Trust & data handling · Last updated 5 September 2026
We ask businesses to trust us with contracts, employee records and the documents behind their filings. This page says what happens to them: where they are processed, which companies are involved, how long anything is kept, and what we have undertaken never to do. Where a claim depends on another company's conduct, we link their terms instead of summarising them.
The application and its API run on Vercel, pinned to the Mumbai region (bom1). Your account data, your documents and your compliance record are held in a libSQL database hosted by Turso. Requests are served over TLS only — the site sends HSTS with a two-year max-age, so a browser that has seen it once will not fall back to HTTP. Some processing necessarily happens outside India: the models that answer a legal question or read a contract are operated by providers hosted abroad, and so is our transactional email. Section 16 of the DPDP Act permits transfer outside India except to a territory the Central Government restricts by notification, and no such notification has been issued. If one is, we will move or drop the affected processor rather than ask you to accept the transfer.
Every company that touches your data on our behalf, what they do with it, and where they do it. This is the complete set VidhiSar can route to — not only those a given deployment has keys for — so there is no provider you could later discover we had not mentioned. Which inference provider serves a particular request depends on configuration. None of them may use your data for their own purposes. Each is used through its commercial API under its own terms, and we link those rather than paraphrase them: read Groq, Google, xAI, Vercel, Turso and Cashfree if the detail matters to your decision. We would rather point you at the source than have you take our summary of someone else's obligations.
When you ask a legal question, draft a document or scan a contract, the text involved is sent to a model provider to produce that answer, and the result comes back to you. That is the whole of it: the request is made, the answer is returned, and nothing about it is sent anywhere else.
Your account data and generated documents are kept while your account is active, because a compliance history that forgets last year's filings is not a compliance history. Delete your account from your profile and your personal data, chat history and documents are removed from our active systems. Billing records are held longer where Indian tax and accounting law requires it — that is the one exception, and it is not discretionary. Deletion is deletion, not deactivation. The full detail, including what a deletion request covers, is in the Privacy Policy.
Under the DPDP Act you can ask what personal data we hold about you, have it corrected, have it erased, and nominate someone to exercise those rights if you cannot. Most of it you can do yourself from your profile without asking us at all. For anything that needs us, write to Swaraj Layek at infovidhisar@gmail.com. We acknowledge within 24 hours and resolve within 15 days — the same commitment published on the Terms of Service, because a grievance route with two different timelines on two different pages is not a commitment.
If personal data in our care is breached, section 8(6) of the DPDP Act requires us to notify the Data Protection Board and every affected Data Principal. We will do that, and we will tell you what happened, what was affected and what we did about it — in the same plain language as the rest of this page, without waiting to have a tidy story first. If you think you have found a security problem, tell us at infovidhisar@gmail.com before telling anyone else, and we will work with you on it.