Privacy Policy
Last updated: September 2026
1. Overview & scope
This Privacy Policy explains what personal data CasePrimus.ai collects, why, how long we keep it, who else sees it, and how to exercise your rights over it - whether you're browsing this website, using the CasePrimus.ai product as a customer, or a person our data practices affect some other way (for example, a company or individual a customer monitors). It applies under India's Digital Personal Data Protection Act (DPDPA) 2023 and, for EU/UK residents, the General Data Protection Regulation (GDPR), and is written to reflect our actual, current data practices rather than a generic template.
This Policy covers two related but distinct surfaces: this marketing website (https://caseprimus.ai), and the CasePrimus.ai product itself (the authenticated dashboard a customer's team signs into). Where a practice differs between the two, we say so explicitly.
2. Who we are
CasePrimus.ai is built by Attestr, a product line of Pegadroid IQ Solutions Private Limited, the registered legal entity operating Attestr's products, including CasePrimus.ai. References to "we," "us," or "CasePrimus.ai" in this Policy mean Pegadroid IQ Solutions Private Limited acting under the CasePrimus.ai and Attestr brands, unless context requires otherwise.
For most of the processing described in this Policy, we act as a data controller - we decide why and how personal data is processed to operate CasePrimus.ai. Where a customer instructs us to monitor a specific company or individual on their behalf, we act as a processor for that specific instruction, with our customer as the controller of that decision - see Section 18.
3. Definitions
| Term | Meaning in this Policy |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. |
| Processing | Anything done with personal data - collecting, storing, using, sharing, or deleting it. |
| Data subject / Data Principal | The individual the personal data is about. "Data Principal" is the DPDPA's own term for the same concept. |
| Customer | The organization that has created a CasePrimus.ai account and pays for the subscription. |
| Monitored party | A company or individual a customer has added to their watchlist for litigation monitoring. |
| Sub-processor | A third-party service provider we use to help operate CasePrimus.ai - see Section 11 and our Sub-processors page. |
4. Two kinds of personal data
CasePrimus.ai handles two genuinely different categories of personal data, and this policy addresses both:
- Our own customers - the people who create a CasePrimus.ai account and their team members: name, email, phone number, and (for the account's billing contact) billing address, GSTIN/tax ID, and the contact details of anyone listed as a billing contact person.
- People and companies our customers monitor - a customer adds a company or individual to their watchlist to track that party's litigation history. For an individual, this can include name, father's name, date of birth, and address. For any monitored party, it includes the names of litigants, advocates, and judges that appear in the court records we retrieve, and the text of the underlying court orders/judgments. These are third parties who have no direct relationship with us - see Section 18 for how we handle this.
5. Information we collect
Information you provide directly. When you submit our contact or demo-request form, we collect your full name, company name, work email address, and optionally your industry and a free-text message describing your use case. When your organization creates a CasePrimus.ai account, we collect the account holder's and team members' name, email, phone number, and (for the billing contact) billing address and GSTIN/tax ID.
Court and litigation records. Fetched from public court databases and litigation-record providers, at a customer's instruction, to monitor a company or individual they specify - see Section 4.
Information collected automatically. Like most websites, our hosting and content-delivery infrastructure automatically logs standard technical information for every visit - IP address, browser type and version, device type, pages viewed, referring URL, and timestamps - and CasePrimus.ai logs which product features a signed-in customer uses and when. This is used for security, abuse prevention, and operating and improving the website and product; we do not use it to build individual visitor profiles.
Information we do not collect through this website. We do not ask this website's forms for financial account numbers, government identifiers, or other sensitive personal information, and you should not include any in the free-text message field.
| Category | Examples | Collected from |
|---|---|---|
| Account & contact | Name, email, phone, role | The customer, at signup/invite |
| Billing | Billing address, GSTIN/tax ID, invoice history | The customer's billing contact |
| Monitored-party identity | Company name, registration number; for a person: name, father's name, DOB, address | The customer, when adding a watchlist entry |
| Court & case data | Litigant, advocate, and judge names; order/judgment text; hearing dates; case status | Public court databases and litigation-record providers |
| Usage & technical | IP address, device/browser, feature usage, timestamps | Automatically, from your use of the website/product |
| Derived | AI-generated summaries, risk scores, reputation scores | Generated by CasePrimus.ai from the above |
6. Where information comes from
Beyond what you or a customer provides directly, court and litigation data is sourced from India's eCourts network and from litigation-record aggregators we work with - see our Sub-processors page for the specific providers, and Section 17 for why this is generally publicly available information rather than something an individual submitted to us directly.
