Confidential Dispatch
Legal

Privacy Policy

How Confidential Dispatch collects, uses, retains and protects personal data on this site and in the Confidential Dispatch application, and your rights under India’s DPDP Act.

Last updated: 31 August 2026

Confidential Dispatch (“we”, “us”, “our”) runs the website at confidentialdispatch.com and the Confidential Dispatch application at app.confidentialdispatch.com. We help organisations collect personal data the right way, so we hold ourselves to the same standard. This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it. It is written to meet our obligations under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules.

This policy speaks to three groups of people. Website visitors (Sections 3 and 4). Firm account holders, the people who sign up for and use the application (Section 5). People whose documents a firm collects through Confidential Dispatch (Section 6). If a firm sent you a link asking for documents, Section 6 is written for you.

1. Who we are

We are the Data Fiduciary for the personal data collected through the website and for the accounts of the firms that use the application. For the documents and details a firm collects from its own clients through the application, that firm is the Data Fiduciary and we act as its Data Processor (see Section 6).

For how to raise a concern or complaint, see Section 10, Grievance redressal.

2. What this policy covers

The website: everything at confidentialdispatch.com, including information about Confidential Dispatch, our educational resources, the DPDP Exposure Self-Check and the waitlist. The application: everything at app.confidentialdispatch.com, where firms collect consent and documents in a compliant way, including the capture pages opened for the people asked to submit them. Both are intended for adults and are not directed at children (see Section 11).

3. The website: what we collect, and why

We collect only what each feature needs, and nothing more.

a) Waitlist. If you join our waitlist, we collect:

  • your email address (required), and
  • your first name (optional, used only to personalise our launch emails).

We use these solely to tell you when Confidential Dispatch launches and about introductory pricing. We will not share them, sell them, or add you to any other marketing list.

b) DPDP Exposure Self-Check. The Self-Check is anonymous. Your answers are not linked to you or your email and are not used to identify you. We may keep non-identifying statistics (for example, how many people answered a question a certain way, and when) to improve the tool. This is not personal data and cannot be traced back to any individual. You can complete the Self-Check without giving us any contact details; the waitlist is entirely separate and optional.

c) Server and security logs. Like any website, our server automatically records basic technical information (such as IP address, browser type, and pages requested) to keep the site secure and working. The website is served through a content delivery network (CDN), which processes this connection data at its global servers to deliver and protect the site. We use this only for security and operational purposes.

d) Cookies and analytics. We use Google Analytics to understand how this website is used: which pages are read, how people arrive, and which links they follow. It sets two cookies (_ga and _ga_ET6SPGQT6K) holding a random identifier, so repeat visits can be counted as one visitor. It does not receive your name or email address, and nothing you type into a form is sent to it. It does not store your IP address; it uses it to determine an approximate location and then discards it. We use it for analytics only: we do not run advertising cookies and do not use it to build an advertising profile of you. Because Google Analytics is a Google service, this usage data is processed outside India, including in the United States.

The analytics cookies are set when the page loads. A notice appears on your first visit, and you can turn analytics off there or at any time from the Cookie settings link in the footer of every page. Turning it off stops further collection and deletes these cookies from your browser. We keep an anonymous count of how many people accept or turn it off; that record holds nothing that identifies anyone.

Google Analytics runs on the website only. It does not run in the application.

4. The website: our legal basis, and your consent

We collect your waitlist details on the basis of your consent, which you give by ticking the consent box when you sign up. That consent is specific to the purpose stated above (launch and introductory-pricing updates). If we ever want to use your details for a new purpose, we will ask you again first.

You can withdraw your consent at any time by emailing [email protected]. Withdrawing is as easy as giving consent was, and it won’t affect anything we did lawfully before you withdrew.

5. The application: firm account holders

This section applies to you if you create or hold an account in the Confidential Dispatch application, whether you set up your firm’s account or were invited to join it.

a) What we collect.

