REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 13 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Management / Operations / Technology / Risk |
| Review Frequency | At least annually and after material business or technology changes |
| Classification | Confidential – Business Continuity & Disaster Recovery Policy |
This Policy establishes the framework for maintaining critical business services, protecting customers and transaction processes, and restoring operations following disruptions affecting REMPINDIA MULTITRADE PRIVATE LIMITED, its gift-card/voucher services, technology systems or critical partners.
This Policy covers critical applications, APIs, websites, transaction systems, customer support, payment and settlement processes, data, infrastructure, personnel, facilities and material third-party dependencies.
Critical processes shall be assessed for customer, financial, operational, contractual and regulatory impact. Recovery priorities shall be based on the consequences of prolonged disruption.
Management shall define appropriate recovery priorities for critical services, including target recovery objectives where practicable. Dependencies on external partners shall be considered in recovery planning.
The continuity team may include Management, Operations, Technology, Information Security, Risk/Fraud, Compliance, Finance, Customer Support, Facilities/HR and relevant partner representatives depending on the incident.
Technology teams shall maintain recovery procedures for critical systems, including backup restoration, infrastructure recovery, application recovery, data validation and security verification.
Where applicable, appropriate alternate infrastructure, cloud resources, backup environments or other recovery arrangements shall be maintained based on risk and business requirements.
Recovered data shall be checked for completeness and integrity before critical transactions are resumed. Reconciliation shall be performed where disruption may have created duplicate, missing or unmatched transactions.
During a disruption, the Company shall prioritise customer safety, transaction integrity and transparent communication. Where transactions cannot be confirmed, appropriate controls shall be applied to prevent duplicate processing or customer loss.
Critical payment, PPI, bank and settlement dependencies shall be documented. Contingency procedures shall address failed, pending, duplicated or unmatched transactions.
Material vendors and partners shall be assessed for continuity capability where appropriate. Critical contractual arrangements should include reasonable availability, incident notification and recovery expectations.
Continuity events shall use approved communication channels. Stakeholders may include employees, management, customers, merchants, PPI/bank/payment partners, vendors and authorities where applicable.
Where facilities or normal working arrangements are unavailable, the Company may implement approved remote or alternate working arrangements subject to security, access and confidentiality controls.
Critical functions shall identify primary and backup responsible personnel where practicable. Appropriate access and knowledge- transfer arrangements shall support continuity.
Material disruptions shall be escalated according to severity, customer impact, financial impact, service criticality and regulatory/contractual requirements.
Business continuity and disaster recovery arrangements shall be tested periodically through tabletop exercises, backup restoration tests, failover tests or other appropriate exercises.
Testing results shall be documented. Identified gaps shall have assigned owners and remediation timelines. Material unresolved gaps shall be escalated to management.
Material continuity events shall be reviewed to identify root causes, customer impact, recovery performance, control gaps and improvements.
Continuity plans, test results, recovery actions, incident records, communications and remediation evidence shall be retained according to applicable requirements.
Business continuity documents may contain sensitive operational information and shall be restricted to authorised personnel. Recovery environments shall follow applicable security requirements.
Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or partner requirements shall not be bypassed.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Continuity governance, activation and material decisions | Director / Management |
| Operations | Business-process continuity and customer operations | Operations Head |
| Technology | Disaster recovery, infrastructure and application recovery | Technology Head |
| Information Security | Security validation and cyber recovery controls | Security Head |
| Risk / Fraud | Fraud monitoring and transaction-risk continuity | Risk/Fraud Head |
| Finance | Settlement, reconciliation and financial continuity | Finance Head |
| Compliance / Legal | Regulatory and contractual continuity requirements | Compliance/Legal Head |
| Partner Owner | PPI/bank/payment/vendor coordination | Partner Owner |
This Policy shall be reviewed at least annually and after a material disruption, major technology change, new critical dependency or significant change in the Company's risk profile.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Management / Operations / Technology | |
| Reviewed By | Risk / Compliance / Finance / Security | |
| Approved By | Director / Authorised Signatory |