StampMitraStampMitra Developers
Legal & Policy Documentation

Privacy Policy

Platform: Stamp Mitra · Operated by: Bani Global Industries LLP · Effective Date: 22 April 2026 · Version: 2.0

PART 1 – INTRODUCTION, DEFINITIONS, SCOPE & LEGAL FRAMEWORK

1. INTRODUCTION

1.1 About this Privacy Policy

This Privacy Policy ("Privacy Policy", "Policy") explains how Bani Global Industries LLP, the owner and operator of the Stamp Mitra platform ("Stamp Mitra", "Platform", "Website", "Application", "we", "our", or "Company"), collects, receives, records, stores, processes, uses, shares, discloses, transfers, secures, retains, and otherwise handles Personal Data and other information relating to individuals who access or use the Platform.

This Privacy Policy forms an integral part of the Platform's Terms of Use and governs all interactions between the Company and any person who accesses, browses, registers, purchases, uploads documents, submits information, communicates with customer support, or otherwise uses any service made available through Stamp Mitra.

By accessing or using the Platform, creating an account, placing an order, uploading any document, submitting any information, or otherwise interacting with the Platform, you acknowledge that you have read, understood, and agreed to this Privacy Policy.

If you do not agree with any provision of this Privacy Policy, you should immediately discontinue the use of the Platform and refrain from submitting any Personal Data.

1.2 About Stamp Mitra

Stamp Mitra is a privately operated legal technology and business services platform owned and managed by Bani Global Industries LLP, established under the laws of India.

The Platform facilitates access to a wide range of legal, regulatory, compliance, documentation, registration, and business support services including, but not limited to:

  • Procurement of physical and electronic stamp papers;
  • Drafting and preparation of legal documents;
  • Affidavits, declarations, agreements and contracts;
  • Notarial coordination and related facilitation;
  • Company incorporation services;
  • Limited Liability Partnership (LLP) registration;
  • One Person Company (OPC) incorporation;
  • Partnership firm registration;
  • GST registration and related compliance services;
  • Trademark, copyright and intellectual property filings;
  • Virtual office services (previously offered directly through Stamp Mitra; now offered under the Vecta Spaces brand, operated by Bani Global Industries LLP);
  • Business registrations and licensing;
  • Tax and regulatory compliance assistance;
  • eSign and digital documentation services;
  • Business advisory and consultancy;
  • Government filing facilitation;
  • Customer support and document management;
  • Online payment collection;
  • Digital verification and identity validation;
  • AI-powered customer assistance and automation features;
  • Other services introduced by the Company from time to time.

The scope of this Privacy Policy extends to all existing and future services offered through the Platform unless expressly stated otherwise.

1.3 Commitment to Privacy

The Company recognizes the importance of protecting the privacy, confidentiality, integrity, and security of Personal Data entrusted to it.

We are committed to processing Personal Data responsibly, lawfully, transparently, and fairly while implementing reasonable technical and organizational safeguards designed to protect such information against unauthorized access, misuse, alteration, disclosure, destruction, or accidental loss.

Privacy protection is incorporated into our operational processes, technology infrastructure, vendor management practices, and customer service operations.

2. DEFINITIONS

Unless the context otherwise requires, the following expressions shall have the meanings assigned below.

2.1 "Account"

Means the registered user profile created on the Platform for accessing services.

2.2 "Applicable Laws"

Means all laws, statutes, regulations, notifications, circulars, governmental guidelines, judicial decisions, rules, and legally enforceable directives applicable in India from time to time.

2.3 "Business Information"

Means information relating to any business entity including but not limited to:

  • Company name
  • LLP details
  • GSTIN
  • PAN
  • CIN
  • LLPIN
  • Registered office
  • Directors
  • Partners
  • Shareholders
  • Authorized signatories
  • Proprietor details
  • Business licenses
  • Registration certificates
  • Financial information relating to business operations.

2.4 "Consent"

Means any free, specific, informed, unconditional, and unambiguous indication by the User signifying agreement to the processing of Personal Data for one or more specified purposes.

Where applicable under law, consent may be obtained electronically through checkboxes, OTP verification, digital signatures, click-wrap agreements, electronic confirmations, or other lawful electronic means.

2.5 "Customer"

Means any natural person, business entity, organization, partnership, LLP, company, trust, association, government body, or other legal entity using the Platform.

2.6 "Personal Data"

Means any information relating to an identified or identifiable natural person including any information that can directly or indirectly identify such individual either alone or in combination with other information.

2.7 "Processing"

Means any operation performed upon Personal Data including collection, recording, organization, storage, adaptation, retrieval, consultation, use, transmission, disclosure, dissemination, alignment, restriction, erasure, destruction, anonymization, or any combination thereof.

2.8 "Platform"

Means the Stamp Mitra website, mobile applications, customer portals, dashboards, APIs, software, digital interfaces, communication systems, and associated online services operated by the Company.

2.9 "Services"

Means every service offered through Stamp Mitra including future services introduced after publication of this Privacy Policy.

2.10 "User"

Means any individual or entity accessing or using the Platform whether registered or unregistered.

