StampMitraDevelopers
Legal & Policy Documentation

Developer Privacy Policy

Developer Platform, API & Developer Services | Version 1.0 | Operator: Bani Global Industries LLP (LLPIN: ACI6373) | Effective Date: 05/10/2026

1. Introduction

BANI GLOBAL INDUSTRIES LLP (“StampMitra”, “Company”, “we”, “us” or “our”) respects the privacy of individuals whose personal data is processed in connection with the StampMitra Developer Platform.

This Developer Privacy Policy (“Privacy Policy”) explains how StampMitra collects, receives, uses, stores, protects, discloses and otherwise processes personal data in connection with:

  • the StampMitra Developer Platform;
  • Developer Accounts;
  • Workspaces;
  • Projects;
  • Sandbox access;
  • Production access;
  • API credentials;
  • API usage;
  • developer documentation;
  • developer support;
  • billing;
  • security monitoring;
  • API logs;
  • webhooks;
  • communications;
  • verification processes; and
  • related developer services.

This Privacy Policy applies specifically to the Developer Platform and developer ecosystem and should be read together with the StampMitra Developer Terms of Service, Data Processing Addendum, API Acceptable Use Policy, API Security Policy and other applicable policies.

The Digital Personal Data Protection Act, 2023 establishes India's statutory framework concerning processing of digital personal data, including obligations concerning Data Fiduciaries and rights of Data Principals.

The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 13 November 2025 and provide detailed rules concerning implementation of the statutory framework. Their provisions have different commencement dates under the notified phased implementation schedule.

Accordingly, this Privacy Policy is intended to operate in accordance with applicable data-protection law as and when the relevant provisions become applicable to the processing concerned.

2. Important Distinction — Developer Data and API Data

StampMitra operates a developer/API platform. Consequently, different categories of personal data may be processed in different legal and operational capacities. This distinction is fundamental.

2.1 Developer Platform Data

When an individual creates or uses a Developer Account, StampMitra may determine the purposes and means of processing information necessary to operate the Developer Platform. Examples include:

  • name;
  • email address;
  • mobile number;
  • account credentials;
  • authentication information;
  • organization information;
  • billing information;
  • support communications;
  • security information; and
  • account activity.

For such processing, StampMitra may act as the relevant Data Fiduciary or equivalent controller under applicable law.

2.2 API Customer Data

A Developer may submit personal data belonging to its own customers, users, clients or other persons through StampMitra APIs. In such circumstances, the Developer may determine the purposes for which the information is collected and submitted.

Depending on the actual processing activity, StampMitra may act as:

  • a Data Processor;
  • a service provider;
  • a Data Fiduciary;
  • an independent controller; or
  • another legally recognized role.

The applicable role depends on the actual facts, purpose, contractual arrangement and applicable law.

StampMitra does not automatically assume that every item of information transmitted through an API is StampMitra's own customer data.

3. Who This Policy Applies To

This Policy applies to:

  • individual Developers;
  • freelancers;
  • consultants;
  • independent developers;
  • students and technical founders using the platform lawfully;
  • employees using an organizational Developer Account;
  • authorized representatives;
  • organizations;
  • API integration teams;
  • Workspace administrators;
  • Project members;
  • Production API users; and
  • persons interacting with the Developer Platform.

It may also apply to individuals whose personal data is processed incidentally through Developer Platform operations.

4. Corporate Identity

The entity responsible for the StampMitra Developer Platform is:

  • BANI GLOBAL INDUSTRIES LLP
  • LLPIN: ACI6373
  • Registered Office: 2-A/3, Kundan Mansion, Asaf Ali Road, Turkman Gate, Central Delhi, NCT of Delhi, India – 110002
  • Legal Contact: [email protected]

5. Categories of Personal Data We May Process

Depending upon how the Developer uses the Platform, StampMitra may process the following categories.

5.1 Identity Information

This may include:

  • full name;
  • username;
  • profile name;
  • organization name;
  • designation;
  • professional information;
  • identity-verification information where required.

5.2 Contact Information

This may include:

  • email address;
  • mobile number;
  • business telephone number;
  • correspondence address;
  • billing address;
  • registered office information where relevant.