  • Account details: your email address, your password (stored only as a salted hash; we never hold the password itself), and, if you turn on two-factor authentication, the secret that generates your codes.
  • Firm details: the firm’s name, the name shown on its capture pages, its logo if uploaded, its type of practice, and the name and email of its grievance contact.
  • Sign-in and session records: when you sign in, sign out, or a sign-in fails; the sessions that keep you signed in; a count of recent failed attempts, used to pause sign-in after repeated failures.
  • Activity record: a tamper-evident record of the actions taken in your firm’s account (for example, a request created, a document downloaded, a member invited). It holds identifiers and cryptographic hashes, not the content of documents.
  • Emails we send you: confirmation of your email address, password resets, team invitations, and notices about your requests (such as documents received). These are transactional messages about your account, not marketing, and carry no unsubscribe.
  • Server and security logs: as described in Section 3©. The application is served through the same CDN.
  • Bot check on sign-in forms: the sign-in, sign-up, password-reset and resend-confirmation forms run a check by Cloudflare (Turnstile) to tell people from automated scripts. It processes connection data (such as IP address and browser signals) at Cloudflare’s servers, which may be outside India, and may set a short-lived technical cookie for the check. It does not receive what you type into the form.

b) Why. To create and secure your account, to sign you in, to provide the application to your firm, to send you the messages above, to keep an accurate record of what was done in the account, and to protect the service from misuse. We collect your details on the basis of your consent, given when you create or join the account, for these purposes. We do not use your details for advertising and do not share them with anyone for marketing.

c) Two-factor authentication is optional. You can turn it on or off from Settings. Turning it off requires your password and a current code. If you lose access to your authenticator, a firm admin can reset it from the Team page; if no admin at your firm can help, contact us at [email protected].

6. The application: people whose documents a firm collects

This section applies to you if a firm sent you a link asking for documents or details through Confidential Dispatch.

a) Who is responsible. The firm that asked you for the documents is the Data Fiduciary. It decides what is collected, why, and for how long, and it is responsible for that data. Confidential Dispatch is the firm’s Data Processor: we operate the system the firm uses, on the firm’s instructions, and we do not use your data for any purpose of our own.

b) Notice and consent. Before you upload anything, the capture page shows you the firm’s notice: what is being asked for, the purpose, how long it will be kept, the rights you have, and the firm’s grievance contact. Nothing is stored until you have read the notice and given your consent. Your consent is recorded against the exact version of the notice you saw, with the date and time, and you can view a receipt of it on the page.

c) What happens to your documents. They are encrypted before they are stored, held on servers in India, and can be seen only by the firm’s authorised staff. Every time a document is viewed or downloaded by the firm, that action is recorded. Your documents are kept for the period stated in the notice and then deleted automatically, including from backups. If you withdraw your consent, the firm removes the data the consent covered; the record that consent was given and withdrawn is kept, as the law requires, but it contains no document content.

d) Emails on the firm’s behalf. If the firm gave us your email address, we may send you a reminder about outstanding documents. These are sent as “firm name via Confidential Dispatch”. We do not send you anything else, and we do not add you to any list.

e) Your rights. Your rights over this data (access, correction, erasure, grievance, nomination) are exercised with the firm, through the grievance contact named in the notice. The firm uses Confidential Dispatch to carry them out. If you want to reach us about how Confidential Dispatch itself handles data, write to [email protected].

7. How long we keep it

Website

  • Waitlist email and name: up to 12 months from the date you sign up. We delete your details earlier once their purpose is served, for example after we have told you about the launch.
  • Self-Check answers: not kept against you. They are anonymous and not linked to your identity.
  • Server and security logs: kept for up to 90 days, then deleted, unless we need to retain a specific record longer to investigate a security incident.
  • Google Analytics data: retained by Google for 14 months from your visit, then deleted. Aggregate reports that are not tied to any individual may be kept longer.

