Privacy Policy
Last updated: 20 September 2026
This Privacy Policy explains how Eshrah ("we", "us") collects, uses, shares, and protects personal data when you use our website and services.
1. Information we collect
- Account information: name, email address, password (hashed), and role (client or lawyer).
- Profile information: for lawyers — practice areas, biography, qualifications, availability.
- Consultation data: matter type, scheduled date/time, your written notes, and any documents you upload.
- Communications: messages you send through the platform and support enquiries.
- Technical data: IP address, device identifiers, browser type, and usage/telemetry data.
- Cookies: essential cookies for authentication and session management.
Payment card details are collected and processed directly by Stripe and are not stored on our systems.
2. How we use your information
- To create and manage your account and provide the Service.
- To match clients with verified lawyers and facilitate video consultations.
- To process bookings and pass relevant order data to Stripe for payment.
- To provide customer support and respond to your enquiries.
- To prevent fraud, abuse, and security incidents.
- To improve and develop the Service.
- To comply with legal obligations.
3. Legal bases for processing
We process your personal information on the following bases: performance of our contract with you, our legitimate interests (improving the Service, fraud prevention), your consent (where required), and compliance with legal obligations.
4. How we share your information
- Lawyers on the platform: when you book a consultation, the assigned lawyer receives your matter details, notes, and uploaded documents.
- Payment processor: we share necessary order and customer data with our payment provider to process payments, prevent fraud, and issue refunds.
- Service providers / subprocessors: hosting, database, video infrastructure, email, and analytics providers acting on our instructions.
- Professional advisers: legal, accounting, and insurance advisers.
- Authorities: where required by law, court order, or to protect rights and safety.
5. International transfers
Some service providers may process data outside the UAE. We use appropriate contractual, organisational, and technical safeguards for international transfers as required by applicable law.
6. Data retention
We retain personal information for as long as your account is active and for a reasonable period afterwards to comply with legal, accounting, and dispute-resolution obligations. Consultation records and documents may be retained for longer periods where required by professional or regulatory rules. When no longer needed, data is deleted or anonymised.
7. Your rights
Subject to applicable UAE data-protection law, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion or restriction of processing.
- Object to processing or withdraw consent.
- Request portability of your data.
- Lodge a complaint with the competent UAE data-protection authority.
To exercise any of these rights, contact us at privacy@eshrah.ai.
8. Security
We implement appropriate technical and organisational measures to protect your personal information, including encryption in transit (TLS), encryption at rest, role-based access controls, audit logging, secure authentication, and regular backups. Access to client matter data is restricted to the assigned lawyer and authorised platform staff on a need-to-know basis. No system is perfectly secure, but we work continuously to safeguard your data and respond to incidents promptly.
9. UAE data-protection compliance
We process personal data in accordance with applicable UAE data-protection requirements, including the UAE Personal Data Protection Law. DIFC or ADGM data-protection rules may apply where the relevant processing is established in those jurisdictions.
Our data-protection commitments include:
- Transparent collection and processing for specified, lawful purposes.
- Data minimisation, accuracy, and appropriate retention periods.
- Security controls appropriate to confidential legal information.
- Appropriate safeguards for cross-border processing.
- Processes for lawful access, correction, deletion, restriction, and portability requests.
If a personal-data breach triggers notification duties under applicable UAE law, we will notify the competent authority and affected individuals as required.
10. Security standards
We apply security controls appropriate to confidential remote legal consultations. In practice this means:
- End-to-end encrypted video infrastructure for consultations.
- Authenticated, role-based access — only the client and assigned lawyer can join a consultation room or view its records.
- Secure document upload and storage, with access tied to the specific matter.
- Network and application security controls, including TLS, hardened authentication, and monitoring for unusual activity.
- Privacy-by-design review of new features that handle sensitive information.
- Vendor due diligence on subprocessors that support video, storage, and payments.
11. Cookies
We use essential cookies required for authentication and session management. We do not use advertising cookies. You can manage cookie preferences in your browser settings; disabling essential cookies may prevent you from signing in.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email.
13. Contact us
Email: privacy@eshrah.ai.