5.3 Account Information

This may include:

  • account ID;
  • Workspace ID;
  • Project ID;
  • account status;
  • role;
  • permissions;
  • authentication records;
  • account creation date;
  • account configuration;
  • security settings.

5.4 Authentication Information

This may include:

  • password-related security information;
  • OTP verification records;
  • authentication timestamps;
  • login attempts;
  • authentication status;
  • token metadata;
  • credential identifiers;
  • recovery events.

StampMitra is not intended to store plaintext passwords where secure password-storage practices are technically applicable.

5.5 API Credential Information

This may include:

  • API Key identifiers;
  • credential creation dates;
  • credential status;
  • scope;
  • Project association;
  • last-used information;
  • rotation information;
  • revocation records.

Secret credential values may be protected through technical security controls and may not be displayed in full after creation where the Platform is designed accordingly.

6. Organization Information

Where an organization registers or requests Production access, StampMitra may process:

  • legal name;
  • entity type;
  • registered address;
  • business address;
  • authorized representative details;
  • website/domain;
  • tax information;
  • registration information;
  • business-use information;
  • expected API volume;
  • industry information;
  • technical information;
  • verification documentation.

The precise information required may vary according to the requested API and applicable compliance requirements.

7. Billing and Payment Information

Where paid services are used, StampMitra may process:

  • billing name;
  • billing address;
  • tax information;
  • invoice information;
  • transaction identifiers;
  • subscription information;
  • payment status;
  • payment-related metadata.

Where payment processing is performed by a third-party payment provider, StampMitra may receive only the information reasonably necessary to confirm and administer the transaction.

Payment-card credentials may be processed by the relevant payment service provider rather than being stored directly by StampMitra, where the relevant payment architecture operates that way.

8. API Request and Response Data

A Developer may submit information through APIs. Such information may include, depending on the API:

  • name;
  • mobile number;
  • email;
  • address;
  • identification information;
  • business information;
  • document information;
  • application information;
  • transaction information;
  • verification information;
  • e-Stamp-related information;
  • e-Sign-related information;
  • other information required by the relevant Service.

The Developer is responsible for ensuring that it has the lawful basis, authority, notice and permissions necessary to submit such information.

9. API Logs and Technical Data

StampMitra may collect technical information concerning API usage, including:

  • request timestamp;
  • response timestamp;
  • endpoint;
  • HTTP method;
  • status code;
  • request identifier;
  • Project identifier;
  • API credential identifier;
  • IP address;
  • user-agent;
  • latency;
  • request volume;
  • rate-limit events;
  • error information;
  • webhook events;
  • authentication events;
  • security events.

Where feasible and appropriate, StampMitra may minimize the storage of unnecessary personal data within operational logs.

10. IP Addresses

StampMitra may process IP addresses for:

  • authentication;
  • fraud detection;
  • security;
  • access control;
  • abuse prevention;
  • rate limiting;
  • troubleshooting;
  • audit;
  • compliance; and
  • operational analytics.

IP addresses may constitute personal data where they can reasonably be associated with an identifiable individual.

11. Device and Browser Information

When accessing the Developer Platform through a browser or supported device, StampMitra may receive technical information such as:

  • browser type;
  • operating system;
  • device type;
  • screen characteristics;
  • language;
  • timezone;
  • approximate technical location information;
  • referring page;
  • session information;
  • security-related device signals.

12. Cookies and Similar Technologies

StampMitra may use cookies and similar technologies to support:

  • authentication;
  • session management;
  • security;
  • preferences;
  • analytics;
  • performance;
  • fraud prevention;
  • Platform functionality.

Cookies may be:

  • essential;
  • functional;
  • analytical; or
  • other categories depending on implementation.

Where consent is legally required for a particular category of technology, StampMitra will use an appropriate consent or preference mechanism.

13. Information from the Developer

StampMitra may collect information directly from:

  • account registration forms;
  • Production applications;
  • verification forms;
  • API configuration;
  • support tickets;
  • emails;
  • billing interactions;
  • security reports;
  • documentation interactions;
  • surveys; and
  • other direct communications.

14. Information Generated Automatically

Certain information may be generated automatically when the Platform is used. Examples include:

  • login events;
  • API usage records;
  • system events;
  • error logs;
  • security events;
  • performance metrics;
  • transaction references;
  • credential activity;
  • configuration changes.

