Privacy Policy

Effective Date: 9th of June, 2026
Last Updated: 1st of July, 2026
Welcome to The Law School Hub (“Company,” “we,” “our,” or “us”), operator of the website thelawschoolhub.com and its related educational content and services (collectively, the “Services”). Your privacy matters to us, and we are committed to handling your personal data lawfully, fairly, and transparently.
This Privacy Policy explains what information we collect when you visit our website, read our content, subscribe to our newsletters, submit forms or comments, request consultations, or otherwise communicate with us — and the choices and rights available to you. By accessing or using the Services, you acknowledge that you have read and understood this Policy. Where the law requires your consent, we will ask for it before processing your personal data.
Table of Contents
§ 1 Introduction & Scope
This Policy applies to personal data we process about visitors, readers, subscribers, and users of the Services, whether you access them from India, the European Economic Area (EEA), the United Kingdom, the United States, or elsewhere.
It does not apply to third-party websites, platforms, or services that we do not own or control, even where we link to them. When you leave our Services, other organisations’ privacy practices govern your data (see Section 21 — Third-Party Links).
For the purposes of applicable data protection law, The Law School Hub acts as the “Data Fiduciary” (under India’s DPDP Act, 2023) and the “data controller” (under the GDPR and UK GDPR) that determines the purposes and means of processing your personal data. Our contact details are set out in Section 23.
§ 2 Key Definitions
To keep this Policy clear across jurisdictions, the following terms have the meanings below. Terms not defined here carry the meaning given to them under applicable law.
- Personal Data / Personal Information — any information relating to an identified or identifiable individual (for example, your name, email address, IP address, or online identifiers).
- Data Principal (India) / Data Subject (EEA & UK) / Consumer (California) — the individual to whom the personal data relates. In this Policy we address you as the person whose data we handle.
- Data Fiduciary / Controller — the entity that determines why and how personal data is processed (here, The Law School Hub).
- Data Processor — a third party that processes personal data on our behalf and under our instructions (for example, our hosting or analytics providers).
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Sensitive Personal Data — categories requiring heightened protection under certain laws (for example, financial information, health data, or precise geolocation). We do not intentionally collect sensitive personal data through the Services.
- Consent — a free, specific, informed, and unambiguous indication of your wishes by which you agree to the processing of your personal data.
§ 3 Information We Collect
We collect the categories of information described below. We practise data minimisation — collecting only what is reasonably necessary for the purposes set out in this Policy.
A. Information you provide to us
Information you voluntarily give us, for example when you fill out a form, post a comment, subscribe to a newsletter, or request a consultation or enquiry:
- Full name;
- Email address and phone number;
- Educational institution and course details;
- Professional information you choose to share;
- The content of forms, comments, messages, and enquiries you submit.
B. Information collected automatically
When you visit our website, we and our service providers may automatically collect technical and usage information:
- IP address and approximate (city/country-level) location derived from it;
- Browser type, device information, and operating system;
- Referring URLs, date and time of visit, and pages viewed;
- Session duration and clickstream / interaction data.
C. Cookies and similar technologies
We use cookies, web beacons, pixels, and analytics technologies (including session and persistent cookies) to operate the website, remember your preferences, measure performance, and — where you consent — support advertising. Full details are in Section 6 — Cookies & Tracking.
| Category of data | Examples | Source |
| Identity & contact | Name, email, phone, institution | You |
| Educational / professional | Course, institution, professional details | You |
| User-generated content | Comments, form and enquiry content | You |
| Technical & device | IP address, browser, OS, device identifiers | Automatic |
| Usage & analytics | Pages, session duration, clickstream, referrers | Automatic |
| Cookies & identifiers | Cookie IDs, pixels, advertising identifiers | Automatic / third parties |
| Marketing preferences | Subscription status, communication choices | You / automatic |
We do not knowingly collect government identifiers, payment card numbers, passwords for other services, or special-category / sensitive data through the Services.
§ 4 How We Collect Information
We obtain personal data through three principal routes:
- Directly from you — when you register, subscribe, comment, complete a form, request a consultation, or contact us.
- Automatically — through cookies and similar technologies as you interact with the website (see Sections 3 and 6).
- From third parties — for example, analytics and advertising providers, or platforms you use to reach us (such as social media). Where we receive data from third parties, we rely on those parties to have collected it lawfully.
