Haripay

Haripay INDIA PRIVATE LIMITED

BUSINESS CONTINUITY & DISASTER RECOVERY POLICY

POLICY NO. 17 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyHaripay INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
WebsiteHaripay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerManagement / Operations / Technology / Compliance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Business Continuity Document

1. PURPOSE

This Policy establishes the framework for maintaining critical business operations and recovering technology, transaction, customer-support and other essential services following disruption, disaster, cyber incident, partner outage or other business interruption.

2. OBJECTIVES

  • Protect customers and critical business processes.
  • Reduce downtime and operational impact.
  • Define continuity and recovery responsibilities.
  • Maintain critical data and systems through appropriate backup arrangements.
  • Coordinate with key partners and vendors.
  • Test recovery capability and improve resilience.

3. SCOPE

This Policy applies to critical business processes, technology systems, applications, APIs, transaction processing, customer support, settlement/reconciliation, key vendors, PPI/bank/payment partners, facilities, personnel and information required for Haripay operations.

4. BUSINESS DISRUPTION SCENARIOS

  • Cybersecurity incident
  • System/application failure
  • Cloud or hosting outage
  • Network/telecommunication failure
  • Power or facility disruption
  • Payment/PPI/bank partner outage
  • Critical vendor failure
  • Data corruption/loss
  • Natural or other physical disaster
  • Key-personnel unavailability

5. CRITICAL BUSINESS FUNCTIONS

  • Customer support and grievance handling
  • Transaction/order processing
  • Gift-card/voucher issuance and status management
  • Partner/API connectivity
  • Payment and settlement operations
  • Reconciliation and financial controls
  • Fraud/risk monitoring
  • Information security and incident response

6. BUSINESS IMPACT ASSESSMENT

Critical processes shall be assessed for customer impact, financial impact, regulatory/contractual impact, operational dependency, data loss and recovery requirements.

7. RECOVERY PRIORITIES

Recovery priority shall be based on business criticality, customer impact, transaction dependency, security risk, contractual obligations and management assessment.

8. RECOVERY OBJECTIVES

Appropriate Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) shall be defined for critical systems where practicable. Objectives shall be proportionate to business and technology risk.

9. BACKUP & DATA RECOVERY

  • Critical data shall be backed up according to risk and system requirements.
  • Backups shall be protected from unauthorised access.
  • Backup restoration shall be tested periodically where appropriate.
  • Critical backup failures shall be investigated.

10. TECHNOLOGY RECOVERY

  1. Identify affected systems.
  2. Contain security risks.
  3. Restore infrastructure/application components.
  4. Restore trusted data.
  5. Validate system integrity.
  6. Test critical functions.
  7. Reconnect partners/APIs.
  8. Approve return to normal operations.

11. MANUAL / ALTERNATE PROCEDURES

Where technology services are unavailable, approved manual or alternate procedures may be used for critical activities where feasible, with appropriate controls and later reconciliation.

12. PARTNER & VENDOR CONTINUITY

Critical PPI issuers, banks, payment processors, cloud providers and vendors shall be assessed for continuity arrangements where their failure could materially affect Haripay.

13. COMMUNICATION

A disruption communication process shall identify internal escalation, partner coordination, customer communication and management reporting responsibilities. External communications shall be issued only by authorised personnel.

14. INCIDENT ESCALATION

  • Material customer impact
  • Critical system outage
  • Significant transaction disruption
  • Settlement/reconciliation interruption
  • Cybersecurity incident
  • Extended partner outage
  • Potential regulatory/contractual impact

15. CRISIS MANAGEMENT

Management may activate a crisis-management structure for material disruptions and designate an incident/continuity coordinator responsible for coordinating response and recovery.

16. ROLES & RESPONSIBILITIES

  • Management – strategic decisions and crisis oversight
  • Operations – business process continuity
  • Technology – system recovery
  • Information Security – cyber containment and secure recovery
  • Finance – settlement/reconciliation continuity
  • Compliance – regulatory/contractual coordination
  • Customer Support – customer communications
  • Partner Management – external partner coordination

17. ALTERNATE WORKING

Where required, approved remote or alternate working arrangements may be used, subject to information-security, access-control and data-protection requirements.

18. ACCESS DURING DISASTER

Emergency access shall be limited, authorised, logged and reviewed after normal operations resume. Privileged emergency credentials shall be protected.

19. DATA INTEGRITY

Recovered systems and data shall be validated before being returned to production. Suspected corrupted or compromised data shall not be treated as trusted until appropriately reviewed.

20. RETURN TO NORMAL OPERATIONS

  1. Confirm recovery criteria.
  2. Validate systems and data.
  3. Confirm partner connectivity.
  4. Reconcile transactions and financial records.
  5. Remove temporary emergency controls.
  6. Document outstanding issues.
  7. Obtain management closure approval.

21. RECONCILIATION AFTER DISRUPTION

Transactions, payments, refunds, redemptions, settlements and other relevant records processed during or immediately before the disruption shall be reconciled after recovery.

22. TESTING & EXERCISES

  • Tabletop exercises
  • Backup restoration tests
  • System recovery tests
  • Partner communication drills
  • Cyber incident simulations
  • Manual process tests

Testing results shall be documented and material weaknesses shall have corrective actions.

23. PLAN MAINTENANCE

Continuity plans, contact lists, system dependencies and recovery procedures shall be updated following material changes, incidents and testing outcomes.

24. THIRD-PARTY DEPENDENCY

Material dependencies on single vendors, payment processors, PPI issuers, banks or technology platforms shall be documented and appropriate contingency measures considered.

25. RECORD KEEPING

  • Business impact assessments
  • Continuity plans
  • Recovery procedures
  • Backup/testing records
  • Exercise reports
  • Incident logs
  • Partner communications
  • Recovery approvals
  • Post-event reviews

26. POST-INCIDENT REVIEW

Material disruptions shall be reviewed after recovery to identify root causes, control gaps, recovery performance, lessons learned and improvement actions.

27. TRAINING & AWARENESS

Personnel with continuity or recovery responsibilities shall understand their roles and participate in relevant exercises or training.

28. AUDIT & ASSURANCE

Business continuity and disaster recovery controls may be reviewed through internal audits, testing, partner assessments and management reviews.

29. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.

30. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementCrisis decisions, resource allocation and approvalDirector / Authorised Management
OperationsBusiness-process continuity and recoveryOperations Head
Technology / ITInfrastructure/application recovery and backupsTechnology Head
Information SecurityCyber containment and secure recoverySecurity Head
FinanceSettlement and reconciliation continuityFinance Head
ComplianceRegulatory/contractual coordinationCompliance Head
Partner ManagementPPI/bank/payment/vendor coordinationManagement
Customer SupportCustomer support and approved communicationsOperations / Management

31. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in systems, business processes, partner dependencies, critical vendors or applicable requirements, and after material disruptions.

32. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByManagement / Operations / Technology / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED BUSINESS CONTINUITY DOCUMENT

Haripay INDIA PRIVATE LIMITED