Tell us what you are looking for.Start a conversation
Standing Lawyers— home

Legal

Privacy Policy

Last updated

This Privacy Policy explains what personal data Standing Lawyers collects through this website, why we collect it, who it reaches, how long it is kept, how it is protected, and what you can ask us to do about it. Please read it with our Cookie Policy, which explains what is stored on your device, and our Data Protection and Information Security Policy, which explains the safeguards applied to personal data generally.

This policy covers this website. Information you give us in the course of a professional engagement is additionally governed by an advocate's duty of confidentiality and by legal professional privilege, both of which are considerably stronger than anything a privacy policy provides. Our Confidentiality and Conflict of Interest Policy explains that.

1. Who we are, and who is responsible for your data

1.1 Standing Lawyers is a sole proprietorship of an advocate enrolled with a State Bar Council of India. It publishes this website and decides why and how personal data collected through it is processed. In the language of the Digital Personal Data Protection Act, 2023 we are a Data Fiduciary; in the language of the Information Technology Act, 2000 we are a body corporate.

1.2 We can be reached at work@standinglawyers.com and on +91 63766 28978. Clause 11 names the officer responsible for grievances about personal data.

2. The law this policy is written to

2.1 Two regimes are relevant, and they are at different stages, so we set out both rather than blur them.

2.2 In force now. Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 apply to us today. The Explanation to section 43A defines a body corporate to include a sole proprietorship engaged in professional activities, so these rules bind this firm. They require us to publish this policy, to obtain consent before collecting sensitive personal data or information, to restrict disclosure, to maintain reasonable security practices, and to designate a Grievance Officer who resolves grievances within one month. Section 72A of the same Act makes wrongful disclosure of personal information in breach of a lawful contract a criminal offence.

2.3 Coming into force. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into effect in stages. The definitions and the provisions constituting the Data Protection Board of India commenced on 13 November 2025. The Consent Manager registration provisions commence on 13 November 2026. The substantive obligations on Data Fiduciaries and the rights of Data Principals, which are the parts most people mean when they refer to the Act, commence on 13 May 2027.

2.4 We have chosen not to wait. This policy is written to the standard the 2023 Act sets, and the rights described in clause 10 are offered to you now as a matter of firm policy, whether or not the provision conferring them has yet commenced. Where a right becomes a statutory entitlement on 13 May 2027, it does not change what we will do for you in the meantime.

3. The personal data this website collects

3.1 There are four categories, and only the first two involve you telling us anything:

3.2 Information you give us through the enquiry form

3.2.1 The contact form collects your name, your email address, your company if you choose to give one, and the content of your message. Only the name, the email address and the message are required.

3.2.2 You decide what goes in the message. Please keep it brief and free of confidential detail, for the reasons in clause 5 of our Disclaimer. If your message names or describes another person, you are responsible for being entitled to tell us about them.

3.2.3 Please do not put the details of an asset into this form. The instinct when writing to us about a claim is to include everything, and this is the one place not to. Do not send a permanent account number, a folio or client identifier, a policy number, a bank account or member number, a certificate or its distinctive numbers, a scanned identity or succession document, or anything about a person's health or death beyond the fact of it. None of it is needed to tell us whether we can help, and clause 4 explains why this website is the wrong place to store it.

3.2.4 Tell us the nature of the matter instead: what kind of asset, roughly when, whose name it was in, and whether anyone has died. That is enough for a first answer, and if there is detail to exchange we will propose a route for it once we have run the conflict check described in clause 6 of our Confidentiality and Conflict of Interest Policy.

3.3 Information you give us when you apply for a position

3.3.1 The application form collects the role applied for, your name, your email address, your telephone number, a link you may optionally provide, a covering note, your confirmation of the consent shown beside the submit button, and the curriculum vitae you attach. A CV may be a PDF or a Word document of up to five megabytes.

3.3.2 A CV usually contains a good deal about a person. We ask you not to include anything you are not content for us to read, and specifically not to include identity document numbers, financial details, health information or photographs, none of which we need in order to assess an application.