15. Information Received from Third Parties

Where necessary and lawful, StampMitra may receive information from:

  • payment service providers;
  • identity-verification providers;
  • security providers;
  • fraud-prevention services;
  • communication providers;
  • business verification sources;
  • authorized service providers;
  • public or lawful data sources;
  • contractual partners.

16. Purposes of Processing

StampMitra may process personal data for the following purposes.

16.1 Account Creation

To:

  • create Developer Accounts;
  • authenticate users;
  • administer accounts;
  • provide account access;
  • manage Workspaces and Projects.

16.2 API Provisioning

To:

  • activate APIs;
  • generate credentials;
  • authorize requests;
  • enforce API scopes;
  • administer environments;
  • process requests;
  • return responses.

16.3 Production Verification

To evaluate:

  • identity;
  • business information;
  • use case;
  • API requirements;
  • expected volume;
  • security requirements;
  • compliance requirements.

16.4 Security

To:

  • detect unauthorized access;
  • identify credential compromise;
  • prevent fraud;
  • prevent abuse;
  • investigate attacks;
  • protect infrastructure;
  • enforce access controls.

16.5 Service Operation

To:

  • operate APIs;
  • maintain infrastructure;
  • troubleshoot errors;
  • manage capacity;
  • monitor performance;
  • maintain reliability.

16.6 Billing

To:

  • calculate charges;
  • issue invoices;
  • reconcile transactions;
  • administer subscriptions;
  • investigate billing disputes.

16.7 Customer and Developer Support

To:

  • respond to support requests;
  • investigate incidents;
  • troubleshoot integrations;
  • communicate service updates.

16.8 Legal and Compliance

To:

  • comply with applicable law;
  • respond to lawful requests;
  • maintain required records;
  • enforce contractual rights;
  • establish, exercise or defend legal claims.

17. Legal Basis / Permitted Processing

StampMitra will process personal data only where permitted by applicable law.

Depending upon the applicable legal framework and the nature of processing, processing may be based on:

  • consent;
  • specified legitimate or lawful uses;
  • performance of a requested service;
  • compliance with legal obligations;
  • contractual necessity;
  • security and fraud-prevention requirements;
  • other legally recognized grounds.

The precise legal basis may vary depending upon the processing activity and the law applicable at the relevant time.

The DPDP Act contains provisions addressing grounds for processing, notice, consent and certain legitimate uses.

18. Notice and Transparency

Where applicable, StampMitra will provide appropriate notice concerning:

  • categories of personal data;
  • purposes of processing;
  • means of exercising applicable rights;
  • contact mechanisms;
  • other information required by law.

Notices may be provided through:

  • this Privacy Policy;
  • account interfaces;
  • API documentation;
  • consent screens;
  • service-specific notices;
  • contractual documentation.

19. Consent

Where consent is the applicable legal basis, StampMitra will seek consent through an appropriate mechanism.

Consent mechanisms may include:

  • checkboxes;
  • electronic confirmations;
  • account settings;
  • consent screens;
  • API workflow authorization.

Where required by applicable law, consent mechanisms should permit withdrawal through an appropriate process.

Withdrawal of consent does not necessarily invalidate processing lawfully carried out before withdrawal.

20. Developer Responsibility for End-User Consent

Where a Developer collects personal data from its own End Users and submits it to StampMitra, the Developer is responsible for ensuring that:

  • appropriate notice has been provided;
  • required consent has been obtained;
  • the collection is lawful;
  • the intended use has been communicated;
  • the submission is authorized;
  • applicable data-principal rights can be supported.

StampMitra may require evidence of appropriate authorization where reasonably necessary.

21. Data Minimization

StampMitra seeks to process personal data that is reasonably necessary for the relevant purpose.

Developers must not submit unnecessary personal data through APIs. Developers should avoid transmitting:

  • unrelated personal information;
  • excessive document contents;
  • unnecessary identifiers;
  • unrelated sensitive information; or
  • information not required by the relevant API.

22. Accuracy

Developers should ensure that personal data submitted through the Platform is accurate and current where accuracy is relevant to the requested Service.

