Haripay INDIA PRIVATE LIMITED
BUSINESS CONTINUITY & DISASTER RECOVERY POLICY
POLICY NO. 17 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | Haripay INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | Haripay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Management / Operations / Technology / Compliance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Business Continuity Document |
1. PURPOSE
This Policy establishes the framework for maintaining critical business operations and recovering technology, transaction, customer-support and other essential services following disruption, disaster, cyber incident, partner outage or other business interruption.
2. OBJECTIVES
- Protect customers and critical business processes.
- Reduce downtime and operational impact.
- Define continuity and recovery responsibilities.
- Maintain critical data and systems through appropriate backup arrangements.
- Coordinate with key partners and vendors.
- Test recovery capability and improve resilience.
3. SCOPE
This Policy applies to critical business processes, technology systems, applications, APIs, transaction processing, customer support, settlement/reconciliation, key vendors, PPI/bank/payment partners, facilities, personnel and information required for Haripay operations.
4. BUSINESS DISRUPTION SCENARIOS
- Cybersecurity incident
- System/application failure
- Cloud or hosting outage
- Network/telecommunication failure
- Power or facility disruption
- Payment/PPI/bank partner outage
- Critical vendor failure
- Data corruption/loss
- Natural or other physical disaster
- Key-personnel unavailability
5. CRITICAL BUSINESS FUNCTIONS
- Customer support and grievance handling
- Transaction/order processing
- Gift-card/voucher issuance and status management
- Partner/API connectivity
- Payment and settlement operations
- Reconciliation and financial controls
- Fraud/risk monitoring
- Information security and incident response
6. BUSINESS IMPACT ASSESSMENT
Critical processes shall be assessed for customer impact, financial impact, regulatory/contractual impact, operational dependency, data loss and recovery requirements.
7. RECOVERY PRIORITIES
Recovery priority shall be based on business criticality, customer impact, transaction dependency, security risk, contractual obligations and management assessment.
8. RECOVERY OBJECTIVES
Appropriate Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) shall be defined for critical systems where practicable. Objectives shall be proportionate to business and technology risk.
9. BACKUP & DATA RECOVERY
- Critical data shall be backed up according to risk and system requirements.
- Backups shall be protected from unauthorised access.
- Backup restoration shall be tested periodically where appropriate.
- Critical backup failures shall be investigated.
10. TECHNOLOGY RECOVERY
- Identify affected systems.
- Contain security risks.
- Restore infrastructure/application components.
- Restore trusted data.
- Validate system integrity.
- Test critical functions.
- Reconnect partners/APIs.
- Approve return to normal operations.
11. MANUAL / ALTERNATE PROCEDURES
Where technology services are unavailable, approved manual or alternate procedures may be used for critical activities where feasible, with appropriate controls and later reconciliation.
12. PARTNER & VENDOR CONTINUITY
Critical PPI issuers, banks, payment processors, cloud providers and vendors shall be assessed for continuity arrangements where their failure could materially affect Haripay.
13. COMMUNICATION
A disruption communication process shall identify internal escalation, partner coordination, customer communication and management reporting responsibilities. External communications shall be issued only by authorised personnel.
14. INCIDENT ESCALATION
- Material customer impact
- Critical system outage
- Significant transaction disruption
- Settlement/reconciliation interruption
- Cybersecurity incident
- Extended partner outage
- Potential regulatory/contractual impact
15. CRISIS MANAGEMENT
Management may activate a crisis-management structure for material disruptions and designate an incident/continuity coordinator responsible for coordinating response and recovery.
16. ROLES & RESPONSIBILITIES
- Management – strategic decisions and crisis oversight
- Operations – business process continuity
- Technology – system recovery
- Information Security – cyber containment and secure recovery
- Finance – settlement/reconciliation continuity
- Compliance – regulatory/contractual coordination
- Customer Support – customer communications
- Partner Management – external partner coordination
17. ALTERNATE WORKING
Where required, approved remote or alternate working arrangements may be used, subject to information-security, access-control and data-protection requirements.
18. ACCESS DURING DISASTER
Emergency access shall be limited, authorised, logged and reviewed after normal operations resume. Privileged emergency credentials shall be protected.
19. DATA INTEGRITY
Recovered systems and data shall be validated before being returned to production. Suspected corrupted or compromised data shall not be treated as trusted until appropriately reviewed.
20. RETURN TO NORMAL OPERATIONS
- Confirm recovery criteria.
- Validate systems and data.
- Confirm partner connectivity.
- Reconcile transactions and financial records.
- Remove temporary emergency controls.
- Document outstanding issues.
- Obtain management closure approval.
21. RECONCILIATION AFTER DISRUPTION
Transactions, payments, refunds, redemptions, settlements and other relevant records processed during or immediately before the disruption shall be reconciled after recovery.
22. TESTING & EXERCISES
- Tabletop exercises
- Backup restoration tests
- System recovery tests
- Partner communication drills
- Cyber incident simulations
- Manual process tests
Testing results shall be documented and material weaknesses shall have corrective actions.
23. PLAN MAINTENANCE
Continuity plans, contact lists, system dependencies and recovery procedures shall be updated following material changes, incidents and testing outcomes.
24. THIRD-PARTY DEPENDENCY
Material dependencies on single vendors, payment processors, PPI issuers, banks or technology platforms shall be documented and appropriate contingency measures considered.
25. RECORD KEEPING
- Business impact assessments
- Continuity plans
- Recovery procedures
- Backup/testing records
- Exercise reports
- Incident logs
- Partner communications
- Recovery approvals
- Post-event reviews
26. POST-INCIDENT REVIEW
Material disruptions shall be reviewed after recovery to identify root causes, control gaps, recovery performance, lessons learned and improvement actions.
27. TRAINING & AWARENESS
Personnel with continuity or recovery responsibilities shall understand their roles and participate in relevant exercises or training.
28. AUDIT & ASSURANCE
Business continuity and disaster recovery controls may be reviewed through internal audits, testing, partner assessments and management reviews.
29. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.
30. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Crisis decisions, resource allocation and approval | Director / Authorised Management |
| Operations | Business-process continuity and recovery | Operations Head |
| Technology / IT | Infrastructure/application recovery and backups | Technology Head |
| Information Security | Cyber containment and secure recovery | Security Head |
| Finance | Settlement and reconciliation continuity | Finance Head |
| Compliance | Regulatory/contractual coordination | Compliance Head |
| Partner Management | PPI/bank/payment/vendor coordination | Management |
| Customer Support | Customer support and approved communications | Operations / Management |
31. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in systems, business processes, partner dependencies, critical vendors or applicable requirements, and after material disruptions.
32. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Management / Operations / Technology / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
