Applies to: https://legal.indiansmechamber.com/ and the pages, forms and services made available through it
1. Who we are and the law that applies
1.1This website is operated by Indian MSME Helpline Private Limited a Private Limited Company registered under Companies Act, 2013, with its registered office at 1106, New Delhi House Barakhamba Road, Connaught Place, Delhi, India, 110001, India. In this policy, "we", "us" and "our" refer to that entity.
1.2We provide or facilitate legal retainership, advisory and related professional services through advocates enrolled with the relevant State Bar Council(s). The engagement letter or other service document identifies the advocate or entity responsible for a particular matter.
1.3For website administration, enquiries, onboarding, billing, security and our own professional or legal obligations, we decide why and how personal data is processed. When information is supplied in a client matter, our role may depend on the circumstances. Nothing in this policy limits legal professional privilege, advocates’ duties of confidentiality, court rules or other applicable law.
1.4This policy is written for laws in force on its effective date. The Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") have phased commencement. A reference in this policy to a provision that is not yet in force applies from its notified commencement date. Until the relevant DPDP provisions commence, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") continue to apply where relevant. We may follow DPDP-aligned practices voluntarily before they become mandatory.
1.5Privacy questions may be sent to [email protected] or to the postal address above.
2. Scope of this policy
2.1This policy covers personal data handled through the website, contact and retainership forms, consultations, email and WhatsApp communications, payments, invoicing and the delivery of legal services.
2.2It does not govern third-party websites or services reached through links from our website. Those third parties process information under their own notices and terms.
2.3This policy provides general transparency information. Where we ask for personal data, a form, consent request, engagement letter or other specific notice may provide additional details. The more specific notice will apply to that collection and must be read with this policy.
2.4In this policy, "personal data" includes information that identifies you or can reasonably be linked to you. It includes "personal information" and "sensitive personal data or information" where the SPDI Rules apply. From the applicable commencement date, terms defined in the DPDP Act have the meanings given in that Act.
3. Personal data we may collect
We collect data that is reasonably necessary for the relevant purpose. Depending on how you interact with us, this may include:
| Category | Examples |
| Identity and contact details | Name, email address, phone number, postal address, pincode, city and state. |
| Business and onboarding details | Company or business name, designation, business address, annual turnover band, selected retainership plan and information needed for a conflict check. |
| Enquiry and matter information | The message submitted through a form; instructions; documents; contracts; notices; correspondence; facts about parties, witnesses or other persons; consultation notes; and court or public-record information relevant to a matter. |
| Payment and tax information | Billing name and address, GSTIN, PAN where legally required, amount, transaction reference, status and a masked payment-instrument identifier. Card number, CVV, UPI PIN and similar credentials are handled directly by the payment service provider and should not be sent to us. |
| Technical and usage data | IP address, browser and device information, operating system, referring page, pages viewed, date and time, security logs, cookie identifiers and consent choices. |
| Sensitive information contained in a matter | Financial information, health information, biometric or other sensitive information, only where it is relevant to the matter or required by law. |
3.1We may receive information from you, your authorised representatives, staff, accountant, auditor or company secretary; from public and court records; from payment and technology service providers; and from another party where the law permits.
3.2Please do not send passwords, complete payment credentials, Aadhaar details or other highly sensitive information unless we specifically request it and explain why it is necessary.
4. Why we use personal data
We process personal data only for a lawful and stated purpose. The main purposes and conditions are:
| Purpose | Data generally used | Condition or justification |
| Respond to enquiries and arrange consultations | Identity, contact and enquiry details | To take action on your request and communicate with you; consent where required. |
| Conduct conflict checks and decide whether to accept an engagement | Names of the client, business and relevant parties; brief matter information | Necessary to consider the proposed engagement and comply with professional duties; consent where required. |
| Onboard clients and provide legal services | Contact, business, matter and consultation information | Your instructions and consent; steps necessary to provide the requested service; compliance with court, legal and professional obligations. |
| Process payments, issue invoices and maintain records | Contact, billing, tax and transaction information | To administer the service and comply with tax, accounting and record-keeping law. |
| Operate and secure the website and systems | IP address, device, cookie and log data | To provide requested functionality, prevent misuse, investigate incidents and meet cyber-security obligations. |
| Measure website usage | Cookie and usage data | Only with prior consent where the analytics technology is not strictly necessary. |
| Send newsletters or promotional updates | Name, email and communication preferences | Separate, specific opt-in consent. Each message will provide an unsubscribe method. |
4.1We do not sell or rent personal data. We do not use enquiry or matter information for unrelated advertising, and we do not add contact-form users to a marketing list without a separate opt-in.
4.2We may use anonymised or aggregated information for internal analysis where it no longer identifies an individual.
