and other policies, is applicable to your use of the Services, and you explicitly agree and acknowledge to read the Privacy Policy in conjunction with the Terms of Use and the Disclaimer.
The term “Personal Information” shall mean any information that relates to an identified or identifiable individual or entity. This may include, but is not limited to, information that you voluntarily provide to us (such as your name, email address, phone number, or professional details) and information that we collect automatically through your use of our Website or Services (such as IP address, location, device identifiers, browser type, and usage data). “Personal Information” shall include equivalent terms in other Data Protection Laws, such as the GDPR-defined term “Personal Data,” as the context requires.
By accessing and utilising the Website and/or Services, or furnishing your Personal Information, you explicitly agree and acknowledge that you accept the terms delineated in this Policy. The terms ‘User’,’you’ or ’your’ collectively refer to any individual or entity accessing or using the Website, whether for personal purposes or on behalf of others.
By visiting the Website or providing your information, you expressly agree to be bound by this Privacy Policy and agree to be governed by the privacy laws, including but not limited to the Information Technology Act, 2000, Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (IT Rules), and the Digital Personal Data Protection Act (DPDPA), 2023, General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant regulations governing data protection and privacy.
IF YOU DO NOT CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS SET FORTH IN THIS PRIVACY POLICY, PLEASE REFRAIN FROM ACCESSING AND/OR USING OUR WEBSITE.
TO WHOM DOES THIS POLICY APPLY?
- This Policy is inclusive and applies to all Users of our Website, irrespective of their browsing intent or their extent of their utilisation of the Services offered on our Website.
- The applicability of this Policy extends to Users regardless of the device type used for accessing our Website, whether it be a laptop/desktop or a mobile/tablet device.
- You acknowledge that you are an eligible user as per Clause 1.1 of the Terms of Use. If you are below or between the ages of 13-18, or 16-18 (as applicable), and below the contractual age determined by the applicable laws of your country, you confirm that you are using the Website with the consent of a parent or legal guardian. If you do not meet these criteria, please refrain from using our Website and Services or providing Personal Information to us.
WHAT IS THE INFORMATION THAT WE COLLECT FROM YOU?
- To avail our Services, you need to contact us through the Website functionality, which is free of cost and for this purpose, we collect certain Personal Information. This may include, but is not limited to, the following:
- Basic Information: You are required to provide basic information such as your full name;
- Contact Information: such as personal or business email address and mobile number;
- Social Media Platforms: If you subscribe to our blog and newsletters or contact us through social media platforms, including but not limited to LinkedIn, X (formerly Twitter), Instagram, etc., we may collect and process your Personal Information available on these platforms through various third party data analytics and social media management service providers. This may include your name, email address, and phone number as provided on your social media profiles;
- Recruitment Information: If you apply for a job at our Firm through the careers page on our Website, we may collect specific Personal Information, including your full name, email address, phone number, educational information, relevant professional information, and any other information provided in your resume;
- Communication with us: This can include any communication that you send to us, including communications for any inquiries, support, etc.
- Additionally, while you utilise our Website and/or Services, we may collect the following information-
- Device Identification data: This includes information that may assist us in identifying your device, including browser type, and version, your operating system, etc; and
- Other Data: This can include the following, based on your interaction with the Website:
- Number of times you accessed our Website;
- The length of time you spent on the Website;
- The period from which you became and have continued to be active on the Website;
- Other similar statistics we may collect with the intention of improving the user experience of the Website.
- You agree to provide us with your Personal Information whenever you use our Services by performing any of the following functions:
- Accessing our Website by means of any web browser or any device;
- Expressing your interest in our Services on the Website;
- Inquiring about our Services through our Website;
- Initiating and maintaining correspondence with us.
- We strive to take extra precautions to ensure that such Personal Information is kept secure and confidential, and we will only retain this data for as long as necessary for the purposes for which we collect it, as per the permissible laws of the land.
- You understand and agree that all Personal Information, sensitive or otherwise, collected through our Website is provided solely by the User. We do not collect any personal or sensitive information without the User’s explicit input and consent. Users are responsible for the accuracy and completeness of the information they provide. By using our Website and Services, you acknowledge that you are bound by the terms and policies of our third-party service providers. We prioritise user privacy and security by relying on trusted third-party service providers, and we encourage Users to review and understand the policies of these platforms to protect their interests.
- We shall not be liable for any loss or damage sustained by you as a result of any disclosure (inadvertent or otherwise) of any Personal Information concerning your payment information in the course of any online transactions or payments made for any Services offered through the Website. For this purpose, we recommend that you go through the terms of service of third-party service providers.
- This Policy will not apply to any unsolicited information provided by you through the Website or through any other means. This includes but is not limited to information posted on any public areas of the Website. All such unsolicited information shall be deemed to be non-confidential, and we will be free to use and disclose such unsolicited information without limitation.
