Bishop·
PrivacyTermsSupportCookiesAcceptable useRefundsDPA

Legal

Privacy Policy

Every category of data Bishop reads, everything it writes, and what it never touches.

Effective 7 August 2026 · Last updated 7 August 2026

Contents

  1. 1. Who we are and how to contact us
  2. 2. Scope of this Policy
  3. 3. Key definitions
  4. 4. Summary of what Bishop reads and writes
  5. 5. The personal data we collect
  6. 6. What Bishop writes
  7. 7. How we use personal data and our lawful basis
  8. 8. How Bishop uses artificial intelligence
  9. 9. Platform terms: Google, Chrome, Microsoft and Edge
  10. 10. Aggregated and de-identified data
  11. 11. Confidentiality, legal privilege and the limits of what we look at
  12. 12. How we share personal data
  13. 13. Security
  14. 14. Data breach notification
  15. 15. How long we keep personal data
  16. 16. Your rights
  17. 17. Bishop as Data Processor for firms
  18. 18. International data transfers
  19. 19. Children
  20. 20. Beta and pre release features
  21. 21. Grievance Officer and Data Protection contact
  22. 22. Changes to this Policy
  23. 23. Governing law

This Privacy Policy explains how Nexno Lextech Private Limited, which operates the Bishop product (“Bishop”, “we”, “us” or “our”), collects, uses, shares, stores and protects personal data when you visit bishop.work (the “Website”), create an account, install the Bishop browser extension, install the Bishop add-in for Microsoft Office, or use the Bishop application and related services (together, the “Service”).

Bishop is a passive time capture product for law firms and professional services firms. Its single purpose is passive time tracking for law firms and professional services firms. It connects to your work mail, calendar, Microsoft Office applications and browser on a read-only basis, classifies your activity into the matters it belongs to, and shows you a single screen to confirm. Nothing is billed without user confirmation. Because the Service is built for the legal profession and may touch confidential and privileged information, we treat data protection as a core part of the product rather than an afterthought.

Section 5 sets out, in detail, every category of data Bishop reads. Section 6 sets out, in detail, everything Bishop writes and everywhere it writes it. If you read nothing else in this Policy, read those two sections.

Please read this Policy together with our Terms of Service, Cookie Policy, and, where you are a business customer, the Data Processing Addendum. If you do not agree with this Policy, please do not use the Service. If you have questions about this Policy, or a suggestion, you can contact us using the details in Section 1.

1. Who we are and how to contact us#

Bishop is operated by Nexno Lextech Private Limited, a company incorporated in India under the Companies Act, 2013, bearing Corporate Identity Number U85307PN2023PTC221261 with its registered Office Address at Bungalow 1, Sai Niwas Soc, S No 55, Undri, Haveli, Hadapsar, Pune, Pune, Maharashtra, 411028, India.

For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”), the Company is the Data Fiduciary in respect of personal data it determines the purpose and means of processing for (for example, account, billing and Website data). Where the Company processes personal data on behalf of a business customer (for example, the mail, calendar, document and browsing activity data of a firm’s lawyers), the Company acts as a Data Processor, and the business customer is the Data Fiduciary. Section 17 of this Policy explains this split in more detail.

You can reach us at:

  • General, support and privacy queries: support@bishop.work
  • Security and technical queries: tech@bishop.work
  • Grievance Officer: see Section 21

2. Scope of this Policy#

This Policy applies to:

  • Visitors to the Website.
  • Individual users of the Service, including lawyers, fee earners, administrators and other personnel of a customer firm (“Users”).
  • Users of the Bishop browser extension for Google Chrome and other Chromium based browsers, including Microsoft Edge (the “Browser Extension”).
  • Users of the Bishop add-in for Microsoft Office, namely Word, Excel and PowerPoint (the “Office Add-in”).
  • Prospective customers, investors and others who contact us or share their information with us.

This Policy is the privacy policy referenced in the Bishop listing on the Chrome Web Store, the Microsoft Edge Add-ons store, and Microsoft Marketplace, and in our Google API and Microsoft identity platform registrations.

