Privacy Policy

Last updated on Jul 22, 2026

GLOBAL PRIVACY POLICY

DVV Lex - Legal Practice Management Software

Effective date: 23 July 2026

Operator: DVV Global Ltd (Company No. 15642444)

Registered office: Suite RA01, 195-197 Wood Street, London, England, E17 3NU

Privacy contact: info@dvvlex.com

Product creator: Vishnu Vardhan Dalavai

 

Important role distinction. DVV Global Ltd is the controller of website, account, billing, support and security data. For personal data that a subscribing law firm or legal organisation uploads to DVV Lex, that customer will normally be the controller and DVV Global Ltd will act as its processor under a data processing agreement.

1. Introduction

DVV Lex is a cloud-based platform for managing legal practices, cases, clients, hearings, evidence, documents, tasks, communications, billing and related workflows. This Global Privacy Policy explains how DVV Global Ltd ("DVV Global", "we", "us" or "our") collects, uses, stores and shares personal data when you visit dvvlex.com, contact us, create an account, buy a subscription or use DVV Lex from the United Kingdom or another country.

DVV Lex was created by Vishnu Vardhan Dalavai and is operated by DVV Global Ltd, an active private limited company registered in England and Wales under company number 15642444. DVV Global Ltd is the relevant legal entity for this policy.

This policy is intended to provide a global baseline. Where a mandatory privacy law gives an individual greater protection or additional rights, we will apply that law to the extent it governs our processing. Country-specific operational steps, registrations, representatives, contractual clauses or notices may still be required before DVV Lex is actively offered in a new jurisdiction.

2. Scope and data-protection roles

2.1 When DVV Global Ltd is the controller

We act as controller where we decide why and how personal data is used, including data relating to website visitors, prospective customers, account owners, authorised users, billing contacts, support contacts, marketing recipients and platform security.

2.2 When DVV Global Ltd is a processor

Customers may upload or create information about their own clients, counterparties, witnesses, employees, advocates, judges, court personnel and other individuals ("Customer Content"). For that Customer Content, the customer normally decides the purposes and means of processing and acts as controller. We process it only on the customer's documented instructions, to provide and secure the service, and in accordance with our data processing agreement.

If your information appears in Customer Content, please normally direct your request first to the law firm or organisation that controls the relevant account. We will assist that customer in responding where required.

2.3 Customer responsibilities

Customers are responsible for ensuring they have a lawful basis and, where required, an additional condition to process and upload personal data, special category data and criminal offence data. Customers must provide appropriate privacy information, respect confidentiality and legal professional privilege, configure access rights properly, and avoid uploading information that is unnecessary for their work.

3. Personal data we may collect

Identity and contact data: name, job title, organisation, postal address, email address, telephone number, signature and account identifiers.

Account and profile data: username, password hashes or authentication credentials, permissions, role, preferences, subscription tier and account status.

Professional and organisation data: law-firm details, practice areas, professional role, staff information, court or advocate relationships and business contact information.

Transaction and billing data: billing address, invoices, tax information, payment status, payment method type, payment tokens and limited card information returned by the payment provider. We do not normally receive or store complete card numbers or card security codes.

Customer Content: case and matter records, client details, hearing information, evidence, documents, notes, communications, tasks, tags, feedback, billing records and other information entered by users. This may contain confidential information, special category data or criminal offence data.

Support and communication data: messages, requests, call or meeting notes, troubleshooting records, feedback and any files supplied to support.

Technical and usage data: IP address, browser, device, operating system, login history, timestamps, audit logs, feature usage, error reports, approximate location derived from IP address and security events.

Marketing and cookie data: marketing preferences, campaign interactions and data collected through cookies or similar technologies, subject to your choices.

Fraud and verification data: payment risk signals, chargeback information, identity or authority checks, device and network indicators, and records relating to suspected misuse.

4. How we obtain personal data

Directly from you when you register, subscribe, contact us, request a demonstration, use the platform or communicate with support.

From the customer organisation that creates or manages your user account.

Automatically from your device and use of our website or service, including through essential logs and permitted cookies.

From payment providers, identity or fraud-prevention services, resellers, integration partners and publicly available business sources.

From other users who enter Customer Content into the platform.

5. Why we use personal data and our lawful bases

Provide and administer DVV Lex: to create accounts, authenticate users, provide features, process subscriptions and deliver support. We generally rely on performance of a contract or steps requested before a contract.

Billing and records: to process payments, issue invoices, maintain accounting and tax records, manage renewals and collect sums due. We rely on contract, legal obligations and legitimate interests in operating our business.

Security, audit and fraud prevention: to protect users, detect suspicious activity, prevent unauthorised access, investigate incidents and enforce our terms. We rely on legitimate interests and, where applicable, legal obligations.