2.11 "Vendor"

Means any third-party service provider, consultant, technology provider, legal professional, payment processor, cloud provider, document processor, logistics provider, customer support provider, government-authorized intermediary, or other authorized partner engaged by the Company.

3. APPLICABILITY OF THIS POLICY

This Privacy Policy applies to:

  • Visitors browsing the Platform;
  • Registered account holders;
  • Customers purchasing services;
  • Business entities;
  • Corporate clients;
  • Government filing applicants;
  • Existing or historical Virtual Office customers (Virtual Office is now offered under the Vecta Spaces brand);
  • Vendors interacting through the Platform;
  • Individuals contacting customer support;
  • Persons submitting KYC documents;
  • Persons participating in promotional campaigns;
  • Users of APIs and software integrations;
  • Mobile application users;
  • Website visitors;
  • AI-assisted chat users;
  • Live chat users;
  • Future products and services introduced by the Company.

This Policy applies regardless of the device used to access the Platform, including desktop computers, laptops, mobile devices, tablets, smart devices, kiosks, APIs, or other internet-enabled systems.

4. LEGAL FRAMEWORK

The Company processes Personal Data in accordance with applicable Indian laws and internationally accepted privacy principles wherever applicable.

Without limitation, this Policy is intended to align with:

  • The Digital Personal Data Protection Act, 2023, as amended from time to time;
  • The Information Technology Act, 2000;
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, where applicable;
  • The Indian Contract Act, 1872;
  • The Indian Evidence Act, 1872, including provisions relating to electronic records and electronic evidence;
  • The Consumer Protection Act, 2019;
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, where applicable;
  • Applicable taxation laws, anti-money laundering requirements, company law, LLP law, GST regulations, and other statutory obligations governing the services offered by the Platform.

Where any provision of this Privacy Policy conflicts with mandatory legal requirements, the applicable law shall prevail to the extent of such inconsistency.

5. ACCEPTANCE OF THIS PRIVACY POLICY

By accessing or using the Platform, creating an account, submitting any information, uploading any document, placing an order, completing an online payment, communicating with customer support, using AI-powered assistance, or otherwise availing any service provided by the Company, the User expressly acknowledges and agrees that:

  1. the User has read and understood this Privacy Policy;
  2. the User voluntarily provides the information requested by the Platform;
  3. the User authorizes the Company to collect, process, store, share, retain, and otherwise use such information for the purposes described herein;
  4. the User understands that certain services cannot be provided without the collection and processing of necessary information;
  5. where the User provides information relating to another individual, the User confirms that they possess the lawful authority to disclose such information to the Company and have obtained all required permissions or consents;
  6. continued use of the Platform after any amendment to this Privacy Policy shall constitute acceptance of the revised Privacy Policy, unless applicable law requires fresh consent.

6. INFORMATION WE COLLECT

6.1 General

In order to provide, improve, maintain, secure, and lawfully operate the Platform and the Services, the Company may collect, receive, generate, verify, record, store, process, and otherwise handle various categories of information relating to Users.

The nature and extent of information collected may vary depending upon the Services requested, applicable legal requirements, the User's interactions with the Platform, and the permissions granted by the User.

The Company shall collect only such information as is reasonably necessary for legitimate business purposes, legal compliance, contractual obligations, fraud prevention, service delivery, customer support, and operational efficiency.

7. PERSONAL INFORMATION

Depending upon the Services utilized, the Company may collect one or more of the following categories of Personal Data.

7.1 Identity Information

This may include, without limitation:

  • Full Name
  • Father's Name
  • Mother's Name
  • Date of Birth
  • Gender
  • Photograph
  • Signature
  • Nationality
  • Residential Status
  • Occupation
  • Profession
  • Marital Status (where legally required)
  • Customer Identification Number (if generated)
  • User ID
  • Username
  • Profile Photograph

7.2 Contact Information

The Company may collect:

  • Mobile Number
  • Alternate Mobile Number
  • Landline Number
  • Email Address
  • Alternate Email Address
  • Residential Address
  • Correspondence Address
  • Office Address
  • Registered Office Address
  • Communication Preferences
  • Preferred Language
  • State
  • District
  • City
  • Postal Code
  • Country

7.3 Government Identification Information

Where legally required for providing particular Services, the Company may collect information relating to government-issued identification documents including:

  • Permanent Account Number (PAN)
  • Aadhaar Number (where legally permitted)
  • Passport Details
  • Driving Licence
  • Voter Identity Card
  • Any other Government-issued Identification

The Company shall collect only such identification documents as are necessary for lawful verification, compliance, regulatory filings, identity validation, fraud prevention, or as otherwise required under applicable law.

8. BUSINESS INFORMATION

For business registration, incorporation, compliance, taxation, licensing, intellectual property, and other corporate services, the Company may collect information including:

  • Company Name
  • LLP Name
  • Proprietorship Details
  • Partnership Firm Details
  • LLPIN
  • CIN
  • GSTIN
  • PAN
  • TAN
  • Registered Office Address
  • Principal Place of Business
  • Nature of Business
  • Date of Incorporation
  • Authorized Capital
  • Paid-up Capital
  • Shareholding Pattern
  • Partner Details
  • Director Details
  • Designated Partner Details
  • Shareholder Information
  • Beneficial Ownership Information
  • Business Contact Details
  • Bank Account Information
  • Cancelled Cheque
  • Registration Certificates
  • Licenses
  • Trade Licenses
  • Shops and Establishment Certificates
  • Professional Tax Registration
  • Import Export Code
  • MSME Registration
  • Startup India Registration
  • FSSAI Registration
  • Other statutory registrations as applicable.

