JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 01 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Management / Information Security / Technology / Compliance |
| Review Frequency | At least annually and upon material change |
| Classification | Confidential – Information Security Policy |
This Policy establishes the information-security and cyber-security framework of JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED for protecting customer information, gift-card/voucher data, transaction records, applications, APIs, infrastructure, credentials, business information and other information assets from unauthorised access, misuse, alteration, disclosure, disruption or destruction.
This Policy applies to all employees, directors, contractors, consultants, systems, applications, APIs, databases, cloud services, endpoints, networks, websites, mobile/web applications, gift-card/voucher platforms, payment integrations, third parties and information assets used for or on behalf of the Company.
Management shall provide appropriate oversight, resources and accountability for information security. Security responsibilities shall be assigned to appropriate personnel and material risks shall be escalated to management.
The Company shall maintain an appropriate inventory of material hardware, software, applications, cloud services, databases, APIs, domains, certificates and other critical information assets. Asset ownership shall be assigned where appropriate.
Customer, payment, voucher, authentication, transaction and confidential business information shall be protected through appropriate access controls, encryption or other security safeguards proportionate to risk.
Systems shall be monitored for relevant vulnerabilities and security updates. Critical vulnerabilities shall be prioritised based on exploitability, exposure and business impact.
Security-relevant events shall be logged and monitored according to system criticality. Logs should support investigation of authentication events, administrative activity, transaction anomalies, security incidents and other material events.
Employees shall exercise caution with suspicious links, attachments, requests for credentials, payment instructions and impersonation attempts. Suspected phishing or social-engineering incidents shall be reported immediately.
Critical business and security-relevant data shall be backed up according to business requirements. Backups shall be protected from unauthorised access and tested periodically where appropriate.
Third parties with access to Company information or systems shall be subject to risk-based security due diligence and appropriate contractual controls, consistent with the Third-Party / Vendor Risk Management Policy.
Suspected or confirmed cyber incidents shall be handled under the Company's Cyber Incident Response Policy, including identification, containment, investigation, evidence preservation, recovery, communication and post-incident corrective actions.
Potential data breaches shall be assessed promptly. Required containment, investigation, notification, partner coordination and regulatory actions shall be undertaken by authorised personnel according to applicable requirements.
Critical offices, systems, devices and information storage areas shall receive physical security controls proportionate to risk, including access restrictions where appropriate.
Material technology changes shall undergo appropriate security and risk review. Production changes shall be authorised and traceable. Security testing shall be performed according to system criticality.
Information-security controls shall support business continuity and disaster recovery arrangements. Critical technology dependencies shall be identified and recovery requirements documented.
Relevant personnel shall receive periodic training on passwords, phishing, data handling, incident reporting, customer information protection, secure use of systems and other applicable security responsibilities.
Security controls may be tested through vulnerability assessments, access reviews, configuration reviews, application security testing, incident exercises and other assurance activities proportionate to risk.
Employees, vendors and relevant partners shall report suspected security incidents, unauthorised access, credential compromise, data leakage, malware, phishing and other material security events through approved channels.
Security exceptions shall be documented, risk-assessed, approved by authorised management and reviewed periodically. Exceptions shall not override mandatory legal, regulatory or contractual requirements.
| Function | Responsibility | Escalation |
|---|---|---|
| Board / Management | Security governance, resources and material risk decisions | Director / Management |
| Information Security | Security framework, monitoring, incident coordination and assurance | Management |
| Technology | Systems, infrastructure, applications, access and patching | Technology Head |
| Compliance / Legal | Regulatory, contractual and privacy requirements | Compliance/Legal Head |
| Risk / Fraud | Security-risk linkage, fraud signals and escalation | Risk/Fraud Head |
| Operations | Operational security controls and process compliance | Operations Head |
| Employees / Contractors | Follow security requirements and report incidents | Functional Head |
| Vendors / Partners | Meet contractual security requirements and cooperate on incidents | Partner Owner |
Security records, logs, approvals, incidents, assessments, training records, access reviews and remediation evidence shall be retained according to the Company's approved data-retention requirements.
This Policy shall be reviewed at least annually and whenever there is a material change in business operations, technology, threat environment, product architecture, regulatory requirements or security risk.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Information Security / Technology / Compliance | |
| Reviewed By | Legal / Risk / Operations | |
| Approved By | Director / Authorised Signatory |