StampMitra may rely on information supplied by the Developer or external sources and may not independently verify every item.

23. Purpose Limitation

Personal data should be used only for purposes permitted under applicable law and the relevant contractual arrangement.

StampMitra shall not intentionally use Developer-submitted personal data for unrelated purposes merely because the data is technically accessible.

24. Children's Data

A child is defined under the DPDP Act as an individual who has not completed eighteen years of age.

The Developer must not submit children's personal data unless:

  • the relevant API expressly permits such processing; and
  • all legally required conditions are satisfied.

Where processing children's data is permitted, additional safeguards may apply.

StampMitra may restrict or refuse processing where the required conditions are not satisfied.

25. Sensitive or High-Risk Information

Developers should not submit sensitive or high-risk personal information unless the relevant API expressly requires or permits it. Examples may include:

  • financial credentials;
  • authentication secrets;
  • passwords;
  • biometric information;
  • highly sensitive identity information;
  • health information;
  • private communications.

Where a Service legitimately requires specific information, the Developer must follow the Service-specific requirements.

26. Identity Documents

Where an API requires identity documentation, StampMitra may process information appearing on such documents.

The Developer must ensure that:

  • submission is lawful;
  • the person has been appropriately informed;
  • only required documents are submitted;
  • documents are submitted through authorized channels.

Developers must not upload fabricated, altered or fraudulently obtained documents.

27. e-Stamp and Document Data

Where the Developer uses e-Stamp or document-related APIs, personal data may appear within:

  • party information;
  • address information;
  • transaction information;
  • instrument information;
  • document content;
  • identification information.

Such data may be processed to provide the requested Service and for associated legal, operational, security and audit purposes.

28. e-Sign Data

Where e-Sign functionality is used, processing may include information necessary to:

  • identify the signer;
  • initiate signing;
  • authenticate the signer;
  • complete the signing workflow;
  • maintain transaction records;
  • demonstrate transaction integrity.

Additional service-specific terms may apply.

29. Data Sharing

StampMitra may disclose or make personal data available to categories of recipients where reasonably necessary and lawful, including:

  • infrastructure providers;
  • cloud service providers;
  • payment providers;
  • communication providers;
  • security providers;
  • verification providers;
  • technology vendors;
  • authorized service providers;
  • professional advisers;
  • auditors;
  • legal advisers;
  • regulators;
  • governmental authorities;
  • law-enforcement agencies where legally required.

30. Underlying Service Providers

StampMitra may use Underlying Service Providers to provide certain APIs and Services.

Such providers may process information required to perform the relevant transaction.

StampMitra may not publicly disclose the identity or commercial arrangements of specific upstream providers where such information is confidential.

The absence of public disclosure does not prevent StampMitra from using appropriate service providers to perform the contracted Service.

31. Confidential Upstream Architecture

Developers shall not assume that an API response identifies every organization involved in the underlying processing chain.

Technical architecture may involve multiple systems and service providers.

StampMitra may abstract upstream providers through its API layer to provide a unified developer experience.

32. Data Processors and Subprocessors

StampMitra may engage third parties to process personal data on its behalf where permitted by applicable law. Such parties may provide:

  • cloud hosting;
  • infrastructure;
  • databases;
  • monitoring;
  • communications;
  • security;
  • analytics;
  • support;
  • document processing;
  • payment services.

Where legally required, appropriate contractual and technical controls shall be applied.

33. International Processing

Personal data may be processed or stored outside India where legally permitted and where appropriate safeguards or conditions apply.

Where the DPDP Act or applicable rules impose restrictions on processing personal data outside India, StampMitra shall comply with the applicable restrictions.

The DPDP Act expressly addresses processing of personal data outside India and permits the Central Government to impose restrictions concerning such processing.

34. Data Security

StampMitra implements reasonable technical and organizational measures appropriate to the risks associated with the processing. Measures may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • authentication controls;
  • access control;
  • role-based permissions;
  • credential protection;
  • network security;
  • logging;
  • monitoring;
  • backup controls;
  • vulnerability management;
  • incident response;
  • secure development practices.

No information system can guarantee absolute security.

