CasePrimus.aiby Attestr

Privacy Policy

Last updated: September 2026

1. Overview & scope

This Privacy Policy explains what personal data CasePrimus.ai collects, why, how long we keep it, who else sees it, and how to exercise your rights over it - whether you're browsing this website, using the CasePrimus.ai product as a customer, or a person our data practices affect some other way (for example, a company or individual a customer monitors). It applies under India's Digital Personal Data Protection Act (DPDPA) 2023 and, for EU/UK residents, the General Data Protection Regulation (GDPR), and is written to reflect our actual, current data practices rather than a generic template.

This Policy covers two related but distinct surfaces: this marketing website (https://caseprimus.ai), and the CasePrimus.ai product itself (the authenticated dashboard a customer's team signs into). Where a practice differs between the two, we say so explicitly.

2. Who we are

CasePrimus.ai is built by Attestr, a product line of Pegadroid IQ Solutions Private Limited, the registered legal entity operating Attestr's products, including CasePrimus.ai. References to "we," "us," or "CasePrimus.ai" in this Policy mean Pegadroid IQ Solutions Private Limited acting under the CasePrimus.ai and Attestr brands, unless context requires otherwise.

For most of the processing described in this Policy, we act as a data controller - we decide why and how personal data is processed to operate CasePrimus.ai. Where a customer instructs us to monitor a specific company or individual on their behalf, we act as a processor for that specific instruction, with our customer as the controller of that decision - see Section 18.

3. Definitions

TermMeaning in this Policy
Personal dataAny information relating to an identified or identifiable natural person.
ProcessingAnything done with personal data - collecting, storing, using, sharing, or deleting it.
Data subject / Data PrincipalThe individual the personal data is about. "Data Principal" is the DPDPA's own term for the same concept.
CustomerThe organization that has created a CasePrimus.ai account and pays for the subscription.
Monitored partyA company or individual a customer has added to their watchlist for litigation monitoring.
Sub-processorA third-party service provider we use to help operate CasePrimus.ai - see Section 11 and our Sub-processors page.

4. Two kinds of personal data

CasePrimus.ai handles two genuinely different categories of personal data, and this policy addresses both:

  • Our own customers - the people who create a CasePrimus.ai account and their team members: name, email, phone number, and (for the account's billing contact) billing address, GSTIN/tax ID, and the contact details of anyone listed as a billing contact person.
  • People and companies our customers monitor - a customer adds a company or individual to their watchlist to track that party's litigation history. For an individual, this can include name, father's name, date of birth, and address. For any monitored party, it includes the names of litigants, advocates, and judges that appear in the court records we retrieve, and the text of the underlying court orders/judgments. These are third parties who have no direct relationship with us - see Section 18 for how we handle this.

5. Information we collect

Information you provide directly. When you submit our contact or demo-request form, we collect your full name, company name, work email address, and optionally your industry and a free-text message describing your use case. When your organization creates a CasePrimus.ai account, we collect the account holder's and team members' name, email, phone number, and (for the billing contact) billing address and GSTIN/tax ID.

Court and litigation records. Fetched from public court databases and litigation-record providers, at a customer's instruction, to monitor a company or individual they specify - see Section 4.

Information collected automatically. Like most websites, our hosting and content-delivery infrastructure automatically logs standard technical information for every visit - IP address, browser type and version, device type, pages viewed, referring URL, and timestamps - and CasePrimus.ai logs which product features a signed-in customer uses and when. This is used for security, abuse prevention, and operating and improving the website and product; we do not use it to build individual visitor profiles.

Information we do not collect through this website. We do not ask this website's forms for financial account numbers, government identifiers, or other sensitive personal information, and you should not include any in the free-text message field.

CategoryExamplesCollected from
Account & contactName, email, phone, roleThe customer, at signup/invite
BillingBilling address, GSTIN/tax ID, invoice historyThe customer's billing contact
Monitored-party identityCompany name, registration number; for a person: name, father's name, DOB, addressThe customer, when adding a watchlist entry
Court & case dataLitigant, advocate, and judge names; order/judgment text; hearing dates; case statusPublic court databases and litigation-record providers
Usage & technicalIP address, device/browser, feature usage, timestampsAutomatically, from your use of the website/product
DerivedAI-generated summaries, risk scores, reputation scoresGenerated by CasePrimus.ai from the above

6. Where information comes from

Beyond what you or a customer provides directly, court and litigation data is sourced from India's eCourts network and from litigation-record aggregators we work with - see our Sub-processors page for the specific providers, and Section 17 for why this is generally publicly available information rather than something an individual submitted to us directly.