5. Consent and withdrawal
5.1Where consent is required, we ask for a clear affirmative action and provide information about the specific data and purpose. We do not treat silence, pre-ticked boxes, scrolling or continued browsing as consent for non-essential processing.
5.2You may withdraw consent through the method shown at the point of collection, through cookie settings where applicable, or by emailing [email protected] with the subject "Withdraw consent". We normally implement a valid withdrawal within 7 working days, or sooner where technically possible.
5.3Withdrawal does not affect processing already carried out lawfully. It may prevent us from continuing a service where the relevant processing is necessary. We may retain limited information where required by law, professional obligations, court process, privilege or the establishment, exercise or defence of legal claims.
5.4Information submitted only for an enquiry is used to respond to that enquiry and related follow-up. It is not used for marketing unless you separately opt in.
6. Children and persons represented by a lawful guardian
6.1The website’s enquiry and retainership services are intended for persons who are 18 years of age or older. We do not knowingly invite a child to purchase a service or independently instruct us through the website.
6.2A legal matter may nevertheless contain personal data about a child. We process it only where relevant to the matter and on the instructions or authority of a parent, lawful guardian, court or other person legally entitled to act. From the commencement of the applicable DPDP provisions, we will obtain verifiable parental consent unless an exemption or other lawful authority applies.
6.3We do not knowingly use tracking, behavioural monitoring or targeted advertising directed at children.
6.4Where a person with a disability has a lawful guardian authorised to act on their behalf, we verify the guardian’s authority to the extent reasonably required by applicable law.
7. Who may receive personal data
We disclose only what is reasonably necessary for the stated purpose. Recipients may include:
| Recipient category | Information and purpose |
| Website hosting, cloud, content-delivery and security providers | Technical data, website content and form submissions needed to host, deliver and protect the website. |
| Email, communications and document-management providers | Correspondence and documents needed to communicate and manage the engagement. |
| Payment gateways, banks and payment service providers | Contact, amount and transaction information needed to process and confirm payment. The provider may independently process payment credentials under its own privacy notice. |
| Accountants, auditors and professional advisers | Billing, payment and business records needed for tax, audit, compliance or advice. |
| Advocates, counsel, local counsel, experts and service professionals | Matter information reasonably necessary to provide the service, subject to confidentiality and privilege where applicable. |
| Courts, tribunals, arbitrators, opposing parties, regulators and public authorities | Information required by a filing, process, law, order or professional obligation. |
| Persons authorised by you | Information covered by your instruction or authority. |
7.1A recipient may act as our service provider or may independently determine aspects of its processing, depending on its role. We use written confidentiality, data-protection and security terms where appropriate and legally required.
7.2We do not share enquiry or matter data with an affiliate, promoter body or group entity for that entity’s marketing unless you have separately consented.
7.3Professional communications are protected by applicable advocates’ confidentiality duties and Sections 132 to 134 of the Bharatiya Sakshya Adhiniyam, 2023, subject to the statutory exceptions, client consent and valid legal process.
8. Processing outside India
8.1Some technology providers may store or route website traffic, communications or support data outside India. Matter files and privileged material are not transferred outside India unless the engagement requires it, the transfer is permitted by law and appropriate safeguards are applied.
8.2While the SPDI Rules apply, sensitive personal data or information is transferred only where the recipient ensures the same level of data protection and the transfer is necessary for performance of a lawful contract or you have consented.
8.3From the applicable commencement date of the DPDP framework, transfers will also comply with any restriction, condition or order issued by the Central Government. Sector-specific localisation requirements, where applicable, will prevail.
8.4Safeguards may include contractual purpose limits, confidentiality, access controls, encryption in transit, appropriate protection at rest and deletion or return requirements.
9. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the stated purpose, legal or professional obligations and the establishment, exercise or defence of legal claims. Our usual periods are:
| Category | Usual retention period |
| Enquiries that do not become an engagement | Up to 12 months after the last meaningful contact. |
| Conflict-check records | Normally 8 years after the check, or longer where needed to identify a continuing professional conflict. |
| Client matter files | Normally 8 years after the matter closes, or longer while any appeal, execution, limitation period, complaint, investigation or claim remains relevant. |
| Invoices, receipts, ledgers and tax records | For the period required by applicable tax, accounting and entity law, and longer where proceedings or investigations are pending. |
| Server, access and security logs | At least 180 days where the CERT-In directions apply; selected audit and security logs may be retained for up to one year or longer where an incident or law requires. |
| Marketing consent and suppression records | While subscribed; after withdrawal, limited evidence and suppression records may be retained for up to 3 years. |
| Backups | Until overwritten under the normal backup rotation, ordinarily within 90 days, unless isolated for security, continuity or legal reasons. |
9.1When a retention period ends, we securely delete or irreversibly anonymise the data. Data in routine backups is allowed to age out and is not restored for ordinary use after deletion.