3.4 Measurement of how this website is used

3.4.1 We record a limited amount of information about page views on our own servers. No cookie is involved and no third party receives it. For a sampled proportion of views we record: the path of the page viewed, with any query string removed; the domain of the referring website, or that the visit was direct, never the full referring address; a broad device category such as mobile or desktop; an approximate country derived from the network request; and a session identifier described in clause 3.4.2.

3.4.2 The session identifier is a keyed one-way digest of the day, your network address and your browser's user agent string, truncated. Three properties follow and each is deliberate. Your network address and user agent are inputs to the digest and are never themselves stored. The digest cannot be reversed without a secret held on the server. Because the day forms part of the input, the identifier changes daily, so the same visitor returning tomorrow is a different value and nothing can be joined across days, by us or by anyone who obtained a copy of the data.

3.4.3 This identifier exists to count how many distinct people visited on a given day. It is never attached to an enquiry, never sent to your browser, and never used to build a profile.

3.5 Anti-abuse records

3.5.1 To stop the forms being used to send bulk or automated messages, we keep a short-lived counter against a keyed one-way digest of the network address a submission came from. The record holds the digest, the name of the action, a count and timestamps. It holds nothing about you, nothing about your message, and no address that can be recovered from it.

3.6 What this website does not collect

3.6.1 For completeness, and because absences are as material as inclusions:

  • We set no cookies and load no third party content of any kind. There is no advertising network, no social media pixel, no embedded map, no embedded video, no externally hosted font and no tag manager on this website.
  • We do not collect sensitive personal data or information as the SPDI Rules define it, meaning passwords, financial information such as bank account, card or payment details, physical, physiological or mental health condition, sexual orientation, medical records and history, or biometric information. Please do not send any of it through this website.
  • We do not knowingly collect personal data of children. See clause 12.
  • We do not buy personal data, we do not sell it, we do not rent it, and we do not share it for advertising or marketing by anyone.
  • We operate no marketing list. There is no newsletter and no subscription, so submitting an enquiry will not result in marketing communications.
  • We do not use your personal data for automated decision-making or profiling, and we do not use anything you submit through this website to train any machine learning model.
  • We will never ask you for banking credentials. Not an internet banking password, not a card number, not a card verification value, not a one time password, and not access to any account of yours. There is no field on this website that asks for any of them and there never will be. Recovery of unclaimed assets attracts impersonation precisely because the money is real, so treat any such request, however it reaches you and whoever it appears to come from, as fraudulent.
  • We do not ask you to pay us out of anything you recover, and no money you recover passes through this firm. Clause 8 of our Anti-Money Laundering and Client Due Diligence Policy explains that arrangement.

4. This website keeps no copy of what you submit

4.1 This is the most important operational fact in this policy, and it is unusual enough to state precisely. When you submit the enquiry form or the application form, the content is delivered to the firm by email and by nothing else. The website writes no database record of it, stores no file, and has no screen anywhere in its administrative area that lists enquiries or applications. Your CV is not uploaded to any file store; it travels as an attachment to the email and nowhere else.

4.2 Once the email has been delivered, the only copies in existence are the message in the firm's mailbox and whatever remains in the transient logs of the providers named in clause 7.

4.3 One consequence follows and we would rather state it than have you discover it. If the email cannot be sent, your message does not reach us at all, because there is no stored copy to fall back on. The website is built to tell you so honestly: a failure shows you an error and the firm's own address, rather than a confirmation for something we never received. If you see that error, please write to us directly.

5. Why we process your personal data, and on what basis

5.1 We process personal data for these purposes and no others:

PurposeData usedBasis
Reading and answering your enquiry, and deciding whether we are able to actEverything in clause 3.2Your voluntary submission of it to us for that purpose, and our legitimate interest in responding to a person who has written to us
Running a conflict of interest check before we can reply substantivelyNames of the parties and a description of the matterOur professional obligation as advocates, and the necessity of the check before any engagement
Assessing your application for a positionEverything in clause 3.3Your express consent, recorded by the checkbox beside the submit button
Understanding in aggregate which pages of this website are usefulThe pseudonymous records in clause 3.4Our legitimate interest in maintaining a useful website, using data from which you cannot be identified
Preventing abuse of the formsThe records in clause 3.5Our legitimate interest in keeping this website usable and in protecting it from automated misuse
Meeting legal, regulatory, tax and professional obligations, and establishing, exercising or defending legal claimsWhatever the obligation or claim requiresCompliance with law, and (from 13 May 2027) section 17(1)(a) of the Digital Personal Data Protection Act, 2023

5.2 We do not use your personal data for a new purpose that is incompatible with the one it was given for. If we ever need to, we will ask you first.