7. Cookies & similar technologies

This website sets no cookies of its own beyond what's strictly necessary to make its own pages function correctly. The CasePrimus.ai product uses one strictly-necessary session cookie to keep a signed-in user logged in. Neither the website nor the product runs analytics or advertising cookies today. See our Cookie Policy for detail, including what we'd do if that ever changes.

8. How we use information

We use the information described above to:

PurposeData usedLegal basis (see Section 10)
Respond to inquiries & demo requestsContact-form submissionLegitimate interests / consent
Create & administer accounts, billingAccount, billing dataContract
Provide the monitoring service configuredMonitored-party & court dataContract (with customer) / legitimate interests
Operate, secure & improve the website/productUsage & technical dataLegitimate interests
Comply with legal obligationsBilling, account dataLegal obligation

We do not sell personal information.

9. Automated processing & AI

CasePrimus.ai uses AI (via our sub-processor Anthropic, and optionally AWS Bedrock - see Section 11) to generate case summaries, risk narratives, and reputation scores from publicly available court records. This is informational, not determinative: a CasePrimus.ai reputation or risk score is an input a customer's own team reviews and decides how to act on - we do not make, and CasePrimus.ai is not designed to make, automated decisions about an individual that produce legal or similarly significant effects without human review.

Where GDPR applies, Article 22 gives you the right not to be subject to a decision based solely on automated processing that produces such effects. If you believe a decision has been made about you this way in connection with CasePrimus.ai, contact us using Section 23 - we will investigate and, where Article 22 applies, ensure meaningful human review.

11. How we share information

We use a small number of third-party service providers to operate CasePrimus.ai - for billing, payment processing, email delivery, AI-assisted summarization, cloud hosting, and court-record retrieval. See our Sub-processors page for the full, current list, what each one receives, and where it's hosted. This website itself is hosted on Netlify, which also processes contact-form submissions (Netlify Forms).

We may also disclose information if required to do so by law, regulation, or valid legal process (for example, a court order or a lawful request from a government authority), or to protect the rights, property, or safety of CasePrimus.ai, our users, or the public. In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy's commitments continuing to apply. We do not sell or rent your personal information to unrelated third parties for their own marketing purposes.

12. International data transfers

CasePrimus.ai operates for a global customer base with infrastructure and team members in multiple countries, including India. Some of our sub-processors (see Section 11) are located outside India; where that's the case, we rely on the provider's own contractual data-protection commitments (e.g. Standard Contractual Clauses) for that transfer.

Under the DPDPA, cross-border transfer of personal data is permitted by default, subject to any country-specific restriction the Indian government may notify from time to time - we monitor for any such restriction affecting our own sub-processor list. Under GDPR, a transfer of personal data out of the EEA/UK relies on an adequacy decision or an appropriate safeguard such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, as applicable to each recipient.

13. Data retention

We keep personal data only for as long as necessary for the purposes it was collected, plus any period required by applicable law:

Data typeRetention period
Account & billing recordsFor as long as the account is active, plus a limited period afterward for legal/accounting obligations
Product activity logs24 months
Monitored-party dataFor as long as the customer actively monitors that party; deleted (including downloaded court documents) when the entry is removed
Website contact/demo submissionsAs long as reasonably necessary to respond, then deleted or anonymized
Account-deletion request recordsRetained after account deletion only where a legal/accounting obligation requires it (e.g. issued invoices)

14. Security

Data is encrypted in transit and at rest, access to it is role-based and permission-gated within a customer's own account, and documents are served through short-lived, authenticated links rather than public URLs. We use reasonable administrative, technical, and physical safeguards consistent with Pegadroid IQ Solutions Private Limited's ISO/IEC 27001-certified information security management system (see our About page for certification detail), and conduct periodic vulnerability assessment and penetration testing of the product. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

15. Breach notification

If we become aware of a personal data breach that poses a risk to your rights or freedoms, we will assess it promptly and, where required, notify the relevant supervisory authority (within 72 hours of becoming aware, where GDPR applies) and affected individuals or customers without undue delay, describing the nature of the breach and the steps we're taking in response.