This Policy does not apply to third party websites, services or products that we link to or integrate with. Those are governed by their own privacy policies, and we encourage you to read them.

Where Bishop processes the personal data of a firm’s clients or third parties contained inside a User’s mail, calendar, documents or browsing activity, it does so on the instructions of, and as a Data Processor for, the customer firm. The firm remains responsible, as Data Fiduciary, for the lawful basis on which that data is processed and for notifying its personnel that the Service is in use.

3. Key definitions#

We use the following terms in this Policy. They carry the meanings given to them in the DPDP Act and DPDP Rules where applicable.

  • Personal data: any data about an individual who is identifiable by or in relation to such data.
  • Data Principal: the individual to whom personal data relates.
  • Data Fiduciary: the person who, alone or with others, determines the purpose and means of processing personal data.
  • Data Processor: a person who processes personal data on behalf of a Data Fiduciary.
  • Processing: any operation performed on personal data, including collection, recording, organisation, storage, use, sharing, disclosure and erasure.
  • Customer or firm: the organisation that subscribes to the Service and on whose behalf Users access it.
  • Connected account: a mail, calendar or other third party account that a User authorises Bishop to access.
  • Connected surface: any of the four ways Bishop observes activity, namely the mail and calendar API integrations, the Browser Extension, the Office Add-in, and the Bishop web application itself.
  • Page details: the address, title and domain of a web page, together with timing information about your visit. Page details do not include the body of the page, meaning the text, images and other content displayed on it. An address or title is written by the website itself and may contain information, as Section 5.3 explains.
  • Draft time entry: an unconfirmed record proposed by Bishop, consisting of a duration, a matter classification and a narrative, which has no billing effect until you confirm it.

4. Summary of what Bishop reads and writes#

The table below is a summary. Sections 5 and 6 give the detail.

SurfaceWhat Bishop readsWhat Bishop writes to that surface
Gmail and Google CalendarMessage metadata and subject lines, never message bodies. Calendar event metadata and contentNothing
Outlook mail and calendar, via Microsoft GraphMessage metadata and subject lines, never message bodies. Calendar event metadata and contentNothing
Word, Excel and PowerPoint, via the Office Add-inDocument identity and activity metadataNothing. No changes to the content, properties or formatting of any document
Chrome and Chromium based browsers, via the Browser ExtensionPage address, page title and activity timing. Never page body content. Addresses and titles may themselves contain subject lines, document names or matter references, as explained in Section 5.3Nothing to any website you visit. Local browser storage on your own device only, for configuration and queueing
Bishop application and serversYour account, settings and confirmed entriesYour account, settings, classifications, draft and confirmed time entries

5. The personal data we collect#

5.1 Information you give us directly#

  • Identity and contact data: name, work email address, job title, firm name, phone number.
  • Account credentials: login identifiers and authentication data (we do not store plaintext passwords; authentication is handled as described in Section 13).
  • Billing and transaction data: billing name, billing address, GSTIN, tax identifiers, subscription tier, seat count, and records of payments. Card and bank details are handled directly by our payment processor and are not stored by us.
  • Configuration you choose: matter lists, capture rules, and the block lists you or your firm set for the Browser Extension.
  • Communications: messages you send to support, sales or our Grievance Officer, and your responses to surveys or feedback requests.

5.2 Information from your connected mail and calendar accounts (read-only)#

When you authorise Bishop to connect to a mail or calendar account through the Google APIs or Microsoft Graph, we access, on a read-only basis, the data needed to classify your activity into matters and prepare draft time entries for your confirmation. Depending on the integration this can include:

  • Calendar event metadata and content: titles, dates, times, durations, attendee names and email addresses, locations, and event descriptions.
  • Email metadata and subject lines: sender and recipient names and addresses, subject lines, and timestamps. Bishop does not read the body of your messages.
  • Contact and directory information associated with the above.

We access this data on a read-only basis. We do not send mail, modify your calendar, or change anything in your connected accounts. Our use of data from Google and Microsoft accounts is further restricted as described in Section 9.

