Privacy notice

Version 2026-09-23

This notice says what personal data Next Gen Payment Wallet India Private Limited holds about you, why, and what you can make us do about it. It is written under the Digital Personal Data Protection Act 2023.

Who is responsible

Sahi Setu is a brand of Next Gen Payment Wallet India Private Limited. Next Gen Payment Wallet India Private Limited, registered office 4th Floor, 402, Alpha-1, I.A. Surajpur, Greater Noida Alpha Road, Alpha 1, Gautam Buddha Nagar, Greater Noida, Uttar Pradesh 201310, is the Data Fiduciary for the data described here. That means we decide why and how it is processed, and we answer for it.

What we hold

What you give us: your mobile number, your name, the language you chose, and on your profile your email address, date of birth and state if you give them; the documents and photographs you upload, your vehicle details, the evidence and case details you record, what you write to an advocate or to support, and the members of your household you add.

Some of that is sensitive by its nature — a document you upload may carry an Aadhaar or PAN number, a bank account or a medical fact. We treat identifiers of that kind as encrypted data throughout: they are never written to a log, never put in a web address, and shown masked wherever they appear.

What the product produces: your plan and what you have used of it, payment records, the letters and applications prepared for you, the record of who opened which document and when, a notification token if you allowed notifications, and the phones signed in to your account (the make and model, the app version and when each was last used), so you can see them and sign one out.

Why we hold it

To run the product you asked for: to sign you in, to keep your documents and give them back to you, to prepare what you asked to be prepared, to connect you to an advocate, to take payment, and to tell you about something that needs you. We do not sell it and we do not use it to advertise to you.

Your consent is what permits this, and the app records which version of this notice and of the terms you accepted and when. You can see that record, and withdraw your consent, under Your data.

Who else sees it

Only those who have to. An advocate you chose to consult sees what you send them. Our staff see a document only through a grant you created, and that access is recorded.

We use service providers who process data on our instructions and for no purpose of their own: Amazon Web Services stores it, Amazon Textract reads a document you asked to have read, a payment gateway takes payments, an SMS provider delivers your sign-in code, and Google’s Firebase Cloud Messaging delivers notifications to your phone (only a notification’s short text and the ids the app needs to open it, never a document’s title or your details), and Agora (Agora.io) runs the real-time part of chat and voice calls with an advocate: the sound of a call, and the signal that a new message has arrived or that someone is typing (the words of a chat message do not go through Agora; they come from our own servers). We share with the police or a court where the law requires it, and we will tell you when we are allowed to.

If you choose to fetch a vehicle’s or a licence’s details from the government registry, we send the registration or licence number (and, for a licence, the date of birth on it) to Surepass, a verification provider, who asks the registry for us. From the answer we keep only the vehicle’s details and the validity dates; the owner’s name, address, phone number and photo are not kept. We keep a record that a lookup was made, without the number. This is optional: you can always type the details yourself.

If you ask for a drafted document in a language other than English, the advocate preparing it may have the English draft translated by Sarvam AI, an Indian translation provider, and then checks and corrects the translation before it is sent to you. The draft can contain the names, addresses and other details you gave for the document. Only the text of the draft is sent, only for a document you asked for in another language, and only by an advocate we have allowed to translate; nothing is sent from your phone. We keep the draft and its translation encrypted with your request, and delete them when your account is deleted.

When the app, our staff console or our servers run into an error, a report of it goes to Sentry, an error-tracking service, which keeps it in its European Union region, in Germany. A report says what went wrong, on which screen or page, and on what kind of phone or browser. It is not meant to carry anything about you: the app, the console and the servers are set up not to attach personal data, and phone numbers, identity numbers and sign-in tokens are removed from a report before it is sent. We use the reports only to fix faults, and Sentry deletes them automatically, at the latest after 90 days.

Where it is kept

On Amazon Web Services in the Mumbai region, in India. Your account, your documents, your evidence and everything you have written stay there. Files are encrypted at rest with a key we control, identifiers are encrypted again on top of that, and everything travels over an encrypted connection.

Two exceptions, and we would rather say them than let you assume otherwise. Chat and voice calls with an advocate happen in real time through Agora (Agora.io), whose nearest region to India is Singapore: the sound of a call, and the signals that tell the app a message has arrived or someone is typing, pass through Agora’s servers outside the country while the conversation is happening. The words of a chat message are not sent through Agora. What is kept afterwards — the thread, and any recording — is stored in India with everything else. And the error reports described above are kept by Sentry in the European Union.

How long we keep it

While your account is open, and then no longer than we need to. When you ask us to close your account there is a seven-day wait, and after it your documents, evidence, vehicles, applications, cases and messages are deleted permanently along with the files behind them.

We keep the fact that a payment was made — the amount, the date and the receipt number — for as long as company and tax law require. It is not linked to you afterwards.

What you can make us do

Get a copy of everything we hold about you. Ask us to correct something that is wrong or incomplete. Ask us to erase your data by closing your account. Withdraw a consent you gave. Nominate somebody to exercise these rights if you die or cannot act for yourself.

The first four are buttons in the app, under Your data, and they work without asking anybody. Nomination is not built yet; until it is, write to the grievance officer and we will act on it.

How it is protected

Every read of your data is scoped to you, so another account asking for it is told the thing does not exist rather than that it is not theirs. Staff reach a document only through a grant you made. A web firewall sits in front of the service, sign-in codes are rate-limited, and access to documents is recorded where you can read it.

Children

The app is for adults and we do not knowingly hold data about anybody under 18. If you believe a child's data is here, tell the grievance officer and we will remove it.

Grievance officer

If something about your data has not been put right, write to our grievance officer: Sukant, Director, Next Gen Payment Wallet India Private Limited, grievance@sahisetu.com, +91 93100 29327, 4th Floor, 402, Alpha-1, I.A. Surajpur, Greater Noida Alpha Road, Alpha 1, Gautam Buddha Nagar, Greater Noida, Uttar Pradesh 201310. You may also complain to the Data Protection Board of India.

Changes to this notice

When we change it we give the new text a version, and the app asks you to accept it before you carry on. The version you accepted, and the date, stay in your consent record.