Acceptable Use Policy

What may not be done with Lawzer, what we do when it happens, and the due diligence we owe as an intermediary under Indian law.

Contractualv1.0In force from 9 September 2026

Drafted against

  • Information Technology Act, 2000 — sections 2(1)(w), 43, 65, 66, 66E, 67, 69A and 79
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — rules 3(1)(b), 3(1)(d) and 3(2)
  • Bharatiya Nyaya Sanghita, 2023
  • Copyright Act, 1957

1.Who this binds

This policy applies to every User of Lawzer and forms part of the Terms of Service. A Customer is responsible for its Users observing it.

To the extent we receive, store or transmit content on a Customer's behalf, we are an intermediary within the meaning of section 2(1)(w) of the Information Technology Act, 2000. Rule 3(1)(b) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires us to inform Users of what they may not host, display, upload, publish, transmit, store or share. That is what clause 2 does, and the safe harbour in section 79 of the Act depends on our doing it.

2.Content that must not be put into the service

A User must not host, upload, store, transmit or share any information which:

  1. belongs to another person and to which the User has no right;
  2. is obscene, pornographic, paedophilic, or invasive of another's privacy including bodily privacy; is insulting or harassing on the basis of gender; is racially or ethnically objectionable; or relates to or encourages money laundering or gambling;
  3. is harmful to a child;
  4. infringes a patent, trade mark, copyright or other proprietary right;
  5. deceives or misleads the recipient about the origin of the message, or knowingly communicates information which is patently false or misleading, or which is patently false or untrue and written with intent to mislead or harass for financial gain or to cause injury;
  6. impersonates another person;
  7. threatens the unity, integrity, defence, security or sovereignty of India, its friendly relations with foreign states, or public order, or causes incitement to the commission of any cognisable offence, or prevents the investigation of an offence, or is insulting to another nation;
  8. contains a software virus or any computer code, file or programme designed to interrupt, destroy or limit the functionality of any computer resource;
  9. violates any law in force.

3.Conduct that is not allowed

Attacking the service
No unauthorised access attempts, credential stuffing, brute forcing, privilege escalation, injection, denial of service, port scanning, or attempts to read another workspace's data. Section 43 of the IT Act, 2000 makes unauthorised access civilly actionable and section 66 makes it an offence.
Circumventing limits
No evading rate limits, plan entity or user caps, storage quotas or access controls; no sharing one account between people to avoid buying seats.
Reverse engineering
No decompiling, disassembling or deriving the source code, the statutory catalogue or the applicability and due-date logic, except to the extent Indian law permits an act that cannot be contracted out of. Section 65 of the IT Act protects source code specifically.
Scraping and resale
No automated extraction of the statutory catalogue or any part of the interface, and no reselling, sublicensing or providing access to the service as part of your own product, without our written agreement.
Using it as general file storage
The evidence vault is for records that evidence a compliance obligation — acknowledgements, challans, resolutions, minutes, agreements. It is not a media library or a backup drive.
Misrepresenting a professional identity
No entering a membership number of the Institute of Company Secretaries of India or the Institute of Chartered Accountants of India that is not yours, and no holding yourself out in the workspace as a professional you are not. The audit trail is relied on in statutory audit; a false attribution corrupts it.
Interfering with another Customer
No conduct that degrades the service for anyone else, and no probing of another workspace even where you believe you have found a way in. If you find one, clause 6 tells you what to do.

4.What a Customer must do

  • Have a lawful basis for the personal data it puts in its workspace, and give the notice its own Data Fiduciary duties require under section 5 of the Digital Personal Data Protection Act, 2023.
  • Not upload personal data it does not need for a compliance purpose. Aadhaar numbers, in particular, should be redacted to the last four digits before an Aadhaar-bearing document is uploaded as evidence.
  • Keep its own user list current — remove people who have left, and review roles when someone changes job.
  • Not use the service to store the records of an entity it has no mandate for.
  • Tell us promptly of a suspected compromise of its workspace.

5.What we do about a breach

Proportionately, and with reasons.

  1. For most breaches: we write to the Customer's administrators, say what we have seen and ask for it to stop within a stated period.
  2. Where content is unlawful on its face, or we receive a court order or a notification from an authorised government agency, we remove it or disable access within 36 hours, as rule 3(1)(d) of the IT Rules, 2021 requires, and tell the Customer what we removed and why.
  3. Where a complaint concerns material that is obscene, that impersonates a person, or that is an intimate image, we act within 24 hours under rule 3(2)(b).
  4. Where continued access would endanger the service, another Customer or a person, we suspend the individual account or the workspace immediately and explain afterwards.
  5. For a serious or repeated breach we may terminate under clause 11 of the Terms of Service. Fees for the current term are forfeited, and we retain what the law requires us to retain.
  6. We report to the police or to CERT-In where an incident warrants it.

6.Reporting abuse or a vulnerability

Abuse of the service, or content that breaches clause 2: write to contact@lawzer.in. Acknowledged within 24 hours, disposed of within 15 days.

A security vulnerability: the Information Security Policy sets out how to report one and what we undertake in return. In short — tell us privately, do not access data that is not yours, give us reasonable time, and we will not pursue you for a good-faith report.

Read next