5.3 Information from the Bishop Browser Extension#

The Browser Extension exists to do one thing: observe how long you spend on work applications and websites in your browser, so that time can be classified into matters and proposed to you as a draft time entry. This is the user facing feature for which the Extension collects web browsing activity, and it is described prominently in our store listings and in the Extension’s own interface. The Extension collects no data for any other purpose.

What the Extension reads:

  • Page details, namely the address (URL) of the page, the page title, and the domain.
  • Activity timing, namely when a tab became active, when it stopped being active, when the browser became idle, and the resulting duration.
  • The browser profile identifier used to associate captured activity with your Bishop account.

Page addresses and titles can themselves contain information, and we want you to know this before you consent. Bishop does not open a page or read what is displayed on it. But the address and the title are written by the website, not by us, and on some sites they carry meaningful content. A webmail tab is commonly titled with the subject line of the message you have open. A document editor is commonly titled with the file name. A court filing portal or a document management system commonly puts the case title, cause number, client name or matter number into the address or the title. Where that is so, Bishop will receive it, because it is part of the address or title we capture in order to work out which matter you were working on.

This means that page titles captured by the Extension may include email subject lines, chat contact names, document names, case titles and matter references. We treat all of it as confidential and potentially privileged, under Section 11, and it is subject to the same restrictions, retention limits and deletion rights as everything else in this Policy. We disclose it here, and again in the Extension itself before capture begins, so that you can decide with full knowledge which sites you are willing to let Bishop see.

What the Extension does not read:

  • The Extension does not open, load or read the body of any page. It does not read the text, images, media, tables or documents displayed on a page, and it does not read the body of any message shown on a page.
  • The Extension does not read anything you type. It does not record keystrokes, form fields, search boxes, chat messages, comment boxes or message drafts.
  • The Extension does not read passwords, payment card details, banking details or any credential, whether typed, autofilled or stored in your browser.
  • The Extension does not take screenshots or record your screen.
  • The Extension does not read cookies, local storage or session storage belonging to the websites you visit.
  • The Extension does not read your browser history, bookmarks or downloads.
  • The Extension does not inject scripts into, alter, or interact with the websites you visit.

Your consent before anything is collected:

The Extension collects nothing when it is installed. Before any capture begins, it shows you a screen inside the Extension setting out what it collects, including the point about addresses and titles above, and what it never collects. It also invites you to set up your block list at that moment, so that any site you consider private is excluded before the first capture rather than after it. Capture starts only when you take the affirmative step of accepting that disclosure. If you decline, the Extension stays installed and dormant and collects nothing.

If we later change what the Extension collects or how we use it, we will show you the revised disclosure in the Extension and ask you to accept it again.

Your control over what is collected:

  • Block list. You or your firm can add any website or domain to a block list. Bishop collects nothing at all from a blocked site: not the address, not the title, not the duration. This is intended for banking, health, personal mail, and any other site you consider private.
  • Pause. You can pause capture at any time from the Extension. While paused, nothing is collected.
  • Review before submission. Captured activity is presented to you as a draft. You decide what is submitted, what is edited, and what is discarded. Discarded activity never becomes a time entry.
  • Uninstall. Removing the Extension stops all collection immediately.

We recognise that a browser on a work device may still be used for personal purposes. The consent screen, the block list, the pause control and the discard control exist so that you retain meaningful control over what leaves your device. Your firm is responsible for notifying its personnel that the Extension is in use and for configuring it consistently with its own policies and applicable employment and data protection law.

5.4 Information from the Bishop Office Add-in#

The Office Add-in runs inside Microsoft Word, Excel and PowerPoint. Its purpose is the same as the rest of the Service: to observe work activity and propose draft time entries.

What the Add-in reads in Word, Excel and PowerPoint:

  • Document identity and activity metadata, namely the document name, the document identifier, the storage location or file path where available, and the periods during which the document was open and actively being worked on.

What the Add-in does not read:

  • In Word, Excel and PowerPoint, the Add-in does not read the content of your documents. It does not read the body text of a document, the values or formulas in a spreadsheet, or the text of a presentation.
  • The Add-in does not read your mail or calendar at all. Outlook mail and calendar are read separately through Microsoft Graph, not through the Add-in.
  • The Add-in does not read your contacts, your task list or your notes.