8. How we use information
We use the information described above to:
| Purpose | Data used | Legal basis (see Section 10) |
|---|---|---|
| Respond to inquiries & demo requests | Contact-form submission | Legitimate interests / consent |
| Create & administer accounts, billing | Account, billing data | Contract |
| Provide the monitoring service configured | Monitored-party & court data | Contract (with customer) / legitimate interests |
| Operate, secure & improve the website/product | Usage & technical data | Legitimate interests |
| Comply with legal obligations | Billing, account data | Legal obligation |
We do not sell personal information.
9. Automated processing & AI
CasePrimus.ai uses AI (via our sub-processor Anthropic, and optionally AWS Bedrock - see Section 11) to generate case summaries, risk narratives, and reputation scores from publicly available court records. This is informational, not determinative: a CasePrimus.ai reputation or risk score is an input a customer's own team reviews and decides how to act on - we do not make, and CasePrimus.ai is not designed to make, automated decisions about an individual that produce legal or similarly significant effects without human review.
Where GDPR applies, Article 22 gives you the right not to be subject to a decision based solely on automated processing that produces such effects. If you believe a decision has been made about you this way in connection with CasePrimus.ai, contact us using Section 23 - we will investigate and, where Article 22 applies, ensure meaningful human review.
10. Legal bases for processing (EEA/UK)
Where GDPR applies, we rely on:
- Consent - for the signup consent checkbox and any optional marketing communications.
- Contract - to provide the CasePrimus.ai product to a customer who has an account with us, and to take steps toward entering into a contract at your organization's request.
- Legitimate interests - to respond to inquiries, secure our systems, improve the website and product, and (for monitored-party data) to provide third-party litigation-risk monitoring as a legitimate business due-diligence function, balanced against the monitored party's own rights and expectations.
- Legal obligation - where retention or disclosure is required by applicable law (for example, tax record-keeping).
12. International data transfers
CasePrimus.ai operates for a global customer base with infrastructure and team members in multiple countries, including India. Some of our sub-processors (see Section 11) are located outside India; where that's the case, we rely on the provider's own contractual data-protection commitments (e.g. Standard Contractual Clauses) for that transfer.
Under the DPDPA, cross-border transfer of personal data is permitted by default, subject to any country-specific restriction the Indian government may notify from time to time - we monitor for any such restriction affecting our own sub-processor list. Under GDPR, a transfer of personal data out of the EEA/UK relies on an adequacy decision or an appropriate safeguard such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, as applicable to each recipient.
13. Data retention
We keep personal data only for as long as necessary for the purposes it was collected, plus any period required by applicable law:
| Data type | Retention period |
|---|---|
| Account & billing records | For as long as the account is active, plus a limited period afterward for legal/accounting obligations |
| Product activity logs | 24 months |
| Monitored-party data | For as long as the customer actively monitors that party; deleted (including downloaded court documents) when the entry is removed |
| Website contact/demo submissions | As long as reasonably necessary to respond, then deleted or anonymized |
| Account-deletion request records | Retained after account deletion only where a legal/accounting obligation requires it (e.g. issued invoices) |
14. Security
Data is encrypted in transit and at rest, access to it is role-based and permission-gated within a customer's own account, and documents are served through short-lived, authenticated links rather than public URLs. We use reasonable administrative, technical, and physical safeguards consistent with Pegadroid IQ Solutions Private Limited's ISO/IEC 27001-certified information security management system (see our About page for certification detail), and conduct periodic vulnerability assessment and penetration testing of the product. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Breach notification
If we become aware of a personal data breach that poses a risk to your rights or freedoms, we will assess it promptly and, where required, notify the relevant supervisory authority (within 72 hours of becoming aware, where GDPR applies) and affected individuals or customers without undue delay, describing the nature of the breach and the steps we're taking in response.