- Access to your Personal Information is limited to employees, agents, partners, and third parties, who we reasonably believe will need that information to enable us to provide Services to you. However, we are not responsible for the confidentiality, security, or distribution of your own Personal Information by our partners and third parties (who have their own privacy policies) outside the scope of our agreement with such partners and third parties.
- When you use our Website, we collect and store your information, which is provided by you from time to time. In general, you can browse the Website without telling us who you are or revealing any Personal Information about yourself. Once you give us your Personal Information, you are not anonymous to us. Where possible, we indicate which fields are required and which fields are optional. You always have the option to not provide information by choosing not to use a particular service, product, or feature on the Website.
HOW DO WE COLLECT THE INFORMATION?
- We employ various methods to gather information, ensuring a comprehensive understanding of user interactions and preferences. The collection of Personal Information is facilitated through the following processes:
- Information you give us: When you provide us with the information referred to in Clauses 2.1 and 2.2 through the methods outlined in Clause 2.3;
- Session Management: We study session metrics to understand how users interact with the Website. This helps us learn the average time users spend on the Website and when they prefer to engage. We use tools like Google Analytics (or alternatives) to collect anonymous data, including the number of views, how long users stay, and where they’re visiting from. This data allows us to optimise the user experience, making informed enhancements to cater to user preferences and behaviours;
- User analytics: We analyse user behaviour and preferences within the Website to track and ensure accuracy, promptly identify any unusual behaviour, and detect fraudulent activities, allowing us to take immediate corrective action.
- In addition to direct user interactions, we leverage cookies and similar technologies to enhance the functionality and user experience on the Website. These allow us to collect and process additional information for various purposes:
- Cookies: We utilise cookies, which are small text files stored on your device’s hard drive by web browsers. These cookies help us and third parties identify Users, track preferences, analyse usage patterns, and optimise the Website’s functionality to provide a customised experience. Cookies enable us to store preference information and understand browsing activities. You may manage cookie preferences through your browser settings. Below is the limited list of the categories of cookies we use, along with their purposes:
- Strictly Necessary Cookies: These cookies are needed to run our Website, to keep it secure when you are accessing the Website, and to obey regulations that apply to us. They also help us keep your details safe and private;
- Functional Cookies: These cookies are used for remembering things such as your region or country, your preferred language, accessibility options like large font or high-contrast pages;
- Performance Cookies: These cookies tell us how you and our other users use our Website. We combine all this data together and study it. This helps us to improve the performance of our Services and/or the Website;
- Session Cookies: We use session cookies, which are stored temporarily during your browsing session and deleted when you close your browser or application. These cookies support Website functionality and help us analyse usage, including pages visited, links clicked, content viewed, and time spent on each page.
- Analytics Cookies: Analytics cookies collect data about your use of the Website, allowing us to improve its performance. These cookies provide aggregated information to monitor site functionality, track page visits, identify technical issues, analyse user traffic, and measure the effectiveness of our advertising, including emails sent to you.
- Purpose of Cookies We Use: We utilise Personal Information obtained through cookies to enhance the speed, security of your interaction with us, and overall user experience. These cookies serve various purposes, including but not limited to:
- Preferences: Cookies enable the Website to remember information that alters the site’s behaviour or appearance, such as your preferred language or geographic region. By retaining your preferences, we can customise and present advertisements and other content tailored to you.
- Security/Optimisation: Cookies play a crucial role in maintaining security by verifying Users, preventing fraudulent use of Services, and safeguarding User data from unauthorised access. Specific types of cookies assist in blocking various types of attacks, such as attempts to pilfer content from Website forms.
- Processing: Cookies contribute to the efficient functioning of the Website, allowing us to deliver the Services expected by visitors and/or Users. These cookies facilitate tasks like navigating web pages and accessing secure sections of the Website.
- Analytics and Research: Cookies aid in comprehending how individuals utilise our Services, enabling us to enhance them for a better User experience. This data-driven insight helps us refine and improve our offerings.
- Web Beacons, Pixel Tags, and Trackers: We may employ web beacons, pixel tags, and tracking URLs, which are tiny graphic images and/or small blocks of code placed on Website pages, ads, or in our emails that allow us to determine whether you performed a specific action. When you access these pages or when you open an email, you let us know that you have accessed the web page or opened the email. These tools help us measure responses to our communications and improve our web pages and promotions;
- Log Files: Our servers automatically collect information sent by Users’ devices, known as log files. This data may include IP addresses, device information, browser type, and timestamps. Log files are instrumental in analysing trends, administering the Website, and diagnosing technical issues;
- Third-Party Analytics: We may integrate third-party analytics services to further understand user behaviour. These services utilise their own tracking technologies to compile reports on Website activity, aiding us in improving our Services;
- Location Data: As part of our Services, we may also collect precise geolocation data, including GPS signals, device sensors, Wi-Fi access points, and cell tower IDs. We collect this type of data if you grant us access to your location. You can withdraw your consent at any time by disabling the GPS or other location-tracking functions on your device;
- Information from other sources: We may collect Personal Information from other sources, including but not limited to
- If a User or any third party submits a complaint about you, we may receive information relating to the specific complaint made in order to understand and, where relevant, address the complaint; and
- To the extent permitted by applicable law, we may receive additional information about you, such as references, demographic data, and information to help detect fraud and safety issues from (i) third-party service providers, other third parties, and/or partners, or (ii) Users and any other individuals, entities, and authorities, and combine it with information we have about you. For example, we may receive information about you and your activities on and off the Website, including from users, members of the public, governmental, public, or tax authorities, or about your experiences and interactions with and/or from our partners. We may receive health information, including, but not limited to, health information related to contagious diseases.