35. API Security

StampMitra may implement:

  • API authentication;
  • API Keys;
  • OAuth or equivalent mechanisms where applicable;
  • rate limits;
  • IP allowlists;
  • scopes;
  • request validation;
  • abuse detection;
  • anomaly detection;
  • webhook authentication;
  • credential rotation.

Security controls may differ by API.

36. Data Breach and Security Incidents

Where a personal-data breach occurs, StampMitra will respond in accordance with applicable law and its incident-response procedures.

Depending on the circumstances, response may include:

  • containment;
  • investigation;
  • impact assessment;
  • remediation;
  • credential rotation;
  • notification to relevant parties;
  • regulatory reporting;
  • cooperation with affected Developers.

Where StampMitra processes data on behalf of a Developer, contractual DPA requirements may govern notification and cooperation.

37. Data Retention

StampMitra does not retain personal data indefinitely merely because it was once collected.

Retention periods may depend upon:

  • purpose;
  • nature of data;
  • contractual requirements;
  • legal obligations;
  • security requirements;
  • audit requirements;
  • dispute resolution;
  • financial/accounting requirements;
  • fraud prevention;
  • regulatory requirements.

Different data categories may therefore have different retention periods.

38. API Log Retention

API logs may be retained for periods reasonably necessary for:

  • security;
  • troubleshooting;
  • abuse prevention;
  • billing;
  • audit;
  • compliance;
  • dispute resolution.

Specific retention periods may vary by log category and system.

39. Account Retention

Closing or deleting a Developer Account does not necessarily result in immediate deletion of every record.

Certain information may be retained where necessary for:

  • legal compliance;
  • tax/accounting obligations;
  • security;
  • fraud prevention;
  • contractual enforcement;
  • dispute resolution;
  • regulatory requirements.

40. Backups

Deleted information may remain temporarily within secure backup systems.

Backup retention is governed by operational and security requirements.

Where appropriate, expired information may be removed through normal backup rotation rather than immediate physical deletion from every backup copy.

41. Data Deletion

Where deletion is legally required and technically appropriate, StampMitra may delete or anonymize personal data.

Deletion may be subject to:

  • legal retention;
  • contractual requirements;
  • active disputes;
  • fraud investigations;
  • security requirements;
  • backup cycles.

42. Data Anonymization

StampMitra may use anonymized or aggregated information for legitimate purposes such as:

  • service analytics;
  • performance analysis;
  • capacity planning;
  • security research;
  • product improvement.

Where information is genuinely anonymized so that an individual is no longer identifiable, it may no longer constitute personal data under applicable law.

43. Data Principal Rights

Subject to applicable law, a Data Principal may have rights relating to personal data, including rights concerning:

  • access to information;
  • correction;
  • erasure;
  • grievance redressal;
  • nomination;
  • consent management where applicable.

The DPDP Act expressly provides for rights of access, correction and erasure, grievance redressal and nomination.

The availability, scope and implementation of such rights depend upon the relevant legal provisions being applicable to the processing at the time of the request.

44. Requesting Correction

Where applicable, an individual may request correction of inaccurate personal data.

StampMitra may require reasonable information to verify the identity and authority of the requester.

45. Requesting Erasure

Where applicable, an individual may request erasure of personal data.

Erasure may not be immediate where retention is legally required or otherwise permitted.

46. Grievance Redressal

Privacy-related grievances may be submitted to: Legal Team, BANI GLOBAL INDUSTRIES LLP — Email: [email protected]

The grievance should include sufficient information to enable investigation, including where appropriate:

  • name;
  • contact details;
  • account identifier;
  • relevant Project;
  • nature of concern;
  • relevant dates;
  • supporting information.

47. Identity Verification for Rights Requests

To protect individuals from unauthorized disclosure, StampMitra may take reasonable steps to verify the identity of a person making a privacy request.

StampMitra will seek to avoid collecting unnecessary information solely for verification.

48. Developer-Submitted Data Rights Requests

Where the Developer is responsible for personal data submitted through an API, the Developer should ordinarily manage Data Principal requests concerning that data.

StampMitra may provide reasonable assistance where required by the applicable contractual arrangement or law.

The DPA may establish detailed procedures for such requests.

49. Third-Party Requests

A person may not automatically obtain another person's personal data merely by claiming to be that person's representative.