5.5 Information we collect automatically#

  • Usage data: features used, screens viewed, actions taken, confirmations and edits, and timestamps.
  • Device and technical data: IP address, browser type, operating system, device identifiers, and approximate location derived from IP address.
  • Extension and Add-in operational data: version installed, error and crash diagnostics, and connection status, used to keep the Extension and Add-in working and secure.
  • Cookies and similar technologies: as described in our Cookie Policy.

5.6 Information from third parties#

  • From your firm or administrator, when they provision your account, manage seats, or deploy the Extension or Add-in across the firm.
  • From identity providers when you sign in using single sign on.
  • From integration providers, limited to what you authorise.

We do not buy personal data from data brokers, nor is any data ever sold.

6. What Bishop writes#

This Section states, exhaustively, everything Bishop writes and where.

6.1 Bishop does not write to your connected accounts, documents or the websites you visit#

  • Google Gmail and Calendar. Bishop writes nothing. It does not send, draft, reply to, forward, label, categorise, archive, move or delete any message. It does not create, modify, respond to or delete any calendar event.
  • Microsoft Outlook mail and calendar, accessed through Microsoft Graph. Bishop writes nothing. It does not send, draft, reply to, forward, flag, categorise, move or delete any message, and it does not create, modify, respond to or delete any calendar item.
  • Word, Excel and PowerPoint. Bishop writes nothing. The Add-in does not insert, alter or remove any content, does not change document properties or metadata, does not apply formatting, does not add comments or tracked changes, and does not save, rename or move any file.
  • Websites you visit in your browser. Bishop writes nothing. The Extension does not inject scripts, modify pages, submit forms, click controls, set cookies, or write to the storage of any website you visit.

6.2 What is written to your own device#

The Browser Extension writes to local browser storage on your own device, and only the following:

  • Your Bishop connection status and authentication token.
  • Your capture configuration, including your block list.
  • A short lived queue of captured page details and timings awaiting transmission to Bishop, so that activity is not lost if your connection drops.

This storage is on your device. It is cleared when you uninstall the Extension or sign out.

6.3 What is written to Bishop’s own systems#

Within Bishop’s own servers, we write and store:

  • Your account, firm, seat and configuration records.
  • The activity Bishop has observed from the connected surfaces, for the retention period described in Section 15.
  • Bishop’s own outputs, namely the matter classification, the proposed duration, and the generated narrative for each draft time entry.
  • Your edits, confirmations and discards.
  • Confirmed time entries and the billing information derived from them.
  • Security, audit and diagnostic logs.

The narrative and the billing information are generated inside Bishop. They are presented to you as a draft, you can alter them, and they have no billing effect until you confirm them. They are never written back to your mailbox, your calendar, your documents or your browser.

6.4 Export to your firm’s systems#

Where your firm has configured an export or integration, confirmed time entries and the billing information derived from them may be transmitted from Bishop to a practice management, accounting or billing system nominated by your firm. This happens only for entries you have confirmed, only where your firm has set up the export, and in accordance with your firm’s instructions as Data Fiduciary. No unconfirmed draft, no raw mail or document content, and no raw page details are exported in this way.

7. How we use personal data and our lawful basis#

We process personal data to provide, secure and improve the Service. The table below sets out our purposes and the lawful basis we rely on under the DPDP Act (consent or a legitimate use) and, during the transition period, the Information Technology Act, 2000 and the rules made thereunder.

PurposeLawful basis
To create and administer your accountPerformance of the contract with you or your firm; legitimate use
To connect to your mail and calendar and classify activity into mattersYour consent given at the point of authorisation, on behalf of and under instruction from your firm
To observe browser activity through the Browser Extension and classify it into mattersYour consent, given by accepting the in-product disclosure before any capture begins, on behalf of and under instruction from your firm
To observe activity in Microsoft Office through the Office Add-in and classify it into mattersYour consent given when you install or are assigned the Add-in, and the contract with your firm
To prepare draft time entries for your confirmationYour consent and the contract with your firm
To export confirmed entries to your firm’s nominated systemsPerformance of the contract; your firm’s documented instruction
To process subscriptions, billing and taxPerformance of the contract; compliance with legal obligation
To provide support and respond to grievancesPerformance of the contract; legitimate use
To secure the Service and prevent fraud and abuseLegitimate use; legal obligation
To maintain and improve the reliability and accuracy of the ServiceLegitimate use, on aggregated or de-identified data only, as described in Section 10
To send service and transactional communicationsPerformance of the contract
To send marketing communicationsYour consent, which you may withdraw at any time
To comply with law and respond to lawful requestsCompliance with legal obligation

