JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 03 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Management / Operations / Technology / Information Security |
| Review Frequency | At least annually and after material disruption or significant business/technology change |
| Classification | Confidential – Business Continuity & Disaster Recovery Policy |
This Policy establishes the framework for maintaining critical business services and recovering technology, data and operational capabilities following disruptions affecting JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED and its gift-card/voucher business.
This Policy applies to critical business processes, websites, applications, APIs, databases, cloud services, payment integrations, gift-card/voucher systems, communication channels, facilities, employees, vendors and technology partners supporting Company operations.
Management shall provide oversight and resources for business continuity and disaster recovery. Critical functions shall have designated owners and appropriate recovery arrangements.
The Company shall periodically assess the impact of disruptions on critical services, customers, revenue, transactions, regulatory obligations, data and partner dependencies. Recovery priorities shall be based on business impact and risk.
Critical services shall be assigned recovery priorities based on customer impact, financial impact, contractual obligations, security risk and operational dependency. Recovery objectives shall be documented where appropriate.
Disaster recovery arrangements shall support restoration of critical applications, infrastructure, databases, configurations and other technology capabilities following a major disruption.
Where appropriate, critical systems shall have documented recovery environments, configurations or procedures. Recovery arrangements shall be reviewed after major technology changes.
Where disruption results from cyber attack or ransomware, recovery shall be coordinated with the Cyber Incident Response Policy. Systems shall not be restored to production until appropriate security validation and containment checks have been completed.
Critical PPI, bank, payment processor, merchant, cloud, technology and other service-provider dependencies shall be assessed. Material providers should maintain appropriate continuity arrangements and incident communication mechanisms.
A material disruption may require activation of a management-led crisis response. The response shall establish incident leadership, priorities, communications, business decisions, partner coordination and recovery tracking.
Disruptions shall be assessed according to severity and escalated to Management, Operations, Technology, Information Security, Risk, Finance, Compliance, Customer Support and relevant partners as required.
During material disruptions, communications shall be controlled by authorised personnel. Customers, employees, vendors and partners shall receive accurate information appropriate to the incident. Sensitive security information shall not be unnecessarily disclosed.
After recovery, transaction, voucher, payment, settlement and customer records shall be reconciled where appropriate to identify duplicate, missing, inconsistent or incomplete records before normal processing resumes.
Testing shall produce documented results, identified gaps, responsible owners and corrective actions. Material weaknesses shall be escalated and tracked until remediation or formally accepted risk.
Relevant personnel shall be trained on continuity responsibilities, escalation, communication, manual workarounds, incident reporting and recovery procedures appropriate to their roles.
Continuity plans, recovery procedures, critical contacts and escalation information shall be maintained and updated after material organisational, technology or partner changes.
Business continuity assessments, recovery tests, incident records, backup tests, exercise results, approvals and remediation evidence shall be retained according to the Company's record-retention requirements.
Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual obligations shall continue to apply.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Continuity governance, priorities, resources and crisis decisions | Director / Management |
| Operations | Business process continuity and customer operations | Operations Head |
| Technology | Infrastructure, applications, backup and technical recovery | Technology Head |
| Information Security | Security validation, cyber recovery and incident coordination | Security Head |
| Risk / Fraud | Risk assessment, fraud controls and disruption impact | Risk/Fraud Head |
| Finance | Settlement, reconciliation and financial continuity | Finance Head |
| Compliance / Legal | Regulatory, contractual and legal continuity requirements | Compliance/Legal Head |
| Customer Support | Customer communications and support during disruption | Support Head |
| Partner Owner | Critical vendor/PPI/bank/payment partner coordination | Management |
This Policy shall be reviewed at least annually and following a material disruption, major technology change, significant partner change or material change in business risk.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Operations / Technology / Information Security | |
| Reviewed By | Risk / Compliance / Legal / Finance | |
| Approved By | Director / Authorised Signatory |