BrilliusLaw Logo
  • Platform
  • Features
  • Pricing
  • About Us
  • Blog
  • Contact Us
Get Started→

Privacy Policy

Brillius Technologies Pvt. Ltd. (BrilliusLaw)Version: 1.0Effective date: 5 October 2026

1About this policy

BrilliusLaw is a legal technology platform operated by Brillius Technologies Pvt. Ltd., a company incorporated in India. BrilliusLaw provides tools for case and matter management, hearings and tasks, document management, legal research, AI-assisted drafting and analysis, and related communications.

This Privacy Policy explains what personal data BrilliusLaw collects, how and why it is used, with whom it is shared, how it is protected, how long it is kept, and the rights available to individuals. It applies to the BrilliusLaw websites, web and mobile applications, BrilliusLaw Campus, and any other service that links to this policy (together, the “Services”).

Where BrilliusLaw relies on consent, it asks for that consent separately and clearly.

2Who this policy covers and the role of BrilliusLaw

This policy covers three groups of people:

  • Users: individuals who create an account and use the Services, such as advocates, members of law firms, legal professionals and law students;
  • Visitors: individuals who visit the BrilliusLaw websites without signing in; and
  • Individuals in case files: people whose information is stored in the Services by a law firm or advocate but who do not use the Services themselves, such as clients, opposing parties, witnesses, other advocates, judges and family members.

The law firm, advocate or organisation that holds a BrilliusLaw workspace and gives users access to it is referred to as the customer. An independent advocate with an individual workspace is both a user and a customer.

In this policy, an organisation means any entity, other than a law firm or an individual advocate, that holds a BrilliusLaw workspace. Examples include:

  • a company’s in-house legal department;
  • a chamber of advocates practising together;
  • a legal aid body or non-governmental organisation; and
  • a college or university that gives its students access to BrilliusLaw Campus.

BrilliusLaw processes personal data in two different capacities.

Account Data. This is information about users and visitors, such as account, profile, login and usage details. BrilliusLaw decides why and how Account Data is processed. For Account Data, BrilliusLaw is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the “DPDP Act”).

Matter Data. This is the information a customer and its users store in, create in or retrieve through the Services for legal or academic work, such as client records, case details, documents, evidence, notes, drafts, invoices, and AI prompts and outputs. The customer decides why and how its Matter Data is processed. For Matter Data, the customer is the Data Fiduciary, and BrilliusLaw acts as the customer’s Data Processor. BrilliusLaw processes Matter Data only on the customer’s instructions, in line with the Terms of Service and any data processing agreement between BrilliusLaw and the customer.

Each customer is responsible for:

  • having a lawful basis to collect and upload Matter Data;
  • giving any notices, and obtaining any consents, that its clients and other individuals in case files require; and
  • controlling which of its users can access which Matter Data.

The customer retains ownership of its Matter Data at all times.

3Information collected

3.1Information provided by users

  • Account and profile details: name, email address, mobile number, password, username, profile photograph, address, the name of the user’s firm or organisation, role and designation.
  • Professional details: for advocates, practice name, office address, practice areas and Bar Council enrolment details; for students, college, course and year of study, and documents needed to verify eligibility.
  • Consent records: acceptance of this policy and the Terms of Service, the user’s age declaration, and the user’s choices about notifications.
  • Communications: messages sent to BrilliusLaw, support requests and feedback.
  • Subscription details: plan, billing details, invoices and payment status, where the customer or user uses paid Services.

3.2Matter Data entered by customers and their users

  • Client details: names and contact details, and identity or KYC information.
  • Case details: case numbers, CNR numbers, court, parties, advocates and hearing dates.
  • Case work: documents, evidence, notes, tasks, drafts, invoices and payment records.
  • AI interactions: prompts, questions, instructions, uploaded files, conversation history, and AI-generated outputs such as drafts, summaries and research notes.

Matter Data may include sensitive information about individuals in case files, such as criminal, financial or health records, information about family matters or sexual offences, or information about children. BrilliusLaw treats all Matter Data as confidential.

3.3Information collected automatically

  • Device and technical data: IP address, browser type, device type and operating system.
  • Usage data: login times, pages and features used, and actions taken in the Services.
  • Security and audit logs: records of key actions, such as creating, changing, deleting or approving records.
  • Diagnostic data: error reports and performance information.

3.4Information from other sources

  • Court and public legal sources: case status, hearing information, orders and other records from court systems and publicly available legal databases, when a user requests them.
  • Sign-in providers: the user’s name, email address and photo, if the user chooses to sign in with a third-party account.
  • Customers: details added by an administrator when a user is given access to a workspace.
  • Integrations: information from third-party services that a customer or user chooses to connect.