6. Withdrawing consent

6.1 Where we rely on your consent, you may withdraw it at any time by writing to us. Withdrawal is as easy as giving consent was: one email is enough and you do not need to give a reason.

6.2 Withdrawal operates from the time we receive it and does not make unlawful anything done before then. Where we are required by law or by professional obligation to keep a record, we will tell you what we must keep and why.

7. Who else your personal data reaches

7.1 We do not sell personal data and we do not disclose it for anyone's marketing. A small number of service providers process personal data on our behalf in order to make this website and our email work. We name them, because a reader is entitled to know exactly where an enquiry travels:

ProviderRoleHandles a submission?Location
NetlifyHosting and server-side processingYes, in memory only, while processingUnited States, global delivery network
Google Cloud (Firebase)Website content and measurement recordsNoSingapore (asia-southeast1)
ResendDelivers the message to us and the acknowledgement to youYes, including a CV attachmentAsia Pacific (Tokyo)
GoDaddyThe firm's mailbox, where the message is then heldYes, once deliveredAs determined by that provider

7.2 Two entries in that table deserve a sentence rather than a cell. Google Cloud holds the published content of this website and the pseudonymous measurement records described in clause 3.4, and it holds no enquiry and no application, because none is ever written to it. Resend is the one provider a submission cannot avoid: it is the route by which your message reaches us rather than a copy of it, so your name, email address, message and any attached CV necessarily pass through it.

7.3 Each provider is engaged to process personal data only on our instructions and for the purpose described. We do not authorise any of them to use it for their own purposes.

7.4 We may also disclose personal data where we are required to do so by law, by a court, or by a regulator with jurisdiction over us, and where necessary to establish, exercise or defend a legal claim. Where we are compelled to disclose and are not prohibited from telling you, we will tell you.

7.5 Transfer outside India. Several of the providers above operate outside India, so your personal data may be processed outside India. Indian law presently permits such transfers except to a country the Central Government restricts by notification, and we do not transfer to any restricted country. Contractual terms with each provider govern their handling of the data. If the position changes when section 16 of the Digital Personal Data Protection Act, 2023 commences, we will update this policy before the change takes effect.

8. How long personal data is kept

CategoryRetention
An enquiry, in the firm's mailboxFor as long as needed to answer it and to keep a reasonable record of what was asked of us, and thereafter for as long as any professional, regulatory or limitation-related obligation requires. Where an enquiry leads to an engagement, the retention of the matter file governs instead
An application for a position that does not proceedDeleted from the mailbox once the recruitment for that role is concluded, unless you have asked us to keep it on file for future openings, in which case it is deleted after twelve months or on your request, whichever is earlier
Client and matter recordsFor the period professional record-keeping, limitation periods and tax law require. Our Data Protection and Information Security Policy explains this
Pseudonymous page view records and daily session markers (clause 3.4)Not retained beyond thirty days from creation
Daily aggregate countersKept indefinitely. These are counts only. They contain no identifier of any kind and nobody can be identified from them
Anti-abuse records (clause 3.5)Short-lived. They carry an expiry a little beyond the end of the rate-limiting window they exist to enforce

8.1 When a retention period ends, the data is deleted. Where deletion is not immediately possible because a record sits within a backup, the backup itself expires on its own cycle and the data is not restored into use in the meantime.

9. How personal data is protected

9.1 Our Data Protection and Information Security Policy sets out the measures in full. In summary: everything is transmitted over encrypted connections; data at rest is encrypted by the hosting platforms; administrative access requires an individual account and a session that expires; access is limited to those who need it; the architecture in clause 4 means there is no store of submissions for anyone to reach; and the identifiers described in clauses 3.4 and 3.5 are keyed one-way digests rather than the underlying addresses.