9. KYC INFORMATION

For compliance with applicable laws and verification requirements, the Company may collect Know Your Customer (KYC) information including:

  • PAN Card
  • Aadhaar Card (where legally permissible)
  • Passport
  • Utility Bills
  • Electricity Bill
  • Telephone Bill
  • Bank Statement
  • Rent Agreement
  • Sale Deed
  • Passport-sized Photograph
  • Signature
  • Live Selfie (where verification requires)
  • Video Verification (where legally permitted)
  • Proof of Registered Office
  • Identity Proof
  • Address Proof
  • Digital Verification Records

The Company may also verify such information through authorized third-party verification providers where legally permitted.

10. DOCUMENT INFORMATION

The Company may receive and process documents uploaded by Users including:

  • Stamp Paper Applications
  • Affidavits
  • Agreements
  • Contracts
  • Memorandum of Understanding
  • Power of Attorney
  • Lease Agreements
  • Sale Deeds
  • Gift Deeds
  • Indemnity Bonds
  • Declarations
  • Legal Notices
  • Partnership Deeds
  • Incorporation Documents
  • GST Documents
  • Trademark Documents
  • Copyright Applications
  • Government Forms
  • Identity Documents
  • Business Documents
  • Court Documents
  • Supporting Evidence
  • Attachments submitted through customer support

Users are solely responsible for ensuring that documents uploaded are accurate, lawful, and do not infringe the rights of third parties.

11. VIRTUAL OFFICE INFORMATION (EXISTING / HISTORICAL SUBSCRIBERS)

For Users who previously availed Virtual Office Services directly through Stamp Mitra, or who continue to hold an active Virtual Office subscription originated through the Platform, additional information may have been collected, including:

  • Business Registration Details
  • Director or Partner Information
  • Authorized Occupant Information
  • Mail Handling Preferences
  • Courier Details
  • Office Use Authorization
  • Government Filing Information
  • KYC Documentation
  • Postal Instructions
  • Contact Persons
  • Authorized Representatives
  • Business Activity Details

Virtual Office is now offered under the Vecta Spaces brand, operated by Bani Global Industries LLP.

12. PAYMENT INFORMATION

The Company may collect transaction-related information including:

  • Payment Status
  • Transaction Reference Number
  • Order Value
  • Invoice Details
  • GST Details
  • Payment Gateway Reference
  • Refund Information
  • Credit Notes
  • Wallet Credits
  • Promotional Credits
  • Subscription Information
  • Billing Address

For security reasons, the Company does not store complete debit card, credit card, UPI PIN, net banking credentials, CVV, or similar payment authentication information.

Payments are processed by authorized payment service providers in accordance with their respective privacy policies and applicable laws.

13. ACCOUNT INFORMATION

When a User creates an account, the Company may collect:

  • Username
  • Password (stored in encrypted or hashed form)
  • Account Preferences
  • Saved Addresses
  • Saved Documents
  • Order History
  • Saved Drafts
  • Communication Preferences
  • Notification Preferences
  • Subscription Preferences
  • Customer Support History

14. COMMUNICATION INFORMATION

The Company may retain records of communications including:

  • Emails
  • Live Chat Conversations
  • AI Chat Conversations
  • WhatsApp Communications
  • SMS Messages
  • Voice Calls
  • Customer Support Tickets
  • Complaint Records
  • Feedback
  • Reviews
  • Survey Responses
  • Escalation Requests

Such communications may be monitored, recorded, and retained for quality assurance, training, dispute resolution, legal compliance, fraud prevention, and customer support.

15. TECHNICAL INFORMATION

When Users access the Platform, certain technical information may be collected automatically, including:

  • IP Address
  • Device Identifier
  • Device Model
  • Operating System
  • Browser Type
  • Browser Version
  • Screen Resolution
  • Time Zone
  • Device Language
  • Date and Time of Access
  • Session Duration
  • Referral URL
  • Exit Pages
  • Network Information
  • Error Logs
  • Crash Reports
  • Performance Metrics
  • Security Logs
  • Authentication Logs

16. USAGE INFORMATION

The Company may collect information relating to how the Platform is used, including:

  • Pages Visited
  • Buttons Clicked
  • Search Queries
  • Navigation Flow
  • Features Used
  • Time Spent on Pages
  • Downloads
  • Uploads
  • Form Completion Status
  • Checkout Behaviour
  • Cart Abandonment
  • Login Activity
  • Purchase History
  • Service Preferences

Such information assists in improving user experience, platform performance, and service quality.

17. LOCATION INFORMATION

Subject to User permissions and applicable law, the Company may collect:

  • Approximate Location
  • IP-based Geographic Location
  • State
  • City
  • Country
  • GPS Location (where permission is granted)
  • Location used for service eligibility
  • Address verification information

Location information may be used to determine service availability, applicable taxes, jurisdiction-specific requirements, fraud prevention, and customer support.

