Legal
Privacy Policy
Last updated: 3 October 2026
This notice is published under the Digital Personal Data Protection Act, 2023, Section 43A of the Information Technology Act, 2000 and Rule 4 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Who we are
PATENT.Deals, available at https://patent.deals, is operated by WIN Legal Advisors, a division of World of Willpower Private Limited (CIN: U86900PN2026PTC251855; GSTIN: 27AAECW3784C1Z7), A1/202, Samruddhi CHS, Kumbhare Park, Kothrud, Pune, Maharashtra, India 411038 (Registered Office). For the purposes of the DPDP Act, we are the Data Fiduciary for the personal data described below. You can reach us at vrushali@winlegaladvisors.com, at care@worldofwillpower.com, or on WhatsApp at +91 8808748088.
2. What we collect and why
- Invention disclosures — the description, technical field and target jurisdictions you type into the screening form. Purpose: to produce the preliminary screening report you asked for. We do not ask for your name, email address or phone number to run a screening, and you should not include personal data in the disclosure.
- Screening reports — the full report is shown in your browser for that session only. To run and improve the service, we keep a short record of each screening that is not linked to your name: the first 240 characters of the disclosure, the technical field, jurisdictions, the screening indicator and verdict, approximate country, and the AI usage and cost. Only our authorised administrator can see these records.
- Account details (optional) — if you create an account, we store your username, name, company name and type, email address and WhatsApp number. Purpose: to manage your account and contact you about your enquiry.
- Anonymous visit statistics — the page viewed, referring website, approximate country/city, device and browser type, and a one-way code that changes daily. No cookies are used and IP addresses are not stored for this. Purpose: understanding how the site is used.
- Legal assistance requests — the contact details and message you send when you write to us or our advocates by email or WhatsApp. Purpose: to respond to your request.
- Technical and security logs — IP address, browser type and timestamps generated when you use the service. Purpose: keeping the service secure, preventing abuse, debugging faults, and meeting the log-retention duty in the CERT-In directions of 28 April 2022.
We do not ask for sensitive personal data such as passwords, financial account credentials, health information or biometric data, and you should not send it to us.
Confidentiality of your invention. An invention disclosure can affect novelty if it becomes public. Submit only what you are comfortable sharing with the processors listed in section 4, and consider speaking to a registered patent agent before disclosing a commercially sensitive invention anywhere.
3. Consent and lawful basis
For screenings and legal-help requests we rely on the free, specific, informed and unambiguous consent you give when you choose to submit the information. Security and fraud-prevention logging is carried out to protect the service and, where applicable, to comply with the CERT-In directions, which is a legal obligation rather than a general "legitimate interest" — Section 7 of the DPDP Act is a closed list of specified uses and we do not claim any broader exemption under it.
You may withdraw consent at any time by writing to vrushali@winlegaladvisors.com. Withdrawal is as easy as giving consent and does not affect processing already carried out.
The DPDP Act, 2023 and the DPDP Rules, 2025 come into force in phases. The Board-related provisions commenced on 13 November 2025; the consent-manager provisions commence on 13 November 2026; and the principal notice, consent, fiduciary-duty and Data Principal rights provisions commence on 13 May 2027. Until a provision is operative, the corresponding statement on this page is our readiness commitment rather than a claim that the duty is already in force.
4. Sharing, processors and independent recipients
We do not sell personal data and we do not share it for advertising. Some parties act only on our instructions under contract (processors); others decide their own purposes and are independent recipients.
- Processor — cloud hosting provider, which runs the website and the screening service.
- Processor — AI model provider (OpenAI), which analyses your invention disclosure to produce the report. Under the provider's API terms, submitted content is not used to train its models; the provider may keep it for a limited period for abuse monitoring.
- Processor — web search and page-retrieval service, used only to look up publicly available patent pages when that feature is switched on.
- Independent recipients — the advocate you ask for help, who owes you separate professional duties of confidentiality.
- Disclosure to a court, a regulator or a lawfully authorised government agency, where the law requires it.
Where a processor operates infrastructure outside India, the transfer is made only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and only under a written contract that requires confidentiality, purpose limitation, security safeguards and deletion or return on termination, as Rule 7 of the SPDI Rules, 2011 requires.
4A. Use of artificial intelligence
Your report is produced by a large language model that reads the invention disclosure you submit. It is an automated, preliminary assessment and not legal advice; it is not a search of any official patent register. We do not use AI to make any decision that produces a legal effect for you, we do not generate synthetic images, audio or video, and we do not offer any tool that creates or alters such media, so the synthetic-content duties in Rule 3(3) of the IT Rules, 2021 (as amended by G.S.R. 120(E) dated 10 February 2026) do not arise on this site. Personal data you enter is not used to train third-party models. The AI features on this site, what data they receive and the limits of their output are described in full on our legal disclaimer page, consistent with the MeitY India AI Governance Guidelines (5 November 2025), which are guidance rather than binding rules.
5. Retention schedule
- Invention disclosures and reports — not stored by us after the report is returned to your browser. The AI provider handles transient copies under its own retention policy.
- Legal opinion and remediation requests — 3 years from closure, so the advocate and we can answer any question about the advice given.
- Security and technical logs — 180 days on systems located in India, as the CERT-In directions of 28 April 2022 require, and then deleted.
6. Your rights as a Data Principal
- Right to access a summary of your personal data and how it is processed (Section 11).
- Right to correction, completion, updating and erasure of your personal data (Section 12).
- Right to grievance redressal through our Grievance Officer (Section 13).
- Right to nominate another individual to exercise your rights in the event of death or incapacity (Section 14).
Write to care@worldofwillpower.com to exercise any right, in English or in Marathi or Hindi if you prefer; we will reply in the language you write in. As our own service commitment we respond within 30 days, and usually much sooner — the DPDP Act does not itself fix a 30-day deadline.
If our answer does not satisfy you, first raise it with our Grievance Officer, whose details and timelines are on the Grievance Officer page. The Data Protection Board of India was established on 13 November 2025. The statutory route for a Data Principal's complaint becomes available in accordance with the phased commencement of the relevant provisions and the Board's prescribed electronic process.
7. Children
The service is not intended for anyone under 18. We do not knowingly process the personal data of children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by Section 9 of the DPDP Act.
8. Security and incident response
We use encryption in transit, access controls, least-privilege credentials kept only on the server, and a documented internal security policy that we review at least once a year. These are reasonable security practices within the meaning of Rule 8 of the SPDI Rules, 2011; we do not claim any certification we do not hold.
- Server logs are retained for 180 days and system clocks are synchronised to NIC or NPL time, as the CERT-In directions of 28 April 2022 require.
- A named point of contact is designated for CERT-In, and reportable cyber security incidents are reported within 6 hours of our noticing or being told of them.
- For a personal data breach we tell affected users without delay, in plain language, what happened, what data was involved, what we are doing and what they should do, and we report to the Data Protection Board of India, with the detailed report following within 72 hours, in the manner the DPDP Rules prescribe once that provision is in force.
9. Grievance redressal
Vrushali Thorat, Attorney and Solicitor, Grievance Officer, A1/202, Samruddhi CHS, Kumbhare Park, Kothrud, Pune, Maharashtra, India 411038 (Registered Office). Email: vrushali@winlegaladvisors.com. We acknowledge every complaint within 24 hours and resolve it within 7 days.
10. Changes
We will post any change on this page with a new "last updated" date.