Where we rely on your consent, you may withdraw it at any time as described in Section 16. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may mean that parts of the Service can no longer be provided to you.

8. How Bishop uses artificial intelligence#

Bishop uses machine learning and large language models to interpret the activity it observes, classify it into the correct matter, and draft a short narrative for each time entry. We want to be specific about what this means for your data.

  • The classification and drafting are assistive. A human, namely you, reviews and confirms every entry before it has any billing effect. Bishop does not autonomously create or submit billable time.
  • We use a combination of Gemini from Google, Claude from Anthropic and self-hosted models to perform model inference. Content sent for inference is transmitted securely and is subject to the contractual protections described in Section 12.
  • We do not use or retain the content of your mail, calendar, documents, page details or matters to train, fine tune or improve any general purpose, generalised or non-personalised artificial intelligence or machine learning model, including any third party foundation model.
  • Where we improve our own classification quality, we do so using aggregated, de-identified or synthetic data, or data for which the firm has given specific instructions, and not in a way that identifies any client, matter or individual.
  • We maintain human oversight of automated processing and provide a means for you to query or correct any classification.

If at any time the substantive automated decision making provisions of the DPDP regime impose additional obligations, we will update this Section and our practices accordingly.

9. Platform terms: Google, Chrome, Microsoft and Edge#

Bishop reaches your data through four platform programmes, each with its own developer requirements. This Section applies to data obtained through each of them and prevails over any more general statement in this Policy in respect of that data.

9.1 Limited use of Google user data (Google APIs)#

Bishop’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Google user data only to provide and improve the user facing features of the Service that are prominent in the Bishop interface, namely classifying your activity into matters and preparing draft time entries for your confirmation.
  • We do not transfer Google user data to third parties except as necessary to provide or improve those user facing features, to comply with applicable law, to protect against security threats, abuse or technical problems, or as part of a merger or acquisition with notice to you, in each case consistent with this Policy.
  • We do not use Google user data for serving advertising, including personalised, retargeted or interest based advertising.
  • We do not use Google user data to develop, improve or train generalised or non personalised artificial intelligence or machine learning models.
  • We do not sell Google user data, and we do not transfer it to data brokers, information resellers or advertising platforms.
  • We do not use or transfer Google user data to determine creditworthiness or for lending purposes.
  • We do not allow humans to read your Google user data unless we have your affirmative consent to read specific messages, it is necessary for security, abuse prevention or to comply with applicable law, the data has been aggregated and de-identified and is used for internal operations, or you have asked us to and we need to for support.

9.2 Limited use of data collected by the Browser Extension (Chrome Web Store)#

Bishop’s use and transfer of user data collected by the Browser Extension complies with the Chrome Web Store Developer Program Policies, including the Limited Use policy. In particular:

  • The Extension has a single purpose: passive time tracking for law firms and professional services firms.
  • The Extension collects, uses and transmits only the data strictly necessary for that single purpose and its related operational purposes, namely maintaining, securing and measuring the performance and reliability of that feature.
  • The Extension collects web browsing activity only to the extent required for that user facing feature, which is described prominently on the Extension’s store listing pages and in the Extension’s own interface.
  • Before the Extension collects anything, it presents an in-product disclosure describing what will be collected and how it will be used, and requires your affirmative action to accept it. If our data handling practices change after you install the Extension, we will disclose that change to you in the product.
  • We do not sell data collected by the Extension, and we do not transfer it to data brokers, information resellers or advertising platforms.
  • We do not use or transfer data collected by the Extension for personalised advertising, or to determine creditworthiness or for lending purposes.
  • We do not use data collected by the Extension to develop, improve or train generalised or non personalised artificial intelligence or machine learning models.
  • These restrictions apply to the raw data the Extension collects and, equally, to any data we aggregate, anonymise, de-identify or derive from it. The general permission in Section 10 to use de-identified data for lawful business purposes does not extend to data originating from the Extension, from Google APIs, or from Microsoft.