9.2A legal hold, court order, statutory duty, professional obligation, privilege issue or pending claim may require a longer period. In that case, access and use are restricted to that purpose.
10. Security safeguards
10.1We use reasonable technical and organisational safeguards appropriate to the nature of the data and the risks involved. Measures may include:
- TLS encryption for data transmitted through supported website and communication channels, and appropriate protection for stored matter data and backups.
- Role-based and need-to-know access, strong authentication, periodic access review and prompt removal of access when responsibilities change.
- Masking, obfuscation or minimisation where complete identifiers are not needed.
- Logging, monitoring, vulnerability management, malware protection and procedures for detecting and investigating unauthorised access.
- Backups, restoration testing, business-continuity arrangements and incident-response procedures.
- Confidentiality obligations, vendor controls and appropriate privacy and security training.
10.2No method of transmission or storage is completely secure. We do not guarantee absolute security, but we investigate suspected incidents and take reasonable steps to contain, remediate and prevent recurrence.
11. Your choices and rights
11.1While the SPDI Rules apply, you may review and correct personal information you provided, withdraw consent where processing depends on consent and raise a grievance with the Grievance Officer.
11.2From the applicable commencement date of the DPDP Act, you may also exercise the statutory rights to obtain the prescribed access information, seek correction, completion, updating or erasure, use the grievance mechanism, nominate another individual in the circumstances recognised by law and withdraw consent.
11.3To make a request, email [email protected] from the email address or phone number already associated with you and clearly state the request. We may ask for limited additional information to verify identity or authority. We do not ask for more verification data than reasonably necessary.
11.4We acknowledge requests within 3 working days and ordinarily complete them within 30 days. Consent withdrawals are normally implemented within 7 working days. Where more time is reasonably required, we will explain the reason and the expected completion date.
11.5A request may be limited where retention or disclosure is required by law, court process, professional obligations or legal privilege, or where responding would adversely affect another person’s rights. We will explain the applicable limitation unless the law or privilege prevents us from doing so.
11.6If your data appears in another client’s matter file, we may need to consult or refer the request to that client and will not disclose privileged or confidential matter information merely because it contains your personal data.
12. Cookies and similar technologies
12.1We may use essential cookies or similar storage to provide requested website functionality, protect forms, maintain security and remember privacy choices. Where consent is legally required for such technology, we obtain it.
12.2Analytics, advertising or other non-essential technologies are activated only after the required consent. Refusing them should not prevent access to the core website.
12.3You may change a non-essential cookie choice through the website’s privacy or cookie settings where available. The Cookie Policy should identify each deployed category, purpose, provider and lifespan.
13. Personal data breaches and cyber incidents
13.1We maintain procedures to identify, contain, investigate and remediate suspected personal-data breaches and cyber-security incidents.
13.2Where a cyber incident is reportable under the CERT-In directions issued under section 70B of the Information Technology Act, 2000, we report it to CERT-In within the applicable period, currently 6 hours from noticing it or it being brought to our notice.
13.3From the applicable commencement date of the DPDP breach provisions, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the periods prescribed by law. Other notifications will be made where required by contract, court order or sector law.
13.4A notification may describe the nature of the incident, the data affected, likely consequences, measures taken and practical steps you may take. We may withhold information where disclosure would create a security risk or is prohibited by law.
14. Grievance redressal
14.1Contact the Grievance Officer for a concern about collection, use, disclosure, security, correction, withdrawal or any failure to act on a privacy request.
| Name | Mr. Sandeep Bhist |
| Designation | Secretary General |
| Email | [email protected] |
| Phone | +91 9999902336 |
| Address | 1106, New Delhi House, Barakhamba Road, Connaught Place, New Delhi 110001, India |
| Working hours | Monday to Saturday, 10:00 AM to 07:00 PM, excluding public holidays in Delhi |
14.2We acknowledge a grievance within 3 working days and aim to resolve it within 30 days. This period is intended to satisfy the one-month grievance period under the SPDI Rules where they apply and to remain within any applicable DPDP grievance period.
14.3Please provide your name and contact details, the relevant date or transaction, a clear description of the concern, the outcome requested and any reference number.
14.4From the date the relevant DPDP complaint right becomes operative, a Data Principal who is dissatisfied after exhausting our grievance mechanism may approach the Data Protection Board of India through the mechanism made available by the Board.
15. Changes to this policy
15.1We may update this policy when our processing, service providers or legal obligations change. The version and effective date at the top identify the current policy.
15.2Material changes will be notified through the website, email or another reasonable method. Where a new purpose requires consent, we will seek fresh consent rather than relying on a previous consent for an unrelated purpose.
15.3Previous versions may be requested from [email protected]
16. Contact details