WHY DO WE COLLECT YOUR INFORMATION?
- You agree and acknowledge that we shall collect your information only for lawful and legally permissible purposes, which are as follows:
- Contractual Necessity: We process your Personal Information to fulfil our contractual obligations with you, which include, without limitation, tasks such as facilitating your access to our Website, enabling communication between you and legal professionals, and responding to your inquiries or service requests;
- Research and development: We will utilise Personal information to deliver the Services and to develop, test, and enhance the quality and usability of both the Website and Services;
- Communicate with you: We use your Personal Information to communicate with you concerning Services via different channels (e.g., by phone, e-mail, chat);
- Fraud Prevention and Credit Risks: We use Personal Information to prevent and detect fraud and abuse to protect the security of our users;
- Troubleshoot Problems: We use your Personal Information to provide functionality, analyse performance, fix errors, and improve the usability and effectiveness of the Website and/or Services;
- Compliance with law: To be able to perform any contractual and legal obligation;
- Enhancing User Experience: To analyse user behaviour and preferences for improving our Services and user experience, and to be able to provide location-specific services;
- Providing alerts/notifications: To effectively communicate with you through emails/SMS/notifications through the Website to inform you about any other new Services that we may from time to time develop.
- In the course of operating the Website and/or Services, we collect and utilise Personal Information in accordance with our Privacy Policy.
- You consent and recognise that your Personal Information may be disclosed on our Website, authorised by you for the purpose of utilising our Services. Additionally, you agree and acknowledge that we are permitted to communicate with you through messaging, calls, emails, or other means to facilitate the performance of our Services wherever necessary.
WHO DO WE SHARE YOUR PERSONAL INFORMATION WITH AND WHY?
To facilitate our Services and enhance user experience, we may share Personal Information with the following entities:
- Third-party Service Providers: We may collaborate with third-party service providers to carry out various functions on our behalf, such as email communications, data analysis, marketing support, content transmission, hosting services, data storage, customer service, etc. While these third-party service providers may have access to the necessary Personal Information to fulfil their functions, they are prohibited from using it for any other purposes. Moreover, they are obligated to process the Personal Information in compliance with applicable laws. While we do not own or control these third parties, when you interact with them and choose to use their services, you are providing your information to them. Your use of these services is subject to the privacy policies of those providers;
- Professional Consultants or Collaborators: In certain situations, we may engage independent professionals or consultants (such as legal experts, advisors, or IT security consultants) to assist in providing or enhancing our Services. These professionals are contractually bound to maintain the confidentiality and security of any Personal Information they may access in the course of such engagement;
- Business Transfers: In the course of our business development, we may engage in the sale or acquisition of other businesses or services. In such transactions, user information is typically considered one of the transferred business assets but continues to be governed by the commitments outlined in any pre-existing Privacy Policy, unless the user provides alternative consent. Additionally, in the unlikely scenario of the acquisition of the Firm, any of its affiliates, or a substantial portion of their assets, user information will naturally be among the transferred assets;
- Legal Compliance: In compliance with applicable laws and regulations, we may disclose Personal Information to government entities or regulatory authorities when required, with/without any notice/intimation to you. This includes instances where such disclosures are necessary for legal proceedings, investigations, or to meet regulatory obligations. Also, we may share any information about you with government and law enforcement agencies without your permission as may be considered necessary or appropriate by us to respond to valid claims and legal processes, to protect our property and rights or the property or rights of a third party, to protect the safety of the public or any person, or to prevent or stop any illegal, unethical or legally actionable activity;
- Service Improvement: We may share certain aggregated, anonymised information with third parties (for example, for Google Analytics) in order to assess the Website usage and information pertaining to the ease of navigation;
- Collaborations: We may share your Personal Information with reputable partners to facilitate joint initiatives, promotions, or integrated services; and
- Growth and Expansion: As our Firm evolves and expands, there may be instances where sharing Personal Information with new entities or parties becomes necessary for the enhancement of our Services. Any such sharing will be carried out with the utmost consideration for user privacy and in accordance with relevant legal frameworks.