4How information is used

BrilliusLaw uses personal data only for the following purposes:

  • To provide the Services: create and manage accounts, run case, hearing, task, document and billing workflows, and enable collaboration within a customer’s workspace.
  • To process documents: extract text, index documents and make them searchable for the customer’s users.
  • To provide AI features: generate drafts, summaries, analyses and research responses when a user chooses to use these features.
  • To retrieve court information: fetch case status and orders from court systems when a user requests it.
  • To communicate with users: send OTPs and login codes, account and security notices, reminders, invoices, payment confirmations and renewal reminders, and emails about new features and product updates, through in-app notifications, email, or messaging services the user has enabled.
  • To provide support: respond to questions and resolve issues reported by users and customers.
  • To keep the Services secure: authenticate users, prevent fraud and misuse, monitor for security threats, and maintain audit trails.
  • To improve the Services: understand how features are used, using aggregated or de-identified information only.
  • To comply with law: meet legal and regulatory obligations and respond to lawful requests.

BrilliusLaw does not sell or rent personal data, and does not use Matter Data for advertising. If BrilliusLaw wants to use personal data for a new purpose, it will inform the affected users first and seek their consent where the law requires it.

5Artificial intelligence features

BrilliusLaw offers AI features to assist with legal research, drafting, document analysis and summarisation.

  • When AI is used: AI features run only when a user chooses to use them. The relevant Matter Data, such as a selected document or case details, is processed to generate the response.
  • AI service providers: some AI processing is performed by carefully selected service providers acting on behalf of BrilliusLaw. They process data only to produce the requested output, under contractual obligations of confidentiality and security.
  • No training on Matter Data: BrilliusLaw does not use Matter Data, documents or AI conversations to train AI models, and does not permit its service providers to do so.
  • Professional judgment: AI outputs may be inaccurate, incomplete or out of date. They assist, but do not replace, professional legal judgment. Users must review all AI-generated content, citations and conclusions before relying on them.

6Consent and withdrawal

  • BrilliusLaw asks for a user’s consent when the user creates an account, and separately for optional features such as messaging notifications.
  • A user can withdraw consent at any time, as easily as it was given, through account settings or by contacting BrilliusLaw.
  • Withdrawal does not affect processing carried out before it. It may mean the user can no longer use some or all of the Services.

7Sharing of information

BrilliusLaw shares personal data only in the following circumstances:

  • Service providers: trusted third parties that help operate the Services, such as cloud hosting and storage providers, database and authentication services, AI and document-processing services, communication and messaging providers, and payment processors. They may use personal data only to provide their services to BrilliusLaw, under contracts that require confidentiality and appropriate security.
  • Within the customer’s workspace: administrators and users of the same workspace can access information according to the roles and permissions the customer sets.
  • At a user’s direction: when a user chooses to share a document, draft or link with someone, or to connect a third-party integration.
  • BrilliusLaw personnel: a limited number of authorised BrilliusLaw personnel may access customer data where needed to provide support the customer has requested, to maintain security, or to comply with law. They are bound by confidentiality obligations.
  • Legal requirements: where required by law, court order or a lawful request from a government authority. Unless legally prohibited, BrilliusLaw will notify the affected customer before disclosing Matter Data, and will disclose only what is required.
  • Business transfers: in connection with a merger, acquisition or restructuring of BrilliusLaw. Personal data would remain protected under this policy, and affected users would be notified.

Customers may request a current list of the service providers that process Matter Data by contacting BrilliusLaw.

8Storage and transfers outside India

Data is primarily stored on secure cloud infrastructure. Some service providers may process personal data outside India, for example to provide AI or communication features.

Any transfer outside India will comply with Section 16 of the DPDP Act and any restrictions notified by the Government of India. BrilliusLaw requires appropriate contractual and security safeguards from all recipients.

9Security

Given the confidential nature of legal information, BrilliusLaw uses reasonable technical and organisational safeguards, including:

  • encryption of data in transit and at rest;
  • logical separation of each customer’s data from other customers’ data;
  • role-based access controls within each workspace;
  • secure authentication, with one-time codes stored only in protected form;
  • restricted and monitored access by BrilliusLaw personnel;
  • audit logs of key actions; and
  • periodic security reviews and an incident-response process.

No method of transmission or storage is completely secure. Users must protect their login credentials and inform BrilliusLaw promptly if they suspect unauthorised access to their account.

10Retention

BrilliusLaw retains personal data only for as long as necessary for the purposes in this policy, or as required by law. In general:

  • Account Data is kept while the user’s account is active, and deleted or anonymised within a reasonable period after the account is closed.
  • Matter Data is kept while the customer’s workspace is active. When a customer leaves, it will have an opportunity to export its Matter Data, after which the Matter Data is deleted.
  • Deleted content is removed from active systems and, after a limited period, from backups.
  • Security and audit logs are kept for the periods required by applicable law, including the Directions issued by the Indian Computer Emergency Response Team (CERT-In).
  • Consent records may be kept after an account is closed, as evidence of the user’s choices.