9.3 Microsoft user data (Microsoft Graph and the Office Add-in)#

Our access to Outlook mail and calendar data through Microsoft Graph, and to Office application data through the Office Add-in, is read-only and is used solely to provide the user facing features described above. We handle Microsoft user data consistent with the Microsoft APIs Terms of Use, the Microsoft Marketplace certification policies and applicable Microsoft data handling requirements. We apply the same restrictions on advertising, data sale and generalised model training set out in Sections 9.1 and 9.2.

The Office Add-in makes no changes to any mail item, calendar item or document, as set out in Section 6.1. We are pursuing Microsoft Entra publisher verification and Microsoft 365 Certification.

9.4 Microsoft Edge Add-ons#

Where the Browser Extension is installed from the Microsoft Edge Add-ons store, we handle data collected by it in accordance with the Microsoft Edge Add-ons store developer policies, and the commitments in Section 9.2 apply equally.

9.5 Permissions, scopes and why we need each one#

We request the narrowest permissions necessary for the Service to function, and all access to your accounts, documents and pages is read-only. The current and authoritative list is shown on the consent screen, the store listing, or the installation prompt at the time you connect an account or install the Extension or Add-in.

SurfacePermission or scopeAccessWhy we need it
Google APIgmail.readonlyRead-onlyRead email metadata and subject lines, never message bodies, to classify activity into matters and draft time entry narratives
Google APIcalendar.readonlyRead-onlyRead calendar events to identify billable activity and durations
Google APIopenid, userinfo.email, userinfo.profileRead-onlyAuthenticate you and create your account
Microsoft GraphMail.ReadRead-onlyRead Outlook email metadata and subject lines, never message bodies, to classify activity and draft narratives
Microsoft GraphCalendars.ReadRead-onlyRead Outlook calendar events for time capture
Microsoft GraphUser.Read, offline_accessRead-onlyAuthenticate you and maintain your connection
Office Add-inRead level permission in the add-in manifestRead-onlyRead the identity and activity metadata of the document you are working on, so activity can be timed and classified. Bishop does not request or use any write level permission
Browser ExtensionstorageLocal device onlyStore your connection status and capture configuration, and queue captured activity for transmission
Browser Extensiontabs and idleRead-onlyDetect which tab is active and when the browser is idle, so durations are measured accurately
Browser ExtensionHost permissions for the sites from which activity is capturedRead-only, page details onlyRead page details, namely address, title and domain, from the sites you have not blocked, so activity can be classified into matters. No page content is read

You can review and revoke Bishop’s access at any time through your Google Account permissions or Microsoft account permissions, by disconnecting the account in Bishop, by removing the Office Add-in, or by removing the Browser Extension from your browser. Revoking access stops further access and may disable parts of the Service.

10. Aggregated and de-identified data#

The restrictions in Section 9 apply to data originating from Google APIs, from Microsoft, and from the Browser Extension, and they apply to that data both in its raw form and after it has been aggregated, anonymised, de-identified or otherwise derived. Nothing in this Section overrides Section 9.

Subject to that, we may create aggregated, anonymised or de-identified data from personal data, for example to understand usage patterns, measure capture accuracy, and improve the Service. Once data has been aggregated or de-identified so that it can no longer reasonably be linked to an individual, it is no longer personal data. We do not attempt to re-identify de-identified data.

11. Confidentiality, legal privilege and the limits of what we look at#

We recognise that mail, calendar, document and browsing activity belonging to lawyers may reveal legally privileged and confidential client information. We process it solely to provide the Service. We do not review it for any independent purpose, we restrict internal access to it, and we do not disclose it except as instructed by the firm or as required by law. Our role as a service provider does not create any lawyer client relationship, and our access does not waive any privilege belonging to the firm or its clients.