Service improvement: to diagnose faults, analyse performance, understand feature use and improve DVV Lex. We rely on legitimate interests using proportionate or aggregated data, and consent where non-essential cookies require it.

Communications and marketing: to send service notices and respond to enquiries, and to send permitted business marketing. We rely on contract or legitimate interests for service messages, and consent or another lawful route permitted by applicable electronic-marketing rules for marketing.

Legal and regulatory purposes: to establish, exercise or defend legal claims, comply with lawful requests, protect rights and cooperate with regulators or law enforcement. We rely on legal obligations and legitimate interests.

Where we process special category data for our own controller purposes, we will also identify an applicable condition under Article 9 UK GDPR, such as explicit consent or processing necessary for legal claims. Where criminal offence data is involved, we will process it only where authorised by law. For Customer Content, the customer determines and documents the relevant lawful basis and additional conditions.

6. Cookies and similar technologies

We may use strictly necessary cookies to operate logins, security, load balancing and user preferences. We will not set non-essential analytics, advertising or similar cookies on a user's device unless we have a valid legal basis and, where required, consent. You can manage available choices through our cookie banner or settings. Withdrawing consent does not affect processing that occurred before withdrawal.

A separate Cookie Policy should identify the cookies and similar technologies actually deployed, their providers, purposes and durations. Browser settings may also allow you to block or delete cookies, although essential functions may then be unavailable.

7. How we share personal data

We do not sell personal data. We may share it only where reasonably necessary with:

cloud hosting, storage, backup, email, messaging, customer support, security, analytics and software-integration providers acting under contract;

payment processors, banks, card schemes and fraud-prevention providers;

professional advisers, auditors, insurers and legal representatives subject to confidentiality obligations;

government bodies, regulators, courts, law-enforcement agencies or other recipients where disclosure is required or permitted by law;

a buyer, investor or successor in connection with a proposed or completed corporate transaction, subject to appropriate safeguards; and

other parties where you or the relevant customer has instructed or authorised the disclosure.

For Customer Content, we use subprocessors only as allowed by our data processing agreement. Current subprocessor information may be provided through our website, contractual documentation or on request.

8. International transfers

Some service providers may process personal data outside the United Kingdom. Where UK data-protection law restricts a transfer, we will use an approved safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism. We will carry out required transfer-risk assessments and apply supplementary measures where appropriate. Contact us for further information about relevant safeguards.

9. Retention and deletion

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide the service, comply with legal and accounting obligations, resolve disputes and enforce agreements. The period depends on the type of data, sensitivity, risk, contractual requirements and applicable limitation periods.

Account and subscription data is generally retained while the account is active and afterwards for the period needed for contractual, tax, accounting, security or legal-claims purposes.

Customer Content is retained and deleted in accordance with the customer's contract, account settings and data processing agreement, subject to secure backup cycles and legal preservation requirements.

Security and audit records are retained for a proportionate period based on security and compliance needs.

Marketing records are retained until consent is withdrawn, an objection is made, or the information is no longer needed; suppression records may be kept to honour opt-outs.

When data is no longer required, we will delete or anonymise it, unless a legal obligation or lawful preservation requirement applies. Customers should export required information before account closure and follow the termination process in their agreement.

10. Security and confidentiality

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include encryption in transit, access controls, authentication, logging, backups, vulnerability management, staff confidentiality requirements and incident-response processes.

No online service can be guaranteed completely secure. Customers must use strong credentials, protect authentication factors, assign least-privilege access, keep devices secure, remove former users promptly and notify us without undue delay of suspected compromise.

Where we act as processor, we will notify and assist the relevant customer regarding qualifying personal-data breaches as required by the data processing agreement and applicable law.

11. Payment information and fraud prevention

Payments are handled by the payment provider made available at checkout. That provider may act as an independent controller for parts of its processing and will apply its own privacy notice. We may receive transaction identifiers, payment status, risk signals, limited card details and chargeback information, but we do not normally store complete payment-card details.

We and our payment partners may use automated risk indicators to identify suspicious transactions. We may request further verification, delay activation, refuse a payment, suspend an account or investigate suspected fraud. We do not make solely automated decisions producing legal or similarly significant effects unless we have a lawful basis and provide any notices and safeguards required by law.

12. Marketing communications

You may opt out of marketing at any time by using the unsubscribe method in a message or contacting info@dvvlex.com. Opting out of marketing does not stop essential service, security, billing or account communications. We may keep a minimal suppression record so that we respect your choice.