11Rights of Data Principals

Subject to applicable law, every Data Principal (the individual to whom personal data relates, whether a user, a visitor or an individual in a case file) has the right to:

  • Access: obtain a summary of their personal data, how it is processed, and the parties it has been shared with.
  • Correction: have inaccurate or incomplete personal data corrected, completed or updated.
  • Erasure: have personal data deleted when it is no longer needed, unless the law requires it to be kept.
  • Withdraw consent: at any time, as described in Section 6.
  • Nominate: nominate another person to exercise these rights in the event of their death or incapacity.
  • Grievance redressal: raise a grievance with BrilliusLaw and, if it is not resolved, complain to the Data Protection Board of India.

To exercise these rights, a Data Principal may contact BrilliusLaw using the details in Section 19. BrilliusLaw may need to verify the requester’s identity before acting on a request, and will respond within the timelines prescribed under applicable law.

12Individuals in case files

The personal data of an individual in a case file forms part of a customer’s Matter Data, and that customer controls it. An individual in a case file should therefore send any request first to the law firm or advocate handling the matter. If an individual in a case file contacts BrilliusLaw instead, BrilliusLaw will forward the request to the relevant customer and assist the customer in responding.

13Age requirement

The Services, including BrilliusLaw Campus, are intended only for users aged 18 years and above. BrilliusLaw does not knowingly collect Account Data from anyone under 18. If BrilliusLaw learns that an account has been created by a person under 18, it will close the account and delete the associated Account Data.

This does not apply to information about minors that forms part of Matter Data, which is the responsibility of the customer handling the matter.

14Cookies and similar technologies

BrilliusLaw uses cookies, browser storage and similar technologies that are necessary to operate the Services, such as keeping users signed in, remembering preferences and maintaining security.

BrilliusLaw does not use advertising cookies. If BrilliusLaw introduces non-essential cookies or analytics in the future, it will update this policy and ask for consent where required. Users and visitors can control or clear cookies and browser storage through their browser settings, although some features may not work properly without them.

15Communications

  • BrilliusLaw sends users service-related communications, such as login codes, account notices, hearing and task reminders, and security alerts.
  • Where a user opts in, these may be sent through messaging services such as WhatsApp. A user can turn messaging notifications off at any time in account settings.
  • Messages sent through third-party platforms are also subject to the privacy terms of those platforms.
  • BrilliusLaw may also send users emails about new features, product updates and tips for using the Services. Every such email includes an unsubscribe link, and a user can opt out at any time without affecting service communications.

16Third-party links and integrations

The Services may contain links to third-party websites, or allow customers and users to connect third-party services such as court systems, legal databases or payment providers. The privacy practices of those third parties are governed by their own policies, and BrilliusLaw is not responsible for them.

17Data breaches

If BrilliusLaw becomes aware of a personal data breach, it will act promptly to contain and investigate it. BrilliusLaw will notify the Data Protection Board of India, CERT-In, affected customers and affected Data Principals, as required by applicable law and within the prescribed timelines.

18Changes to this policy

BrilliusLaw may update this policy to reflect changes in the Services, its practices or legal requirements. Each version carries a version number and effective date. BrilliusLaw will notify users of material changes through the Services or by email, and will seek fresh consent where required.

19Contact and Grievance Officer

For questions, requests or grievances about this policy or personal data, please contact:

Grievance Officer: CVSS Jyothsna Email: grievance@brilliuslaw.com Address: Brillius Technologies Pvt. Ltd., 4th Floor, P Elite, 1-62/99, Plot No. 99, Kavuri Hills Phase 2 Road, Madhapur, Hyderabad, Telangana 500081

BrilliusLaw will acknowledge each grievance promptly and resolve it within the timelines prescribed under applicable law. This policy is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.

20Governing law

This policy is governed by the laws of India, including the DPDP Act, the Information Technology Act, 2000 and the rules made under it. Subject to applicable law, the courts at Hyderabad, Telangana shall have jurisdiction.

Read the Terms of Service
BrilliusLaw

From Clients to Cases, Keep Everything Connected.

Honouring India's Constitutional Heritage with Modern Legal Technology.

PlatformPlatformAll Features
Features
CompanyAbout UsWho We ServePartnersContact
ResourcesBlogLaw LibraryMy JournalSupport

© 2026 @brilliuslaw. All rights reserved.

  • Privacy Policy
  • Terms of Service