§ 5 Purposes & Legal Bases for Processing
We process your personal data only where we have a lawful basis to do so. The table below maps each purpose to the legal basis we rely on under the GDPR/UK GDPR and the ground we rely on under India’s DPDP Act, 2023.
| Purpose | Data used | Basis (GDPR / UK GDPR) | Ground (DPDP Act) |
| Operate & maintain the Services | Technical, usage | Legitimate interests | Legitimate use / consent |
| Respond to enquiries & consultations | Identity, content | Consent / contract | Consent (voluntarily provided) |
| Deliver educational content & newsletters | Identity, marketing | Consent | Consent |
| Analyse traffic & improve the Services | Usage, cookies | Consent / legitimate interests | Consent |
| Personalise your experience | Usage, preferences | Consent / legitimate interests | Consent |
| Advertising & measurement | Cookies, identifiers | Consent | Consent |
| Security & fraud prevention | Technical, usage | Legitimate interests / legal obligation | Legitimate use / legal obligation |
| Comply with law & enforce terms | As necessary | Legal obligation / legitimate interests | Legal obligation |
| A note on consent under the DPDP Act Unlike the GDPR, India’s DPDP Act, 2023 relies primarily on consent, together with a limited set of “certain legitimate uses” under Section 7. Where we rely on your consent, you may withdraw it at any time; withdrawal will not affect processing carried out before withdrawal, and may limit your ability to use certain features. |
§ 6 Cookies & Tracking Technologies
Cookies are small text files stored on your device. We use them, along with pixels and similar technologies, for the purposes described below. Where required by law (for example, in the EEA and UK), non-essential cookies are set only after you provide consent through our cookie banner, and you can change your choices at any time.
| Type | Examples / provider | Purpose | Typical duration |
| Strictly necessary | Session & security cookies | Enable core functions and keep the site secure | Session |
| Preference / functional | Language, display settings | Remember your choices and preferences | Up to 12 months |
| Analytics | Google Analytics (_ga, _gid) | Understand how the site is used so we can improve it | _ga: up to 24 months; _gid: 24 hours |
| Advertising | Google AdSense / ad partners | Serve and measure ads and limit repetition | Up to 13–24 months |
The specific cookies and providers above are examples and may change over time. You can control cookies through your browser settings (including blocking or deleting them), and manage advertising preferences via Google Ads Settings. Blocking some cookies may affect how the website functions.
§ 7 How We Share & Disclose Information
| We do not sell your personal information. We do not sell your personal data for monetary or other valuable consideration, and we do not disclose it to third parties for their own independent marketing without your consent. |
We may share personal data in the following limited circumstances:
a. Service providers (processors)
Trusted third parties who process data on our behalf and under contract, to help us with website hosting, email delivery, analytics, security monitoring, and marketing services. They are permitted to use your data only to provide services to us.
b. Legal & regulatory requirements
Where we are required or permitted to do so — for example, to comply with a law, court order, or lawful request from a government or regulatory authority, or to establish, exercise, or defend legal claims.
c. Business transfers
In connection with a merger, acquisition, corporate restructuring, financing, or sale of assets, your data may be transferred as part of that transaction, subject to appropriate confidentiality and protection.
§ 8 Third-Party Services & Advertising
We may use third-party services that collect information via cookies and similar technologies, including:
- Google Analytics — to measure and analyse website traffic and usage;
- Google Search Console — to monitor and improve our presence in search results;
- Google Ads & Google AdSense — to display and measure advertising, where applicable.
These providers may use cookies and identifiers to serve advertisements and analyse usage across websites. You can manage ad personalisation through Google’s advertising settings and learn more from Google’s own privacy resources. We do not control, and are not responsible for, the independent data practices of these third parties.
§ 9 International Data Transfers
We operate globally, and your personal data may be processed and stored in countries other than the one in which you live, including countries that may have different data protection standards.
Where we transfer personal data across borders, we take steps to ensure it is protected in line with this Policy and applicable law, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Agreement / Addendum, where relevant);
- Data Processing Agreements with our service providers;
- Adequate technical and organisational security measures; and
- Other lawful transfer mechanisms recognised under applicable law.
Transfers of the personal data of Indian Data Principals are handled in accordance with the DPDP Act, 2023 and any restrictions the Government of India may notify.
§ 10 Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. The indicative periods below are applied on a purpose-by-purpose basis.
| Type of data | Indicative retention period |
| Account / registration data | Duration of your account, plus up to 3 years after closure or inactivity |
| Newsletter & marketing contacts | Until you unsubscribe, plus up to 24 months |
| Comments & user-generated content | Until removed by you or us, or as needed to provide the Services |
| Enquiry / consultation correspondence | Up to 3 years for record-keeping and dispute resolution |
| Analytics & usage data | Typically up to 26 months, then aggregated or anonymised |
| Cookies | As set out in the cookie table (Section 6) |
| Legal & compliance records | As required by applicable law |
When personal data is no longer required, we securely delete, anonymise, or destroy it.
