REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 12 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Information Security / Technology / Risk / Compliance |
| Review Frequency | At least annually and after material incidents or major changes |
| Classification | Confidential – Cyber Incident Response Policy |
This Policy establishes a structured process to identify, report, contain, investigate, eradicate, recover from and learn from cyber-security incidents and cyber-fraud events affecting REMPINDIA MULTITRADE PRIVATE LIMITED, its systems, customers, transactions, gift-card/voucher services and relevant partners.
This Policy applies to cyber incidents involving applications, APIs, websites, cloud infrastructure, endpoints, databases, accounts, credentials, transaction systems, customer information, gift-card/voucher systems, third parties and partner interfaces.
Incidents shall be prioritised based on customer impact, financial impact, data sensitivity, service availability, scope, regulatory significance and likelihood of continued harm.
Employees, contractors and relevant partners shall report suspected incidents promptly through designated security or management channels. Reports should include what happened, when it occurred, affected systems and any available evidence.
The Company shall maintain appropriate response ownership. Depending on severity, the response team may include Technology/Security, Risk/Fraud, Compliance, Operations, Legal, Finance, Customer Support, Management and relevant external partners.
Where an incident involves financial fraud, unauthorised transactions, voucher misuse or payment manipulation, the Fraud/Risk team shall coordinate transaction blocking, investigation, customer protection, partner escalation and recovery actions.
Where customers may be affected, appropriate protective actions may include account restriction, voucher blocking, transaction monitoring, password/security reset, customer notification and coordination with payment/PPI partners, subject to investigation and applicable requirements.
Investigations shall determine the attack vector, affected assets, timeframe, scope, customer/transaction impact, evidence, root cause and required remediation.
Relevant logs, transaction records, access records, emails, system images where appropriate, alerts, communications and other evidence shall be preserved securely. Evidence shall be handled to maintain integrity and confidentiality.
Where a partner, vendor, PPI issuer, bank, payment processor or other third party reports or causes a relevant incident, the Company shall coordinate response actions, information exchange, customer impact assessment and remediation.
Where reporting, cooperation or information sharing is required by applicable law, regulation, contractual obligation or competent authority, the Company shall coordinate through authorised personnel and preserve required records.
Incident communications shall be controlled, accurate and based on verified information. External communications shall be approved by authorised management and relevant functions.
Material incidents shall undergo a post-incident review covering root cause, response effectiveness, customer impact, financial impact, control gaps and corrective actions.
Corrective actions shall have an owner, priority and target date. Material overdue actions shall be escalated to management.
Where notification is required or appropriate, customers shall receive clear information on relevant impacts and recommended protective actions. Confidential investigation information shall not be disclosed unnecessarily.
Finance and Risk/Fraud shall track financial impact, refunds, reversals, recoveries, partner claims and other losses associated with material cyber-fraud incidents.
Incident records shall include detection, triage, actions, evidence, communications, decisions, partner coordination, recovery and closure information and shall be retained according to applicable requirements.
Incident response procedures should be periodically tested through tabletop exercises, simulations, technical testing or other appropriate methods.
Relevant personnel shall receive training on incident identification, reporting, phishing, social engineering, fraud indicators, evidence preservation and escalation.
Incident information shall be shared strictly on a need-to-know basis. Sensitive technical, customer and investigative information shall be protected against unauthorised disclosure.
Cyber incidents affecting critical services shall be coordinated with the Business Continuity and Disaster Recovery framework to support safe service restoration.
Any deviation from this Policy shall be documented and approved by authorised management. Mandatory legal, regulatory or partner incident requirements shall not be bypassed.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Material incident decisions, risk acceptance and external escalation | Director / Management |
| Technology / Security | Detection, containment, investigation and recovery | Security/Technology Head |
| Risk / Fraud | Cyber-fraud analysis, transaction controls and recovery | Risk/Fraud Head |
| Compliance / Legal | Regulatory, contractual and legal coordination | Compliance/Legal Head |
| Operations | Operational continuity and customer-process actions | Operations Head |
| Customer Support | Customer reports and approved communications | Support Head |
| Finance | Loss, refund, recovery and reconciliation | Finance Head |
| Partner Owner | PPI/bank/payment/vendor coordination | Partner Owner |
This Policy shall be reviewed at least annually and after a material cyber incident or material change in technology, products, partners, regulatory requirements or threat profile.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Risk / Compliance | |
| Reviewed By | Legal / Operations / Finance | |
| Approved By | Director / Authorised Signatory |