Data protection and DPDP readiness
1. The operating boundary
PRAMAAN's live India service is designed around India-hosted matter storage. Customer matter records and documents are stored in India-hosted systems. AI inference is a separate processing step and may use approved processors outside India.
This page describes PRAMAAN's data protection posture. It is not a standalone legal opinion or a promise that every customer use case automatically satisfies the Digital Personal Data Protection Act, 2023.
2. Roles
For customer matter data, the firm decides what to upload, which users may access it, and whether AI features may process it. PRAMAAN processes that data to provide the service and to meet the platform commitments it makes to the firm.
The firm remains responsible for client authority, privilege, confidentiality, conflict checks, and any client-specific or matter-specific restriction on processing.
3. Notice and consent gates
PRAMAAN separates account creation from AI-processing authorization. Firm administrators should review the Terms, Privacy Notice, AI Processing Disclosure, and Approved AI Processors before enabling AI features for matter content.
If India-only AI inference is required, firm administrators can request an India-resident inference policy from the settings panel. The firm chooses its inference policy, can change it, and PRAMAAN records policy changes in the audit log.
4. Security controls
- Firm-scoped access and role-based permissions.
- Encryption in transit and at rest for platform storage paths.
- Audit records for material product actions and AI inference policy changes.
- Controlled internal access for support, security, debugging, legal compliance, and approved quality workflows.
- Processor review for services that may handle customer data.
5. Rights, correction, and deletion
Firm administrators may request export, correction, deletion, or restriction of firm data where available under the service agreement and applicable law. Because firms control the client relationship, data-principal requests about matter data should generally be routed through the firm.
6. Breach and incident handling
PRAMAAN will investigate suspected security incidents and notify affected customers as required by the applicable agreement and law. Customers should maintain their own internal incident and client-notification procedures for matter-specific duties.