18. INFORMATION FROM THIRD PARTIES

The Company may receive information about Users from authorized third parties, including:

  • Payment Gateways
  • Government Portals
  • Identity Verification Providers
  • Banking Partners
  • Credit Assessment Partners (where applicable)
  • Business Registration Authorities
  • Technology Providers
  • Customer Support Platforms
  • Analytics Providers
  • Marketing Partners
  • Fraud Prevention Service Providers
  • Logistics Partners
  • Authorized Vendors

The Company shall process such information only for lawful purposes and in accordance with applicable legal obligations.

19. INFORMATION COLLECTED AUTOMATICALLY

19.1 Automatic Collection of Information

When a User accesses or interacts with the Platform, certain information may be collected automatically through technical means to facilitate the operation, security, performance, and continuous improvement of the Platform.

Such collection may occur through cookies, web beacons, pixels, software development kits (SDKs), server logs, browser storage, application programming interfaces (APIs), device identifiers, analytics technologies, or other similar technologies.

This information generally does not directly identify an individual on its own but may become Personal Data when combined with other information held by the Company.

19.2 Types of Automatically Collected Information

The Company may automatically collect information including, but not limited to:

  • IP Address;
  • Device Identifier;
  • Device Model;
  • Device Manufacturer;
  • Operating System;
  • Browser Type;
  • Browser Version;
  • Mobile Network Information;
  • Internet Service Provider;
  • Language Preferences;
  • Time Zone;
  • Session Duration;
  • Navigation History within the Platform;
  • Clickstream Data;
  • Error Reports;
  • Diagnostic Logs;
  • Crash Reports;
  • Browser Configuration;
  • Security Events;
  • Login Attempts;
  • Authentication Records;
  • Referral URLs;
  • Exit Pages;
  • Date and Time of Access;
  • API Requests;
  • Feature Usage Statistics.

20. COOKIES AND SIMILAR TECHNOLOGIES

20.1 Use of Cookies

The Platform uses cookies and similar technologies to enhance user experience, improve security, remember user preferences, optimize platform functionality, measure performance, and support business operations.

Cookies are small text files stored on a User's device that enable recognition of the browser or device during future visits.

20.2 Types of Cookies

The Company may use the following categories of cookies:

(a) Essential Cookies

These cookies are necessary for the proper functioning of the Platform and cannot generally be disabled.

They enable features including:

  • User authentication;
  • Session management;
  • Shopping cart functionality;
  • Security controls;
  • Payment processing;
  • Fraud prevention;
  • Account access.

(b) Functional Cookies

These cookies remember User preferences and improve usability.

Examples include:

  • Preferred language;
  • Saved login preferences;
  • Interface customization;
  • Region selection;
  • Notification preferences.

(c) Performance Cookies

These cookies collect statistical information regarding Platform usage, including:

  • Page performance;
  • Loading speed;
  • Error rates;
  • User navigation;
  • Feature adoption;
  • Website optimization.

(d) Analytics Cookies

These cookies help the Company understand how Users interact with the Platform.

Information collected may include:

  • Most visited pages;
  • User journey;
  • Session duration;
  • Bounce rates;
  • Device categories;
  • Geographic distribution;
  • Conversion rates;
  • Search behaviour.

(e) Marketing Cookies

Subject to applicable law and User consent where required, marketing cookies may be used to:

  • Measure advertising effectiveness;
  • Personalize advertisements;
  • Deliver relevant promotions;
  • Prevent repetitive advertisements;
  • Track campaign performance.

21. ANALYTICS SERVICES

The Company may use third-party analytics providers to understand Platform usage, improve services, identify technical issues, and optimize customer experience.

Such providers may collect information regarding:

  • Device usage;
  • Browsing behaviour;
  • Feature interaction;
  • Conversion metrics;
  • Session analytics;
  • Performance metrics;
  • User engagement.

Analytics providers may process data in accordance with their own privacy policies and applicable legal requirements.

The Company takes reasonable steps to ensure that analytics providers process information under appropriate contractual and security obligations.

22. AI-POWERED FEATURES AND AUTOMATED PROCESSING

22.1 AI Services

The Platform may incorporate artificial intelligence ("AI"), machine learning, automation tools, natural language processing, generative AI, intelligent document processing, optical character recognition (OCR), or similar technologies to improve operational efficiency and user experience.

AI-assisted features may include:

  • Customer support;
  • Chat assistants;
  • Document drafting;
  • Legal document generation;
  • Content recommendations;
  • Search functionality;
  • Form completion assistance;
  • Data extraction;
  • OCR processing;
  • Translation services;
  • Document classification;
  • Risk detection;
  • Fraud monitoring;
  • Workflow automation.

22.2 AI Processing of User Information

Information submitted by Users may be processed using AI systems solely for purposes including:

  • Responding to customer queries;
  • Drafting legal documents;
  • Improving service quality;
  • Detecting fraudulent activity;
  • Improving automation;
  • Identifying operational issues;
  • Assisting customer support teams;
  • Enhancing document accuracy.