- We do not ever sell or rent your Personal Information without your express approval.
- We do not share Personal Information with advertisers or third-party sites displaying our interest-based ads. However, advertisers may infer user interests from interactions with ads and might provide us with demographic information to enhance ad relevance. Advertisers can serve ads directly to your browser, receiving your IP address, and may use cookies to evaluate ad effectiveness. We do not control these cookies or the practices of third-party advertisers, so please refer to their privacy policies for more information.
- We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations. If you no longer wish to receive correspondence, emails, or other communications from third parties, you are responsible for contacting the third party directly.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
In compliance with applicable laws, we retain your Personal Information for a duration no longer than necessary for the purpose for which it was collected or as mandated by relevant laws. However, certain data related to you may be retained beyond this period if we reasonably believe it is necessary to prevent fraud, mitigate potential abuse, allow us to exercise our legal rights, defend against legal claims, or fulfil other legitimate purposes required by law. You understand that we may continue to retain your Personal Information in anonymised form for analytical and research purposes. Additionally, we may continue to retain your Personal Information for the following purposes, including but not limited to:
- Legitimate Business Interest: We may retain your Personal Information as necessary for our legitimate business interests, such as the prevention of money laundering, fraud detection and prevention, and enhancing safety;
- Legal, Tax, Reporting, and Auditing Obligations: We may retain and use your Personal Information to the extent necessary to comply with our legal, tax, reporting, and auditing obligations;
- Shared Information: Information you have shared with others, such as reviews and forum postings, may continue to be publicly visible on the Website, even after your Account is cancelled; and
- Residual Copies: Because we take measures to protect data from accidental or malicious loss and destruction, residual copies of your Personal Information may not be removed from our backup systems for a limited period of time.
HOW DO WE PROVIDE FOR THE SECURITY OF YOUR PERSONAL INFORMATION WITH US?
- We prioritise the security of your data, utilising secure cloud servers where your Personal Information is encrypted at rest, adding an extra layer of protection against unauthorised access. All data transfers are safeguarded through Secure Sockets Layer (SSL) technology, ensuring your Personal Information remains secure during transmission. We implement reasonable physical, electronic, and procedural safeguards to ensure the confidentiality and integrity of your information. Accessing your information is facilitated through a secure server, and once in our possession, your data is subject to strict security guidelines to prevent unauthorised access. Further, access to your information is restricted to our internal team members only to maintain confidentiality and security.
- We work to protect the security of your Personal Information during transmission by using encryption protocols. We use multi-layered controls to help protect our infrastructure, constantly monitoring and improving our applications, systems, and processes to meet the growing demands and challenges of security. We ensure that the third parties who provide services to us under appropriate contracts take appropriate security measures to protect your Personal Information in line with our policies.
- You understand and agree that despite the security measures in place, we cannot be held liable for any issues related to data security. Nevertheless, we implement reasonable physical, electronic, and procedural safeguards to maintain the confidentiality and integrity of your information. As part of this commitment, it is imperative that you also review and adhere to the terms of service and privacy policy of our third-party service providers.
- While we take comprehensive measures to safeguard your information, users acknowledge and accept the inherent security implications of data transmission over the Internet and the World Wide Web. Despite our efforts, complete security cannot be guaranteed, and inherent risks persist. Users bear the responsibility of safeguarding login and password records for their Accounts. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on the Website. While acknowledging these risks, we remain committed to continually enhancing our security protocols to address emerging threats and maintain the trust of our users.
HOW DO WE HANDLE DATA BREACHES AND SECURITY INCIDENTS?
In the event of a data breach or security incident, we maintain a proactive approach to ensure swift resolution and mitigate potential risks. We have established a comprehensive incident response plan designed to address such occurrences promptly and effectively:
- Identification: We promptly identify and acknowledge any signs of a data breach or security incident within our systems or infrastructure;
- Containment: Immediate action is taken to contain the impact of the breach, preventing further unauthorised access or damage to data;
- Notification: We prioritise transparency by promptly notifying affected parties, including users and relevant stakeholders, about the breach and its potential impact on their data;
- Collaboration: We collaborate with relevant authorities, such as regulatory bodies and law enforcement agencies, to report the incident and comply with any legal obligations or regulatory requirements; and
- Post-Incident Assessment: Following the resolution of the incident, we conduct thorough assessments to evaluate the effectiveness of our response measures and identify areas for improvement.
WHO IS THE DATA CONTROLLER AND DATA PROCESSOR OF YOUR PERSONAL INFORMATION?
- We will act as the data controller where we make decisions on how your Personal Information is used in connection with the Website or our Services. We will act as the data processor where we only use your Personal Information as authorised and instructed by a third party in connection with the Website, our applications or Services.
- Where we are acting as the data controller, we are responsible for the obligations of a data controller under data protection laws in connection with the processing of your Personal Information, and we use this Privacy Policy to provide you with information about our use of your Personal Information.
