Privacy Policy
One Step Law (“One Step Law”, “we”, “us”, or “our”) operates the One Step Law Blog (the “Blog”).
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you access or use the Blog.
Who We Are
For the purposes of the DPDP Act, One Step Law acts as the Data Fiduciary in respect of personal data that we determine the purpose and means of processing.
For privacy-related questions, requests, or grievances, you may contact us using the details above.
Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through or in connection with the Blog, including information provided when you:
- visit or browse the Blog;
- contact us;
- subscribe to a newsletter or other communication, where available;
- submit an article, comment, feedback, or other material, where such functionality is available;
- participate in surveys, forms, events, or other activities conducted through the Blog; or
- otherwise interact with us through the Blog.
This Policy does not apply to third-party websites, applications, platforms, or services that may be accessible through links on the Blog.
What Is Personal Data?
For the purposes of this Privacy Policy, “personal data” means data about an individual who is identifiable by or in relation to that data.
Depending on how you interact with the Blog, personal data may include:
- name;
- email address;
- telephone number;
- organisation or professional information;
- information contained in communications you send to us;
- information contained in submissions or comments;
- preferences relating to communications;
- IP address or other technical information, where it constitutes personal data under applicable law;
- device, browser, operating system, and similar technical information;
- information relating to your use of the Blog; and
- any other information that you voluntarily provide to us.
We seek to collect only personal data that is reasonably necessary for the relevant purpose.
Personal Data We Collect
4.1 Information You Provide Directly
We may collect personal data that you voluntarily provide to us, including when you:
- contact us by email or through a contact form;
- subscribe to a newsletter;
- submit an article or writing sample;
- submit feedback;
- participate in an online form, survey, or event;
- request information from us; or
- communicate with us regarding the Blog.
You should avoid providing sensitive, confidential, or unnecessary personal information through publicly accessible portions of the Blog.
4.2 Information Collected Automatically
When you access the Blog, certain technical information may be generated or made available to the Blog's hosting, security, or technology service providers.
This may include:
- IP address;
- browser type;
- device type;
- operating system;
- date and time of access;
- pages or resources requested;
- referring website;
- approximate location derived from technical information; and
- technical logs relating to security and performance.
Where such information constitutes personal data under applicable law, we will process it in accordance with this Privacy Policy and applicable law.
4.3 Search and Website Interaction
Where the Blog provides a search function, search terms may be processed to provide search results.
Where the search function operates entirely within the user's browser, search terms are not transmitted to One Step Law merely because a user performs a search.
Purposes for Which We Process Personal Data
A. Providing and Operating the Blog
To:
- operate and maintain the Blog;
- provide requested features and functionality;
- respond to communications;
- administer subscriptions or registrations, where applicable; and
- provide services or information requested by you.
B. Communications
Where you have requested or consented to receive communications, we may use your contact information to:
- send newsletters;
- provide updates about One Step Law;
- communicate regarding submissions or enquiries; and
- provide information relating to content, events, or activities that you have requested.
You may withdraw your consent to such communications at any time.
C. Security and Fraud Prevention
We may process technical and other information where reasonably necessary to:
- protect the Blog against unauthorised access;
- detect or investigate security incidents;
- prevent fraud, abuse, malicious activity, or attacks;
- maintain system integrity; and
- protect the rights, property, and security of One Step Law, our users, and others.
D. Legal and Regulatory Compliance
We may process personal data where necessary to:
- comply with applicable law;
- comply with lawful orders or directions;
- respond to governmental or regulatory requests;
- establish, exercise, or defend legal rights or claims; or
- investigate or prevent unlawful activity.
E. Improvement of the Blog
Where permitted by applicable law, we may use relevant information to understand how the Blog is used, identify technical issues, improve functionality, and improve the quality and relevance of our Content.
Where analytics or similar technologies are used in the future, we will update this Privacy Policy and, where required, obtain the appropriate consent.
Lawful Basis for Processing
We will process digital personal data only for a lawful purpose.
Depending on the circumstances, processing may be based on:
- Consent provided by you for a specified purpose;
- a certain legitimate use permitted under the DPDP Act; or
- another lawful basis or circumstance recognised under applicable law.
Where processing is based on consent, the consent will be requested in a manner that is free, specific, informed, unconditional, and unambiguous, as required by applicable law.
