Privacy

What we hold, and what we will not do with it.

Wakalat carries privileged legal material. This policy sets out exactly what is collected, how matter data and documents are protected, what happens to a question you ask the AI assistant, and how to have your information removed.

Effective 31 July 2026 · Applies to wakalat.app, the Wakalat mobile apps, and the AI legal assistant.

In short
  • Matter workspaces, messages and vault documents are privileged. They are matter-scoped, encrypted, and unreachable by anyone who is not a party to that matter.
  • Documents are only ever served through short-lived signed links issued after an authorisation check — never a public bucket URL.
  • Your AI assistant question is sent to an external inference provider to generate the answer. No identity, session or account field is ever attached to it.
  • We never sell your data, and we never use privileged matter content for advertising or to train models.
  • You can view and delete your assistant history, request deletion of a vault document, and close your account.
  • Every privileged and administrative action is written to an append-only audit log.

This summary is for orientation only. The numbered sections below are the operative terms.

01

Who we are and what this covers

Wakalat is a technology platform that helps people in Pakistan find verified advocates and law firms, and gives lawyers and their clients a private workspace to run a matter. Wakalat is not a law firm, does not provide legal advice, and is not a party to the relationship between you and any advocate you engage.

This policy covers the Wakalat website, the Wakalat mobile applications, and the AI legal assistant. It explains what we collect, why, who it is shared with, how long it is kept, and what you can ask us to do about it.

We are building to the Prevention of Electronic Crimes Act 2016 and to Pakistan's pending personal data protection legislation: consent is captured explicitly, retention periods are defined, and deletion requests are honoured.

02

What we collect

Account and identity

  • Your name, email address and phone number, and the password or sign-in credentials held by our authentication layer.
  • For advocates and firms: your Bar Council enrolment details and supporting documents, and your CNIC, submitted for verification.
  • Two-factor authentication settings for lawyer, firm-administrator and platform-administrator accounts.

Professional profile

  • Practice areas, languages, city and court tier — the last of which is derived from your verified enrolment category, never typed in freely.
  • Your profile photograph, if you upload one. This is stored in a separate public bucket because it is shown on your public profile.
  • Notable reported judgments you have expressly chosen to list, and client reviews published with the reviewer's consent.

Matter and case-room data

  • Consultation requests and intake details you submit to an advocate, including any documents attached.
  • Messages exchanged in a case room, case events, status updates, court orders, hearings and notes.
  • Documents in the vault, including every version, and the engagement agreement and fee milestones recorded against the matter.

AI legal assistant

  • The text of the question you ask, its language, and any filters you applied.
  • The answer returned, its citations, its confidence level, and how the assistant responded — for example whether it answered or declined.
  • If you are signed in, the question is linked to your account. If you are not, it is linked only to a one-way hash of your network address and a browser cookie. There is deliberately no field in our database that can hold a raw IP address for the assistant.

Technical and operational

  • Session records, device push-notification tokens if you enable push on mobile, and your notification preferences.
  • An append-only audit log of privileged and administrative actions, recording who acted, on what, and when.
  • Rate-limiting counters used to keep the assistant and other endpoints available.
03

How we use it

  • To verify advocates and firms before they become publicly discoverable, and to withdraw them if their standing lapses.
  • To operate search and public profiles, using neutral relevance and rotation — ranking is never sold and never presented as a performance leaderboard.
  • To run the case room: delivering messages, documents, hearings, notifications and the fee ledger to the parties to that matter.
  • To send you transactional email, SMS and push notifications you have not turned off, such as hearing reminders and matter updates.
  • To answer questions put to the AI legal assistant from our curated corpus of Pakistani law.
  • To investigate complaints and content flags, and where warranted to escalate a complaint to the relevant Bar Council.
  • To keep the platform secure, prevent abuse, and meet our legal obligations.

We do not sell personal data. We do not use privileged matter content — messages, vault documents, intake details — for advertising, for product analytics, or to train any model.

04

Privileged matter data

Matter workspaces, in-room messages and vault documents are treated as privileged, and that treatment is built into the system rather than promised in prose.

