CYBERVED AI PRIVATE LIMITED
BUSINESS CONTINUITY & DISASTER RECOVERY POLICY
POLICY NO. 17 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Management / Operations / Technology / Risk |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Business Continuity Controlled Policy |
1. PURPOSE
This Policy establishes the framework for maintaining critical business services and recovering systems, data and operations following disruption, disaster, cyber incident, technology failure, partner outage or other material event affecting CYBERVED AI PRIVATE LIMITED.
2. OBJECTIVES
- Protect customers, employees, information and critical business operations.
- Reduce downtime and operational impact.
- Define recovery priorities and responsibilities.
- Maintain appropriate backup and recovery arrangements.
- Coordinate with PPI, banking, payment and technology partners.
- Test and improve continuity capabilities.
3. SCOPE
This Policy applies to critical business processes, employees, facilities, applications, APIs, cloud infrastructure, transaction systems, customer support, payment/voucher operations, data and critical third-party services.
4. BUSINESS DISRUPTION EVENTS
- Cyber-security incident
- System or application failure
- Cloud/infrastructure outage
- Power or connectivity failure
- Natural disaster
- Fire or physical disruption
- Critical vendor/partner outage
- Data loss or corruption
- Pandemic or workforce disruption
- Other material operational event
5. BUSINESS IMPACT ASSESSMENT
Critical processes shall be assessed for customer impact, financial impact, regulatory/contractual impact, dependency, recovery requirements and acceptable downtime.
6. CRITICAL SERVICES
- Customer account and support services
- Payment and transaction processing
- Gift-card/voucher issuance and status systems
- Settlement and reconciliation
- Fraud and security monitoring
- Partner/API connectivity
- Core data and records
7. RECOVERY PRIORITIES
Recovery shall prioritise services according to business criticality, customer impact, security considerations, legal/regulatory obligations and operational dependencies.
8. RECOVERY OBJECTIVES
For critical systems, appropriate recovery time and recovery point objectives should be defined based on risk, technical capability, partner arrangements and business requirements.
9. BACKUP POLICY
- Critical data shall be backed up according to business requirements.
- Backup access shall be restricted.
- Backups should be protected against unauthorised alteration or deletion.
- Recovery procedures shall be periodically tested where appropriate.
10. DISASTER RECOVERY STRATEGY
Depending on the nature of the disruption, recovery may involve restoration from backup, failover to alternate infrastructure, temporary manual procedures, partner-based continuity arrangements or other approved recovery measures.
11. INCIDENT ACTIVATION
- Identify and assess the disruption.
- Determine whether continuity activation is required.
- Notify responsible management and response teams.
- Prioritise critical services.
- Activate recovery procedures.
- Communicate with affected stakeholders.
- Restore and validate services.
- Close activation and conduct post-event review.
12. CRISIS MANAGEMENT
Management shall coordinate material disruptions, prioritise business decisions, approve external communications and ensure appropriate stakeholder coordination.
13. COMMUNICATIONS
During a material disruption, communications shall be coordinated through authorised personnel. Customer, partner, employee and regulatory communications shall be accurate, timely and appropriate to the situation.
14. THIRD-PARTY CONTINUITY
Critical vendors and PPI/bank/payment partners shall be considered in continuity planning, including contact information, dependencies, alternate arrangements and escalation paths where available.
15. MANUAL / ALTERNATE PROCEDURES
Where automated services are unavailable, approved temporary manual or alternate processes may be used when secure and operationally feasible. Such activities shall be documented and reconciled after restoration.
16. DATA RECOVERY
Recovered data shall be checked for integrity, completeness and consistency before being used for critical operations.
17. CYBER INCIDENT COORDINATION
Cyber-related disruptions shall be managed jointly with the Cyber Incident Response & Cyber Fraud Policy and Information Security & Cyber Security Policy.
18. PAYMENT / SETTLEMENT CONTINUITY
Payment, settlement and reconciliation dependencies shall be incorporated into continuity planning to reduce customer and financial impact during outages.
19. EMPLOYEE CONTINUITY
Critical roles shall have designated backups or alternate arrangements where practical. Essential contact lists shall be maintained securely.
20. ALTERNATE WORKING
Where necessary, approved alternate working arrangements may be activated, subject to information-security, privacy and access-control requirements.
21. TESTING & EXERCISES
- Backup restoration tests
- System recovery tests
- Tabletop exercises
- Communication tests
- Partner escalation tests
- Scenario-based continuity exercises
22. TEST RESULTS
Test results shall document scope, date, participants, findings, recovery performance, gaps and corrective actions.
23. POST-INCIDENT REVIEW
After a material disruption, the Company shall review the event, identify root causes and implement corrective or preventive actions.
24. RECORD KEEPING
Continuity plans, recovery procedures, test results, incident records, contact lists and corrective actions shall be retained according to applicable requirements.
25. PLAN MAINTENANCE
Continuity plans shall be updated following material technology, process, partner, office, staffing or business changes.
26. EXCEPTIONS
Exceptions to continuity requirements shall be documented, risk-assessed and approved by authorised management.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Crisis decisions, prioritisation and oversight | Director / Management |
| Operations | Business process continuity and service coordination | Operations Head |
| Technology / IT | Infrastructure recovery, backups and restoration | Technology Head |
| Information Security | Security controls and cyber recovery coordination | Security Head |
| Compliance / Legal | Regulatory/contractual continuity considerations | Compliance / Legal |
| Finance | Payment, settlement and financial continuity | Finance Head |
| Vendor Management | Critical partner/vendor continuity coordination | Management |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and following a material disruption, significant test finding, major system/partner change or material change in applicable requirements.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Management / Operations / Technology / Risk | |
| Reviewed By | Compliance / Information Security / Legal | |
| Approved By | Director / Authorised Signatory |