This Privacy Policy explains how Law Tutorial (“we”, “us”, “our”), which operates the website lawtutorial.in, collects, uses, stores, shares and protects your personal data.
This Policy is published in compliance with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made thereunder, to the extent brought into force;
- Section 43A of the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), in particular Rule 4 which requires publication of this Policy;
- Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, relating to grievance redressal; and
- the Consumer Protection (E-Commerce) Rules, 2020.
For the purposes of the DPDP Act, you are the Data Principal and we are the Data Fiduciary.
Legal name: Law Tutorial, a sole proprietorship of Nandhan Kumaran
Registered / business address: 2-103, Kannanvilai, Karungal PO, Kanyakumari District, Tamil Nadu, PIN 629157
Email: in**@*********al.in
Telephone: +91 94880 27801
1. Scope
This Policy applies to personal data we collect through lawtutorial.in, including when you browse the site, create an account, enrol in a course, make a payment, or contact us. It does not apply to any third-party website that we link to; those sites are governed by their own privacy policies.
2. Personal data we collect
We collect only the data described below. We do not collect more than we need for the purposes stated in Section 3.
| Category | Specific data | When collected |
|---|---|---|
| Account & identity | Full name, username, email address, password (stored only in cryptographically hashed form, never in readable form) | On registration |
| Contact & location | Mobile/phone number, city, State, postal address | On registration (our registration form collects these fields) |
| Profile | Learner category (e.g. “I am a…”), profile photo if you upload one | On registration or profile update |
| Learning activity | Courses enrolled in, lessons completed, course progress, quiz attempts and scores, assignment submissions, certificates earned | While you use the courses |
| Transaction | Order records, course purchased, amount, currency, date, payment status, payment reference/transaction ID issued by the payment gateway | On purchase |
| Technical & security | IP address, browser/device user-agent string, login timestamps, session identifiers | Automatically, on login and while browsing |
| Communications | Messages you send us by email, contact form or WhatsApp, and our replies | When you contact us |
2.1 Payment information — important
Online payments are processed by Razorpay Software Private Limited, a payment aggregator authorised by the Reserve Bank of India. Your card number, CVV, UPI PIN, net-banking credentials and similar payment credentials are submitted directly to Razorpay on its own secure interface. We do not receive, see or store those credentials on our servers. We receive only the outcome of the transaction and a reference identifier.
2.2 Sensitive personal data
Under Rule 3 of the SPDI Rules, “sensitive personal data or information” includes passwords and financial information such as bank account, credit card or debit card details. The only such category we handle is your password, which is stored in hashed form and is not readable by us. We do not collect health data, biometric data, sexual orientation, caste, religion or any special category data.
2.3 Device-based login security
To protect accounts against credential sharing, our learning platform records a device signature derived from your browser user-agent and IP address and limits the number of simultaneously active devices per account. This data is used only for account security and is not used for advertising or profiling.
3. Purposes for which we use your data
- To create and administer your account and authenticate your logins;
- To deliver the courses you enrol in and track your progress, quizzes, assignments and certificates;
- To process payments, issue receipts/invoices and maintain statutory financial records;
- To provide learner support and respond to your queries and grievances;
- To secure the platform, prevent unauthorised access, credential sharing, fraud and misuse;
- To send service communications relating to your account, enrolment or a transaction;
- To send updates about new courses or offers, only where you have consented, with an opt-out in every such message;
- To comply with applicable law and to establish, exercise or defend legal claims.
3.1 Basis on which we process
We process your personal data on the basis of the consent you give under Section 6 of the DPDP Act, and for the legitimate uses recognised under Section 7 of that Act (including where you voluntarily provide data for a specified purpose and where processing is required to comply with law). Consent is sought by a clear affirmative action and is limited to the purposes stated above.
4. Cookies and similar technologies
We use the following cookies. We do not use advertising or cross-site tracking cookies.
- Strictly necessary cookies — WordPress authentication and session cookies that keep you logged in and protect forms against cross-site request forgery. The site cannot function without these.