13. Your data-protection rights

Depending on the circumstances, UK data-protection law may give you the right to:

be informed about how your personal data is used;

request access to and a copy of your personal data;

request correction of inaccurate or incomplete data;

request erasure where the legal conditions apply;

request restriction of processing;

object to processing based on legitimate interests and object at any time to direct marketing;

receive certain data in a structured, commonly used and machine-readable format and transmit it to another organisation;

withdraw consent at any time where processing relies on consent; and

seek safeguards in relation to certain automated decisions.

Rights are not absolute and exemptions may apply, including where information must be retained for legal claims or where disclosure would adversely affect another person's rights. We may request information to verify identity and authority. We normally respond within one month, subject to any lawful extension.

If the request relates to Customer Content, please contact the relevant law firm or organisation first. You can contact us about controller data at info@dvvlex.com.

14. Additional regional privacy information

The provisions below apply only where the relevant law covers DVV Global Ltd or the processing in question. They supplement, and do not reduce, the rights described elsewhere in this policy.

14.1 United Kingdom, EEA and Switzerland

Individuals may have rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and safeguards concerning certain automated decisions. Individuals may complain to the ICO in the UK or to the competent supervisory authority in their country. Where EU, EEA or Swiss law requires us to appoint a local representative, we will publish the representative's details before the relevant processing begins. International transfers will use a recognised adequacy decision, approved contractual clauses or another permitted mechanism.

14.2 United States, including California

Where a US state privacy law applies, residents may have rights to confirm processing, know or access information, obtain a portable copy, correct inaccuracies, delete information, opt out of certain sales, targeted advertising, sharing or profiling, limit certain uses of sensitive information, and appeal a refusal. We will not discriminate unlawfully against a person for exercising a privacy right. An authorised agent may submit a request where permitted, subject to verification of identity and authority.

The categories of personal information collected, sources, purposes, recipients and retention criteria are described in Sections 3 to 9. We do not sell personal information for money. We also do not share personal information for cross-context behavioural advertising as those terms are defined by the California Consumer Privacy Act, unless a future notice expressly states otherwise and required opt-out mechanisms are provided. If a covered activity is introduced, we will honour legally recognised opt-out preference signals, such as Global Privacy Control, where required.

14.3 Canada

Where Canadian private-sector privacy law applies, we will handle personal information for identified and appropriate purposes, obtain meaningful consent where required, use proportionate safeguards, and provide access and correction rights subject to lawful exceptions. Complaints may be made to us first and then, where applicable, to the Office of the Privacy Commissioner of Canada or the relevant provincial regulator.

14.4 Australia and New Zealand

Where Australian or New Zealand privacy law applies, individuals may request access to or correction of personal information and may complain about our handling of it. We will take reasonable steps concerning data quality, security, transparency and overseas disclosures. Eligible complaints may be escalated to the Office of the Australian Information Commissioner or the Office of the Privacy Commissioner in New Zealand, as applicable.

14.5 India

Where India's Digital Personal Data Protection Act 2023 and its rules apply and the relevant provisions are in force, data principals may exercise applicable rights to information, correction, completion, updating, erasure, grievance redressal and nomination, and may withdraw consent where processing relies on consent. We will provide any locally required contact, notice, consent and grievance process before offering covered services in India.

14.6 Brazil and Latin America

Where Brazil's LGPD or another applicable Latin American privacy law applies, individuals may have rights to confirmation, access, correction, anonymisation, blocking or deletion, portability, information about sharing and consent, objection, and review of certain automated decisions. Requests and complaints may be made to us and, where applicable, to the competent national authority, including Brazil's ANPD.

14.7 Other jurisdictions

Residents of other jurisdictions, including countries in Asia, Africa and the Middle East, may have additional rights under local law. We will recognise applicable mandatory rights and complaint routes. Before launching targeted services in a new jurisdiction, we will assess local privacy, cybersecurity, data-localisation, electronic-marketing, consumer and professional-confidentiality requirements.

15. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, through ico.org.uk or by using the contact details published there. If you are outside the UK, you may also have the right to contact your local data-protection authority.

16. Children

DVV Lex is a professional business service and is not directed to children. Individuals under 18 must not create an account or purchase a plan. Customer Content may concern children where relevant to a lawful legal matter; in that case, the customer is responsible for ensuring lawful, fair and appropriately protected processing.

17. Third-party links and integrations

DVV Lex may link to or integrate with third-party services. Their processing is governed by their own terms and privacy information unless they act solely as our contracted processor. Customers should review and configure integrations carefully before enabling them.

18. Changes to this policy

We may update this policy to reflect changes in the service, law, regulation or our processing. We will publish the revised version and update the effective date. Where a change is material, we will provide additional notice where reasonably practicable or legally required.

19. Contact us

Data controller: DVV Global Ltd, Company No. 15642444.

Registered office: Suite RA01, 195-197 Wood Street, London, England, E17 3NU.

Email: info@dvvlex.com.