16. Your privacy rights

You can, at any time:

RightWhat it means
AccessGet a copy of the personal data in a CasePrimus.ai account, from Settings.
CorrectionFix inaccurate account or billing information yourself, from Settings.
ErasureRequest deletion of an account and its data - from Settings, or by contacting us.
Withdraw consentWhere processing depends on consent, withdraw it at any time - this doesn't affect processing already carried out.
Restrict / objectAsk us to limit certain processing, or object to processing based on legitimate interests.
PortabilityRequest a portable copy of data you provided to us, in a structured, commonly-used format.

To exercise any of these rights, write to support@caseprimus.ai. Where GDPR applies, we will respond within one month of a valid request (extendable by a further two months for complex requests, with notice to you); we may need to verify your identity before acting on a request. See also our Grievance Officer & Data Protection contact page. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for the UK, the Information Commissioner's Office; for the EEA, your member state's supervisory authority; for India, the Data Protection Board once operational).

17. Notice to visitors in India (DPDPA)

India's Digital Personal Data Protection Act, 2023 ("DPDPA") came into force on 13 November 2025 and is being implemented on a phased timeline - frameworks for registered Consent Managers become active on 14 November 2026, with full enforcement from 13 May 2027. We process personal data of individuals in India with reference to the DPDPA's core principles: lawful and transparent processing, purpose limitation, data minimization, accuracy, storage limitation, and accountability. No government-accredited DPDPA certification scheme currently exists, so this statement is a self-declared commitment rather than a third-party certification.

Much of the litigation and court-record data CasePrimus.ai processes about a monitored party is publicly available information - published by courts as part of open judicial proceedings, a matter of public record under applicable law. This is relevant both to the DPDPA's own treatment of publicly available personal data and to our assessment of when individual notification obligations do or don't apply - see Section 18.

Attestr, the infrastructure CasePrimus.ai is built on, is designed around a consent-first architecture for the identity-verification and onboarding products it operates directly. That consent infrastructure is a separate Attestr product line, distinct from the CasePrimus.ai signup consent checkbox described in Section 5.

Under the DPDPA, you may have the right to obtain a summary of the personal data we process about you and the processing activities carried out, to seek correction or erasure of your personal data, to have a readily available means of grievance redressal, and to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. See Section 23 below for how to reach our grievance officer.

18. If we hold data about you as a monitored party

If CasePrimus.ai holds information about you because a customer of ours is monitoring your litigation history, we are processing this data on that customer's behalf, drawn from public court records. We do not independently market to you or use this data for any purpose beyond providing that monitoring service to our customer.

We do not individually notify every person named in a court record we retrieve - doing so for records already published by a court as part of open judicial proceedings would in most cases be disproportionate or impossible at the scale a litigation-monitoring service operates at, which both GDPR (Article 14(5)) and DPDPA recognize as relevant to whether an individual notification obligation applies. This Policy, published and freely accessible, is how we provide that transparency instead.

If you have questions about your own data in this context, contact us at support@caseprimus.ai and we will work with the relevant customer to address your request.

19. Sensitive personal data

For an individual added as a monitored party, CasePrimus.ai can hold father's name, date of birth, and address - identity-disambiguation fields, used to distinguish the correct individual across court records, not to build a broader profile. We do not knowingly collect health, biometric, genetic, or similarly sensitive special-category data about a monitored party; court records occasionally contain such detail incidentally (for example, where a case itself concerns a medical matter), in which case it is processed only as part of that record, for the same monitoring purpose, and subject to the same access controls as everything else in this Policy.

20. Children's privacy

This website and the CasePrimus.ai product are intended for business use by adults and are not directed at children. We do not knowingly collect personal information from children.

22. Changes to this policy

We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify customer account admins directly.

23. Contact & grievance officer

Questions, requests, or complaints about this Policy - and grievances under the DPDPA - can be sent to support@caseprimus.ai, or via our Grievance Officer & Data Protection contact page. We aim to acknowledge grievances promptly and resolve them within the timeframe required by applicable law.