Scope and who is responsible
This Privacy Policy applies to rohasnagpal.com, pages and tools operated under this domain, communications initiated through the website, and services made available through it, including legal AI resources, AI benchmarks, Should I Sue?, How Should I Sue?, SIS Lawyer Match, waitlists and lawyer empanelment.
Unless a service-specific notice says otherwise, Rohas Nagpal is responsible for deciding how personal data covered by this policy is processed. Questions, requests and grievances may be sent to rohasnagpal@gmail.com.
This policy does not govern independent websites or services that you visit through external links. It also does not govern a lawyer's processing after you contact or retain that lawyer. The lawyer or law firm will provide its own privacy information and will be independently responsible for its professional services.
Key privacy commitments
- I do not sell personal data or rent contact lists.
- I do not currently use personal data for third-party behavioural advertising.
- SIS matter information and documents will not be disclosed to an empanelled lawyer unless you take an affirmative step authorising that disclosure.
- Lawyer matching should initially use only the minimum matter attributes needed, such as jurisdiction, practice area, procedural stage, language and approximate value.
- API keys used in browser-based benchmarks are intended to remain within your browser and be transmitted directly to the relevant model gateway; they should not be submitted to this website's server.
- Service providers receive data only for defined operational purposes, subject to appropriate contractual and security controls where available.
Personal data that may be collected
Information you provide directly
- Identity and contact information: name, email address, telephone number, country, city, language, time zone, organisation and social-media profile.
- Communications: messages, feedback, beta applications, support requests, survey responses and correspondence through email or LinkedIn.
- SIS matter information: your description of a dispute, desired outcome, jurisdiction, parties, chronology, claim value, legal issues and procedural status.
- Uploaded evidence: contracts, notices, pleadings, invoices, emails, screenshots, correspondence and other documents you choose to provide.
- Account and transaction information: account identifiers, service selections, credit balances, payment status, invoices and limited transaction metadata. Payment-card details may be handled directly by a payment provider rather than stored by this website.
- Lawyer applications and panel information: information submitted through the SIS empanelment form, including professional name, email, phone, location, time zone, bar or law-society membership, enrolment or licence number, year of admission, jurisdictions, practice areas, forums, languages, years of experience, non-confidential representative work, matter preferences, availability, consultation formats, billing approach, professional-profile links, insurance status, declarations and privacy acknowledgements.
- Benchmark information: model selections, prompts, answers, scores, run settings, cost estimates, timestamps and your choice to keep a run private or publish it.
Sensitive and third-party information
Legal disputes can contain highly sensitive information, including financial information, allegations of wrongdoing, health information, identity documents, employment information, family information, communications and personal data about opponents, witnesses, employees or other third parties. Provide only information reasonably necessary for the service.
Before providing another person's data, you should have a lawful basis and any authority or consent required to do so. Where possible, redact irrelevant identifiers, financial credentials, authentication secrets, children's information and privileged material.
Technical and usage information
When you access the website, hosting and security systems may automatically receive your IP address, approximate location derived from the IP address, browser and device type, operating system, referring page, requested URL, timestamps, diagnostic information, security events and user-agent string. Interactive tools may also record feature interactions, run identifiers and error information. Lawyer empanelment submissions store the submitting IP address, browser user-agent, source and submission time for application security, audit and abuse prevention.
Sources of personal data
Most personal data comes directly from you. Data may also come from:
- your browser, device, hosting infrastructure and security services;
- public professional registers, bar councils, law societies, court directories and lawyer or law-firm websites used to verify empanelment information;
- publicly available professional profiles such as LinkedIn;
- payment, hosting, communications, model and other service providers;
- another person authorised to act for you; and
- documents or communications you submit that contain information about other people.
If material personal data is obtained from another source, appropriate notice will be given where required by applicable law.
How personal data is used
Personal data may be used to:
- provide, administer and improve the website, SIS services and benchmark tools;
- analyse dispute facts, documents, evidence, potential claims, legal issues and practical options;
- generate reports, recommendations, drafts, scores and other requested outputs;
- create and manage accounts, credits, waitlists, beta access and transactions;
- respond to messages, provide support and request product feedback;
- match users with suitable empanelled lawyers when requested;
- receive, assess and verify lawyer applications, communicate with applicants, record application status, administer the panel and assess professional standing, jurisdiction and panel suitability;
- maintain the integrity of benchmarks and publish results when the user selects publication;
- detect fraud, spam, abuse, security incidents and violations of applicable terms;
- debug, audit, monitor performance and maintain service availability;
- comply with law, court orders and valid governmental requests; and
- establish, exercise or defend legal claims.
I will not use identifiable SIS matter documents for unrelated marketing. If information is aggregated or de-identified so that it can no longer reasonably identify a person, it may be used for research, evaluation, service improvement and statistical reporting, subject to measures designed to prevent re-identification.
Legal bases for processing
The legal basis depends on the service, information and law that applies. Processing may be based on:
- Performance of a contract or steps requested before a contract: to provide a requested service, process a transaction or respond to an application.