Service: DVV Lex, available through dvvlex.com.

 

DVV Global Ltd | Company No. 15642444 | Page

DVV LEX | GLOBAL PRIVACY POLICY

PAYMENT, FRAUD AND REFUND TERMS

Separate commercial terms for DVV Lex subscriptions

Legal position. These payment terms are separate from the Privacy Policy. Nothing in them excludes or limits rights or remedies that cannot lawfully be excluded, including any mandatory consumer rights that apply.

1. Business service and authority

DVV Lex is intended primarily for law firms, legal professionals, advocates, in-house legal teams and other organisations acting for business or professional purposes. The person creating an account or purchasing a plan confirms that they are at least 18 and have authority to bind the relevant customer organisation.

2. Prices, taxes and subscriptions

Prices, billing intervals, included features and applicable taxes are shown at checkout or in the order form. By purchasing a recurring plan, the customer authorises us and our payment provider to collect the displayed charges on each renewal date until the plan is cancelled in accordance with the account process or agreement. Cancellation normally stops future renewal and does not retrospectively cancel the current paid term.

3. Authorised payment methods

The purchaser must use only a payment method they are legally authorised to use and must provide complete and accurate billing information. Using a stolen, misappropriated, unauthorised or fraudulently obtained card or payment credential is strictly prohibited.

4. Suspected stolen-card or fraudulent purchases

If we or a payment partner reasonably suspect fraud or unauthorised use, we may, to the extent permitted by law:

decline, delay or reverse the transaction;

withhold activation or suspend or terminate the relevant account and access to Customer Content;

request identity, business or payment-authority evidence;

preserve relevant records and share them with payment providers, banks, card schemes, regulators or law-enforcement agencies where lawful;

recover chargeback fees, investigation costs and losses from the person or organisation responsible, where legally recoverable; and

take other reasonable steps to protect DVV Lex, customers and payment-card holders.

DVV Global Ltd is not responsible for a purchaser's unauthorised or criminal use of another person's payment method, except to the extent loss results from our own breach of law, negligence or other liability that cannot lawfully be excluded. A genuine cardholder who believes their card was used without permission should contact their bank or card issuer immediately and may also email info@dvvlex.com. Access linked to a disputed transaction may be suspended while the matter is investigated.

5. Refund policy

Except where required by law or expressly stated in an order form, subscription and plan fees are non-refundable once the plan has been purchased and access has been activated. We do not normally provide refunds or credits for non-use, partial use, user error, failure to cancel before renewal, cancellation during a paid term, unused users or features, or a decision to downgrade.

This rule does not affect any mandatory right to a refund, repair, repeat performance, price reduction or cancellation that applies where the service is faulty, not provided with reasonable care and skill, materially misdescribed, not supplied, or where another non-excludable legal right applies. If a statutory cooling-off right applies and the customer expressly requests immediate service during that period, a proportionate charge may be payable for service supplied before cancellation, as permitted by law.

Any goodwill refund is discretionary, does not create an ongoing obligation and may be reduced by usage, transaction charges or other amounts where lawful. Approved refunds are returned to the original payment method where practicable.

6. Chargebacks and payment disputes

Before initiating a chargeback, the customer should contact info@dvvlex.com with the account email, invoice reference and reason for the dispute so we can investigate. This does not limit a genuine cardholder's right to report an unauthorised transaction to their issuer. A chargeback does not automatically cancel contractual sums that remain lawfully due. We may suspend access while a payment is reversed or disputed.

7. Failed payments and suspension

If a payment fails or remains overdue, we may retry collection, request an alternative payment method, restrict features, suspend the account or terminate the subscription after any notice required by the agreement or law. Customers remain responsible for exporting required data and paying undisputed amounts due.

8. Service changes and availability

We may improve, update or modify features and may perform maintenance. Any service commitments, support levels, credits or remedies are governed by the applicable order form, subscription terms or service-level agreement. Nothing in these terms guarantees uninterrupted or error-free operation.

9. Liability safeguards

Nothing in these payment terms excludes liability for fraud or fraudulent misrepresentation, death or personal injury caused by negligence, breach of obligations that cannot be excluded under applicable law, or any other liability that it would be unlawful to exclude. Any other exclusions or limits must be set out in the full DVV Lex Terms of Service and assessed in light of the customer's status and applicable law.

10. Governing law

These payment terms are governed by the laws of England and Wales. For business customers, the courts of England and Wales have exclusive jurisdiction, subject to any different written agreement. If mandatory consumer jurisdiction or rights apply, this clause does not remove them.

11. Payment contact

Company: DVV Global Ltd, Company No. 15642444.

Address: Suite RA01, 195-197 Wood Street, London, England, E17 3NU.

Email: info@dvvlex.com.