- Where we are acting as a data processor, the relevant third party will be acting as a data controller and will be responsible for the obligations of a data controller under data protection laws in connection with the processing of your Personal Information. If you are accessing the Website or our Services through a third party, you should contact them with queries regarding the processing of your Personal Information or compliance with data protection law.
DO WE TRANSFER YOUR PERSONAL INFORMATION ACROSS THE BORDER?
- While our primary practice is to store all data on servers located within India, it’s important to note that certain circumstances may necessitate the transfer of your Personal Information to countries outside your residential country. These transfers may occur for various purposes outlined in this Policy.
- You understand and accept that other countries may have differing (and potentially less stringent) laws relating to the degree of confidentiality afforded to the information it holds and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies, and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar processes. In addition, a number of countries have agreements with other countries providing for the exchange of information for law enforcement, tax, and other purposes.
- If we transfer your Personal Information to third parties for purposes stated in this Policy, we will use our best endeavors to put in place appropriate controls and safeguards to ensure that your Personal Information is kept accurate, adequately protected, and processed only for specified and reasonable purposes in a manner that is fair, transparent and has a lawful basis, and is stored for no longer than is absolutely necessary.
WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?
- You, as a data subject, may have certain rights to your Personal Information with us, as under:
- Request access to your Personal Information: This allows you to receive a copy of the Personal Information we hold about you, and to check that we are lawfully processing it;
- Request the correction of your Personal Information: This allows you to ask for any incomplete or inaccurate information we hold about you to be corrected;
- Request the erasure of your Personal Information: This allows you to ask us to delete or remove your Personal Information from our systems where there is no good reason for us to continue processing it;
- Object to the processing of your Personal Information: This allows you to object to our processing of your Personal Information for a specific purpose (for example, for marketing purposes);
- Request the transfer (data portability) of your Personal Information: This allows you to request the transfer of your Personal Information in a structured, commonly used, machine-readable format, either to you or to a third party designated by you and, if technically feasible, have it transmitted to another controller without any hindrance. This provision is applicable provided that your information is processed by automated means and that the processing is based on your consent, on a contract of which you are a part, or on pre-contractual obligations thereof;
- Request the restriction: You have the right to request the restriction of the processing of your Personal Information. This means we will store your Personal Information but not further process it, except in limited circumstances (e.g., with your consent or for legal claims);
- Request further information on the processing of your Personal Information: You have the right to obtain further information on how we process your Personal Information. This includes details about the purposes of the processing, the categories of Personal Information involved, the recipients or categories of recipients with whom the Personal Information has been or will be shared, and the envisaged retention period of the Personal Information.
- Withdraw your Consent: This right only exists where we are relying on your consent to process your Personal Information. If you withdraw your consent, we may not be able to provide you with access to certain features of our Website. We will advise you if this is the case at the time you withdraw your Consent.
- User’s State-Specific Rights:
- If you are a citizen of India, you may have additional rights listed in Schedule I. Please refer to Schedule I below for more detailed information on your rights.
- If you are a citizen of the European Union, you may have additional rights listed in Schedule II. Please refer to Schedule II below for more detailed information on your rights.
- If you are residing in the United Kingdom, you may have rights listed in Schedule III. Please refer to Schedule III below for more detailed information on your rights.
- If you are residing in the United States including states such as California, Colorado, Connecticut, Delaware, Florida, Iowa, Montana, Nevada, Oregon, Texas, Utah, Vermont, Virginia, or Washington, or are otherwise protected by privacy or consumer health data laws in those jurisdictions, please refer to Schedule IV that outlines state-specific rights and protections afforded to you.
- Please note that these Schedules are supplemental to our Privacy Policy.
- In relation to the above, you can exercise such right by sending us an email with your request to [email protected] along with the necessary proof of identity requirements that we may require prior to processing such a request from you.
- We are committed to respecting and protecting your privacy and will make every effort to accommodate your requests and address your concerns in accordance with applicable laws. It’s important to note that we may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. This ensures that your rights are upheld and that we respond to your inquiries promptly and effectively.
- While we strive to cover the privacy rights of Users in various jurisdictions through this Privacy Policy and the accompanying Schedules, we understand that some Users may be in regions with specific data protection laws that are not explicitly addressed here. If you are a User whose data subject rights are not clearly covered in this Privacy Policy or the Schedules, please reach out to us for assistance at [email protected]. You can contact us to: (a) inquire about the processing of your Personal Information; (b) request access, rectification, or erasure of your Personal Information; (c) restrict or object to the processing of your Personal Information; and (d) exercise any other rights granted under applicable data protection laws in your jurisdiction.
- Please be aware that these rights are subject to legal restrictions. We will respond to your request as soon as possible, typically within one month at the latest. If you believe that our processing of your Personal Information is unlawful, you have the right to complain to the [email protected]. We hope that you will first contact us so that we can assess your objections and clarify any misunderstandings.
