Every website and app collecting user data in India must publish a Privacy Policy under DPDPA 2023. Non-compliance attracts penalties up to ₹250 crore. Our lawyers draft custom, publish-ready documents in 2–3 days.
Mandatory legal pages every Indian website and app must publish — not optional, not just "good practice"
Website legal documents are legally binding pages that govern the relationship between your website/app and its users. They disclose how you collect, use, and protect user data; define the rules of using your platform; and limit your liability for content and transactions. In India, these documents are now mandated by multiple laws — the Digital Personal Data Protection Act (DPDPA) 2023, the Information Technology Act 2000, the IT (Reasonable Security Practices) Rules 2011, and the Consumer Protection (E-Commerce) Rules 2020.
Using generic free templates found online is risky — they often do not reflect your actual data practices, may not comply with the latest DPDPA 2023 requirements, and would not hold up if a user or the Data Protection Board (DPB) scrutinises your Privacy Policy. ClearlyComply's lawyers draft custom documents tailored to your specific website type, data practices, and the states/countries you operate in.
Beyond legal compliance, payment processors like Cashfree and Razorpay, and app store platforms like Google Play and Apple App Store, require a published Privacy Policy before they approve your merchant account or app listing. Without proper legal documents, you cannot accept online payments or publish your app.
Multiple regulations now mandate specific disclosures — non-compliance can be costly
Digital Personal Data Protection Act 2023 requires every Data Fiduciary to publish a clear Privacy Notice, obtain valid consent for data processing, and provide mechanisms for data principals to access, correct, or erase their data. Penalty: up to ₹250 crore.
The IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 require websites collecting sensitive personal data to publish a Privacy Policy covering data collection, purpose, disclosure, and retention. Penalty: compensation claims plus criminal liability.
E-commerce entities must display Refund and Cancellation Policy, seller details, grievance officer contact, and estimated delivery timelines. Non-compliance attracts action from the Central Consumer Protection Authority (CCPA).
If your website is accessible to EU/EEA users — even without targeting them — and collects cookies or user data, GDPR applies. Penalties reach EUR 20 million or 4% of global revenue. Our Standard plan includes GDPR-compliant provisions.
Cashfree, Razorpay, PayU, and Stripe all require a published and accessible Privacy Policy and Terms & Conditions before activating your merchant account. App stores (Google, Apple) also mandate a Privacy Policy link before app approval.
Your Terms & Conditions should assert your intellectual property rights over website content, code, graphics, and branding. A properly drafted IP clause deters copying and strengthens your position if infringement occurs.
If your website or app collects any user data — name, email, phone, IP address, or cookies — you need a Privacy Policy
Every document custom-drafted for your specific website by a practising advocate — not a fill-in template
We collect these via a short intake form — no technical knowledge needed, takes 10 minutes
5-step process — from intake form to publish-ready documents in 2–3 business days
After payment, you receive a 10-minute intake questionnaire via email. You share your website URL, business type, data collected, third-party tools used, and geographic user base. No legal or technical knowledge needed.
Our practising advocate visits your website, reviews the intake form, checks for any compliance gaps (e.g., cookies loaded without consent, data collected without disclosure), and identifies which laws apply to your specific situation.
Your Privacy Policy, Terms & Conditions, Cookie Policy, and Disclaimer are drafted specifically for your website — referencing your actual data practices, third-party tools, and business model. No generic templates are used.
Draft documents are sent to you in MS Word and PDF format within 2–3 business days. You may request up to 2 rounds of revisions to ensure the documents accurately reflect your business operations.
Once approved, you receive the final documents in HTML, PDF, and MS Word format — ready to copy-paste onto your website or embed in your app. We also provide a placement guide showing where each document should be linked (footer, signup form, payment page).
Beyond compliance — why every serious business invests in custom legal documents
One-time fee · Custom-drafted by advocates · Unlimited future use on your website
Yes. Under the Digital Personal Data Protection Act (DPDPA) 2023 and the IT (Reasonable Security Practices) Rules 2011, every website or app that collects personal data from Indian users must publish a Privacy Policy. This applies to any website with a contact form, newsletter signup, login, or analytics tracking. Non-compliance can attract penalties up to ₹250 crore under DPDPA 2023. Additionally, payment gateways (Cashfree, Razorpay) and app stores (Google Play, Apple App Store) require a published Privacy Policy before approving your account or listing.
The Digital Personal Data Protection Act (DPDPA) 2023 is India's comprehensive data privacy law enacted in August 2023. It applies to all entities (called "Data Fiduciaries") that process digital personal data of Indian residents. Key obligations include: publishing a clear Privacy Notice explaining what data is collected and why; obtaining explicit consent before processing personal data; providing users the right to access, correct, and erase their data; appointing a Grievance Officer; and notifying the Data Protection Board of any data breach within the prescribed timeframe. Penalties range from ₹10,000 (failure to maintain contact for grievances) to ₹250 crore (failure to implement reasonable security safeguards).
The Basic plan (₹999) includes four custom-drafted documents: (1) Privacy Policy — DPDPA 2023 and IT Act 2000 compliant, covering data collection, purpose, third-party sharing, retention, and user rights; (2) Terms & Conditions — user obligations, IP ownership, liability limitation, governing law, and dispute resolution; (3) Cookie Policy — types of cookies, purpose, duration, and opt-out mechanism; (4) Disclaimer — limiting liability for content accuracy, third-party links, and professional advice. All documents are delivered in MS Word, PDF, and HTML format within 2–3 business days, with 2 rounds of revisions included.
All documents are custom-drafted by practising advocates specifically for your website and business. We start with a detailed intake questionnaire covering your business type, data collected, third-party tools (Google Analytics, WhatsApp, payment gateways, ad networks), payment methods, and geographic user base. The documents accurately reflect your actual data practices — not a generic fill-in-the-blanks template. This is important because generic templates often fail to disclose third-party tools you actually use (e.g., Meta Pixel, Google Analytics 4) — which itself is a DPDPA 2023 violation.
Yes, if your website or app is accessible to EU/EEA users and you collect any data from them — even just through analytics or cookies — GDPR applies to that data. GDPR fines can reach EUR 20 million or 4% of global annual turnover. Many Indian SaaS companies, e-commerce stores, and app developers have EU users without actively targeting them. Our Standard plan (₹4,999) includes GDPR-compliant provisions alongside DPDPA 2023 compliance — covering both Indian and EU legal requirements in one set of documents.
Yes. E-commerce websites in India must comply with the Consumer Protection (E-Commerce) Rules 2020, which require: (1) Refund and Cancellation Policy — clearly stating the conditions and timelines for refunds; (2) Shipping and Delivery Policy — estimated delivery timelines, courier partners, and delivery failure process; (3) Grievance Officer disclosure — name, designation, and contact email of an internal officer who handles consumer complaints within 30 days. These are included in the Standard plan (₹4,999) alongside the core Privacy Policy and Terms & Conditions.
Standard delivery is 2–3 business days after receiving your completed intake form. Priority 24-hour delivery is available in the Standard and Premium plans. Documents are delivered in three formats: MS Word (editable, for future minor updates), PDF (for records and sharing), and HTML (copy-paste ready for your website pages). We also provide a placement guide explaining exactly where each document should be linked on your website — typically in the footer, on the registration/login page, and on the checkout/payment page.
Businesses that got website legal documents also used these services
Privacy Policy + Terms & Conditions + Cookie Policy + Disclaimer
Custom-drafted by advocates · Ready in 2–3 days · ₹999 one-time fee