StampMitra may require evidence of authority where legally appropriate.

50. Government and Law-Enforcement Requests

StampMitra may disclose personal data where required by:

  • court order;
  • lawful government direction;
  • regulatory requirement;
  • statutory obligation;
  • law-enforcement request having appropriate legal authority.

Where legally permissible, StampMitra may notify the relevant Developer or individual.

51. Legal Claims and Disputes

Personal data may be retained or processed where reasonably necessary to:

  • establish legal rights;
  • defend claims;
  • investigate fraud;
  • enforce agreements;
  • resolve disputes;
  • comply with court proceedings.

52. Marketing Communications

StampMitra may send service-related communications necessary for operating Developer Accounts. These may include:

  • OTPs;
  • security alerts;
  • credential notifications;
  • API status notifications;
  • billing communications;
  • important policy updates;
  • service notices.

Marketing communications, where used, will be subject to applicable law and available preferences.

53. Service Communications

Certain communications cannot necessarily be unsubscribed from because they are required for the operation or security of the Developer Account. Examples include:

  • password/security alerts;
  • account verification;
  • Production access decisions;
  • billing notices;
  • critical service changes;
  • security incident notifications.

54. Analytics

StampMitra may use analytics to understand:

  • Platform performance;
  • API reliability;
  • developer adoption;
  • feature usage;
  • error patterns;
  • operational performance.

Where analytics involves personal data, it shall be processed subject to applicable law and appropriate safeguards.

55. Automated Systems

StampMitra may use automated systems for:

  • fraud detection;
  • abuse prevention;
  • anomaly detection;
  • security monitoring;
  • rate-limit enforcement;
  • operational diagnostics.

Automated systems may generate alerts or restrictions requiring further review.

56. No Sale of Developer Personal Data

StampMitra does not intend to sell Developer personal data as a commercial product.

Nothing in this statement prevents lawful disclosures or processing necessary to:

  • provide Services;
  • use authorized service providers;
  • comply with law;
  • process payments;
  • prevent fraud;
  • enforce contracts;
  • provide requested functionality.

57. No Unauthorized Commercialization of API Data

StampMitra shall not treat personal data submitted through an API as freely reusable commercial inventory.

Use of such data is governed by:

  • the applicable Service;
  • contractual arrangements;
  • applicable law;
  • security requirements;
  • the relevant processing purpose.

58. Developer Responsibility for Data

The Developer remains responsible for ensuring that data submitted through its integration is:

  • lawfully obtained;
  • necessary;
  • accurate where required;
  • appropriately authorized;
  • properly disclosed to the relevant person;
  • not unlawfully excessive.

59. Unlawful Data Submission

StampMitra may reject, restrict or suspend processing where it reasonably believes submitted information involves:

  • fraud;
  • unlawful surveillance;
  • unauthorized identity verification;
  • stolen data;
  • malicious activity;
  • unlawful profiling;
  • prohibited information;
  • regulatory violations.

60. Data Transfers Between Systems

Personal data may move between:

  • Developer applications;
  • StampMitra APIs;
  • internal StampMitra services;
  • databases;
  • security systems;
  • authorized service providers;
  • underlying service providers.

Such transfers are performed to the extent reasonably necessary to provide the relevant Service and subject to applicable controls.

61. Webhook Data

Where webhook functionality is enabled, Developers may receive event information from StampMitra.

The Developer is responsible for securing its webhook endpoint and appropriately protecting any personal data received through it.

62. Developer Security Obligations

Developers must:

  • protect API credentials;
  • restrict internal access;
  • use HTTPS where applicable;
  • validate webhook authenticity;
  • prevent unauthorized access;
  • avoid unnecessary data retention;
  • securely delete information when no longer required;
  • maintain appropriate security controls.

63. Third-Party Links

The Developer Platform may contain links to third-party websites or services.

StampMitra is not responsible for the privacy practices of independently operated third-party websites.

Developers should review the privacy policies of third parties before providing personal data.

64. Third-Party Applications

A Developer may connect external applications to StampMitra.

StampMitra is not responsible for privacy practices outside systems controlled by StampMitra.

Developers should evaluate:

  • third-party permissions;
  • data access;
  • retention;
  • security;
  • contractual terms.