AI-generated outputs should not be interpreted as legal advice, financial advice, tax advice, or professional opinions unless expressly stated otherwise.

Users remain responsible for reviewing AI-generated content before relying upon or using such content.

22.3 Human Review

Where appropriate, AI-generated outputs may be reviewed by authorized personnel to:

  • Improve quality;
  • Correct inaccuracies;
  • Resolve disputes;
  • Investigate fraud;
  • Ensure regulatory compliance;
  • Provide customer support.

23. PURPOSES OF PROCESSING PERSONAL DATA

The Company processes Personal Data solely for lawful purposes connected with the operation of the Platform and provision of Services.

Such purposes include, without limitation:

  • Creating and managing user accounts;
  • Processing service requests;
  • Facilitating procurement of stamp papers;
  • Preparing legal documentation;
  • Processing company registrations;
  • Facilitating LLP registrations;
  • Processing GST registrations;
  • Virtual office administration;
  • Business compliance services;
  • Government filings;
  • Identity verification;
  • KYC verification;
  • Customer authentication;
  • Processing payments;
  • Issuing invoices;
  • Maintaining financial records;
  • Fraud detection and prevention;
  • Risk assessment;
  • Cybersecurity monitoring;
  • Customer support;
  • Complaint resolution;
  • Communication regarding orders;
  • Sending transactional notifications;
  • Delivery of services;
  • Regulatory compliance;
  • Maintaining audit trails;
  • Improving Platform functionality;
  • Product development;
  • Business analytics;
  • Research and development;
  • Quality assurance;
  • Legal proceedings;
  • Internal administration;
  • Corporate governance;
  • Contract management;
  • Enforcement of legal rights;
  • Protection of Users, employees, vendors, and the Platform.

24. LEGAL BASIS FOR PROCESSING

The Company processes Personal Data on one or more lawful grounds permitted under applicable laws.

Such lawful grounds may include:

24.1 Consent

Where processing is based on the User's consent, the Company shall process Personal Data only for the purposes for which consent has been obtained.

24.2 Performance of Contract

Processing may be necessary for:

  • providing requested Services;
  • completing transactions;
  • fulfilling contractual obligations;
  • processing registrations;
  • delivering purchased products;
  • customer support.

24.3 Compliance with Legal Obligations

The Company may process Personal Data where required to comply with:

  • statutory obligations;
  • regulatory requirements;
  • judicial orders;
  • governmental directions;
  • taxation laws;
  • company law;
  • anti-fraud obligations;
  • audit requirements;
  • law enforcement requests.

24.4 Legitimate Business Interests

Subject to applicable law, processing may also be undertaken where reasonably necessary for legitimate interests including:

  • improving services;
  • fraud prevention;
  • cybersecurity;
  • business continuity;
  • operational efficiency;
  • dispute resolution;
  • analytics;
  • system monitoring;
  • platform security.

Such processing shall be balanced against the rights and reasonable expectations of Users.

25. CONSENT MANAGEMENT

25.1 Obtaining Consent

Where consent is required under applicable law, the Company may obtain consent through:

  • account registration;
  • acceptance checkboxes;
  • OTP verification;
  • digital acknowledgements;
  • electronic signatures;
  • click-wrap agreements;
  • document submissions;
  • online confirmations;
  • written communications;
  • any other legally recognized electronic method.

25.2 Withdrawal of Consent

Users may withdraw consent for processing of Personal Data where processing is based solely upon consent.

Withdrawal of consent shall not affect:

  • processing carried out prior to withdrawal;
  • processing required under applicable law;
  • contractual obligations;
  • dispute resolution;
  • fraud investigations;
  • statutory record retention.

Withdrawal of consent may result in the inability of the Company to continue providing certain Services.

25.3 Updating Preferences

Users may update their communication preferences, marketing preferences, account information, and other applicable settings through the Platform or by contacting customer support.

26. AUTOMATED DECISION-MAKING

The Company may use automated systems to assist in:

  • fraud detection;
  • spam prevention;
  • risk assessment;
  • identity verification;
  • workflow routing;
  • customer support prioritization;
  • service recommendations;
  • system security.

The Company does not make solely automated decisions producing legal or similarly significant effects on Users without appropriate human oversight where required under applicable law.

27. ACCURACY OF INFORMATION

Users are responsible for ensuring that all information provided to the Company is:

  • accurate;
  • complete;
  • current;
  • lawful;
  • not misleading.

The Company shall not be responsible for any loss, delay, rejection, regulatory action, or adverse consequence arising from inaccurate, incomplete, false, outdated, or misleading information provided by the User.

28. DISCLOSURE AND SHARING OF PERSONAL DATA

28.1 General Principle

The Company respects the confidentiality of Personal Data and does not sell, rent, lease, trade, commercially exploit, or otherwise disclose Personal Data to third parties except as expressly described in this Privacy Policy, as authorized by the User, or as required or permitted by applicable law.

Personal Data shall be shared only to the extent reasonably necessary for the provision of Services, compliance with legal obligations, protection of legitimate interests, prevention of fraud, operation of the Platform, or other lawful purposes.

