Wizard Legal
Legal

Privacy Policy

Last updated: June 2026 · Wizard Legal

This is a plain-English description of how we actually handle your data. Wizard Legal is the Data Fiduciary under the Digital Personal Data Protection Act, 2023, and this policy also reflects our obligations under the Information Technology Act, 2000.

Who we are

Wizard Legal is operated by Wizard Legal Technologies Pvt. Ltd., 100 Feet Road, Indiranagar, Bangalore, Karnataka 560038, India. For the personal data you give us and the data we generate while providing the service, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act), meaning we decide why and how that data is processed, and we are answerable to you for it.

You can reach us about anything in this policy at [email protected].

What we collect

We collect the information you provide and the data generated while you use the platform:

  • Account details, your name, email and phone number. Passwords are stored only as one-way hashes, never in plain text.
  • Document content, the answers you type into templates, saved drafts, and the finished documents. These often contain personal data about other people (counterparties, employees, family members).
  • AI Review text, the text of contracts you upload for AI Review. The uploaded file itself is virus-scanned and processed in memory without being saved; the analysis results (and, for contract comparison, the full text of both versions) are stored in our database.
  • Signing records, when you use a signing workflow, may include signer and event details such as timestamps, IP address, browser and device details, and an approximate IP-derived location. These details appear in the signing record associated with the document.
  • Payment metadata, order amounts, Razorpay order and payment references, and invoice details (including GSTIN where you provide one). We never see or store your card or UPI credentials.
  • Usage analytics, product usage events (page views, feature usage) tied to your account or session, collected via PostHog when it is configured.
  • If the separately configured first-party public traffic feature is enabled, eligible public-page visits may create a short-lived record containing daily-scoped browser and IP hashes, a coarse network prefix, referrer hostname and browser family. It excludes account, signing, shared-document and token routes; it does not retain exact visitor IP addresses, full user agents or URL query strings.

How we use it

We use your information to draft and store your documents, run AI Review, facilitate eSign, process payments, provide support and improve the platform. We do not sell your personal data.

Third parties who process your data

We use a small number of outside companies (sub-processors) to run parts of the service. Each receives only what it needs for its job:

  • eMudra, if and when the provider-backed Aadhaar eSign or DSC workflow is enabled in production, may receive the document to be signed and the signer details required for that workflow. This option is not currently advertised as production-available.
  • Razorpay, processes card and UPI payments. We only hold Razorpay's order and payment references, never your payment credentials. Processed in India.
  • AI model providers, text you submit to AI Review is sent to a large-language-model provider: OpenRouter, Cerebras or Moonshot (Kimi), or a locally hosted Ollama model when configured. The hosted providers process data on servers outside India, so your contract text may leave India for this analysis.
  • ipapi.co, receives the signer's IP address to derive the approximate location recorded in the signing audit trail. Processes data outside India.
  • PostHog, receives product usage analytics events. Likely processed outside India (EU/US cloud).

Where your data lives

Your structured records, account details, document answers and drafts, signing records, payment references and audit logs, live in a PostgreSQL database on our production server. Generated and uploaded files are kept in S3-compatible object storage; signed documents and their audit-trail PDFs are also stored on our server.

The main exception to data staying on our infrastructure is AI Review: contract text sent to a hosted AI provider (OpenRouter, Cerebras or Moonshot/Kimi) is processed on that provider's servers, which may be outside India.

How long we keep it

Our current practice, by area of the product:

  • Account data, kept for as long as your account is active. You can request deletion of your account.
  • Documents and drafts, kept until you delete them or your account, or as needed to meet legal obligations.
  • Signing records and audit trails, retained with the signed document, because the audit trail is what gives the signature its evidentiary value.
  • AI Review outputs, stored analysis (and the contract text you upload for comparison) is retained while your account is active and is deleted when you delete the review, delete your account, or ask us to erase it, unless we are required to retain it to meet a legal obligation.
  • When enabled, first-party public traffic analytics is retained for the configured short period (30 days by default) and then removed in bounded batches. It remains separate from security audit logs, which have their own access controls and retention needs.

Your rights under the DPDP Act

As a Data Principal under the DPDP Act, 2023, you have the right to:

  • Access, ask us for a summary of the personal data we hold about you and how it is processed
  • Correction, have inaccurate or incomplete personal data corrected or updated
  • Erasure, ask us to delete your personal data where we no longer need it to provide the service or meet a legal obligation
  • Grievance redressal, raise a complaint with our grievance officer and, if unresolved, escalate to the Data Protection Board of India
  • To exercise any of these rights, email us at [email protected]

Grievance officer

Our Grievance Officer for complaints under the DPDP Act and the Information Technology Act, 2000 can be reached at [email protected] (subject line: "Grievance Officer"). We aim to acknowledge grievances promptly and resolve them within the timelines required by law.

Aadhaar & eSign

Aadhaar eSign remains unavailable in the product until the provider-backed workflow has completed production verification. We do not present it as an available signing option while that verification is incomplete.

For the signing methods that are available, we retain the event details needed to show the document owner and signers what happened in the workflow, such as timestamps and any recorded signer context. These details are shared with the document owner and signers when the workflow completes.

Security

We use encryption in transit and at rest, access controls and reputable cloud infrastructure to protect your data. Passwords, tokens and OTPs are stored only as hashes, and uploads are virus-scanned. No system is perfectly secure, but we work hard to keep yours safe.