65. International Developers

Developers outside India may access the Developer Platform where supported.

Such Developers remain responsible for complying with laws applicable to their own collection and processing of personal data.

Additional contractual terms may apply to international use.

66. Cross-Border Data Compliance

Where processing involves international transfers, StampMitra may implement additional contractual, technical or organizational measures where required. Such measures may include:

  • contractual safeguards;
  • transfer restrictions;
  • access controls;
  • encryption;
  • data-location controls.

67. Employee and Contractor Access

Access to personal data within StampMitra is restricted according to operational need.

Employees and contractors may receive access where necessary to:

  • operate Services;
  • provide support;
  • investigate incidents;
  • maintain infrastructure;
  • perform legal/compliance functions.

Access may be subject to confidentiality obligations.

68. Access Control

StampMitra may implement:

  • role-based access;
  • least-privilege controls;
  • authentication;
  • privileged-access controls;
  • audit logging;
  • credential management.

69. Security Auditing

StampMitra may periodically assess its systems and controls to identify:

  • vulnerabilities;
  • excessive permissions;
  • unusual activity;
  • configuration weaknesses;
  • security gaps.

70. Data Breach Cooperation

Where API-submitted personal data is involved in an incident, StampMitra and the Developer may cooperate in accordance with the applicable DPA and law.

Cooperation may include:

  • incident details;
  • affected data categories;
  • affected records;
  • containment measures;
  • remediation;
  • notification support.

71. Privacy by Design

StampMitra seeks to incorporate privacy considerations into:

  • API architecture;
  • access controls;
  • data flows;
  • logging;
  • product development;
  • security processes.

72. Data Protection Impact Assessment

Where required by applicable law or appropriate based on risk, StampMitra may conduct privacy or data-protection assessments for relevant processing activities.

73. Significant Data Fiduciary Requirements

Where StampMitra becomes subject to additional obligations applicable to a Significant Data Fiduciary or equivalent category, it shall implement applicable requirements.

Such requirements may include enhanced governance, security, assessment and accountability measures.

74. Changes to Processing

If StampMitra materially changes how personal data is processed, it may update:

  • this Privacy Policy;
  • relevant notices;
  • consent mechanisms;
  • contractual documentation;
  • API documentation.

75. Changes to This Privacy Policy

StampMitra may amend this Privacy Policy from time to time.

Material changes may be communicated through:

  • the Developer Platform;
  • email;
  • account notifications;
  • website notices;
  • other appropriate communication channels.

The “Last Updated” date identifies the current version.

76. Continued Use

Where continued use constitutes legally valid acceptance of updated terms or notices, continued use after the applicable effective date may constitute acceptance to the extent permitted by law.

Where affirmative consent or another legally required mechanism is necessary, StampMitra will use the appropriate mechanism.

77. Retention of Previous Versions

StampMitra may retain previous versions of Privacy Policies for:

  • compliance;
  • audit;
  • dispute resolution;
  • historical reference;
  • evidentiary purposes.

78. Privacy and Developer Terms

This Privacy Policy should be read together with the StampMitra Developer Terms of Service.

The Terms establish the contractual framework, while this Policy describes personal-data processing practices.

79. Privacy and DPA

Where a Developer enters into a Data Processing Addendum with StampMitra, the DPA governs processing relationships addressed specifically by that DPA.

The DPA may contain additional provisions concerning:

  • processing instructions;
  • security;
  • subprocessors;
  • data-subject requests;
  • breach notifications;
  • deletion;
  • audits;
  • international transfers.

80. Policy Hierarchy

Where this Privacy Policy conflicts with a mandatory legal requirement, the mandatory legal requirement shall prevail.

Where this Privacy Policy conflicts with a specific DPA concerning processing undertaken under that DPA, the DPA shall govern to the extent of the conflict.

81. Legal Compliance

This Policy shall be interpreted consistently with applicable Indian law, including applicable provisions of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as they become applicable.

The DPDP framework expressly permits different provisions to commence on different dates, and the Government's notification provides an 18-month phased implementation structure.

Accordingly, references in this Policy to obligations that are not yet legally operative shall not be interpreted as incorrectly asserting that every provision is already enforceable as of the Policy's publication date.