- Consent: for optional communications, disclosure of matter information to a lawyer, certain sensitive-data processing and other circumstances where consent is requested.
- Legitimate interests: to secure, operate, evaluate and improve services; prevent abuse; maintain records; and communicate about requested products, where those interests are not overridden by your rights.
- Legal obligations: to comply with tax, accounting, regulatory, professional, court and law-enforcement requirements.
- Legal claims and substantial public interests: where applicable to sensitive data and permitted by law.
Where processing relies on consent, you may withdraw it. Withdrawal does not affect processing already lawfully undertaken, and some services may no longer be available if the necessary processing cannot continue.
Artificial intelligence and automated processing
SIS is designed around coordinated AI agents. Depending on the service, submitted text and documents may be converted, searched, classified, summarised, compared with legal sources, sent to one or more AI models, and combined into an assessment or draft. Outputs may include inferred claims, risks, evidence gaps, recommended options and lawyer-matching attributes.
Relevant content may be processed by model providers, document-processing providers, hosting providers or other processors acting on instructions. A service-specific notice at or before collection should identify material providers, retention choices and any configuration relevant to sensitive matter data. I will not knowingly authorise a provider to use identifiable SIS matter content to train a general-purpose model unless that use is clearly disclosed and you expressly consent.
AI output can be incomplete, outdated or wrong. SIS output is decision support and general information, not legal advice, and it does not itself determine legal rights. You decide whether to act, seek human review or contact a lawyer. Lawyer matching may use automated criteria, but empanelment and matching processes may also include human review.
Browser-based AI benchmarks
Some benchmark tools ask you to supply an API key and then send prompts directly from your browser to OpenRouter or another identified model service. Those providers process the prompts, credentials and outputs under their own terms and privacy notices. Some tools store API keys, draft runs or settings in localStorage, sessionStorage or IndexedDB on your device. Clearing the relevant browser storage removes those local copies.
SIS Lawyer Match and empanelled lawyers
If you request a lawyer match, SIS may use limited matter attributes already available from your SIS assessment to identify suitable lawyers. Initial matching should avoid disclosing your identity, documents or detailed narrative to panel lawyers.
You may receive the name and contact details of one or more suitable lawyers. Your contact details, documents, SIS report or matter summary will be sent to a lawyer only after you are shown what will be shared and give explicit permission. Consent for one introduction does not authorise disclosure to unrelated lawyers.
Before accepting a matter, the lawyer will conduct conflicts and professional checks. Contacting a lawyer does not guarantee acceptance. If a lawyer accepts, the lawyer's engagement, fees, advice, confidentiality obligations and data processing are separate from SIS.
Lawyer-panel data submitted through the application form is stored in the website database and used to verify credentials, assess suitability, contact the applicant, administer the panel and make appropriate matches. Verification may include checking public professional registers, reviewing the supplied profile links and contacting professional bodies or referees where appropriate. Internal reviewer notes, status and review timestamps may be added. Empanelment is not a guarantee of future referrals and may be suspended or withdrawn.
The application form also records consent to verification and acknowledgement of this Privacy Policy. Applicants should not submit client names, privileged material or other confidential matter information. If an applicant needs to correct or withdraw an application, they may use the privacy contact details in this policy.
When personal data may be shared
Personal data may be disclosed to:
- Infrastructure and technology providers that provide hosting, storage, security, email, document processing, model access, support and related services.
- Payment providers that process payments, refunds, fraud screening and transaction records.
- Empanelled lawyers when you explicitly request or approve an introduction or transfer.
- Professional advisers, including lawyers, accountants, auditors and insurers, where reasonably necessary and subject to duties of confidence.
- Authorities and other parties where required by law, valid legal process, safety needs or the establishment, exercise or defence of legal claims.
- A successor organisation in connection with a reorganisation, financing, merger, acquisition or transfer of a service, subject to appropriate confidentiality and notice requirements.
I do not sell personal data. At the effective date of this policy, I do not share personal data for cross-context behavioural advertising. If that practice changes, this policy and any legally required preference mechanism will be updated before the change applies.
Cookies, browser storage and external resources
The public website does not currently use third-party behavioural advertising cookies. Certain restricted or interactive areas use strictly necessary session cookies for authentication, security and continuity. The SIS lawyer-application page uses a session cookie to protect the form against cross-site request forgery and to display the confirmation message after a successful submission.
Benchmark and laboratory tools may use localStorage, sessionStorage or IndexedDB to retain API keys, settings, draft runs and run identifiers on your device. This browser storage is not the same as uploading the information to the website server. You can remove it using controls within the tool, where provided, or through your browser settings.
The website loads or links to resources operated by third parties, including Google Fonts, content-delivery networks, social platforms, embedded media and OpenRouter. When your browser connects to those services, they may receive your IP address, user-agent and requesting page and may apply their own storage technologies. Their privacy policies govern their independent processing.
You can restrict cookies and clear website data through your browser. Blocking strictly necessary storage may prevent authentication or interactive tools from functioning properly.
