REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 11 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Information Security / Technology / Compliance |
| Review Frequency | At least annually and upon material change |
| Classification | Confidential – Information & Cyber Security Policy |
This Policy establishes the information-security and cyber-security framework for protecting REMPINDIA MULTITRADE PRIVATE LIMITED's systems, applications, APIs, customer information, transaction information, gift-card/voucher data and business operations against unauthorised access, misuse, alteration, loss and cyber threats.
This Policy applies to employees, contractors, systems, applications, APIs, cloud services, devices, networks, databases, websites, mobile/web interfaces, transaction systems, customer-support systems and third parties processing information on behalf of the Company.
Management shall establish security ownership, responsibilities, risk oversight and appropriate resources. Information Security/Technology shall maintain security controls and report material risks and incidents to management.
Systems shall use appropriate authentication controls based on risk. Multi-factor authentication should be enabled for privileged, administrative and other high-risk access where technically feasible.
Passwords, API keys, tokens, secrets and other authentication credentials shall be protected from disclosure, insecure storage and unauthorised sharing. Default credentials shall be changed before production use.
Customer and transaction data shall be collected, accessed, processed, stored and shared only for legitimate business purposes and in accordance with applicable privacy and contractual requirements.
Sensitive information shall be protected using appropriate encryption or equivalent safeguards in transit and, where appropriate, at rest. Cryptographic keys shall be securely managed and access restricted.
Systems shall be assessed for vulnerabilities using appropriate scanning, testing, vendor advisories and other risk-identification methods. Material vulnerabilities shall be prioritised for remediation according to risk.
Security patches and critical updates shall be evaluated and deployed within risk-based timelines, subject to appropriate testing and operational constraints.
Endpoints and relevant systems shall use appropriate anti-malware, endpoint protection or equivalent security measures where applicable.
Security-relevant events shall be logged and monitored proportionately to risk. Logs shall be protected from unauthorised alteration and retained according to applicable requirements.
Suspected cyber-security incidents shall be reported promptly and handled under the Company's Cyber Incident Response Policy. Material incidents shall be escalated to management and relevant partners or authorities where required.
Critical data and systems shall be backed up according to business and recovery requirements. Backups shall be protected from unauthorised access and tested periodically where appropriate.
Information-security controls shall support business continuity and disaster recovery arrangements for critical systems and dependencies.
Third parties processing Company or customer information shall be subject to appropriate due diligence, contractual security obligations, access restrictions and ongoing risk review.
Cloud and hosting environments shall be configured using appropriate security controls, access restrictions, monitoring, backup and recovery measures.
Company-managed or authorised devices used to access sensitive systems shall be protected by appropriate security controls. Remote access shall use approved secure methods.
Employees and relevant contractors shall receive periodic security awareness covering phishing, social engineering, credential protection, data handling, incident reporting and safe technology use.
Personnel shall remain alert to phishing, impersonation, malicious links, fraudulent support requests and other social-engineering attempts. Suspected events shall be reported immediately.
Material changes to production systems, security controls, APIs, databases or infrastructure shall follow documented change- management and approval procedures.
Security testing may include vulnerability assessments, penetration testing, configuration reviews, code review, access reviews and other appropriate assurance activities based on risk.
Relevant logs, system records, communications and other evidence shall be preserved securely during material incidents. Evidence handling shall support investigation and any required partner or law-enforcement response.
Information shall be retained only for the period required by applicable law, regulatory requirements, contracts and legitimate business needs, and securely disposed of when no longer required.
Security exceptions shall be documented, risk-assessed, approved by authorised management and reviewed periodically. Exceptions shall not override mandatory legal or regulatory requirements.
Information-security risks shall be identified, assessed, prioritised and tracked. Material risks shall have assigned owners and remediation plans.
Security reporting may include material incidents, vulnerabilities, patch status, access reviews, security testing, phishing events, third-party risks, exceptions and remediation status.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Security governance, risk acceptance and material decisions | Director / Management |
| Information Security / Technology | Security controls, monitoring, vulnerability and incident response | Security/Technology Head |
| Compliance | Regulatory, privacy and policy oversight | Compliance Head |
| Operations | Operational security procedures and access coordination | Operations Head |
| Risk / Fraud | Fraud-security linkage and risk assessment | Risk/Fraud Head |
| HR | Joiner/mover/leaver access coordination and awareness | HR Head |
| All Personnel | Follow security requirements and report incidents | Functional Head |
| Third Parties | Contractual security obligations and cooperation | Partner Owner |
This Policy shall be reviewed at least annually and whenever there is a material change in technology, cyber threats, products, partners, regulatory requirements or the Company's risk profile.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Compliance | |
| Reviewed By | Legal / Risk / Operations | |
| Approved By | Director / Authorised Signatory |