StampMitra may voluntarily implement controls ahead of mandatory commencement where commercially, technically or operationally appropriate.

82. Governing Law

This Privacy Policy shall be governed by applicable laws of India.

Nothing in this Policy limits rights or protections that cannot lawfully be excluded.

83. Contact Information

For privacy, data-protection and legal matters:

  • Legal Team, BANI GLOBAL INDUSTRIES LLP
  • LLPIN: ACI6373
  • Registered Office: 2-A/3, Kundan Mansion, Asaf Ali Road, Turkman Gate, Central Delhi, NCT of Delhi, India – 110002
  • Email: [email protected]

84. Privacy Grievance Process

A privacy grievance should include, where available:

  • requester's full name;
  • email/mobile number;
  • Developer Account ID;
  • relevant Project or Workspace;
  • description of the issue;
  • nature of the personal-data concern;
  • relevant dates;
  • supporting documentation.

StampMitra may request reasonable additional information necessary to investigate the matter.

85. Response and Investigation

StampMitra will handle privacy requests and grievances according to applicable legal requirements and its internal procedures.

The response time may depend upon:

  • nature of request;
  • complexity;
  • identity verification;
  • applicable law;
  • information required from third parties;
  • whether the request concerns Developer-controlled data.

86. Fraudulent Requests

StampMitra may reject or restrict requests where it reasonably believes the requester:

  • is impersonating another person;
  • lacks authority;
  • provides fraudulent documentation;
  • seeks unauthorized disclosure;
  • is attempting to circumvent security controls.

87. Data Protection Contact

For purposes of privacy and data-protection communication, the designated contact is: Legal Team — BANI GLOBAL INDUSTRIES LLP, Email: [email protected]

If StampMitra appoints a dedicated Data Protection Officer, Grievance Officer or other statutory privacy officer where required, the relevant designation and contact details may be published through the Developer Platform or an updated version of this Policy.

88. No Waiver of Statutory Rights

Nothing in this Privacy Policy is intended to:

  • unlawfully restrict statutory rights;
  • waive mandatory protections;
  • exclude a regulator's jurisdiction;
  • prevent a lawful complaint;
  • restrict a Data Principal from exercising a right that cannot legally be restricted.

89. Severability

If any provision of this Privacy Policy is held invalid, unlawful or unenforceable, the remaining provisions shall continue to the extent permitted by law.

90. Record of Policy

  • Policy: StampMitra Developer Privacy Policy
  • Document Type: Developer Platform Privacy Policy
  • Version: 1.0
  • Status: FINAL — PUBLISHED POLICY
  • Effective Date: 05 October 2026
  • Last Updated: 05 October 2026
  • Legal Entity: BANI GLOBAL INDUSTRIES LLP
  • LLPIN: ACI6373
  • Registered Office: 2-A/3, Kundan Mansion, Asaf Ali Road, Turkman Gate, Central Delhi, NCT of Delhi, India – 110002
  • Developer Platform: developer.stampmitra.in
  • Legal Contact: [email protected]
  • Prepared by: Legal Team, BANI GLOBAL INDUSTRIES LLP

91. Final Privacy Statement

StampMitra is committed to responsible processing of personal data and to maintaining appropriate technical, organizational and contractual safeguards for information processed through its Developer Platform.

The Platform is designed to provide Developers with controlled access to StampMitra APIs while maintaining appropriate separation between:

  • Developer Account information;
  • operational and security information;
  • Developer-submitted API data;
  • billing information;
  • service-specific information; and
  • confidential upstream service relationships.

Nothing in this Policy authorizes a Developer to submit personal data unlawfully, and nothing in this Policy requires StampMitra to disclose confidential information concerning its underlying commercial or technical service relationships.

BANI GLOBAL INDUSTRIES LLP reserves the right to update this Policy as required by changes in law, regulation, technology, security requirements, business operations or the StampMitra Developer Platform.

© 2026 BANI GLOBAL INDUSTRIES LLP. All rights reserved.

Prepared by: Legal Team — [email protected]

Build with AI

Integrate StampMitra with one copy-paste prompt.

Ready-made prompts for the tools you already use. They know our endpoints, auth and response shapes.