e-suvidha

CYBERVED AI PRIVATE LIMITED

DATA PROTECTION, PRIVACY & RETENTION POLICY

POLICY NO. 14 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerCompliance / Information Security / Operations
Review FrequencyAt least annually / event driven
ClassificationConfidential – Data Protection & Privacy Controlled Policy

1. PURPOSE

This Policy establishes principles and controls for the collection, use, disclosure, protection, retention and secure disposal of personal and business information handled by CYBERVED AI PRIVATE LIMITED in connection with its services.

2. OBJECTIVES

  • Process personal information fairly, lawfully and transparently.
  • Collect information only for legitimate and defined purposes.
  • Protect information against unauthorised access, loss, misuse or disclosure.
  • Provide appropriate customer privacy information and rights mechanisms.
  • Retain information only for applicable requirements.
  • Support privacy-aware operations and third-party governance.

3. SCOPE

This Policy applies to personal information and relevant business information processed through websites, applications, APIs, customer support, payment/voucher operations, employees, contractors, cloud systems and third-party service providers.

4. DATA CATEGORIES

  • Customer identification and contact information
  • Account and authentication information
  • Transaction, payment and order information
  • Gift-card/voucher information
  • Customer support and grievance records
  • Device/technical information where collected
  • Employee/vendor information
  • Security and audit logs

5. PURPOSE LIMITATION

Information shall be collected and used for defined business, service, security, legal, contractual and compliance purposes. Secondary uses shall be subject to applicable requirements and appropriate safeguards.

6. DATA MINIMISATION

Only information reasonably necessary for the relevant purpose shall be collected or retained, subject to legal, regulatory, contractual and operational requirements.

7. NOTICE & TRANSPARENCY

Appropriate privacy notices shall explain relevant categories of information, purposes, disclosures, rights and contact/escalation mechanisms, as applicable.

8. CONSENT / LAWFUL BASIS

Where consent is required, it shall be obtained through an appropriate mechanism. Where processing is based on another lawful basis, the Company shall document and apply the relevant basis consistent with applicable law.

9. DATA ACCURACY

Reasonable measures shall be taken to maintain accurate and up-to-date information where accuracy is relevant to the purpose of processing.

10. CUSTOMER RIGHTS

Requests concerning applicable privacy rights shall be handled through designated channels and within timelines required by applicable law. Verification may be required before action on a request.

11. DATA ACCESS

Access to personal information shall be limited to authorised personnel with a legitimate business need. Privileged access shall be controlled and reviewed.

12. DATA SECURITY

  • Access controls and authentication
  • Encryption or equivalent safeguards where appropriate
  • Secure transmission
  • Logging and monitoring
  • Backup and recovery controls
  • Vulnerability and patch management

13. DATA SHARING

Personal information may be shared with authorised PPI, banking, payment, merchant, technology, service or professional partners where necessary for service delivery, security, legal/compliance or other permitted purposes, subject to appropriate safeguards.

14. THIRD-PARTY PROCESSORS

Third parties processing personal information shall be subject to appropriate due diligence, contractual obligations, confidentiality, security requirements and monitoring based on risk.

15. CROSS-BORDER / HOSTED PROCESSING

Where information is processed or stored outside the primary operating jurisdiction, applicable legal, contractual and security requirements shall be assessed and addressed.

16. RETENTION PRINCIPLE

Information shall be retained only for the period necessary for its purpose and applicable legal, regulatory, contractual, accounting, dispute, fraud, audit or security requirements.

17. RETENTION SCHEDULE

Record TypeIndicative Retention BasisOwner
Customer/account recordsApplicable law, contract and operational needOperations / Compliance
Transaction/payment recordsApplicable financial, legal and partner requirementsFinance / Operations
Gift-card/voucher recordsProduct, partner, dispute and legal requirementsOperations
Grievance recordsApplicable complaint/dispute requirementsCustomer Support / Compliance
Security/incident recordsSecurity, legal, audit and incident requirementsInformation Security
Vendor recordsContractual, audit and compliance requirementsVendor Management / Compliance

18. LEGAL HOLD / PRESERVATION

Information subject to litigation, regulatory inquiry, fraud investigation, audit or other preservation requirements shall not be deleted until the applicable hold is released.

19. SECURE DISPOSAL

When retention ends and no preservation requirement applies, information shall be securely deleted, anonymised or otherwise disposed of using methods appropriate to its sensitivity and medium.

20. DATA BREACH / INCIDENT

Suspected personal-data breaches or security incidents shall be handled under the Cyber Incident Response & Cyber Fraud Policy and escalated according to applicable requirements.

21. CUSTOMER GRIEVANCES

Privacy-related complaints shall be handled through the Customer Grievance Redressal Policy and applicable privacy procedures.

22. DATA SUBJECT REQUEST MANAGEMENT

  1. Receive and register the request.
  2. Verify identity where appropriate.
  3. Assess scope and applicable requirements.
  4. Retrieve relevant information.
  5. Apply lawful exceptions or restrictions where applicable.
  6. Respond through the approved channel.
  7. Record the outcome.

23. CHILDREN / VULNERABLE PERSONS

Where services involve information relating to children or other protected categories, additional safeguards shall be applied as required by applicable law and product design.

24. MARKETING / COMMUNICATIONS

Marketing or promotional communications shall follow applicable consent, preference, opt-out and legal requirements.

25. EMPLOYEE CONFIDENTIALITY

Employees and contractors shall protect personal information and shall access or disclose it only for authorised purposes.

26. TRAINING & AWARENESS

Relevant personnel shall receive training appropriate to their role on privacy, data handling, security, incident reporting and confidentiality.

27. AUDIT & MONITORING

Privacy and retention controls may be periodically reviewed through access reviews, data-flow assessments, vendor reviews, sample checks and internal or external audits.

28. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management, while preserving mandatory legal and regulatory requirements.

29. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementPrivacy governance and risk oversightDirector / Management
Compliance / LegalLegal/privacy requirements and escalationsCompliance / Legal Head
Information SecurityTechnical security and incident controlsSecurity Head
OperationsData collection, use and retention processesOperations Head
Customer SupportPrivacy requests and complaintsSupport Head
Technology / ITSystems, access, backups and deletion controlsTechnology Head
Vendor ManagementThird-party privacy/security oversightManagement

30. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in applicable law, products, data flows, technology, partners or processing activities.

31. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Information Security / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – DATA PROTECTION & PRIVACY CONTROLLED POLICY