REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 15 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Compliance / Risk / Operations / Technology |
| Review Frequency | At least annually and upon material change |
| Classification | Confidential – Third-Party / Vendor Risk Policy |
This Policy establishes the framework for identifying, assessing, approving, contracting, monitoring and exiting third-party and vendor relationships that may affect REMPINDIA MULTITRADE PRIVATE LIMITED's customers, information, technology, transactions, operations or compliance obligations.
This Policy applies to vendors, service providers, technology providers, consultants, cloud/hosting providers, payment and PPI partners, merchants, outsourced service providers and other third parties whose services or access may materially affect the Company.
Third parties shall be classified according to criticality, access to data, transaction impact, operational dependency, financial exposure, regulatory relevance and information-security risk.
Vendor risk shall be assessed using factors such as criticality, data sensitivity, transaction volume/value, access privileges, geographic exposure, substitutability, incident history and dependency.
Material or high-risk third parties shall be approved by designated authority before production onboarding. Risk acceptance for identified gaps shall be documented.
Vendors with access to systems or confidential information shall maintain security controls proportionate to risk. Security requirements may include authentication, encryption, access control, logging, vulnerability management and incident response.
Vendors processing personal or customer information shall process it only for authorised purposes and in accordance with applicable privacy requirements and contractual instructions.
Third-party access shall be limited to the minimum required, reviewed periodically and revoked promptly when no longer required or when the relationship ends.
Material subcontracting or use of sub-processors may require prior notification or approval depending on contractual and risk requirements. Relevant security and confidentiality obligations shall flow down appropriately.
Critical and material vendors shall be monitored based on service performance, incidents, security findings, SLA performance, customer impact, financial/operational health and other relevant risk indicators.
Where appropriate, service levels shall define availability, response, resolution, reporting, escalation and service-credit or remediation arrangements.
Vendors shall promptly notify the Company of material incidents affecting Company systems, customer information, transactions or services, subject to applicable contractual and legal requirements.
Critical vendors should maintain appropriate continuity and recovery capabilities. The Company may assess recovery arrangements based on vendor criticality.
Management shall consider dependence on a single vendor, technology provider, payment partner or other critical service. Material concentration risks should have mitigation or contingency arrangements where practicable.
Material vendors may be assessed for financial stability, pricing, settlement exposure, prepaid balances, security deposits and other financial dependencies relevant to the relationship.
Where relevant, vendor compliance with contractual, legal, regulatory, security and privacy obligations shall be reviewed periodically.
The Company may request reasonable assurance such as security questionnaires, audit reports, certifications, test results or other evidence proportionate to the vendor's risk.
Material vendor incidents shall be escalated to Management, Risk, Information Security, Compliance and other relevant functions according to severity.
Identified vendor control gaps shall have documented remediation plans, owners and target dates. Material overdue issues may result in restrictions, enhanced monitoring or escalation.
The Company may suspend access, transactions or services where a vendor presents material security, fraud, compliance, operational or customer risk, subject to contractual and legal considerations.
Exit procedures shall address service continuity, access revocation, data return/deletion, credential rotation, outstanding transactions, financial reconciliation, customer impact and transition to an alternative provider where required.
Vendor records shall include due diligence, approvals, contracts, risk assessments, reviews, incidents, performance records and exit documentation as applicable.
Relevant employees responsible for third-party management shall receive appropriate training on vendor due diligence, information security, privacy, fraud and escalation requirements.
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Approval of material relationships and risk acceptance | Director / Management |
| Procurement / Operations | Vendor onboarding, commercial and performance coordination | Operations Head |
| Compliance / Legal | Due diligence, contracts and regulatory requirements | Compliance/Legal Head |
| Risk | Vendor risk assessment and monitoring | Risk Head |
| Information Security | Security assessment and incident requirements | Security Head |
| Technology | Technical integration, access and continuity | Technology Head |
| Finance | Financial exposure, billing and reconciliation | Finance Head |
| Partner Owner | Ongoing relationship and escalation | Partner Owner |
This Policy shall be reviewed at least annually and whenever there is a material change in the vendor ecosystem, products, technology, regulatory requirements or risk profile.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Risk / Operations / Technology | |
| Reviewed By | Legal / Finance / Information Security | |
| Approved By | Director / Authorised Signatory |