28.2 Categories of Recipients

Subject to applicable laws, Personal Data may be shared with one or more of the following categories of recipients:

  • Government departments;
  • Statutory authorities;
  • Regulatory authorities;
  • Courts and tribunals;
  • Law enforcement agencies;
  • Payment gateway providers;
  • Banking partners;
  • Identity verification providers;
  • Cloud infrastructure providers;
  • Hosting service providers;
  • Technology partners;
  • Cybersecurity service providers;
  • Customer relationship management (CRM) providers;
  • Customer support providers;
  • Communication service providers;
  • SMS gateway providers;
  • Email service providers;
  • WhatsApp Business service providers;
  • Document processing partners;
  • Digital signature providers;
  • eSign service providers;
  • Virtual office partners;
  • Business registration consultants;
  • Chartered Accountants;
  • Company Secretaries;
  • Advocates and legal consultants;
  • Trademark and intellectual property professionals;
  • Logistics and courier service providers;
  • Analytics providers;
  • Fraud prevention service providers;
  • Audit firms;
  • Insurance providers;
  • Financial institutions;
  • Other service providers engaged by the Company.

All such disclosures shall be limited to information reasonably necessary for the relevant purpose.

29. GOVERNMENT AUTHORITIES

The Company may disclose Personal Data to governmental authorities, regulators, law enforcement agencies, courts, tribunals, statutory bodies, or other competent authorities where such disclosure is:

  • required by applicable law;
  • necessary to comply with judicial orders;
  • required pursuant to summons or notices;
  • necessary for investigations;
  • required for taxation purposes;
  • required under company law;
  • required under anti-money laundering regulations;
  • required for fraud investigations;
  • necessary to establish, exercise, or defend legal claims;
  • necessary to protect public interest;
  • otherwise legally permitted.

The Company may disclose information without prior notice to the User where prohibited by law or where prior notice may prejudice an investigation or legal proceeding.

30. PAYMENT PROCESSORS

Payments made through the Platform may be processed by authorized third-party payment service providers.

The Company may share information necessary to complete payment transactions, including:

  • Customer name;
  • Billing address;
  • Contact details;
  • Transaction amount;
  • Invoice information;
  • Order reference;
  • Payment status;
  • Tax information.

The Company does not store complete payment card numbers, CVV, UPI PINs, internet banking credentials, or other payment authentication information unless expressly required by applicable law and securely processed in accordance with industry standards.

Users acknowledge that payment service providers operate under their own privacy policies and security standards.

31. PROFESSIONAL ADVISORS

The Company may disclose Personal Data to professional advisors engaged by the Company, including:

  • Advocates;
  • Chartered Accountants;
  • Company Secretaries;
  • Tax Consultants;
  • Auditors;
  • Compliance Advisors;
  • Financial Consultants;
  • Corporate Advisors.

Such disclosures shall be limited to the extent reasonably necessary for obtaining professional advice, regulatory compliance, audits, litigation, or corporate governance.

32. BUSINESS TRANSFERS

In the event of:

  • merger;
  • acquisition;
  • restructuring;
  • amalgamation;
  • demerger;
  • sale of business;
  • transfer of assets;
  • insolvency proceedings;
  • investment transaction;
  • strategic partnership;
  • corporate reorganization,

the Company may transfer Personal Data to the relevant successor entity or acquiring organization, subject to applicable legal requirements and appropriate confidentiality obligations.

The successor entity shall continue processing Personal Data in accordance with this Privacy Policy or an equivalent privacy framework.

33. INTERNATIONAL DATA TRANSFERS

The Company primarily stores and processes Personal Data within India.

However, certain authorized technology service providers, cloud infrastructure providers, communication platforms, analytics providers, or software vendors engaged by the Company may process Personal Data outside India where permitted under applicable law.

Where cross-border transfers occur, the Company shall take reasonable steps to ensure that appropriate contractual, organizational, technical, and security safeguards are implemented to protect Personal Data.

Such transfers shall be carried out only where permitted under applicable legal requirements.

34. THIRD-PARTY WEBSITES AND SERVICES

The Platform may contain links to or integrations with third-party websites, applications, software, payment gateways, communication platforms, government portals, APIs, or online services.

The Company does not own or control such third-party platforms and shall not be responsible for:

  • their privacy practices;
  • security measures;
  • content;
  • availability;
  • policies;
  • terms of use;
  • collection or processing of Personal Data.

Users are encouraged to review the privacy policies of third-party services before providing Personal Data.

35. DATA RETENTION

35.1 Retention Principles

The Company retains Personal Data only for as long as reasonably necessary to:

  • provide requested Services;
  • fulfil contractual obligations;
  • comply with applicable law;
  • satisfy regulatory requirements;
  • resolve disputes;
  • enforce legal rights;
  • maintain audit records;
  • prevent fraud;
  • ensure business continuity.

35.2 Retention Period

The retention period may vary depending upon:

  • the nature of the Service;
  • contractual requirements;
  • statutory obligations;
  • taxation requirements;
  • corporate record-keeping obligations;
  • limitation periods prescribed by law;
  • litigation requirements;
  • regulatory investigations.

Certain records may be retained even after account closure or deletion requests where required under applicable law or where necessary to establish, exercise, or defend legal claims.

