IPR
15 January 2026
Understanding IPR Protection for Indian Startups
Nilendu Bhagat, Founder
I get some version of this call at least once a month: a founder, usually a few months into building something real, asking almost in passing whether they "should probably trademark the name at some point." By the time they've called, someone has usually already tried to register a confusingly similar mark, or a co-founder relationship has soured and nobody's quite sure who owns the code. The question always comes a little later than it should.
So here's the honest version of what I tell them. Start with the trademark — the name and logo are the identity the whole business gets built around, and they're the easiest thing for someone else to copy. File early, even before you've properly launched. It costs little and it buys you priority, which matters enormously if a dispute ever comes up.
Copyright is a bit more forgiving — it protects original written and creative work, including code, the moment you create it. But "automatic" protection is cold comfort in a dispute if you can't prove when you created something, which is where registration earns its keep. If there's a genuinely novel technical process underneath the product, that's a separate conversation about patents, and a longer one.
The part founders consistently underestimate is trade secrets — your pricing model, your internal processes, the client list you've built by hand. None of that gets registered anywhere. It's protected entirely through contracts: employment agreements, NDAs, confidentiality clauses that are actually specific rather than boilerplate. I've lost count of how many founders have told me a verbal understanding with an early hire was "basically fine." It never is, and it's the first thing that falls apart when that hire leaves for a competitor.
If you take one thing from this: trademark first, contracts around your secrets and your codebase second, and treat copyright and patent filings as something you revisit as the product grows — not a box you tick once and forget.
Real Estate
2 February 2026
RERA Compliance: A Practical Checklist for Developers
Anshika Kathal, Co-Founder
Almost every RERA dispute that lands on my desk has the same shape. Nobody set out to mislead anyone. A project changed — a timeline slipped, a floor plan got revised, unit inventory shifted — and the filing simply never caught up with reality. Months later, a buyer notices the gap, and what should have been a five-minute correction becomes a formal complaint.
So the checklist I actually give developers is less about the initial registration and more about what happens after it. First: treat the registration as a living document. Any material change — timeline, sanctioned plan, inventory — needs to be reflected with the authority, not just noted in an internal file somewhere. I promise it's a smaller headache to update than to explain later.
Second, and this is the one that causes real trouble: the escrow account. Funds from allottees have to sit in a designated account, and withdrawals need to track construction progress with proper certification. Loose bookkeeping here is, in my experience, the single most common reason a regulator starts looking closely at a project.
Third — and this one's easy to underestimate — is the public project page. Buyers treat it as gospel now, more than any brochure. Carpet area figures, promised amenities, delivery dates: if what's filed doesn't match what's marketed, that gap becomes the buyer's evidence in a dispute, not yours.
None of this is dramatic advice. It's procedural, almost boring — which is exactly why it works. Revisit the filing at every real milestone, and most of these disputes simply never get a chance to start.
Employment & Labour
20 February 2026
Employment Disputes in India: What Employers Should Know
Tanmay Bhoria, Co-Founder
Here's something that surprises most employers the first time they hear it: in the termination disputes I've worked on, the question almost never ends up being "was this the right call?" It's "can you prove it?" An employer can have every reason in the world to let someone go, and still lose, simply because nobody wrote anything down at the time.
Performance-based terminations are where this bites hardest. The issues are real, everyone in the room agrees the person wasn't performing — but eighteen months later, sitting in front of a court with no warnings, no reviews, no improvement plan on paper, a completely justified decision can start to look arbitrary. Contemporaneous documentation isn't a formality. It's the entire case.
Severance calculations are the quieter problem. The errors I see are almost never deliberate — they come from policies applied inconsistently across different employee categories, small differences that add up to real exposure. A written severance policy, applied the same way every time, protects you far better than a fair decision made ad hoc.
And then there's the non-compete clause employers reach for and discover, right when they need it, was drafted too broadly to actually enforce. A narrower, precisely scoped clause holds up. An aggressive one usually doesn't, and you only find out at the worst possible moment.
My honest advice, every time: build the paper trail before you need it. Nobody ever regrets having it. Plenty of people regret not having it.
Technology & Data Privacy
8 March 2026
Data Privacy Law in India: Getting Ready for Compliance
Nilendu Bhagat, Founder
Almost every business owner I talk to about data privacy asks a version of the same question: "we already have a privacy policy on the website — isn't that compliance?" I understand why they think that. It's also almost never true, and it's usually the first thing we have to gently correct.
Real compliance starts somewhere much less glamorous: a data mapping exercise. What personal data do you actually collect, where does it live, who can touch it, and why are you holding it at all? Almost every business I've walked through this with is surprised — sometimes uncomfortably so — by how much data they're sitting on with no clear reason to still have it. That alone is a liability, independent of anything else.
Consent is the next place things usually go wrong. It needs to be specific to a purpose and genuinely revocable, not one blanket "I agree" checkbox at signup that's expected to cover everything forever. If data collected for one reason quietly gets used for another — marketing analytics is the classic case — that generally needs its own, fresh consent.
The area businesses are least prepared for, without exception, is breach response. Not whether a breach might happen, but what happens in the first hour if it does. A documented plan — who's notified, on what timeline, who's responsible for what — isn't paperwork for its own sake. It materially changes your liability if the day ever comes.
The way I'd put it to any business, regardless of size: treat privacy as something your team actually does, with legal oversight — not a document your lawyer wrote once that nobody operationally follows.