Last updated: 28 September 2026
This notice explains how Kapish Tech handles personal data, and is issued under the Digital Personal Data Protection Act, 2023.
About you: name, email address, mobile number, profession and membership number, and records of your payments.
What you upload: the case documents you put into the service. These routinely contain personal and financial data about your clients — GSTINs, demand figures, notices and orders.
Automatically: log records of access, for security.
When you upload a client's documents, you are the Data Fiduciary for that client's data and we act as a Data Processor on your instructions. You are responsible for having whatever consent or lawful basis is required before you upload it. We process it only to provide the service to you.
Reviewers and team members. Where you add a reviewer — typically your CA or advocate — or a management user, they see the matters you give them access to. You decide who those people are; adding them is your instruction to us to let them in, and removing them is yours to give too.
Expert help. Where you ask for expert help, members of our own team read the documents and drafts on that case in order to prepare the draft you asked for, and for no other purpose. You confirm this each time you ask, and access ends when the draft is delivered. [To be confirmed by counsel.]
To operate your account, read and analyse the documents you upload, prepare drafts you ask for, take payment, and meet our legal obligations. We do not sell personal data, and we do not use your documents to train our own models.
Document contents are sent to Anthropic's Claude API for analysis and drafting. That processing may take place outside India. [Confirm the provider's data-retention terms and record the cross-border transfer basis before launch.]
GstLitigation Fetch is our Chrome extension. It reads the notices and orders on your own signed-in GST portal pages and saves their documents on your own computer, one folder per case. It is optional; the service works without it.
Your GST portal credentials are never seen, stored, filled in or transmitted by the extension. You sign in to the portal yourself, on the portal's own page, including its captcha.
The extension sends nothing to us and nothing to anyone else. It reads no site other than gst.gov.in and this one, holds no account credential of yours, and carries no analytics or tracking of any kind. Documents reach this service only when you choose to upload them.
We keep your account data while the account is open, and case documents until you delete them or close the account. After closure they are erased within a reasonable period, except where a law requires us to keep them.
Under the DPDP Act you may ask for access to your personal data, its correction, its erasure, and you may withdraw consent or nominate another person to exercise your rights. Write to the Grievance Officer named below; we will respond within the period the Act allows.
Access is protected by password and one-time-password login, traffic is encrypted in transit, and case data is separated by account. No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Board as the Act requires.
Shailja Bokadia, support@gstlitigation.com.