35.3 Deletion and Anonymization

Upon expiry of applicable retention periods, the Company may:

  • permanently delete information;
  • anonymize Personal Data;
  • aggregate information for statistical purposes;
  • archive information where legally required.

Information that has been anonymized so that it can no longer reasonably identify an individual may be retained indefinitely for analytics, research, reporting, service improvement, security monitoring, and business intelligence purposes.

36. INFORMATION SECURITY

36.1 Security Commitment

The Company is committed to protecting Personal Data through reasonable technical, organizational, physical, and administrative safeguards appropriate to the nature of the information processed.

However, no method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, while the Company endeavors to protect Personal Data, it cannot guarantee absolute security.

36.2 Security Measures

The Company may implement security measures including, without limitation:

  • encryption of data in transit using industry-standard protocols;
  • encryption of data at rest where appropriate;
  • secure cloud infrastructure;
  • firewall protection;
  • intrusion detection and prevention systems;
  • malware protection;
  • endpoint security controls;
  • vulnerability assessments;
  • penetration testing;
  • secure software development practices;
  • role-based access controls;
  • multi-factor authentication for administrative access;
  • password hashing;
  • secure backup procedures;
  • disaster recovery mechanisms;
  • business continuity planning;
  • audit logging;
  • security monitoring;
  • incident response procedures;
  • periodic security reviews.

The Company continually evaluates and enhances its security controls to address evolving technological and cybersecurity risks.

37. CONFIDENTIALITY

Access to Personal Data is restricted to authorized employees, officers, consultants, contractors, and service providers who require such access for legitimate business purposes and who are subject to appropriate confidentiality obligations.

The Company implements reasonable measures to prevent unauthorized access, disclosure, alteration, or misuse of Personal Data.

38. SECURITY INCIDENTS

In the event of a suspected or confirmed security incident involving Personal Data, the Company shall take reasonable steps appropriate to the nature and severity of the incident, which may include:

  • identifying and containing the incident;
  • assessing the scope and impact;
  • implementing remedial measures;
  • notifying affected Users where required by applicable law;
  • notifying competent regulatory authorities where legally required;
  • preserving relevant records for investigation;
  • cooperating with law enforcement agencies where appropriate.

Nothing in this Privacy Policy shall be construed as an admission of liability or fault by the Company solely by reason of taking such responsive measures.

39. USER RIGHTS

39.1 General Rights

Subject to applicable law, Users may have certain rights concerning their Personal Data processed by the Company.

Such rights shall be exercised in accordance with applicable legal requirements and may be subject to statutory limitations, contractual obligations, regulatory requirements, and the Company's legitimate interests.

39.2 Right to Access Information

Users may request information regarding:

  • the categories of Personal Data processed;
  • the purposes for which Personal Data is processed;
  • the categories of recipients with whom Personal Data has been shared;
  • the source of Personal Data, where applicable;
  • the retention practices applicable to such information.

The Company may verify the identity of the requesting User before responding to any such request.

39.3 Right to Correction

Users may request correction, updating, or completion of inaccurate, incomplete, or outdated Personal Data maintained by the Company.

The Company reserves the right to seek documentary evidence before making any requested corrections where reasonably necessary.

39.4 Right to Erasure

Subject to applicable law, Users may request deletion or erasure of Personal Data that is no longer required for the purposes for which it was collected.

The Company may decline or defer such requests where retention is necessary:

  • to comply with legal obligations;
  • for taxation and accounting requirements;
  • for fraud prevention;
  • for dispute resolution;
  • for ongoing contractual obligations;
  • for pending investigations;
  • for the establishment, exercise, or defence of legal claims;
  • for audit and regulatory purposes.

Deletion of Personal Data may result in suspension or termination of certain Services.

39.5 Right to Withdraw Consent

Where processing is based solely upon consent, Users may withdraw such consent at any time by contacting the Company or by using available account settings, where applicable.

Withdrawal of consent shall not affect:

  • the lawfulness of processing undertaken before withdrawal;
  • processing required by law;
  • processing necessary for contractual performance;
  • processing necessary to protect legal rights.

39.6 Right to Nominate

Where permitted under applicable law, a User may nominate another individual to exercise applicable rights on the User's behalf in the event of death or incapacity, subject to verification and legal documentation.

39.7 Verification of Requests

To protect the privacy and security of Users, the Company may require reasonable identity verification before processing any request relating to Personal Data.

The Company reserves the right to reject requests that are fraudulent, repetitive, manifestly unfounded, excessive, or otherwise contrary to applicable law.

40. USER RESPONSIBILITIES

Users agree and undertake that they shall:

  • provide only accurate, complete, and lawful information;
  • promptly update any information that becomes inaccurate or outdated;
  • ensure that all uploaded documents are genuine and lawfully obtained;
  • obtain all necessary permissions before submitting Personal Data relating to any third party;
  • maintain the confidentiality of their account credentials;
  • immediately notify the Company of any unauthorized access or suspected compromise of their account;
  • comply with all applicable laws while using the Platform;
  • refrain from uploading unlawful, defamatory, fraudulent, infringing, or malicious content.

Users shall remain solely responsible for the accuracy and legality of information submitted through the Platform.

