JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 02 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Information Security / Technology / Risk / Compliance |
| Review Frequency | At least annually and after material incidents |
| Classification | Confidential – Cyber Incident Response Policy |
This Policy establishes the framework for preparing for, detecting, reporting, assessing, containing, investigating, recovering from and learning from cyber incidents and cyber-enabled fraud affecting JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED, its customers, gift cards/vouchers, systems, applications, APIs, data or third-party services.
This Policy applies to employees, contractors, systems, applications, websites, APIs, cloud services, endpoints, databases, payment integrations, gift-card/voucher platforms, third parties and any cyber event affecting Company operations.
Incidents shall be classified according to potential or actual impact, including customer impact, data sensitivity, financial loss, operational disruption, regulatory significance, system criticality and scope.
Management shall designate appropriate personnel from Information Security, Technology, Risk/Fraud, Compliance, Operations, Legal, Finance and Customer Support as required. External specialists may be engaged where appropriate.
Employees, contractors and relevant partners shall report suspected cyber incidents immediately through approved channels. No employee shall knowingly suppress or delay escalation of a material security incident.
The response team shall determine what happened, affected systems, likely attack vector, customer impact, data involved, ongoing threat, financial impact and immediate containment requirements.
Investigations shall collect and analyse relevant logs, transaction information, authentication records, system events, communications, device information and other evidence proportionate to the incident. Forensic specialists may be engaged where required.
Relevant digital and documentary evidence shall be preserved with appropriate integrity and access controls. Evidence handling shall be documented for material incidents.
Where personal, customer, credential, transaction or confidential information may have been compromised, the incident shall be assessed promptly and handled in accordance with applicable legal, contractual, privacy and regulatory requirements.
A cyber incident affecting a material vendor, PPI, bank, payment processor, merchant or technology provider shall be assessed for impact on Company operations and customers. The relevant partner shall be required to provide appropriate information and cooperation under contractual arrangements.
Incident communications shall be controlled by authorised personnel. Material incidents shall be escalated to Management, Information Security, Technology, Risk/Fraud, Compliance, Legal and other functions according to severity. External communications shall be made only by authorised persons.
Where a legal, regulatory, contractual or law-enforcement reporting obligation applies, the designated responsible function shall coordinate reporting within applicable requirements and preserve supporting evidence.
Affected systems shall be restored using secure recovery procedures. Before returning systems to normal operation, appropriate validation shall confirm that the threat has been contained and security controls are functioning.
Material incidents shall undergo a post-incident review covering root cause, control gaps, response effectiveness, customer impact, financial impact and corrective/preventive actions.
Lessons from incidents shall be incorporated into security controls, fraud rules, training, monitoring, architecture, vendor requirements and business continuity arrangements where appropriate.
Incident records shall include incident date/time, reporter, affected systems, classification, actions, evidence, decisions, communications, impact, recovery and closure information.
Incident information shall be shared on a need-to-know basis. Investigation details, credentials, security weaknesses and other sensitive information shall be protected from unauthorised disclosure.
Relevant personnel shall receive periodic incident-response training. Tabletop exercises, simulations or technical drills may be conducted based on risk and criticality.
The Company may engage cybersecurity, forensic, legal, payment, technology or other specialist support during material incidents, subject to appropriate confidentiality and contractual controls.
Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual requirements shall continue to apply.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Incident governance, resources and material decisions | Director / Management |
| Information Security | Incident coordination, triage, containment and security analysis | Management |
| Technology | Technical containment, recovery, systems and logs | Technology Head |
| Risk / Fraud | Fraud assessment, transaction/voucher controls and loss analysis | Risk/Fraud Head |
| Compliance / Legal | Regulatory, privacy and legal coordination | Compliance/Legal Head |
| Operations | Business impact, process controls and continuity | Operations Head |
| Finance | Financial impact, refunds/reversals and reconciliation | Finance Head |
| Customer Support | Customer reporting and approved communications | Support Head |
| Partner Owner | Third-party and payment/PPI/bank coordination | Management |
This Policy shall be reviewed at least annually and after material cyber incidents or significant changes to systems, products, partners, threats or applicable requirements.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Risk | |
| Reviewed By | Compliance / Legal / Operations / Finance | |
| Approved By | Director / Authorised Signatory |