JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 06 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Management / Compliance / Information Security / Operations |
| Review Frequency | At least annually and upon material legal, product, technology or data-processing change |
| Classification | Confidential – Data Protection & Records Policy |
This Policy establishes the Company's framework for responsible collection, use, access, storage, disclosure, protection, retention and disposal of personal, customer, transaction, voucher and business information handled by JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED.
This Policy applies to customer information, employee and contractor information, transaction and payment-related records, gift-card/voucher information, business records, communications, system logs, security records and information processed by employees, contractors and authorised third parties.
Personal and customer information shall be collected through authorised channels and used only for legitimate purposes such as account management, gift-card/voucher issuance or servicing, transaction processing, customer support, fraud prevention, compliance, security, reconciliation and other disclosed or legally permitted purposes.
Where applicable, customers shall be provided appropriate privacy information regarding the categories of information collected, purposes, relevant disclosures, retention principles and available rights or contact mechanisms.
Access to personal and confidential information shall be based on business need and least privilege. Access shall be reviewed periodically and removed when no longer required.
Information may be shared with authorised employees, vendors, payment/PPI/banking partners, merchants, technology providers, professional advisers, regulators or law-enforcement authorities where permitted or required, and subject to appropriate safeguards and contractual controls.
Third parties processing information on behalf of the Company shall be subject to appropriate due diligence, contractual confidentiality, security, privacy, access, incident-reporting and data-return/deletion requirements according to risk.
Where information is processed, stored or transferred outside the Company's primary operating environment, applicable legal, contractual and security requirements shall be assessed and appropriate safeguards implemented.
Reasonable processes shall be maintained to identify and correct materially inaccurate or incomplete customer or business information where correction is required for the relevant purpose.
Requests relating to access, correction, deletion, consent or other applicable privacy rights shall be handled through designated channels and assessed according to applicable law, contractual requirements and operational procedures.
Suspected or confirmed unauthorised access, disclosure, loss, alteration or destruction of personal or confidential information shall be escalated and managed under the Company's Cyber Incident Response Policy, including assessment of notification obligations where applicable.
Records shall be retained for the period required by applicable law, regulation, contractual obligation, legitimate business need, dispute requirements, security needs or audit requirements, as applicable.
Where records are relevant to litigation, investigation, regulatory review, dispute or other legal requirement, normal deletion shall be suspended to the extent necessary and authorised.
At the end of the applicable retention period, information shall be securely deleted, destroyed, anonymised or otherwise disposed of using methods appropriate to its sensitivity and storage medium, subject to legal holds and continuing obligations.
Backup copies shall be managed consistently with business continuity and security requirements. Expired data in backups shall be handled through appropriate backup lifecycle processes where technically feasible.
Material business and transaction records shall be protected against unauthorised alteration or deletion. Where appropriate, records shall maintain traceability, timestamps and audit information.
Systems handling material customer, transaction or security information should maintain appropriate logs and audit trails to support security, operational review, investigation and reconciliation.
Relevant personnel shall receive periodic training on data protection, privacy, secure handling, phishing, confidentiality, incident reporting and records management.
The Company may conduct access reviews, data-flow reviews, vendor assessments, security assessments, retention reviews and other assurance activities to evaluate compliance with this Policy.
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual requirements shall continue to apply.
Evidence of privacy notices, consent or preference records where applicable, access reviews, incidents, vendor assessments, retention decisions, disposal records and other relevant controls shall be retained according to applicable requirements.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Data governance, risk acceptance and policy approval | Director / Management |
| Compliance / Legal | Privacy, regulatory and contractual requirements | Compliance/Legal Head |
| Information Security | Security controls, access, monitoring and incidents | Security Head |
| Technology | Systems, storage, backups and technical controls | Technology Head |
| Operations | Operational data handling and records | Operations Head |
| Customer Support | Customer privacy requests and complaint escalation | Support Head |
| Vendor Management | Third-party data-processing controls | Vendor Owner |
| Employees / Contractors | Secure and authorised handling of information | Functional Head |
This Policy shall be reviewed at least annually and whenever there is a material change in applicable privacy/data requirements, products, technology, data processing, vendors or business operations.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Information Security / Operations | |
| Reviewed By | Legal / Technology / Vendor Management | |
| Approved By | Director / Authorised Signatory |