AntChambers

ANT LLP · antchambers.com

Privacy Policy

This explains what happens to personal data when you use this website and when your firm uses AntChambers. It is written to be read, not to be survived.

Effective
11 September 2026
Applies to
antchambers.com and the AntChambers service
Governing law
India · courts at Mumbai
Clause 01

Who we are

AntChambers is a product of ANT LLP, a limited liability partnership incorporated in India. In this policy “we”, “us” and “our” mean ANT LLP.

Clause 02

Two different roles, and the difference matters

We handle personal data in two quite different capacities, and your rights differ depending on which one is in play.

  • This website. When you send an enquiry, we decide why and how that information is used. Under the Digital Personal Data Protection Act, 2023 we are theData Fiduciary for it, and you deal with us directly.
  • Your firm’s instance. The clients, matters, timesheets, bills and documents inside AntChambers belong to the firm. The firm decides what goes in, who may see it and how long it stays. The firm is the Data Fiduciary; we are aData Processor acting on the firm’s instructions under a written agreement.

If you are a client of a law firm that uses AntChambers and you want to see, correct or erase what is held about you, ask the firm. We cannot act on your request directly, because acting on it without the firm’s instruction would breach the firm’s own duties to you. Our obligations as processor are set out in the Data Processing Addendum.

Clause 03

What this website collects

Enquiry details reach us when you send the prepared email. There is no website account. Our hosting provider may process technical request information, such as IP address, requested URL and browser details, to deliver and secure the site.

WhatWhy we ask
Work emailTo reply to your enquiry.
Firm nameTo know who is asking and to prepare a relevant answer.
Named active user countTo calculate your subscription and understand how many people need access.
Preferred meeting time (optional, IST)To propose a slot that suits you; availability is confirmed by email.
Your enquiryFree text. Please do not put client names or matter details in it.

The forms on this site open a pre-filled message in your own email application. That means your enquiry reaches us as an ordinary email. The website has no enquiry database; technical hosting requests are separate from the contents of your message.

We use it to answer your enquiry and, if you become a customer, to administer the relationship. We do not sell it, rent it, or use it to build advertising profiles. We do not send marketing to people who only asked a question.

Clause 04

Cookies and analytics

This website sets no cookies and runs no analytics. There is no Google Analytics, no tag manager, no advertising pixel, no session recording, no heat mapping and no third-party script of any kind. Nothing is stored in your browser and no profile of your visit is built.

We mention it because it is unusual and because you would otherwise have to take a cookie banner’s word for it. There is no banner here because there is nothing to consent to.

If that ever changes, this clause changes with it and the effective date at the top of this page moves. We will not quietly add a tracker under an unchanged policy.

Clause 05

Data inside your firm’s instance

A practice-management system holds a great deal about people who never agreed anything with us: clients, opposing parties, witnesses, and the firm’s own staff. We treat all of it as the firm’s, held under the firm’s instructions.

  • We do not use firm data to train models, build benchmarks, or produce market reports.
  • We do not pool it with any other firm’s records. Each firm has its own instance, database, document store and backup boundary.
  • We access it only to operate the service — a fault to diagnose, a migration to run, a restore to perform — and only to the extent that work requires.
  • Our staff are bound by written confidentiality obligations, and access is limited to named personnel for a specific task.

The full processor terms, including the sub-processor list and the breach notification timetable, are in the Data Processing Addendum.

Clause 06

Where your data sits

Instances, databases, document stores and backups are hostedin India. The infrastructure provider is named in the Data Processing Addendum supplied with a subscription, and we will tell you who it is on request before you buy.

We do not transfer firm data outside India. If that ever needs to change for a particular firm, it would be agreed with that firm in writing first, and recorded on its order — not decided by us and announced afterwards.

Clause 07

Who else can reach it

The firm receives the applicable provider names, roles and locations in its completed sub-processor schedule before go-live. The publicData Processing Addendum describes that process; it is not a completed provider inventory for a particular installation.

Beyond those, we disclose personal data only where the law requires it — a valid order from a court or a competent authority. Where we are lawfully able to tell the firm before complying, we will, so the firm can take its own advice. Where we are prohibited from telling them, we will say so as soon as the prohibition lifts.

We do not sell personal data. There is no circumstance in which we would.

Clause 08

How long we keep it

Enquiries that go nowhere
Deleted within twelve months of the last exchange, unless you ask us to keep in touch.
Customer records
Kept for the life of the subscription, then for as long as tax and company law require us to retain the commercial record.
Backups
The standard service scope retains daily backups for 30 days. The agreed retention and recovery arrangements are recorded in the firm’s service schedule.
After termination
The instance is retained for a period stated in the firm’s agreement so the export can be completed, and is then destroyed along with its backups. The agreement states the reminder, the grace period and the point at which the instance becomes read-only.
Clause 09

How we protect it

The measures we actually operate, described plainly. What is on thedeployment and security page is the same list in more detail.

  • One private instance per firm — separate application stack, database, document store and backup boundary. Firm records are never in a shared table.
  • Traffic encrypted in transit, with certificates managed as part of the service.
  • Sign-in by email and password, with the option to require a second factor. Repeated failures lock the account. Passwords are stored so that nobody at our end can read them.
  • Per-module permissions enforced by the application, not merely hidden from the screen.
  • An audit trail recording who changed what and when, and sign-ins alongside.
  • The standard service scope includes tested releases, monitored service health and daily encrypted off-server backups, with restore verification before launch and quarterly thereafter. The service schedule records the agreed arrangements.

No system is beyond compromise and we will not claim otherwise. If a breach affects your firm data, we notify the firm under the Data Processing Addendumand assist with its notification obligations. For data we control, we make notifications required by applicable law.

Clause 10

Your rights

Under the Digital Personal Data Protection Act, 2023, in respect of data for which we are the Data Fiduciary — which on this website means your enquiry — you may:

  • Ask what we hold about you and what we have done with it.
  • Have it corrected if it is wrong, incomplete or out of date.
  • Have it erased, unless we are required by law to keep it.
  • Withdraw consent at any time, as easily as you gave it.
  • Nominate someone to exercise these rights on your behalf if you die or become incapable of acting.
  • Complain to us first, and to the Data Protection Board of India if we do not resolve it.

Write to privacy@antchambers.com. We do not charge for any of this.

For data held inside a firm’s instance, these requests go to the firm, for the reason given in clause 02.

Clause 11

Grievance redressal

If something about how we handle your data is wrong, we would rather hear it from you than from a regulator.

Grievance Officer
The Grievance Officer, ANT LLP
We will respond within
30 days of receiving your complaint.

If you are not satisfied with our response, you may complain to theData Protection Board of India through the process available under applicable law, after using our grievance-redressal process where required.

Clause 12

Children

This website and the AntChambers service are sold to law firms and are not directed at children. We do not knowingly collect personal data of anyone under 18 through this site. If you believe we have, tell us and we will delete it.

Matter records inside a firm’s instance may relate to children — in family or protection work, for instance. That data is the firm’s, held under the firm’s instructions and its own professional obligations, and clause 05 applies to it.

Clause 13

Changes to this policy

When we change this policy we move the effective date at the top of the page. For a change that materially affects how we handle personal data, we will tell customers directly rather than relying on you to re-read the page.

Where this policy conflicts with a signed order or master services agreement, that agreement prevails.