International data transfers
The website is operated from India and may use service providers or empanelled lawyers located in other countries. Personal data may therefore be processed outside your country, including in countries whose data-protection laws differ from yours.
Where applicable law requires transfer safeguards, appropriate mechanisms will be used, such as adequacy decisions, standard contractual clauses, contractual protections, explicit consent or another recognised legal basis. Information about a safeguard relevant to your data may be requested using the contact details below.
Lawyer matching does not, by itself, authorise an international transfer of your detailed matter information. Any proposed transfer to a lawyer will be disclosed as part of the consent step.
How long data is retained
Personal data is retained only for as long as reasonably necessary for the purpose collected, including providing the service, maintaining security, resolving disputes and meeting legal, tax, accounting and professional obligations. Relevant criteria include the sensitivity and volume of data, user expectations, limitation periods, contractual requirements and the feasibility of deletion from backups.
| Category | Typical retention approach |
|---|---|
| Waitlists and beta enquiries | Until access is provided, you withdraw, or the list is no longer operationally necessary; limited suppression records may be kept to respect opt-outs. |
| Communications and support | For the time needed to respond and maintain a reasonable record of the interaction. |
| SIS matter data and documents | For the service period stated at collection and any limited period needed for delivery, security, disputes or legal compliance. Deletion may be requested, subject to lawful exceptions. |
| Benchmark runs | Public runs may remain available until unpublished or deleted. Private runs are retained only as needed to provide the selected functionality. Local browser data remains until you or the browser removes it. |
| Transactions | For legally required tax, accounting, fraud-prevention and dispute periods. |
| Lawyer applications and panel records | While an application is considered, while the lawyer remains empanelled, and for a reasonable period afterward for verification, re-application, complaints, matching history and compliance. Unsuccessful or withdrawn applicants may request deletion, subject to lawful recordkeeping and security exceptions. |
| Technical and security logs | For a limited operational period proportionate to debugging, fraud prevention and security needs. |
When data is no longer required, it is deleted, anonymised or isolated from ordinary use. Residual copies may remain in protected backups until those backups are overwritten in the ordinary course.
Security
Reasonable administrative, technical and organisational measures are used or required to protect personal data against unauthorised access, alteration, disclosure, loss and destruction. Depending on the service, these may include access controls, encryption in transit, credential controls, logging, rate limits, backups, provider review and data-minimisation practices.
No system is completely secure. You are responsible for protecting your device, browser storage, passwords and API keys. Do not send passwords, private cryptographic keys, one-time codes, full payment-card details or unnecessary identity documents through ordinary email or LinkedIn messages.
If a personal-data breach creates a legally reportable risk, affected individuals and the appropriate authority will be notified as required by applicable law.
Your privacy rights and choices
Depending on where you live and which law applies, you may have rights to:
- know whether and how your personal data is processed;
- request access to or a copy of personal data;
- correct inaccurate or incomplete data;
- request deletion or erasure;
- restrict or object to certain processing;
- receive portable data in an appropriate format;
- withdraw consent;
- opt out of sale, targeted advertising or certain profiling where applicable;
- nominate another person to exercise rights where applicable;
- appeal or seek review of a refused request; and
- complain to a competent data-protection or supervisory authority.
To exercise a right, email rohasnagpal@gmail.com with the subject Privacy Request. Describe the service involved and the right you wish to exercise. Reasonable information may be requested to verify identity and protect against fraudulent requests. You may use an authorised agent where permitted by law, subject to verification of that authority.
Requests will be answered within the period required by applicable law. A request may be limited or refused where an exception applies, including protection of another person's rights, legal obligations, security, fraud prevention or legal claims. Reasons will be provided where required.
Additional regional information
India: Rights and grievance procedures under the Digital Personal Data Protection Act, 2023 and its rules apply as the relevant provisions come into force. You may contact the privacy and grievance contact below before approaching the Data Protection Board of India where applicable.
EEA and United Kingdom: Where the GDPR or UK GDPR applies, you may have rights of access, rectification, erasure, restriction, objection and portability and may complain to your local supervisory authority. Where legitimate interests are relied upon, information about those interests may be requested.
California: If the California Consumer Privacy Act applies to the relevant processing, California residents may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information and receive equal treatment. Personal data is not currently sold or shared for cross-context behavioural advertising.
Children's privacy
The website and SIS services are not directed to children under 18, and I do not knowingly solicit personal data from children. A parent, guardian or properly authorised representative should contact me before submitting information concerning a child. If you believe a child has provided personal data without appropriate authorisation, please request its deletion.
Changes, questions and grievances
This policy may be updated when services, providers, laws or processing practices change. The updated version will be posted on this page with a revised date. If a change materially affects an existing use of sensitive data, additional notice or consent will be provided where required.
Rohas Nagpal
rohasnagpal@gmail.comPlease use the subject “Privacy Request” or “Privacy Grievance” and identify the relevant website feature or service.
This policy is intended to provide transparent information about data practices. It does not reduce any non-waivable rights available under applicable data-protection law.