RANAPAY INDIA PRIVATE LIMITED
DATA PROTECTION, PRIVACY & RETENTION POLICY
POLICY NO. 14 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Information Security / Operations |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for responsible collection, use, access, sharing, protection, retention and disposal of personal, customer, transaction and business information handled by RanaPay.
2. OBJECTIVES
- Protect personal and confidential information.
- Use information only for legitimate and defined purposes.
- Apply appropriate security controls.
- Limit access to authorised personnel.
- Manage data retention and secure disposal.
- Support customer privacy and applicable legal requirements.
- Manage data incidents and third-party processing risks.
3. SCOPE
This Policy applies to personal information, customer information, transaction data, gift-card/voucher information, employee information, business records and other data processed by RanaPay through websites, applications, APIs, systems, partners, vendors and internal processes.
4. DATA PROTECTION PRINCIPLES
- Purpose limitation
- Data minimisation
- Accuracy
- Transparency
- Security and confidentiality
- Need-to-know access
- Retention limitation
- Accountability
5. DATA CATEGORIES
- Customer identity/contact information
- Transaction and order information
- Gift-card/voucher information
- Payment-related references
- Support and grievance records
- Fraud/risk information
- Employee and contractor information
- Business and technical information
Sensitive or restricted information shall receive enhanced controls appropriate to its risk.
6. LAWFUL & PURPOSE-BASED PROCESSING
Personal information shall be collected and processed for legitimate business, contractual, legal, security, fraud-prevention, customer-support or other documented purposes, subject to applicable requirements.
7. DATA COLLECTION
Only information reasonably necessary for the stated purpose should be collected. Customer-facing notices and forms should communicate relevant collection and use information where required.
8. DATA ACCURACY
Reasonable measures shall be taken to keep information accurate and up to date for the purposes for which it is used.
9. CUSTOMER PRIVACY
RanaPay shall provide appropriate privacy information through its website, applications or other customer-facing channels and shall handle privacy requests according to applicable law and operational procedures.
10. DATA ACCESS
Access shall be based on role, business need and least privilege. Sensitive information shall not be accessed merely for convenience.
11. DATA SHARING
Information may be shared with authorised PPI issuers, banks, payment processors, merchants, technology providers, service providers, professional advisers, regulators or authorities where necessary for legitimate purposes and permitted by applicable law and contractual arrangements.
12. THIRD-PARTY PROCESSORS
Third parties handling personal or confidential information shall be subject to appropriate due diligence, contractual controls, confidentiality obligations, security requirements and monitoring under the Third-Party / Vendor Risk Management Policy.
13. CROSS-BORDER / EXTERNAL TRANSFERS
Where information is transferred to or accessed from another jurisdiction, RanaPay shall apply the safeguards and legal requirements applicable to such transfer.
14. INFORMATION SECURITY
Data shall be protected through appropriate administrative, technical and physical controls consistent with the Information Security & Cyber Security Policy.
15. ENCRYPTION & SECURE TRANSFER
Sensitive information shall be protected during transmission using appropriate secure mechanisms. Encryption at rest shall be applied where appropriate based on risk and system capability.
16. DATA RETENTION
Records shall be retained only for as long as necessary to fulfil the applicable business, legal, regulatory, contractual, accounting, fraud-prevention or dispute-management purpose, subject to any mandatory retention period.
17. RETENTION SCHEDULE
| Record Type | Retention Approach | Owner |
|---|---|---|
| Customer/account records | As required by applicable law, product/partner requirements and legitimate business purpose | Operations / Compliance |
| Transaction records | As required for legal, accounting, dispute, fraud and partner purposes | Finance / Operations |
| KYC/verification records | As required by applicable law and partner requirements | Compliance |
| Grievance records | For applicable complaint, audit and legal requirements | Customer Support / Compliance |
| Security/incident records | For security, audit, legal and incident-management requirements | Information Security |
| Vendor records | For contractual, audit and risk-management requirements | Vendor Management / Compliance |
18. DATA DISPOSAL
When information is no longer required and no legal or operational hold applies, it shall be securely deleted, anonymised, destroyed or otherwise disposed of using methods appropriate to the medium and sensitivity.
19. LEGAL / LITIGATION HOLD
Deletion shall be suspended where records are subject to a legal, regulatory, audit, dispute, investigation or other authorised hold.
20. CUSTOMER DATA REQUESTS
Where applicable, customer requests relating to access, correction, deletion, consent or other privacy rights shall be received, verified, assessed and handled according to applicable law and RanaPay's documented procedures.
21. IDENTITY VERIFICATION
Reasonable verification shall be completed before disclosing, modifying or deleting sensitive customer information to reduce the risk of social engineering or unauthorised access.
22. DATA BREACH / INCIDENT
Suspected loss, unauthorised access, disclosure or compromise of personal or confidential information shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and applicable legal/contractual procedures.
23. DATA MINIMISATION
Systems and processes should avoid collecting or retaining unnecessary information. Where possible, data fields and access should be limited to the minimum required.
24. MASKING / REDACTION
Sensitive information should be masked or redacted in reports, screenshots, support communications and test environments where full values are not required.
25. TEST / DEVELOPMENT DATA
Production customer or sensitive data should not be used in development or testing unless specifically authorised and appropriately protected.
26. EMPLOYEE RESPONSIBILITIES
- Use data only for authorised purposes
- Protect credentials and devices
- Do not disclose confidential data without authority
- Report suspected data incidents
- Follow retention and disposal procedures
- Complete required privacy/security training
27. TRAINING & AWARENESS
Personnel handling customer or confidential information shall receive appropriate privacy, data-handling and information-security awareness.
28. RECORD OF PROCESSING / DATA INVENTORY
Where appropriate to the scale and nature of processing, RanaPay shall maintain an inventory or documented description of major data categories, purposes, systems, recipients, retention requirements and responsible owners.
29. MONITORING & AUDIT
Compliance with this Policy may be assessed through access reviews, vendor reviews, data-retention checks, security assessments, internal audits or other assurance activities.
30. NON-COMPLIANCE
Actual or suspected non-compliance shall be investigated and may result in corrective action, access restriction, disciplinary measures or contractual action, subject to applicable requirements.
31. POLICY EXCEPTIONS
Exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by an authorised person. Mandatory legal or regulatory requirements shall not be overridden.
32. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Compliance | Privacy governance, legal/regulatory oversight and data-risk review | Management |
| Information Security / IT | Technical data security, access, logging and incident support | Security Head |
| Operations | Data collection, customer processes and records | Operations Head |
| Customer Support | Privacy-related customer requests and communication | Compliance |
| Finance | Financial record retention and accounting records | Finance Head |
| Third-Party Management | Vendor due diligence and contractual data controls | Compliance / Management |
| All Users | Secure and lawful handling of information | Manager / Compliance |
33. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in applicable privacy requirements, products, systems, partners or data-processing activities.
34. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Information Security / Operations | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
