API Setu Compliance

Version 1.0 Effective: 30 July 2026 Last updated: 30 July 2026
All Legal & Compliance Pages

1. Overview

Where the Stayvora Technologies platform connects to government API infrastructure (such as APIs made available through API Setu) to facilitate a Center's submission of a government service application, we follow the principles below to ensure that access is consent-based, purpose-limited, and secure.

Government API calls are made only after the end customer has given explicit, informed consent for the specific service being requested (see our Customer Consent Policy). No government data lookup or submission is made without a specific, active customer request behind it.

3. Purpose Limitation

Data retrieved via a government API is used solely to complete the specific service the customer requested (e.g. verifying details for a PAN application) and is never repurposed for an unrelated use, such as marketing or profiling.

4. Data Minimization

We request and process only the specific data fields a government API requires to complete the requested service — never broader access than the transaction genuinely needs, and never speculative data collection "in case it's useful later."

5. Secure Processing & Authorized Access

Government API calls are made only through authorized platform functions, by authenticated Center staff acting on a specific, consented customer request. Access to government API credentials and response data is limited to the systems and personnel that need it, consistent with our Security Policy.

6. Audit Logging

Requests made through a government-facing API are logged (requesting Center, timestamp, and the service invoked) to support accountability and investigation, without logging more of the underlying government data than is operationally necessary for that audit trail.

7. No Unauthorized Sharing

Data obtained through a government API integration is not shared with any party beyond the Center that initiated the request and the systems strictly necessary to complete it, without the customer's further consent.

8. Retention & Deletion

Government API response data is retained only for as long as necessary to complete and record the requested service, per our Data Retention Policy, and can be deleted on request per our Data Deletion Policy, subject to any legal retention requirement.

9. User Rights

Customers may ask the Center they applied through what government data was accessed on their behalf and why, and may request deletion of that data subject to the exceptions in our Data Retention/Data Deletion Policies.

10. Government API Compliance

Our use of any government-facing API is subject to the terms, rate limits, and usage conditions set by the API provider (e.g. API Setu, UIDAI, or a specific department), in addition to this policy — see our API Usage Policy.