§ 11 Data Security & Breach Notification
We implement reasonable administrative, technical, and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, including:
- SSL/TLS encryption of data in transit;
- Secure hosting environments and firewall protection;
- Access controls and the principle of least privilege;
- Regular software updates and monitoring;
- Data minimisation and, where appropriate, masking or pseudonymisation.
| If a data breach occurs In the event of a personal data breach that is likely to affect you, we will act promptly to contain and remediate it, and we will notify affected individuals and the relevant supervisory authority as required by applicable law — including, under India’s DPDP framework, intimation to affected Data Principals and the Data Protection Board of India, and, under the GDPR/UK GDPR, notification to the competent authority within the applicable timeframe. |
No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.
§ 12 Your Privacy Rights — Overview
Depending on where you live, you may hold some or all of the rights below. We honour these rights for all users to the extent applicable, and we will not discriminate against you for exercising them. Jurisdiction-specific detail follows in Sections 13–16.
| ■ Access Request a copy of the personal data we hold about you. | ■ Correction Ask us to correct inaccurate or incomplete data. |
| ■ Deletion / erasure Request that we delete your personal data, where permitted. | ■ Restriction Ask us to limit how we process your data in certain cases. |
| ■ Portability Receive certain data in a structured, machine-readable format. | ■ Object Object to certain processing, including direct marketing. |
| ■ Withdraw consent Withdraw consent at any time where we rely on it. | ■ Grievance / complaint Raise a concern with us or a supervisory authority. |
To exercise any right, contact us using the details in Section 23. We may need to verify your identity before acting on a request.
§ 13 GDPR & UK GDPR Rights (EEA & United Kingdom)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right of access — to obtain confirmation of processing and a copy of your data;
- Right to rectification — to correct inaccurate or incomplete data;
- Right to erasure (“right to be forgotten”) — in certain circumstances;
- Right to restrict processing;
- Right to data portability;
- Right to object — including to processing based on legitimate interests and to direct marketing;
- Right to withdraw consent — where processing is based on consent;
- Rights relating to automated decision-making — see Section 20.
We aim to respond to requests within one month, extendable by up to two further months for complex requests, as permitted by law.
| Right to lodge a complaint You have the right to complain to your local data protection supervisory authority. In the UK, this is the Information Commissioner’s Office (ico.org.uk). In the EEA, you may contact the authority in your country of residence. We would appreciate the chance to address your concerns first — please contact us using Section 23. |
§ 14 India — Digital Personal Data Protection Act, 2023
The Law School Hub endeavours to comply with applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025, as they come into force in a phased manner, together with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which continue to apply during the transition.
As a Data Principal under the DPDP Act, you have the right to:
- Access a summary of your personal data and the processing we carry out;
- Correct, complete, or update your personal data, and request erasure where permitted;
- Withdraw consent as easily as it was given;
- Grievance redressal through our Grievance Officer (see below); and
- Nominate another individual to exercise your rights in the event of your death or incapacity.
We will respond to Data Principal requests within the timelines prescribed under the DPDP framework — ordinarily within a maximum of 90 days. Where we process personal data on the basis of your consent, we provide a clear, standalone notice describing the data collected, the purpose, and how you may exercise your rights and raise complaints.
| Children’s data (India) Under the DPDP Act, a “child” is anyone under 18 years of age. We do not knowingly process the personal data of children without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. See Section 18. |
You may also escalate unresolved complaints to the Data Protection Board of India, with a further right of appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), in accordance with the DPDP framework.
§ 15 California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), gives you the following rights:
- Right to know — the categories and specific pieces of personal information we collect, the sources, the business purposes for collection, and the categories of third parties with whom we share it;
- Right to delete — request deletion of personal information we collected from you, subject to exceptions;
- Right to correct — request correction of inaccurate personal information;
- Right to opt out of sale or sharing — although we do not sell personal information, you may direct us not to “share” it for cross-context behavioural advertising;
- Right to limit use of sensitive personal information — where applicable;
- Right to non-discrimination — we will not discriminate against you for exercising your rights.
You may submit a request yourself or through an authorised agent. We will verify your request and respond within 45 days, extendable by a further 45 days where reasonably necessary. We honour the Global Privacy Control (GPC) signal as a valid opt-out of sale/sharing where your browser transmits it.
| “Shine the Light” (Cal. Civ. Code § 1798.83) California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. As noted above, we do not share personal information for third parties’ independent direct marketing. |
§ 16 Other U.S. State Privacy Rights
Residents of certain other U.S. states — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others with comprehensive privacy laws — may have rights similar to those described above, such as the rights to access, correct, delete, and obtain a portable copy of their personal data, to opt out of targeted advertising and the sale of personal data, and to appeal a denied request.
