Legal Requests from Authorities

Effective Date: 9 October 2026
Last Updated: 9 October 2026
Version: 2026-10-09

1. What this policy covers

This policy describes how we respond when a court, a law-enforcement or regulatory authority, or anyone else with legal process asks us for Customer Content or for personal data about the people who use MandateRoom. It supports section 17 of our Terms of Service and the Data Processing Addendum. We are an operator based in India, and we use infrastructure providers based in the United States, so a request can reach us, or reach them, from several countries.

2. One door, and formal requests only

Send legal process to hello@mandateroom.com with "Legal process" in the subject line, and to Delhi NCR, India. We log every request when it arrives. We act on a formal instrument: a court order, a subpoena, a warrant, a notice under a statute, or a direction of a regulator, that identifies the authority, the legal basis, the scope, and the data sought. We do not disclose data in response to a telephone call, a message on a chat application or an email without that authority. Someone who is a party to litigation with a Customer should serve the Customer; a private litigant's subpoena to us about a Customer's Room will be referred to the Customer.

3. What we do with a request

  1. Check it. We check that the authority and the instrument are genuine, that the authority has jurisdiction over us or over the data, and what exactly it asks for.
  2. Redirect it. We are a processor of Customer Content. Where the law allows, we tell the authority to ask the Customer, which controls the data and is best placed to respond.
  3. Tell the Customer. Before we disclose anything about a Customer, we tell the Customer, unless the law forbids it or we have a good-faith belief that notice would endanger a person. If the law forbids notice, we tell the Customer as soon as the prohibition ends.
  4. Challenge it where it is unlawful or overbroad. We ask the authority to narrow a request that is broader than its legal basis, and, where we reasonably believe that a request is unlawful or that it conflicts with the law of another country, we object or seek to have it set aside.
  5. Disclose the minimum. We disclose only what the instrument validly requires, and we prefer to produce information about a Room, such as logs, over its content. We give the Customer a copy of what we disclosed unless the law forbids it.
  6. Record it. We keep a record of each request, our assessment and what we did, and we will summarise requests in a short transparency note once we receive any.

4. Requests from India

We comply with valid directions under Indian law, including orders from Indian courts, production notices from the police and orders under section 69 of the Information Technology Act, 2000, which can require assistance with interception, monitoring and decryption and can bind us to confidentiality. Where an Indian order forbids us to tell a Customer, we will not. We report cyber incidents to the Indian Computer Emergency Response Team (CERT-In) within the time its directions require; such a report describes the incident and does not include Customer Content unless CERT-In specifically requires it.

5. Requests from the United States and from other countries

An order from a court or authority in another country does not bind us in India by itself, and an Indian order does not by itself justify disclosure to a foreign authority. We will deal with a request from outside India by asking for the proper international route where one exists, such as a mutual legal assistance request, unless the order is validly enforceable against us. For personal data of people in the European Union or the United Kingdom, we apply the rule that a foreign authority's order is not on its own a legal basis for a transfer under the GDPR or the UK GDPR. Our US providers are subject to US law and may receive requests directly. We do not control how they respond, and a request to a provider may reach data that we hold there.

6. Emergencies

We may disclose limited information without prior notice where we believe in good faith that there is an imminent risk of death or serious physical harm, and we will record what we disclosed and why.

7. The truth about what we can access

We do not claim that we are unable to read stored data. The person who administers the Service can technically access what we store, and a lawful order can require us to produce it. We restrict that access to the purposes in section 7 of our Terms of Service. We do not give an authority direct access to our systems, we do not build in a means of access, and we do not weaken our security in response to a request.

8. Costs

Where the law allows, we may recover our reasonable costs of responding to a request that is made because of a Customer's dispute or transaction.

9. Questions

Write to hello@mandateroom.com. This policy applies from the date at the top of this page and we update it as the law changes.