ARE CHILDREN ALLOWED TO USE OUR WEBSITE AND/OR SERVICES?
- This Website and/or Services are strictly prohibited for use by individuals under the age of eighteen (18) years or the age of majority as defined by the applicable laws of their country of residence. Specifically, individuals under the age of sixteen (16) residing in European Union (EU) countries and those under thirteen (13) years old in the United States or United Kingdom are also restricted from accessing our Website and Services (collectively referred to as “Minors”) Accessing or using the Website and/or Services by Minors constitutes a violation of our Terms of Use and Privacy Policy.
- We do not knowingly collect, solicit, or process any Personal Information from Minors. We implement commercially reasonable age verification measures and data protection practices to prevent such unauthorised collection and usage.
- If you are a parent or legal guardian (”Guardian”) and believe your child has provided us with Personal Information, we urge you to promptly contact us at [email protected]. Upon verification of your Guardian status, we will promptly take all necessary steps to remove and delete such information from our records.
HOW CAN YOU EXPRESS YOUR COMPLAINTS AND CONCERNS?
User satisfaction is one of the key focus areas and an integral part of our Website’s founding principles and business policies. We strongly believe that User satisfaction is the most important factor in the growth and development of our business, and hence, we have adopted user-centricity as a priority in developing our business processes. The terms below shall constitute our “User Grievance Redressal Policy”, which outlines the framework for addressing User grievances:
- Objective: The objective of this Grievance Policy is to provide a framework:
- to ensure the provision of timely and effective resolution of issues raised by the User; and
- to keep the User informed about the manner in which they can reach out to us to resolve their queries and grievances.
- Governing Principles: The policy on grievance redressal is governed by the following principles:
- User shall be treated fairly at all times;
- issues raised by Users are always attended to with courtesy and on time;
- Users are provided with effective and satisfactory resolution within a reasonable time period; and
- Users are fully informed of avenues to escalate their issues/ grievances if they are not fully satisfied with the response to their complaints.
- Grievance Redressal: Any User can reach out to our Grievance Redressal Officer through electronic mode by way of email communication at [email protected]. Users can expect a reply within 7 days; and
- Must Know: You must know and understand that-
- We DO NOT solicit confidential details like your OTP/CVV/PIN/Card Number/ Bank account details through any means.
- Scamsters/fraudsters attempt various techniques such as ‘phishing’ to contact, influence, and defraud consumers. We regularly caution our Users against sharing any personal or payment-sensitive information with unknown persons, as such sharing leads to unauthorised use and/or fraud and consequent financial loss.
- We shall not be liable for any loss, damage, or expense incurred by a User where the User has shared personal and/or payment-sensitive information with scamsters/fraudsters.
- We also request and encourage our Users to report such attempts or incidents to us at [email protected] to enable us to investigate and explore legal recourse.
HOW ARE CHANGES MADE TO THIS POLICY?
This Policy may be updated at our sole discretion or due to changes in the law. Such changes, unless otherwise stated, will be effective from the day and date of posting on the Website. We reserve the right to update the Policy without obligation to notify Users. It is recommended to regularly review this Policy for any changes, as your continued access and use of the Website will be considered your approval and acceptance of all modifications to this Policy. In cases where applicable law mandates, we may notify you of updates through email. If you do not agree with this Policy governing our Website, please refrain from using the Website or the Services provided by us.
HOW CAN YOU CONTACT US?
Should you need additional information or have any questions or complaints regarding the handling of your Personal Information, please reach out to us in writing at:
Email: [email protected]
Schedule I- Indian Residents
We are committed to safeguarding the privacy rights of our Users in India. This schedule outlines our compliance with Indian privacy laws, including theInformation Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (IT Rules), and the Digital Personal Data Protection Act (DPDPA), 2023. These regulations ensure that Personal Data is processed fairly, lawfully, and transparently.
YOUR DATA SUBJECT RIGHTS:
- Right to Consent: Your explicit consent is required for the collection and processing of your Sensitive Personal Data or Information (SPDI).
- Right to Access: You have the right to access your Personal Data and obtain a copy of it.
- Right to Correction: You can request corrections to any inaccurate or incomplete Personal Data.
- Right to Withdrawal of Consent: You can withdraw your consent to the processing of your Personal Data at any time.
- Right to Review Information: You can review the information you have provided and ensure it is accurate and up-to-date.
- Right to Grievance Redressal: You have the right to lodge a complaint regarding the processing of your Personal Data with our Grievance Officer.
DATA RETENTION AND DE-IDENTIFICATION:
We are committed to retaining Personal Information only for as long as necessary to fulfil the purposes for which it was collected, as outlined in our main Privacy Policy (see Clause 6). We may also take measures to de-identify Personal Information in accordance with applicable laws and regulations.
