everra LEGALSign in

Privacy policy

Everra holds privileged client files. This policy says exactly what we do with personal data, who else can reach it, and what you can require of us — in plain terms, because a policy nobody can read protects nobody.

Version 1.0 · Effective on acceptance

Before publishing: this draft is accurate to how Everra is actually built, but it is not executed legal advice. It needs review by qualified counsel, particularly the controller and processor roles, the transfer basis, and the retention periods. Bracketed items must be completed.

1. Who is responsible for what

Everra is operated by [legal entity name], [registered address], [company registration number]. This distinction decides who answers to whom, so it comes first.

  • For your client files, you are the Data Fiduciary and we are the Data Processor. Matters, documents, evidence, client records and hearing notes belong to the firm. We process them only on the firm’s instructions, and we never decide what goes into them.
  • For your own account, we are the Data Fiduciary. The name, email and billing details of the people who subscribe are ours to hold, because we decide to collect them in order to run the service.

If you are a client of a firm that uses Everra and want to exercise a right over your case file, ask the firm. They control that data; we cannot act on it without them.

2. What we collect

  • Account data — name, work email, role, firm name, and a password stored only as a bcrypt hash. We never hold your password.
  • Billing data — invoice history, amounts, GST details, and the payment identifiers Razorpay returns. Card and bank details never reach us; they are entered on Razorpay’s own page.
  • Customer Data — everything the firm puts into the service: matters, clients, documents, evidence, hearings, tasks, drafts and notes.
  • Authentication data — session tokens, two-factor secrets, and the public key of any device registered for Face ID or Touch ID. Biometric data itself never leaves your device and we never receive it.
  • Operational logs — timestamps, IP address, and the action taken, kept so a firm can audit who opened which file.
  • Court data — case status retrieved from the eCourts services when a firm links a matter to a case number.

We do not buy data, we do not enrich profiles, and we do not collect anything for advertising.

3. Why we process it

  • To provide the service — performance of the contract with the firm.
  • To bill — performance of the contract, and legal obligation for tax records.
  • To secure accounts — legitimate interest in preventing unauthorised access to privileged files.
  • To send service email — invoices, receipts, hearing reminders and security notices. These are part of the service, not marketing.
  • To meet legal obligations — retention of financial records, and response to lawful orders.

We do not use Customer Data to train machine-learning models, our own or anyone else’s.

4. Client files and privilege

Material in Everra is frequently subject to legal professional privilege. We treat it accordingly.

  • We do not read Customer Data. Staff access is limited to what is needed to resolve a fault the firm has reported, and is logged.
  • We do not disclose Customer Data to a third party except on the firm’s instruction or where compelled by law.
  • If we receive a legal demand for Customer Data, we will notify the firm before responding wherever the law permits, so the firm can assert privilege itself. Privilege belongs to the client, and we are not the right party to waive it.

5. Who else touches the data

These are every third party in the path. There are no others.

  • Vercel — hosting, and storage of uploaded documents. Processes all service traffic.
  • Neon — the managed Postgres database holding all records.
  • Resend — delivery of transactional email. Receives the recipient address and the message.
  • Razorpay — payment processing. Receives the payer’s name, email and the amount; holds the card details we never see.
  • Microsoft — our own mailbox, where replies to Everra addresses arrive.
  • eCourts / National Informatics Centre — receives a case number when a firm asks for case status.

Each is bound by a data-processing agreement. We have no analytics provider, no advertising network and no third-party tracking of any kind — an unusual claim, and a deliberate one for software that holds privileged material.

6. Where the data lives

The database and document storage are provisioned in [region]. Firms that require Indian data residency should confirm the region on their order form, as it is set per deployment.

Where a processor operates outside India, the transfer relies on contractual safeguards and on the transfer being necessary to perform the contract with the firm. A firm on a dedicated deployment can require that its data stay in a named region.

7. How long we keep it

  • Customer Data — for the subscription term. On termination it stays available for export for 30 days, then is deleted within a further 90 days, backups included.
  • Account data — for the term, then 12 months, so a returning firm is not made to start again.
  • Financial records — eight years, as Indian tax law requires. This period cannot be shortened on request.
  • Access logs — 12 months.

A firm may ask for earlier deletion of its Customer Data at any time, and we will act on it.

8. Your rights

Under the Digital Personal Data Protection Act 2023 you may:

  • ask what personal data we hold about you and why;
  • have inaccurate data corrected, and incomplete data completed;
  • have data erased where we no longer need it;
  • nominate someone to exercise these rights if you die or become incapacitated;
  • complain to us, and then to the Data Protection Board of India.

Where the GDPR applies, you additionally have rights of portability, restriction and objection, and may complain to your own supervisory authority.

Write to privacy@everra-legal.com. We respond within 30 days. We will ask you to verify your identity first, because handing case data to the wrong person is the failure this policy exists to prevent.

9. How it is protected

  • Encrypted in transit with TLS, and at rest by the storage layer.
  • Passwords stored as bcrypt hashes, never in plain text or reversible form.
  • Two-factor authentication, mandatory for owners and administrators.
  • Face ID and Touch ID lock on the vault, using device-bound keys that never leave the device.
  • Every record scoped to its organisation, enforced in the data layer rather than in the interface.
  • Access to client files logged, and visible to the firm.

If a breach affects your personal data we will notify the Data Protection Board and the affected firms without undue delay, with what happened and what to do.

10. The mobile app

The Everra app for iOS and Android handles data exactly as the website does, and adds nothing of its own.

  • No tracking, no advertising identifier, no analytics SDK. We do not track you across apps or websites owned by other companies.
  • Face ID and Touch ID authenticate you on the device. The biometric never leaves it and is never transmitted to us.
  • Notifications, if you allow them, remind you of hearings and deadlines. They are generated on your device from your own matters.
  • Files you download for offline reading are stored in the app’s private container and removed when you sign out.
  • Permissions are requested only when a feature needs them, and refusing one disables only that feature.

11. Cookies and tracking

Everra sets one cookie: the session cookie that keeps you signed in. It is essential, HttpOnly, Secure and SameSite, and it carries no profile of you.

There are no advertising cookies, no pixels and no third-party trackers, which is why the site shows no consent banner — there is nothing to consent to.

12. Children

Everra is professional software and is not directed at anyone under 18. We do not knowingly collect a child’s personal data. Where a case file concerns a minor, that data is Customer Data controlled by the firm, held under the firm’s own duties.

13. Grievance officer

As the DPDP Act requires, one named person is answerable for complaints about how we handle personal data.

  • Name: [grievance officer name]
  • Email: privacy@everra-legal.com
  • Address: [registered address]

If we have not resolved your complaint to your satisfaction, you may escalate to the Data Protection Board of India.

14. Changes to this policy

We may change this policy on 30 days’ notice by email to the firm’s administrator. Changes that materially reduce protection give the firm the right to terminate before they take effect. Every version is dated, and the previous one is available on request.

Questions about this policy: privacy@everra-legal.com.