We do not routinely monitor the content or activity we process. Human access to it is limited to the narrow circumstances described in Section 9.1 and to what is strictly necessary to investigate a security incident, respond to a support request you have made, or comply with law, in each case under access controls and logging.

12. How we share personal data#

We do not sell personal data. We do not share Google user data, Microsoft user data or data collected by the Browser Extension with third parties for advertising, and we do not use it to train generalised or non personalised artificial intelligence or machine learning models. We share personal data only in the circumstances below.

12.1 Service providers and sub-processors#

We engage trusted third parties to help us run the Service, such as cloud hosting, model inference, payment processing, analytics, email delivery and customer support. They process personal data only on our documented instructions, under written contracts that require appropriate security and confidentiality, and only to the extent needed to perform their function.

12.2 Your firm#

If you use Bishop through a firm account, your firm’s administrators can access your account information, configuration, and the time entries associated with your account, consistent with the firm’s own policies. Your relationship with your firm is governed by your firm’s policies, not this Policy.

12.3 Your firm’s nominated systems#

Where your firm has configured an export, confirmed time entries and derived billing information are transmitted as described in Section 6.4.

12.4 Legal and regulatory disclosures#

We may disclose personal data where we believe in good faith that it is necessary to comply with applicable law, a court order, or a lawful request from a public authority, to enforce our agreements, or to protect the rights, safety and property of Bishop, our customers or others.

12.5 Business transfers#

If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honour the commitments in this Policy, we will notify you of any change in the entity responsible for your personal data, and we will update this Policy and make any filings required with the relevant authorities. Where the data concerned originates from Google APIs, from Microsoft, or from the Browser Extension, any such transfer will be made only in accordance with the applicable platform requirements in Section 9.

13. Security#

We implement reasonable security practices and procedures designed to protect personal data, consistent with the requirements of the Information Technology Act, 2000, the rules made thereunder, and the DPDP regime. These include:

  • Encryption of data in transit using TLS, and encryption of data at rest.
  • Read-only access scopes and permissions for every connected surface, so that Bishop cannot send, alter or delete data in your accounts, documents or browser.
  • Access controls based on least privilege, with authentication and role based permissions.
  • Network and application security controls, logging and monitoring.
  • Segregation of customer data and tenant isolation.
  • Secure software development practices and regular review.
  • Vendor due diligence and contractual security obligations for sub-processors.

We are currently pursuing SOC 2 and ISO 27001 certification as part of our security roadmap, and all endeavours are being made to ensure that we are compliant with their requirements from day one. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will respond as set out in Section 14.

14. Data breach notification#

If we become aware of a personal data breach affecting your personal data, we will take prompt steps to contain and assess it. Where we act as Data Fiduciary, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP regime, including notification to affected individuals within the prescribed period. Where we act as Data Processor for a firm, we will notify the firm without undue delay so that the firm can meet its own obligations, and we will assist the firm as required by the Data Processing Addendum.

15. How long we keep personal data#

We keep personal data only for as long as necessary for the purposes set out in this Policy, after which we erase or anonymise it.

  • Account and configuration data: for the duration of your account, and for a limited period afterwards to handle wind down, disputes and legal obligations.
  • Mail and calendar data processed for classification: retained only as long as needed to generate and confirm entries, and in line with the retention configuration agreed with your firm. We are designed to minimise retention of raw content.
  • Page details captured by the Browser Extension: retained only as long as needed to generate and confirm entries, and in line with the retention configuration agreed with your firm. Page details for activity you discard are deleted.
  • Confirmed time entries: retained for the period instructed by your firm, since these form part of the firm’s billing records.
  • Billing and tax records: retained for the period required by Indian tax and company law.
  • Support communications: retained for a reasonable period to maintain a record of our interactions.

When the purpose for which personal data was collected is no longer served, including where you withdraw consent, uninstall the Extension or Add-in, or your account is closed, we will erase the personal data unless retention is required by law, in line with Section 8(7) of the DPDP Act and the DPDP Rules.

16. Your rights#

Subject to applicable law, you have the following rights in respect of your personal data.