To exercise these rights, contact us using Section 23. If we deny your request, you may appeal by replying to our decision; where an appeal is denied, you may contact your state Attorney General.
§ 17 CalOPPA & Do Not Track Signals
a. Do Not Track
Because there is no universally accepted standard for interpreting browser “Do Not Track” (DNT) signals, our website does not currently respond to them. However, we do honour the Global Privacy Control (GPC) signal as described in Section 15.
b. Third-party tracking
Third-party services operating on our website may collect information about your online activities over time and across different websites. We do not control this third-party tracking.
§ 18 Children’s Privacy
Our Services are intended for a general audience and are not directed at children. Age thresholds differ by jurisdiction, and we respect the stricter standard that applies to you:
- United States (COPPA): we do not knowingly collect personal information from children under 13.
- India (DPDP Act): we do not knowingly process the personal data of anyone under 18 without verifiable parental or guardian consent, and we do not direct tracking or targeted advertising at them.
- EEA / UK: we do not knowingly offer information-society services directly to children below the applicable age of digital consent without appropriate consent.
If we learn that we have collected personal data from a child without the required consent, we will promptly delete it. Parents or guardians who believe their child has provided personal data may contact us using Section 23.
§ 19 Email & Marketing Communications
If you subscribe to our newsletters or updates, we may send you legal updates, educational content, announcements, and marketing communications. We send marketing emails in accordance with applicable law, including the CAN-SPAM Act (United States) and equivalent electronic-marketing rules.
You can unsubscribe at any time using the unsubscribe link in any marketing email, or by contacting us. We will still send you essential service-related messages (for example, responses to your enquiries) where necessary.
§ 20 Automated Decision-Making & Profiling
We do not use your personal data to make decisions producing legal or similarly significant effects about you based solely on automated processing, without human involvement. Any analytics-based personalisation we carry out is used to improve content and experience, not to make consequential decisions about you. Where any such processing is introduced, we will update this Policy and provide the disclosures required by law.
§ 21 Third-Party Links
Our website may contain links to third-party websites, resources, and services. We are not responsible for the privacy practices, security, content, or policies of those third parties. We encourage you to review the privacy policies of any website you visit before providing personal data.
§ 22 Your Privacy Choices
You can exercise control over your personal data in the following ways:
- Adjust or disable cookies through your browser settings;
- Manage advertising preferences via Google Ads Settings;
- Unsubscribe from marketing emails at any time;
- Request access to, correction of, or deletion of your personal data;
- Withdraw consent where processing is based on it;
- Enable a Global Privacy Control (GPC) signal in a supported browser.
§ 23 Grievance Redressal & How to Contact Us
For any questions, privacy requests, or concerns about this Policy or your personal data, please contact us. We aim to acknowledge requests within 72 hours and resolve them within the timelines required by applicable law.
| Email: thelawschoolhub@gmail.com Website: thelawschoolhub.com |
In accordance with the Information Technology Act, 2000 and the IT Rules, 2011, our team will address complaints within the period prescribed by law (ordinarily within one month). Under India’s DPDP framework, Data Principal requests will be addressed within a maximum of 90 days. EEA/UK residents may also contact their supervisory authority (see Section 13); California and other U.S. state residents may exercise the rights described in Sections 15–16.
§ 24 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the “Last Updated” date at the top of this page, and material changes will take effect upon posting. We encourage you to review this Policy periodically. Your continued use of the Services after changes are posted constitutes acceptance of the updated Policy.
§ 25 Governing Law & Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of India, without prejudice to any additional rights and protections available to you under the data protection laws of your own country or region. Nothing in this Policy limits the mandatory rights you have under applicable law.
§ 26 Compliance Coverage
This Privacy Policy is designed to align with the following laws and frameworks, as applicable:
India
- Digital Personal Data Protection Act, 2023 (DPDP Act);
- Digital Personal Data Protection Rules, 2025;
- Information Technology Act, 2000;
- Information Technology (Reasonable Security Practices) Rules, 2011.
International, EU, UK & United States
- GDPR (European Union);
- UK GDPR;
- CCPA & CPRA (California);
- CalOPPA (California Online Privacy Protection Act);
- COPPA (Children’s Online Privacy Protection Act);
- ePrivacy Directive (EU Cookie Law);
- CAN-SPAM Act (United States);
- Other U.S. state privacy laws; and general international privacy best practices.
§ 27 Acknowledgement
By using The Law School Hub website and Services, you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree with this Policy, please do not use the Services.