  • All such data is encrypted in transit and at rest.
  • Access is strictly matter-scoped and isolated per firm. An advocate at the same firm who is not a party to your matter cannot reach it.
  • Every server action re-checks your permission against your session — the interface only reflects what you may do, it never grants it.
  • Documents are served only through short-lived signed links issued after an authorisation check. There are no raw or guessable storage URLs.
  • Every privileged or administrative action is written to an append-only audit log with the actor's identity and a timestamp.
05

The AI legal assistant and your questions

The assistant answers only from a curated corpus of Pakistani legal material and always cites what it relied on. At launch that corpus is statutes only; case law is not yet included. It gives legal information, never legal advice.

What leaves our systems

To generate an answer, your question and the retrieved legal text are sent to an external inference provider. Two rules govern that call and are enforced in one place in our code so they cannot be bypassed:

  • No identity, session or authentication field may be included in what is sent. The provider receives your question and the legal passages — not who you are.
  • Request and response bodies are never written to our application logs, because they contain what you typed.

The provider's identity, its processing location and its retention terms are published on the assistant's coverage page before the assistant is opened to the public.

What we keep

We store your question and the answer so that a later complaint can be investigated against what was actually shown to you. If you are signed in, you can view this history and delete it at any time from the assistant.

Please do not paste privileged material, another person's confidential information, or documents from an ongoing matter into the assistant. It is a general legal-information tool, not part of your case room. Use the case room for anything confidential.

06

Who we share data with

We share data with the service providers needed to run the platform, each limited to what its function requires:

  • Cloud database and hosting providers, for the application and its records.
  • An object-storage provider, for vault documents in a private bucket and profile photographs in a separate public bucket.
  • An email provider for transactional email, and an SMS provider for phone verification and alerts.
  • A realtime messaging provider that delivers live case-room updates to authorised participants only, after the same access check that governs the underlying data.
  • Mobile push-notification services, if you enable push.
  • An external inference provider, for AI assistant answers, on the terms in section 5.

Some of these providers process data outside Pakistan. Where that is the case we rely on the provider's contractual data-protection commitments.

Beyond providers, we disclose data in three situations: to the relevant Bar Council where a complaint is escalated, and only what that complaint requires; to a court or authority where we are legally compelled; and to the parties to your matter, who can see the matter's own content by design.

07

Retention and deletion

  • Assistant history: deletable by you at any time from the assistant.
  • Vault documents: the client of a matter can request deletion of a document. The matter's assigned lawyer resolves that request, and both the request and its resolution are recorded in the document's access log.
  • Verification records: decisions to approve, reject or suspend — with the reviewer's identity, timestamp and reason — are kept permanently. They are the basis on which a profile is trusted.
  • Audit logs: append-only and retained. They exist precisely so that access to privileged data can be reconstructed after the fact.
  • Matter records: retained while the matter is active and afterwards for the period the parties may need them, subject to any professional retention obligation that applies to your advocate.
  • Account closure: on request we close your account and remove your public profile from search. Records we are required to keep — audit entries, verification decisions, and material under an open complaint — are retained.

To request account closure or deletion of specific data, write to the address at the foot of this page.

08

Your choices and rights

  • Access and correction: you can view and edit your profile and account details at any time.
  • Consent: a client review is published only with the reviewer's consent, and a notable judgment appears on your profile only because you chose to list it. Both can be withdrawn.
  • Notifications: you control which notifications you receive, and by which channel, from your notification preferences. We will still send you essential account and security messages.
  • Discoverability: an advocate can ask for their public profile to be withdrawn from search.
  • Deletion: as set out in section 7.
09

Security

Encryption in transit and at rest; server-enforced role-based access control checked on every request; two-factor authentication for lawyer, firm-administrator and platform-administrator accounts; per-firm tenant isolation; signed, expiring document links; and an append-only audit trail.

No system is perfectly secure. If you believe an account or a matter has been accessed improperly, contact us immediately and we will investigate against the audit log.

10

Cookies

We use cookies that are necessary for the service: a session cookie to keep you signed in, a preference cookie for your language choice, and — for visitors who use the assistant without signing in — an identifier cookie that is combined with your network address and hashed, so that rate limits can be applied without us storing who you are.

We do not run third-party advertising or cross-site tracking cookies.

11

Children

Wakalat is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will remove it.

12

Changes to this policy

If we change this policy we will update the effective date above. Where a change materially affects how your data is handled, we will tell you in the product or by email before it takes effect.

Questions about this document? Write to info@wakalat.app.

Privacy Policy | Wakalat