  • Right to access: to obtain a summary of the personal data we process about you and the processing activities undertaken.
  • Right to correction and completion: to have inaccurate or incomplete personal data corrected, completed or updated.
  • Right to erasure: to request erasure of personal data that is no longer necessary for the purpose for which it was processed, subject to legal retention requirements.
  • Right to withdraw consent: to withdraw consent at any time where we rely on consent, with the same ease as it was given.
  • Right to grievance redressal: to have your grievances addressed by our Grievance Officer (Section 21).
  • Right to nominate: to nominate another individual to exercise your rights in the event of your death or incapacity, in the manner prescribed under the DPDP regime.

Where your firm is the Data Fiduciary for the data in question, we will refer your request to your firm, or assist your firm in responding to it, as appropriate.

To exercise these rights, contact us by any of our official channels. We may need to verify your identity before acting on a request. We will respond within the timelines required by applicable law. There is no fee for a reasonable request, although we may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive or repetitive.

If you are not satisfied with our response, you may have the right to complain to the Data Protection Board of India, once it is operational and exercising the relevant functions.

17. Bishop as Data Processor for firms#

When a firm subscribes to Bishop and provisions Users, the firm decides why and how its personnel’s and clients’ data is processed in Bishop. In that context:

  • The firm is the Data Fiduciary, and is responsible for the lawful basis, notices and consents required for the data it puts into, or authorises Bishop to access through, the Service, including through the Browser Extension and the Office Add-in.
  • The firm is responsible for notifying its personnel that the Browser Extension and Office Add-in are deployed, and for configuring capture rules and block lists consistently with its own policies and with applicable employment and data protection law.
  • Bishop is the Data Processor, and processes that data only on the firm’s documented instructions, as set out in the Data Processing Addendum.
  • If you are a User and you have questions about how your firm uses Bishop, or you wish to exercise rights in respect of data your firm controls, please contact your firm in the first instance. We will support your firm in responding.

18. International data transfers#

Bishop is operated from India and primarily processes and stores data in India. Some of our sub-processors may process personal data outside India, for example for model inference or infrastructure. Where personal data is transferred outside India, we do so in accordance with the DPDP regime, including any restrictions the Government of India notifies on transfers to particular countries, and we put in place appropriate safeguards with the recipient. If your firm requires data to be processed only within a specific region, this can be addressed in your agreement with us.

19. Children#

The Service is intended for use by legal and professional services personnel and is not directed at children. We do not knowingly collect personal data of children as defined under the DPDP Act. If we learn that we have collected such data without the required verifiable consent, we will erase it.

20. Beta and pre release features#

Where you use a beta, pilot or pre-release feature, the data protection commitments in this Policy apply in full. Beta features may be less reliable or may be withdrawn, as described in our Terms of Service, but they carry no reduction in the protections set out here.

21. Grievance Officer and Data Protection contact#

In accordance with the Information Technology Act, 2000, the rules made thereunder, and the DPDP regime, the following officer is responsible for addressing your grievances and queries about this Policy and our processing of personal data.

  • Grievance Officer: Prathik Karthikeyan
  • Email: prathik@bishop.work

We will acknowledge grievances within the period required by law and resolve them within the prescribed timelines. If we are designated a Significant Data Fiduciary under the DPDP regime, we will appoint a Data Protection Officer and update this Section with their contact details.

22. Changes to this Policy#

We may update this Policy from time to time to reflect changes in the Service, our practices, or the law. When we make material changes, we will update the effective date above and notify you by a reasonable means, such as a notice on the Website or an email. Where the change affects what the Browser Extension or Office Add-in collects or how it is used, we will disclose the change in the product itself. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised Policy, subject to any consent we are required to obtain afresh.

23. Governing law#

This Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy are subject to the dispute resolution and jurisdiction provisions of our Terms of Service.

Questions about this page? Write to prathikx@gmail.com.

Bishop·

Passive time tracking for law firms.

How it worksSecurityFAQContact

Built for Indian Tier-1 practices.  ·  © 2026 Bishop

PrivacyTermsSupportCookiesAcceptable useRefundsDPA

Bishop is a product of Nexno Lextech Private Limited, Pune, India · CIN U85307PN2023PTC221261