e-suvidha

CYBERVED AI PRIVATE LIMITED

BUSINESS CONTINUITY & DISASTER RECOVERY POLICY

POLICY NO. 17 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerManagement / Operations / Technology / Risk
Review FrequencyAt least annually / event driven
ClassificationConfidential – Business Continuity Controlled Policy

1. PURPOSE

This Policy establishes the framework for maintaining critical business services and recovering systems, data and operations following disruption, disaster, cyber incident, technology failure, partner outage or other material event affecting CYBERVED AI PRIVATE LIMITED.

2. OBJECTIVES

  • Protect customers, employees, information and critical business operations.
  • Reduce downtime and operational impact.
  • Define recovery priorities and responsibilities.
  • Maintain appropriate backup and recovery arrangements.
  • Coordinate with PPI, banking, payment and technology partners.
  • Test and improve continuity capabilities.

3. SCOPE

This Policy applies to critical business processes, employees, facilities, applications, APIs, cloud infrastructure, transaction systems, customer support, payment/voucher operations, data and critical third-party services.

4. BUSINESS DISRUPTION EVENTS

  • Cyber-security incident
  • System or application failure
  • Cloud/infrastructure outage
  • Power or connectivity failure
  • Natural disaster
  • Fire or physical disruption
  • Critical vendor/partner outage
  • Data loss or corruption
  • Pandemic or workforce disruption
  • Other material operational event

5. BUSINESS IMPACT ASSESSMENT

Critical processes shall be assessed for customer impact, financial impact, regulatory/contractual impact, dependency, recovery requirements and acceptable downtime.

6. CRITICAL SERVICES

  • Customer account and support services
  • Payment and transaction processing
  • Gift-card/voucher issuance and status systems
  • Settlement and reconciliation
  • Fraud and security monitoring
  • Partner/API connectivity
  • Core data and records

7. RECOVERY PRIORITIES

Recovery shall prioritise services according to business criticality, customer impact, security considerations, legal/regulatory obligations and operational dependencies.

8. RECOVERY OBJECTIVES

For critical systems, appropriate recovery time and recovery point objectives should be defined based on risk, technical capability, partner arrangements and business requirements.

9. BACKUP POLICY

  • Critical data shall be backed up according to business requirements.
  • Backup access shall be restricted.
  • Backups should be protected against unauthorised alteration or deletion.
  • Recovery procedures shall be periodically tested where appropriate.

10. DISASTER RECOVERY STRATEGY

Depending on the nature of the disruption, recovery may involve restoration from backup, failover to alternate infrastructure, temporary manual procedures, partner-based continuity arrangements or other approved recovery measures.

11. INCIDENT ACTIVATION

  1. Identify and assess the disruption.
  2. Determine whether continuity activation is required.
  3. Notify responsible management and response teams.
  4. Prioritise critical services.
  5. Activate recovery procedures.
  6. Communicate with affected stakeholders.
  7. Restore and validate services.
  8. Close activation and conduct post-event review.

12. CRISIS MANAGEMENT

Management shall coordinate material disruptions, prioritise business decisions, approve external communications and ensure appropriate stakeholder coordination.

13. COMMUNICATIONS

During a material disruption, communications shall be coordinated through authorised personnel. Customer, partner, employee and regulatory communications shall be accurate, timely and appropriate to the situation.

14. THIRD-PARTY CONTINUITY

Critical vendors and PPI/bank/payment partners shall be considered in continuity planning, including contact information, dependencies, alternate arrangements and escalation paths where available.

15. MANUAL / ALTERNATE PROCEDURES

Where automated services are unavailable, approved temporary manual or alternate processes may be used when secure and operationally feasible. Such activities shall be documented and reconciled after restoration.

16. DATA RECOVERY

Recovered data shall be checked for integrity, completeness and consistency before being used for critical operations.

17. CYBER INCIDENT COORDINATION

Cyber-related disruptions shall be managed jointly with the Cyber Incident Response & Cyber Fraud Policy and Information Security & Cyber Security Policy.

18. PAYMENT / SETTLEMENT CONTINUITY

Payment, settlement and reconciliation dependencies shall be incorporated into continuity planning to reduce customer and financial impact during outages.

19. EMPLOYEE CONTINUITY

Critical roles shall have designated backups or alternate arrangements where practical. Essential contact lists shall be maintained securely.

20. ALTERNATE WORKING

Where necessary, approved alternate working arrangements may be activated, subject to information-security, privacy and access-control requirements.

21. TESTING & EXERCISES

  • Backup restoration tests
  • System recovery tests
  • Tabletop exercises
  • Communication tests
  • Partner escalation tests
  • Scenario-based continuity exercises

22. TEST RESULTS

Test results shall document scope, date, participants, findings, recovery performance, gaps and corrective actions.

23. POST-INCIDENT REVIEW

After a material disruption, the Company shall review the event, identify root causes and implement corrective or preventive actions.

24. RECORD KEEPING

Continuity plans, recovery procedures, test results, incident records, contact lists and corrective actions shall be retained according to applicable requirements.

25. PLAN MAINTENANCE

Continuity plans shall be updated following material technology, process, partner, office, staffing or business changes.

26. EXCEPTIONS

Exceptions to continuity requirements shall be documented, risk-assessed and approved by authorised management.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementCrisis decisions, prioritisation and oversightDirector / Management
OperationsBusiness process continuity and service coordinationOperations Head
Technology / ITInfrastructure recovery, backups and restorationTechnology Head
Information SecuritySecurity controls and cyber recovery coordinationSecurity Head
Compliance / LegalRegulatory/contractual continuity considerationsCompliance / Legal
FinancePayment, settlement and financial continuityFinance Head
Vendor ManagementCritical partner/vendor continuity coordinationManagement

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and following a material disruption, significant test finding, major system/partner change or material change in applicable requirements.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByManagement / Operations / Technology / Risk
Reviewed ByCompliance / Information Security / Legal
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – BUSINESS CONTINUITY CONTROLLED POLICY