We will not make consent a condition for processing where the relevant processing can lawfully be undertaken on another basis.
Notice and Consent
Where consent is required, we will provide a notice that explains, in clear and plain language:
- the personal data proposed to be processed;
- the specific purpose for processing;
- the relevant service, feature, or use enabled by processing;
- the means through which consent may be given;
- the means through which consent may be withdrawn; and
- the means through which applicable rights may be exercised.
The DPDP Rules require the notice to be independently understandable and to provide appropriate means for withdrawing consent and exercising rights.
Withdrawal of Consent
Where we process your personal data on the basis of consent, you may withdraw that consent at any time.
You may request withdrawal by contacting:
We will provide a method for withdrawing consent that is as easy as the method through which consent was given, where required by applicable law.
Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
Where consent is withdrawn, we will cease the relevant processing unless continued processing is permitted or required under applicable law.
Where required by the DPDP Act, personal data will be erased following withdrawal of consent unless retention is necessary for a specified purpose or to comply with law.
Your Rights as a Data Principal
Subject to applicable law and prescribed procedures, you may have the following rights under the DPDP Act:
9.1 Right to Access Information
You may request information regarding:
- the personal data being processed by us;
- the processing activities undertaken in relation to your personal data;
- the identity of other Data Fiduciaries and Data Processors with whom your personal data has been shared, where applicable; and
- other information concerning the processing of your personal data as prescribed by law.
9.2 Right to Correction, Completion and Updating
You may request correction, completion, or updating of personal data that is inaccurate, incomplete, or outdated.
9.3 Right to Erasure
You may request erasure of your personal data, subject to circumstances in which retention is required or permitted by applicable law.
9.4 Right to Grievance Redressal
You have the right to approach us regarding any concern relating to our processing of your personal data or the exercise of your rights.
We will maintain an appropriate mechanism for receiving and addressing such grievances.
9.5 Right to Nominate
You may have the right to nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity, subject to the applicable procedures.
These rights are reflected in sections 11–14 of the DPDP Act.
How to Exercise Your Rights
To exercise a privacy right, please contact:
Your request should, where reasonably necessary, contain sufficient information to enable us to identify you and understand the nature of your request.
We may take reasonable steps to verify the identity of the person making a request in order to protect personal data against unauthorised disclosure, alteration, or erasure.
We will process requests in accordance with the applicable requirements and timelines under the DPDP Act and DPDP Rules.
Grievance Redressal
If you have a complaint or grievance regarding the processing of your personal data, please first contact us at:
We will provide a readily available mechanism for grievance redressal.
Under the DPDP Act, a Data Principal is required to exhaust the opportunity for grievance redressal with the Data Fiduciary before approaching the Data Protection Board of India.
Where applicable, you may approach the Data Protection Board of India in accordance with the procedure prescribed under the DPDP Act and DPDP Rules.
Sharing of Personal Data
We do not sell your personal data.
We may share personal data where reasonably necessary with:
A. Data Processors
We may engage third-party service providers to process personal data on our behalf, including providers supporting:
- website hosting;
- cloud storage;
- email delivery;
- newsletter distribution;
- website security;
- technical maintenance;
- analytics, where implemented; and
- other technology services required to operate the Blog.
Where applicable, such providers will process personal data only in accordance with our instructions and contractual requirements.
The DPDP Act places responsibility on the Data Fiduciary for processing undertaken by it or on its behalf by a Data Processor and requires appropriate technical and organisational measures.
B. Legal and Regulatory Authorities
We may disclose personal data where required or permitted by applicable law, including pursuant to:
- a court order;
- lawful governmental request;
- regulatory requirement;
- investigation of unlawful activity; or
- enforcement of legal rights.
C. Business Transactions
If One Step Law undergoes a merger, restructuring, acquisition, sale, or similar transaction, personal data may be transferred as part of that transaction, subject to applicable law and appropriate safeguards.
International Transfers
Some service providers used to operate the Blog may process personal data outside India.
Where personal data is transferred or processed outside India, we will comply with applicable requirements under Indian law, including any restrictions or conditions notified by the Central Government.
The DPDP Act permits the Central Government to restrict transfers of personal data to specified countries or territories.
Data Security
We take reasonable security safeguards designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, or unauthorised disclosure or access.