APPEAL PROCESS
If you disagree with the Firm’s response to your privacy rights request or believe your rights have not been adequately addressed, you have the right to appeal. You can submit your appeal in writing to our Data Protection Officer at [email protected] with the subject line ”Appeal of Privacy Rights Request.”
LODGING A COMPLAINT
If you believe your rights have been violated or are dissatisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of India (DPIC). The DPIC is responsible for handling complaints related to data protection and ensuring compliance with the DPDPA.
ADDITIONAL INFORMATION:
For more detailed information on how we handle your Personal Information, including our data collection practices, security measures, and third-party disclosures, please refer to our main Privacy Policy available.
Schedule II- European Union Residents
We are committed to ensuring compliance with the European Union General Data Protection Regulation (GDPR).
Although our Privacy Policy explains how we meet all of our obligations for United Kingdom Users, we also have some Users who are habitually located in the European Union (‘EU Residents’) who have additional rights with respect to their Personal Data.
Personal Data is defined as: “Any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier”. The term “Personal Data” should be considered fundamentally interchangeable with the expression “Personal Information” for the purposes of this Privacy Policy.
Under the GDPR, we are the “Data Controller” and “Data Processor” of Personal Data. As part of our GDPR compliance, we provide and operate the App in a way that ensures: Personal Data (i.e. Personal Information) is processed fairly, lawfully, and in a transparent manner; and collected and processed only for specified and lawful purposes.
We ensure that the Personal Data we collect about you is accurate, complete, and used for its intended purpose. You may access, review, correct, and update your Information by contacting us by email at the contact details below.
EUROPEAN UNION RESIDENTS
In certain circumstances, you have certain rights regarding your Personal Information. A summary of each right and how you can exercise it is detailed below. To exercise any of these rights, please contact us at [email protected]. Such requests should include information to allow us to verify your identity (e.g. your name, address, email address, or other information reasonably required).
Where we receive your request to exercise one of these rights, we will respond without undue delay and within the time required by applicable law. This may be extended in certain circumstances, e.g. where requests are complex or numerous.
We will provide the information free of charge, except where requests are manifestly unfounded or excessive, e.g. because of their repetitive character. In these circumstances, we may charge a reasonable fee or may refuse to act on the request. We will advise you of any fees prior to proceeding with a request. We may ask for additional information to verify your identity before carrying out a request.
HOW CAN YOU EXERCISE YOUR RIGHT?
- Right to access and/or correct your Personal Data
You have the right to access the Personal Data we hold about you, and to be provided with a copy of the information (in most circumstances). You also have the right to correct any information we may hold about you that is inaccurate.
- Right to restrict the use of your Personal Data
You have the right to ask us to restrict the processing of your Personal Data where one of the following applies:
- The processing is unlawful, but you want us to restrict the use of the data instead of deleting it;
- Where you contest the accuracy of your Personal Data, the restriction will apply until we have verified the accuracy or corrected your Personal Data;
- We no longer require the Personal Data for the purposes of the processing, but are required to keep it in connection with a legal claim;
- You have exercised your right to object to the processing. The restriction will apply until we have taken steps to verify whether we have compelling legitimate grounds to continue processing.
- Right to withdraw consent and request deletion of your Personal Data
- You have the right to ask us to delete your Personal Data in most circumstances. There are also certain exceptions where we may refuse a request for erasure, for example, where the Personal Data is required to comply with a legal obligation or for the establishment, exercise, or defence of legal claims.
- You may object to our use of your Personal Data for marketing purposes, and you can let us know via the provided email address.
- Further, you may also object to the processing of your Personal Data in cases where we have used legitimate interests as the basis for processing. In such cases, we will stop processing your Personal Data until we verify that we have compelling legitimate grounds for processing that outweigh your interests, rights, and freedoms in asking us to stop processing the data, or in limited cases where we need to continue processing the data for the establishment, exercise, or defence of legal claims.
- Data retention and anonymisation
We are committed to retaining Personal Information only for as long as necessary to fulfil the purposes for which it was collected, as outlined in our main Privacy Policy (see Clause 6). We may also take measures to de-identify Personal Information in accordance with applicable laws and regulations.
- Right to data portability
In most cases, you have the right to receive all Personal Data you have provided to us in a structured, commonly used, and machine-readable format and to transmit this data to another data controller, where technically feasible.
- Right to lodge a complaint with a supervisory authority
If you are a resident of the EU, you have the right to make a complaint at any time to the regulator in your jurisdiction. To find out how to contact your local regulator, please visit https://edpb.europa.eu/about-edpb/about-edpb/members_en.
We will allow and assist Users who are EU Residents to exercise these rights unless we have compelling and legitimate legal grounds not to (e.g. a legal obligation under United Kingdom legislation, or if the Personal Data has been fully anonymised).