Application, firm account holders

  • Account and firm details: for as long as the account is open. When a firm closes its account, its data is deleted after a 30-day grace period, including the encryption keys that protect its documents.
  • Sessions: expire after 7 days, or immediately when you sign out, change your password, or an admin ends them.
  • Email-confirmation and password-reset links: valid once, for 24 hours and 2 hours respectively.
  • Failed sign-in counts: cleared on a successful sign-in, and in any case after 15 minutes.
  • Activity record: kept as our compliance record. It contains identifiers and cryptographic hashes only, never document content or names.
  • Encrypted backups: kept for 30 days in India, then expire automatically.

Application, documents collected by a firm

  • For the period stated in the firm’s notice, then deleted automatically. Deletion is by destruction of the encryption key, which makes the stored copy unreadable everywhere at once, including in backups.

When a retention period ends, or when a deletion is requested and carried out, the record is permanently removed by an automated process and is not restored from backups.

8. Who we share it with

We do not sell personal data. We share it only with the service providers (Data Processors) we need to run the website and the application, under contracts that require them to protect it and use it only on our instructions:

  • Hosting: our cloud hosting provider. The website, the application, its database, and its encrypted document storage are all hosted in India (Mumbai).
  • Content delivery, security and bot check: Cloudflare. The website and the application are served through its global network, so technical connection data (such as IP address) is processed outside India to deliver and protect them. Its Turnstile check on the application’s sign-in forms is described in Section 5(a).
  • Analytics: Google (Google Analytics), website only, as described in Section 3(d). Google processes this data outside India, including in the United States.
  • Email delivery: our email delivery provider, with servers in India, used only to send the messages described in this policy.

We can provide the identity of our current service providers on request; email [email protected].

Data residency: the personal data you give us, and every document collected through the application, is stored in India. Two categories of data are processed outside India: technical connection data handled by Cloudflare to deliver and protect the sites, and website-usage data handled by Google Analytics. Neither carries your name, your email address, or any document.

We may also disclose personal data if we are legally required to (for example, a lawful order from a court or regulator).

9. Your rights

Under the DPDP Act, you have the right to:

  • Access: ask what personal data is held about you.
  • Correction: ask for it to be corrected or updated.
  • Erasure: ask for it to be deleted.
  • Grievance redressal: raise a concern about how your data is handled (see Section 10).
  • Nominate: nominate another person to exercise these rights on your behalf if you die or become incapacitated.

Website visitors and firm account holders: email [email protected]. We will respond within 30 days (and in any case within the 90-day maximum set by the DPDP Rules). There is no charge to exercise your rights.

People whose documents a firm collected: contact the firm through the grievance contact named in its notice (see Section 6(e)).

10. Grievance redressal

If you have a concern or complaint about how we handle personal data, contact our grievance contact:

We will acknowledge your grievance promptly and aim to resolve it within 30 days, and in any case within the 90-day period set by the DPDP Rules. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

11. Children’s data

The website and the application are intended for adults and are not directed at children (anyone under 18). We do not knowingly collect personal data from children. If you believe a child has submitted personal data to us, email [email protected] and we will delete it. A firm collecting documents from a child through the application is responsible for obtaining verifiable parental consent as the law requires.

12. How we protect your data

We protect the personal data we hold with reasonable security safeguards. Everything is transmitted over an encrypted (HTTPS) connection. Documents collected through the application are encrypted individually before they are stored, with keys held in a managed key service in India, and are stored with access controls so only authorised people can reach them. Every access to a document by a firm is recorded. Account passwords are stored as salted hashes, sign-in can be protected with two-factor authentication, and repeated failed sign-in attempts pause the account. If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by law, and, for data we process on a firm’s behalf, the firm without delay.

13. Languages

You can ask us to provide this notice in English or any language listed in the Eighth Schedule to the Constitution of India. Email [email protected] to request this.

14. Changes to this policy

If we change this policy, we will update the “Last updated” date above, and, where the change is significant, tell waitlist members and firm account holders by email. Please check this page from time to time.