Policies
The governance, privacy, security, and AI policies LegalMind operates under. Each opens as a PDF and can be downloaded or linked directly.
Privacy & data
- Data Protection & Privacy Policy — How personal data is classified, masked, retained, and disposed of, and the confidentiality and threat-intelligence commitments that sit around it. (PDF)
- Cookie Management Policy — Categories of cookies used, their purpose, and how consent is captured and honoured. (PDF)
- Compliance & Regulatory Policy — The regulatory obligations we operate under, including the DPDP Act 2023 and GDPR, and how compliance is monitored. (PDF)
AI
- AI Policy — Principles governing how AI is built into the product and the boundaries placed on its use. (PDF)
- AI Model Governance Policy — Model selection, evaluation, monitoring, and the controls applied across a model’s lifecycle. (PDF)
Security
- Acceptable Usage Policy — Permitted and prohibited use of systems, networks, and information assets. (PDF)
- Access Management Policy — How access is granted, reviewed, and revoked across systems, on least-privilege principles. (PDF)
- Password Policy — Credential strength, rotation, storage, and multi-factor requirements. (PDF)
- Cloud Security Policy — Controls applied to cloud infrastructure, configuration, and shared-responsibility boundaries. (PDF)
- Website Security Policy — Protections applied to public web surfaces, including hardening and monitoring. (PDF)
- Incident Response & Breach Notification Policy — How security incidents are detected, triaged, and escalated, and when affected parties are notified. (PDF)
Operations
- Backup & Recovery Policy — Backup scope and frequency, restoration testing, and recovery objectives. (PDF)
- Business Continuity Policy — Continuity planning for disruption, including roles, dependencies, and resumption priorities. (PDF)
- Risk Management Policy — How risks are identified, assessed, treated, and reviewed. (PDF)