9.2 No transmission over the internet and no system of storage is perfectly secure, and we do not claim otherwise. Please do not send confidential or privileged material through this website.

9.3 If a breach of personal data occurs, we will act on it under the incident procedure in our Data Protection and Information Security Policy, which includes notifying affected people and the appropriate authority within the time the law allows.

10. Your rights, and how to exercise them

10.1 You may ask us to do each of the following. We offer these now as a matter of firm policy; from 13 May 2027 they are also statutory entitlements under the Digital Personal Data Protection Act, 2023 in the sections noted.

  • Access (section 11). Ask for a summary of the personal data we hold about you and the processing we carry out, and for the identities of those with whom we have shared it.
  • Correction, completion and updating (section 12). Ask us to correct data that is inaccurate or misleading, to complete data that is incomplete, and to bring it up to date.
  • Erasure (section 12). Ask us to delete personal data, which we will do unless we are required to keep it for the purpose for which it was given or for compliance with law or professional obligation. Where we must keep something, we will tell you what and why.
  • Withdrawal of consent (section 6). As described in clause 6.
  • Grievance redressal (section 13). Raise a grievance with the officer named in clause 11.
  • Nomination (section 14). Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.

10.2 To exercise any of them, write to work@standinglawyers.com describing what you want. We may ask you for enough information to satisfy ourselves of your identity, because acting on an unverified request is itself a risk to you. We do not charge for this.

10.3 We will acknowledge within three working days and respond substantively within thirty days. Where a request is complex and will take longer, we will tell you within those thirty days why, and when to expect our answer.

10.4 There are limits, and we would rather set them out than surprise you with them. We cannot delete something we are professionally or legally obliged to retain. We cannot disclose, in answer to an access request by one person, information that is confidential or privileged as regards another. And a request that is manifestly unfounded, repetitive or vexatious may be refused, with reasons given.

11. Grievance Officer, and how to escalate

11.1 Under Rule 5(9) of the SPDI Rules, 2011 we designate a Grievance Officer. The Grievance Officer for Standing Lawyers is Mohit Sharma, Advocate, the proprietor of the firm, who may be reached at work@standinglawyers.com, marked "Grievance Officer, data protection", or on +91 63766 28978.

11.2 The Grievance Officer will acknowledge a grievance within three working days and redress it within one month of receipt, which is the period Rule 5(9) prescribes. Our Grievance Redressal Policy sets out the wider complaints procedure.

11.3 If you are not satisfied with our response, you may escalate. When section 13 of the Digital Personal Data Protection Act, 2023 commences on 13 May 2027, a complaint may be made to the Data Protection Board of India, and note that section 13(3) requires you to have exhausted our own grievance mechanism first. Independently of that Act, you may pursue any remedy available to you in law, including before a court of competent jurisdiction, and where your complaint concerns the professional conduct of an advocate you may complain to the State Bar Council under section 35 of the Advocates Act, 1961.

12. Children

12.1 This website is directed at businesses and at people seeking professional employment. It is not directed at children and we do not knowingly collect the personal data of anyone under eighteen.

12.2 If you believe a child has given us personal data, please tell us and we will delete it. Where a matter we are instructed on concerns a child, that data is handled within the engagement and under the safeguards in our Data Protection and Information Security Policy, not under this website policy.

13. Changes to this policy

13.1 We will update this policy when our practice, our providers or the law changes. Two changes already scheduled in law are noted in clause 2.3, and we will revise this policy before each takes effect rather than after.

Effect, review and contact

A This Privacy Policy takes effect on 7 August 2026 and replaces any earlier version of it published on this website. The version published here is the operative version at any given time.

B We review this Privacy Policy at least once a year, and additionally whenever the law, our systems or our practice changes in a way that affects it. Where a change is material we will say so on this page and, where the change concerns personal data and we hold a means of reaching you, we will tell you directly.

C Questions about this Privacy Policy, and any request or complaint arising from it, should be sent to work@standinglawyers.com, marked for the attention of the Grievance Officer where it is a complaint. We can also be reached on +91 63766 28978.