- Functional cookies — a small flag cookie that lets cached pages display your logged-in state (for example, showing your name and a Logout link in the header).
- Analytics — aggregated visit statistics used to understand which pages are useful. These are reported to us in aggregate and are not used to build an advertising profile of you.
You can delete or block cookies through your browser settings. If you block strictly necessary cookies, you will not be able to log in.
5. Who we share your data with
We do not sell your personal data. We do not rent or trade it. We share it only with the following categories of recipients, and only to the extent necessary:
| Recipient | Purpose | Data shared |
|---|---|---|
| Razorpay Software Private Limited | Payment processing and fraud checks | Name, email, phone, order amount and reference |
| Web hosting and infrastructure provider | Hosting the website and its database | Data stored on the site, on a confidential basis |
| Email delivery service | Sending account and transactional emails | Name, email address, message content |
| Google (only if you sign in with Google) | Authenticating your login | Your name and email address received from Google |
| Statutory authorities / courts | Where disclosure is required by law or by a lawful order | As legally required |
These recipients are permitted to process your data only for the stated purpose and are required to maintain confidentiality and appropriate security.
6. Retention
We retain your account and learning records for as long as your account remains active, so that you retain access to the courses you have paid for and to your certificates. If you delete your account or withdraw consent, we will erase your personal data, except data we are required to retain under law — in particular transaction and tax records, which are retained for the period prescribed under applicable financial and tax legislation. Data no longer required is deleted or irreversibly anonymised.
7. Security safeguards
In accordance with Section 8(5) of the DPDP Act and Rule 8 of the SPDI Rules, we implement reasonable security safeguards, including:
- encryption of traffic in transit using HTTPS/TLS across the whole site;
- storage of passwords using one-way cryptographic hashing;
- role-based access control, so that staff access is limited to what their role requires;
- a limit on simultaneously active devices per account, to reduce credential sharing;
- keeping the platform and its components updated, and taking regular backups.
No method of transmission or storage over the internet is completely secure. While we take the measures described above, we cannot guarantee absolute security.
8. Data breach
In the event of a personal data breach, we will notify the affected Data Principals and the Data Protection Board of India in the manner and within the timelines required under Section 8(6) of the DPDP Act and the rules made thereunder.
9. Your rights
Subject to the conditions in the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you and the recipients with whom it has been shared (Section 11);
- Correction, completion, updating and erasure of your personal data (Section 12);
- Grievance redressal — a readily available means of raising a grievance with us (Section 13);
- Nomination — nominate another individual to exercise your rights in the event of your death or incapacity (Section 14);
- Withdraw consent at any time (Section 6(4)). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide the paid services.
To exercise any right, write to our Grievance Officer using the details in Section 12. You may be asked to verify your identity before we act on a request.
Under Section 15 of the DPDP Act you are also required, among other duties, not to furnish false particulars or impersonate another person while providing your personal data.
10. Children
Our courses are intended for persons who are 18 years of age or older. Where we knowingly process the personal data of a child (a person below 18 years), we will do so only with verifiable consent of a parent or lawful guardian, as required by Section 9 of the DPDP Act. We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. If you believe a child has registered without such consent, please contact us and we will delete the account and associated data.
11. Changes to this Policy
We may update this Policy from time to time. The revised version will be posted on this page with a new “Last updated” date. Where a change materially affects how we use your personal data, we will take reasonable steps to notify you.
12. Grievance Officer and contact
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Rule 5(9) of the SPDI Rules and Section 13 of the DPDP Act, the Grievance Officer is:
Designation: Grievance Officer, Law Tutorial
Address: 2-103, Kannanvilai, Karungal PO, Kanyakumari District, Tamil Nadu, PIN 629157
Email: in**@*********al.in
Telephone: +91 94880 27801
Hours: Monday to Friday, 10:00 to 18:00 IST (except public holidays)
We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt, as required by Rule 3(2)(a) of the 2021 Rules.
If you are not satisfied with our response, you may approach the Data Protection Board of India constituted under the DPDP Act.
