REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 14 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Compliance / Information Security / Operations |
| Review Frequency | At least annually and upon material legal, regulatory or business change |
| Classification | Confidential – Data Protection & Record-Keeping Policy |
This Policy establishes principles and controls for responsible collection, use, access, storage, sharing, retention and disposal of personal, customer, transaction and business records handled by REMPINDIA MULTITRADE PRIVATE LIMITED in connection with its gift-card and gift-voucher business.
This Policy applies to personal data, customer information, transaction records, voucher information, employee and vendor records, financial records, security logs, communications, contracts, compliance records and other business information handled by the Company or authorised processors.
Only information reasonably required for legitimate business, contractual, customer-service, security, fraud-prevention, legal or regulatory purposes should be collected.
Reasonable measures shall be taken to maintain accurate and relevant records. Material inaccuracies identified through customer requests or internal review should be corrected where appropriate.
Access to personal and confidential information shall be based on business need, least privilege and appropriate role-based controls. Privileged access shall be restricted and reviewed.
Information may be shared with authorised PPI issuers, banks, payment processors, merchants, service providers, technology providers, professional advisers, regulators or authorities where necessary, permitted and subject to applicable obligations.
Third parties processing personal or confidential information shall be subject to appropriate due diligence, contractual safeguards, access limitations and risk-based monitoring.
Where information is transferred outside the applicable jurisdiction or to external service providers, such transfers shall be managed according to applicable legal, contractual, security and privacy requirements.
Customer requests concerning access, correction, deletion, withdrawal or other applicable privacy rights shall be assessed and handled according to applicable law and the Company's procedures.
Privacy-related complaints shall be recorded, investigated and escalated to the designated Compliance/Privacy function as appropriate.
Suspected or confirmed personal-data breaches shall be handled under the Cyber Incident Response Policy, including containment, evidence preservation, impact assessment, remediation and any required notification.
Records shall be retained for no longer than necessary for the purpose for which they are maintained, subject to applicable legal, regulatory, contractual, tax, accounting, dispute, fraud-prevention and business requirements.
The Company shall maintain a documented retention schedule identifying record category, responsible owner, minimum applicable retention period, storage location and disposal method. Where multiple requirements apply, the longer mandatory retention period shall normally be followed.
Where records are relevant to litigation, investigation, audit, dispute or an official request, routine deletion shall be suspended for the affected records until the hold is formally released.
Records required for audit, dispute, compliance or legal purposes shall be maintained in a manner that supports integrity, traceability and retrieval.
Electronic records shall be stored in authorised systems with appropriate access controls, backup, audit trails and protection against unauthorised alteration.
Physical records containing confidential or personal information shall be stored securely with controlled access and protected against loss, damage and unauthorised disclosure.
When retention is no longer required, records shall be securely deleted, destroyed or anonymised using methods appropriate to the medium and sensitivity of the information.
Backups shall be managed according to business continuity and security requirements. Backup copies may have different deletion cycles where necessary for system recovery, subject to applicable requirements.
Compliance with data-protection and record-keeping controls may be reviewed through access reviews, audits, security monitoring, retention reviews and control testing.
Relevant personnel shall receive periodic training on privacy, confidentiality, secure data handling, phishing, access controls, incident reporting and record management.
Any exception shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Data governance and material risk decisions | Director / Management |
| Compliance / Privacy | Privacy requirements, complaints and data governance | Compliance/Privacy Head |
| Information Security | Security controls, incidents and access safeguards | Security Head |
| Operations | Record creation, maintenance and retention processes | Operations Head |
| Finance | Financial and settlement records | Finance Head |
| Technology | Systems, backups, access and secure deletion | Technology Head |
| HR | Employee records and personnel access lifecycle | HR Head |
| Partner Owner | Third-party data-processing oversight | Partner Owner |
This Policy shall be reviewed at least annually and whenever there is a material change in privacy law, data-processing activities, products, technology, partners or business risk.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Information Security / Operations | |
| Reviewed By | Legal / Risk / Technology / Finance | |
| Approved By | Director / Authorised Signatory |