Depending on the nature of the processing, safeguards may include:
- access controls;
- authentication measures;
- encryption or other appropriate protective measures;
- secure hosting and infrastructure;
- monitoring and logging;
- backups and recovery mechanisms;
- contractual controls over Data Processors; and
- organisational and technical security measures.
The DPDP Rules prescribe appropriate security safeguards including measures relating to encryption, access control, monitoring, backups, logging, contractual safeguards, and organisational measures.
However, no method of transmission or storage over the internet can be guaranteed to be completely secure.
Personal Data Breaches
In the event of a personal data breach, we will take appropriate steps to contain, assess, mitigate, and remediate the breach.
Where required by applicable law, we will notify affected Data Principals and the Data Protection Board of India in the prescribed manner.
The DPDP Rules prescribe requirements concerning notification of affected Data Principals and the Data Protection Board following a personal data breach.
Retention of Personal Data
We will retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, unless:
- continued retention is required by law;
- retention is necessary to establish, exercise, or defend legal rights;
- retention is necessary for security or fraud prevention; or
- another lawful basis for retention applies.
When personal data is no longer required, we will take reasonable steps to erase or anonymise it, subject to applicable legal requirements.
Where applicable, retention and erasure will also comply with the prescribed requirements under the DPDP Rules.
Children's Personal Data
The Blog is intended primarily for a general audience.
Where we knowingly process the personal data of a child, we will comply with the requirements applicable to children's personal data under the DPDP Act and DPDP Rules, including requirements concerning verifiable parental consent where applicable.
We will not knowingly undertake processing that is prohibited in relation to children, including prohibited tracking, behavioural monitoring, or targeted advertising directed at children.
Under the DPDP Act, a child is an individual who has not completed eighteen years of age.
If you believe that a child has provided personal data to us in circumstances where such processing was not authorised, please contact us at ravikant@onesteplaw.com .
Cookies and Similar Technologies
The Blog may use cookies or similar technologies where necessary to operate, secure, maintain, or improve the Blog.
Cookies may be used for purposes such as:
- maintaining website functionality;
- remembering preferences;
- understanding website performance; and
- security and fraud prevention.
Where non-essential cookies or similar technologies are introduced and applicable law requires consent, we will seek the appropriate consent before using them.
The Blog may also contain links to third-party websites that use their own cookies and tracking technologies. We are not responsible for the privacy practices of those third parties.
Third-Party Links
The Blog may contain links to third-party websites, publications, social media platforms, or other resources.
Once you leave the Blog, the third party's privacy policy and terms will apply.
We recommend reviewing the privacy practices of any third-party service before providing personal data to it.
User-Submitted Content
If the Blog allows users or contributors to submit articles, comments, feedback, or other content, personal data contained in those submissions may be processed for purposes including:
- reviewing the submission;
- communicating with the contributor;
- publishing or displaying the submitted material where agreed;
- preventing misuse; and
- maintaining the Blog.
You should not include unnecessary personal data, confidential information, privileged information, or information belonging to another person without appropriate authority in any public submission.
Where an article or contribution is published, certain information such as the contributor's name, professional designation, or biography may be publicly displayed where this has been agreed or is otherwise appropriate.
Data Minimisation
We seek to collect and process only personal data that is reasonably necessary for the relevant purpose.
We do not intend to collect sensitive or excessive personal information merely because it is available.
You should therefore provide only information that is relevant to your interaction with the Blog.
Automated Decision-Making
The Blog does not currently use your personal data to make solely automated decisions that produce legal or similarly significant effects on you.
If this changes, we will update this Privacy Policy and implement any safeguards required by applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to the Blog;
- changes to our data processing practices;
- changes in applicable law or regulatory requirements; or
- changes to the DPDP Act or DPDP Rules.
The updated version will be published on this page with a revised “Last Updated” date.
Where required by law, we will provide additional notice or obtain consent before introducing a new processing activity.
Contact Us
For questions concerning this Privacy Policy or the processing of your personal data, please contact:
One Step Law
Privacy Contact:
Ravikant Dabi, Founder – One Step Law
Email:
ravikant@onesteplaw.com
Address:
60, Aamarpali Apartment,
IP Extension, Delhi-110092
For requests concerning your rights under the DPDP Act, please use the subject line:
Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the laws of India.
Any dispute concerning this Privacy Policy shall be subject to the jurisdiction of courts having competent jurisdiction in India, subject to applicable law.