41. CHILDREN'S PRIVACY

The Platform is intended for use by individuals who are competent to enter into legally binding contracts under applicable law.

The Company does not knowingly collect Personal Data from children except where such processing is expressly permitted or required under applicable law and appropriate consent has been obtained from a parent or lawful guardian.

If the Company becomes aware that Personal Data relating to a child has been collected in violation of applicable law, reasonable steps may be taken to delete such information or obtain the necessary lawful authorization.

Parents or legal guardians who believe that a child has provided Personal Data without appropriate authorization may contact the Company using the contact details provided in this Privacy Policy.

42. MARKETING COMMUNICATIONS

The Company may send communications relating to:

  • service updates;
  • transaction confirmations;
  • invoices;
  • payment reminders;
  • compliance alerts;
  • promotional offers;
  • newsletters;
  • product launches;
  • customer surveys;
  • educational content;
  • security notifications.

Where required by applicable law, marketing communications shall be sent only after obtaining the necessary consent.

Users may opt out of receiving marketing communications at any time by using the unsubscribe mechanism provided in such communications or by contacting the Company.

Opting out of marketing communications shall not affect the Company's ability to send transactional, regulatory, security, legal, or service-related communications.

43. GRIEVANCE REDRESSAL

43.1 Commitment

The Company is committed to addressing complaints, grievances, and privacy-related concerns in a fair, transparent, and timely manner.

Users may contact the Company regarding:

  • privacy concerns;
  • correction requests;
  • deletion requests;
  • consent withdrawal;
  • security incidents;
  • misuse of Personal Data;
  • complaints regarding processing activities;
  • questions relating to this Privacy Policy.

43.2 Grievance Officer

In accordance with applicable law, the Company has designated a Grievance Officer to address complaints relating to privacy and Personal Data.

Grievance Officer

Bani Global Industries LLP

Operator of Stamp Mitra

Email: customercare@stampmitra.in

Escalation Email: info@baniglobal.in

The Company shall endeavour to acknowledge and resolve complaints within the timelines prescribed under applicable law.

44. LIMITATION OF LIABILITY

To the maximum extent permitted under applicable law, the Company shall not be liable for any loss, damage, liability, expense, claim, or cost arising directly or indirectly from:

  • inaccurate information supplied by a User;
  • unauthorized access resulting from User negligence;
  • compromise of account credentials by the User;
  • failures of third-party service providers;
  • internet interruptions;
  • telecommunications failures;
  • force majeure events;
  • cyberattacks beyond the Company's reasonable control;
  • malware or viruses introduced through third-party systems;
  • governmental restrictions;
  • delays caused by statutory authorities;
  • actions or omissions of third-party vendors;
  • events beyond the reasonable control of the Company.

Nothing in this Privacy Policy excludes or limits liability where such exclusion or limitation is prohibited by applicable law.

45. CHANGES TO THIS PRIVACY POLICY

The Company reserves the right to modify, amend, update, replace, or revise this Privacy Policy at any time to reflect:

  • changes in applicable law;
  • regulatory requirements;
  • technological developments;
  • operational changes;
  • introduction of new Services;
  • business restructuring;
  • security enhancements.

The updated Privacy Policy shall become effective upon publication on the Platform unless otherwise specified.

Users are encouraged to review this Privacy Policy periodically.

Continued use of the Platform following publication of any revised Privacy Policy shall constitute acceptance of the revised version, except where applicable law requires renewed consent.

46. SEVERABILITY

If any provision of this Privacy Policy is held to be invalid, unlawful, or unenforceable by a court or competent authority, such provision shall be deemed severed only to the extent necessary, and the remaining provisions shall continue in full force and effect.

47. WAIVER

Failure or delay by the Company in exercising any right or remedy under this Privacy Policy shall not constitute a waiver of such right or remedy.

No waiver shall be effective unless expressly made in writing by an authorized representative of the Company.

48. GOVERNING LAW AND JURISDICTION

This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India.

Subject to applicable law and any mandatory dispute resolution mechanism, the courts located in New Delhi, India, shall have exclusive jurisdiction over any dispute arising out of or relating to this Privacy Policy or the processing of Personal Data by the Company.

49. CONTACT DETAILS

For any questions, concerns, requests, or complaints regarding this Privacy Policy or the processing of Personal Data, Users may contact:

Stamp Mitra

A Platform Operated by Bani Global Industries LLP

Customer Support

customercare@stampmitra.in

Privacy & Grievance Escalation

info@baniglobal.in

Corporate Website

www.baniglobal.in

50. DISCLAIMER

Stamp Mitra is a privately owned technology-enabled legal facilitation platform operated by Bani Global Industries LLP.

The Company is not a Government department, Government authority, statutory body, or public office, unless expressly stated for a specific service.

The Platform facilitates access to legal, regulatory, compliance, documentation, registration, and business support services. Where a Service involves interaction with a Government authority or statutory body, the final approval, issuance, registration, certification, or decision shall remain solely within the jurisdiction and discretion of the respective authority.

Nothing contained in this Privacy Policy shall be construed as creating any partnership, agency, employment, or fiduciary relationship between the Company and any Government authority.