16. Your privacy rights
You can, at any time:
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data in a CasePrimus.ai account, from Settings. |
| Correction | Fix inaccurate account or billing information yourself, from Settings. |
| Erasure | Request deletion of an account and its data - from Settings, or by contacting us. |
| Withdraw consent | Where processing depends on consent, withdraw it at any time - this doesn't affect processing already carried out. |
| Restrict / object | Ask us to limit certain processing, or object to processing based on legitimate interests. |
| Portability | Request a portable copy of data you provided to us, in a structured, commonly-used format. |
To exercise any of these rights, write to support@caseprimus.ai. Where GDPR applies, we will respond within one month of a valid request (extendable by a further two months for complex requests, with notice to you); we may need to verify your identity before acting on a request. See also our Grievance Officer & Data Protection contact page. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for the UK, the Information Commissioner's Office; for the EEA, your member state's supervisory authority; for India, the Data Protection Board once operational).
17. Notice to visitors in India (DPDPA)
India's Digital Personal Data Protection Act, 2023 ("DPDPA") came into force on 13 November 2025 and is being implemented on a phased timeline - frameworks for registered Consent Managers become active on 14 November 2026, with full enforcement from 13 May 2027. We process personal data of individuals in India with reference to the DPDPA's core principles: lawful and transparent processing, purpose limitation, data minimization, accuracy, storage limitation, and accountability. No government-accredited DPDPA certification scheme currently exists, so this statement is a self-declared commitment rather than a third-party certification.
Much of the litigation and court-record data CasePrimus.ai processes about a monitored party is publicly available information - published by courts as part of open judicial proceedings, a matter of public record under applicable law. This is relevant both to the DPDPA's own treatment of publicly available personal data and to our assessment of when individual notification obligations do or don't apply - see Section 18.
Attestr, the infrastructure CasePrimus.ai is built on, is designed around a consent-first architecture for the identity-verification and onboarding products it operates directly. That consent infrastructure is a separate Attestr product line, distinct from the CasePrimus.ai signup consent checkbox described in Section 5.
Under the DPDPA, you may have the right to obtain a summary of the personal data we process about you and the processing activities carried out, to seek correction or erasure of your personal data, to have a readily available means of grievance redressal, and to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. See Section 23 below for how to reach our grievance officer.
18. If we hold data about you as a monitored party
If CasePrimus.ai holds information about you because a customer of ours is monitoring your litigation history, we are processing this data on that customer's behalf, drawn from public court records. We do not independently market to you or use this data for any purpose beyond providing that monitoring service to our customer.
We do not individually notify every person named in a court record we retrieve - doing so for records already published by a court as part of open judicial proceedings would in most cases be disproportionate or impossible at the scale a litigation-monitoring service operates at, which both GDPR (Article 14(5)) and DPDPA recognize as relevant to whether an individual notification obligation applies. This Policy, published and freely accessible, is how we provide that transparency instead.
If you have questions about your own data in this context, contact us at support@caseprimus.ai and we will work with the relevant customer to address your request.
19. Sensitive personal data
For an individual added as a monitored party, CasePrimus.ai can hold father's name, date of birth, and address - identity-disambiguation fields, used to distinguish the correct individual across court records, not to build a broader profile. We do not knowingly collect health, biometric, genetic, or similarly sensitive special-category data about a monitored party; court records occasionally contain such detail incidentally (for example, where a case itself concerns a medical matter), in which case it is processed only as part of that record, for the same monitoring purpose, and subject to the same access controls as everything else in this Policy.
20. Children's privacy
This website and the CasePrimus.ai product are intended for business use by adults and are not directed at children. We do not knowingly collect personal information from children.
21. Third-party links
This site may link to third-party websites (for example, attestr.com). We do not control, and are not responsible for, the content or privacy practices of third-party sites.
22. Changes to this policy
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify customer account admins directly.
23. Contact & grievance officer
Questions, requests, or complaints about this Policy - and grievances under the DPDPA - can be sent to support@caseprimus.ai, or via our Grievance Officer & Data Protection contact page. We aim to acknowledge grievances promptly and resolve them within the timeframe required by applicable law.