Digital Personal Data Protection Act (DPDPA) Disclosure
Last updated: 23 July 2026
This page summarises how Synapse: Legal AI Assistant ("Synapse") approaches the Digital Personal Data Protection Act, 2023 ("DPDPA"). It accompanies the Privacy Policy and Terms of Service; the three documents should be read together. Where this summary and the Privacy Policy differ, the Privacy Policy governs.
Who is responsible
Synapse is operated by Yousuf Ali Adnan Mohammed (individual developer), 27-64, Gandhinagar IDPL Colony, Quthbullapur, Hyderabad 500054, Telangana, India. For your account, diagnostics and payment data we act as the Data Fiduciary; for the case content you create about your clients, you remain the Data Fiduciary and we act as your Data Processor on your instructions (Privacy Policy §1 and §8).
Section 17 — Data residency and storage
Your stored data — account records, case files, transcripts, documents and audio — lives in our primary database and file storage, locked to the India-South region. Production region pinning is enforced at backend startup, and the process refuses to start on any violation.
Out-of-region AI processing
Several of the AI providers we rely on process data outside India (the full list is in Privacy Policy §4.2): Anthropic Claude (reasoning and drafting), OpenAI and Google (secondary language processing and document OCR), our text-embeddings provider, and part of our speech-to-text transcription run in the United States. All such calls originate from our India-hosted backend — the app never calls AI vendors directly, and the backend is the DPDPA §17 data-processing boundary — but the AI processing itself occurs abroad.
Automated PII redaction applies to some of those calls and not others:
- Always (all users): fact extraction and document translation —
identifiers (Aadhaar, phone, PAN, bank-account, IFSC, GSTIN, PIN,
driving-licence and passport numbers, case numbers, email addresses and
recognised party names) are tokenised (for example to
[PARTY_1]) before egress. The token map is held only in memory inside the India-hosted backend and is never written to storage. - Only under Privacy Mode (Settings): the case fact sheet used for document drafting.
- Never: the Ask assistant, the Prep / strategy chat, the Research agent and draft-assist features send full case context regardless of Privacy Mode. The app shows an in-product notice to this effect.
Redaction is pattern-based and cannot guarantee that every identifying detail is caught. The full statement is Privacy Policy §4.3.
Under Anthropic's standard commercial terms, inputs may be retained for up to 30 days for abuse monitoring and are not used to train models.
Section 6 — Consent and notice
You provide personal data to operate your practice on Synapse. Where you record consultations, you are responsible for obtaining the consent of the individuals recorded. This disclosure, together with the Privacy Policy, is the notice of the purposes for which we process your data.
Section 11 — Right to access
You can read every action you have taken, with timestamps and target IDs, from Settings → Activity log.
Section 12 — Right to correction and erasure
- Correction: edit your profile fields (full name, bar-council ID, specialization) from Settings → Profile at any time.
- Erasure (data): Settings → "Purge all my data" triggers a hard delete of every case, transcript, document, draft, hearing, audio segment, and research item you own. Stored files are wiped at the same time. Your sign-in is preserved so you can return to an empty workspace.
- Erasure (account): Settings → "Delete my account permanently" removes your sign-in AND all of the above in one irreversible step.
Section 8(5) — Reasonable security safeguards
- Encryption in transit (HTTPS/TLS) for all network traffic.
- On-device encryption at rest (AES-256-GCM) of the local database and audio recordings, with the key held in the platform's secure keystore.
- Row Level Security on every database table; firm-share rows are visible only to active firm seats.
- An audit log on every mutating action.
- Hard purge and account deletion wipe both database rows and stored files.
- PII token maps are held only in memory inside the India-hosted backend and are never persisted to storage.
Grievance redressal
Contact our Grievance Officer — Yousuf Ali Adnan Mohammed, support@synapse-ai.in — for any DPDPA query or grievance, including access, correction and erasure requests. We respond within the timelines required by law. If unresolved, you may escalate to the Data Protection Board of India.
Significant Data Fiduciary
Synapse does not currently meet the volume / nature thresholds that would trigger the Significant Data Fiduciary obligations under DPDPA §10. We will publish a revised disclosure if and when those thresholds are met.
Updates
We may revise this disclosure. The "Last updated" date at the top of this page reflects the current version.