Schedule III: United Kingdom (UK) Residents
We are dedicated to upholding the principles of the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
While our Privacy Policy outlines our commitments to European Union Users, we recognise that Users located in the United Kingdom (‘UK Residents’) have additional rights concerning their Personal Data.
YOUR DATA SUBJECT RIGHTS:
You have a number of rights under applicable Data Protection Laws in relation to your Personal Information. Under certain circumstances, you have the right to:
- ave access to your Personal Information by submitting a request to us;
- ave your Personal Information deleted;
- ave your Personal Information corrected if it is wrong;
- ave the processing of your Personal Information restricted;
- bject to further processing of your Personal Information, including to object to marketing from us;
- ake a data portability request;
- ithdraw any consent you have provided to us;
- estrict any automatic processing of your Personal Information; and
- omplaint to the appropriate supervisory authority.
- o exercise any of these rights, please contact us [email protected].
BASIS FOR PROCESSING:
We will only process your Personal Information when we have a lawful basis to do so, such as consent, contractual necessity, or legitimate interests. Also, please refer to Clause 5 to understand how we process your Personal Information.
PROCESS OF APPEAL:
If you disagree with the Firm’s response to your privacy rights request or believe your rights have not been adequately addressed, you have the right to appeal. You can submit your appeal in writing to our Data Protection Officer at [email protected] with the subject line ”Appeal of Privacy Rights Request”.
Schedule IV: United States Residents
We are dedicated to adhering to the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA) and other relevant state privacy regulations. If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Iowa, Montana, Nevada, Oregon, Texas, Utah, Vermont, Virginia, or Washington, or if you fall under the protections offered by privacy laws in those states, this section serves as an addition to our primary Privacy Policy, detailing your specific rights and protections.
According to the CCPA, ”Personal Information” encompasses any data that can identify, relate to, describe, or be reasonably associated with a specific consumer or household. This includes a variety of information types such as names, addresses, and online identifiers, among others.
We make every effort to ensure that the Personal Information we gather is precise, relevant, and utilised correctly. You have the right to access, delete, and request disclosures regarding your Personal Information. For any questions or to exercise these rights, please reach out to us using the contact details provided below.
YOUR PRIVACY RIGHTS:
- Right to access: You can access the information that has been provided by you by reaching out to us at [email protected].
- Right to withdraw consent: The consent that you provide for the collection, use, and disclosure of your Personal Information will remain valid until such time it is withdrawn by you in writing. If you withdraw your consent, we will stop processing the relevant Personal Information except to the extent that we have other grounds for processing such Personal Information under applicable laws. We will respond to your request within a reasonable timeframe. You may withdraw your consent at any time by contacting us; and
- Right to Opt-Out: You have the right to opt out of certain processing activities, such as the sale of Personal Information or the use of Personal Information for targeted advertising purposes. Firmli will respect your preferences and refrain from such activities upon your request.
- Right to correction: You are responsible for maintaining the accuracy of the information you submit to us, including but not limited to your Contact Information. For any necessary updates or corrections to your Personal Information, Users can easily modify details using the provided App functionalities or by reaching out to us at [email protected].
- Right of Access and Portability: In some jurisdictions, applicable law may entitle you to request certain copies of your Personal Information or information about how we handle your Personal Information, request copies of Personal Information that you have provided to us in a structured, commonly used, and machine-readable format, and/or request that we transmit this information to another service provider, where technically feasible.
- Right of Erasure: In some jurisdictions, you can request that your Personal Information be deleted.
DATA CONTROLLER AND PROCESSOR:
Under various U.S. privacy laws, including but not limited to the California Consumer Privacy Act (CCPA) and other state-specific regulations, we act as the “Data Controller” as well as “Data Processor” of Personal Data. To ensure compliance, we operate our services in a manner that guarantees: Personal Data is processed fairly, lawfully, and transparently; and it is collected and used only for legitimate and specified purposes.
APPEAL PROCESS:
If you disagree with the Firm’s response to your privacy rights request or believe your rights have not been adequately addressed, you have the right to appeal. You can submit your appeal in writing to our Data Protection Officer at [email protected] with the subject line ”Appeal of Privacy Rights Request”
DATA RETENTION AND DE-IDENTIFICATION:
We are committed to retaining Personal Information only for as long as necessary to fulfil the purposes for which it was collected, as outlined in our main Privacy Policy (see Clause 6). We may also take measures to de-identify Personal Information in accordance with applicable laws and regulations.
LODGING A COMPLAINT
If you believe your rights have been violated or are dissatisfied with our response, you have the right to lodge a complaint with the federal agencies such as the Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB). You may also contact the State Attorney General’s Office of your residential state. These organisations are responsible for handling complaints related to data protection and ensuring compliance with the privacy laws.
ADDITIONAL INFORMATION:
For more detailed information on how we handle your Personal Information, including our data collection practices, security measures, and third-party disclosures, please refer to our main Privacy Policy available.