RanaPay

RANAPAY INDIA PRIVATE LIMITED

DATA PROTECTION, PRIVACY & RETENTION POLICY

POLICY NO. 14 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Information Security / Operations
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for responsible collection, use, access, sharing, protection, retention and disposal of personal, customer, transaction and business information handled by RanaPay.

2. OBJECTIVES

  • Protect personal and confidential information.
  • Use information only for legitimate and defined purposes.
  • Apply appropriate security controls.
  • Limit access to authorised personnel.
  • Manage data retention and secure disposal.
  • Support customer privacy and applicable legal requirements.
  • Manage data incidents and third-party processing risks.

3. SCOPE

This Policy applies to personal information, customer information, transaction data, gift-card/voucher information, employee information, business records and other data processed by RanaPay through websites, applications, APIs, systems, partners, vendors and internal processes.

4. DATA PROTECTION PRINCIPLES

  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Transparency
  • Security and confidentiality
  • Need-to-know access
  • Retention limitation
  • Accountability

5. DATA CATEGORIES

  • Customer identity/contact information
  • Transaction and order information
  • Gift-card/voucher information
  • Payment-related references
  • Support and grievance records
  • Fraud/risk information
  • Employee and contractor information
  • Business and technical information

Sensitive or restricted information shall receive enhanced controls appropriate to its risk.

6. LAWFUL & PURPOSE-BASED PROCESSING

Personal information shall be collected and processed for legitimate business, contractual, legal, security, fraud-prevention, customer-support or other documented purposes, subject to applicable requirements.

7. DATA COLLECTION

Only information reasonably necessary for the stated purpose should be collected. Customer-facing notices and forms should communicate relevant collection and use information where required.

8. DATA ACCURACY

Reasonable measures shall be taken to keep information accurate and up to date for the purposes for which it is used.

9. CUSTOMER PRIVACY

RanaPay shall provide appropriate privacy information through its website, applications or other customer-facing channels and shall handle privacy requests according to applicable law and operational procedures.

10. DATA ACCESS

Access shall be based on role, business need and least privilege. Sensitive information shall not be accessed merely for convenience.

11. DATA SHARING

Information may be shared with authorised PPI issuers, banks, payment processors, merchants, technology providers, service providers, professional advisers, regulators or authorities where necessary for legitimate purposes and permitted by applicable law and contractual arrangements.

12. THIRD-PARTY PROCESSORS

Third parties handling personal or confidential information shall be subject to appropriate due diligence, contractual controls, confidentiality obligations, security requirements and monitoring under the Third-Party / Vendor Risk Management Policy.

13. CROSS-BORDER / EXTERNAL TRANSFERS

Where information is transferred to or accessed from another jurisdiction, RanaPay shall apply the safeguards and legal requirements applicable to such transfer.

14. INFORMATION SECURITY

Data shall be protected through appropriate administrative, technical and physical controls consistent with the Information Security & Cyber Security Policy.

15. ENCRYPTION & SECURE TRANSFER

Sensitive information shall be protected during transmission using appropriate secure mechanisms. Encryption at rest shall be applied where appropriate based on risk and system capability.

16. DATA RETENTION

Records shall be retained only for as long as necessary to fulfil the applicable business, legal, regulatory, contractual, accounting, fraud-prevention or dispute-management purpose, subject to any mandatory retention period.

17. RETENTION SCHEDULE

Record TypeRetention ApproachOwner
Customer/account recordsAs required by applicable law, product/partner requirements and legitimate business purposeOperations / Compliance
Transaction recordsAs required for legal, accounting, dispute, fraud and partner purposesFinance / Operations
KYC/verification recordsAs required by applicable law and partner requirementsCompliance
Grievance recordsFor applicable complaint, audit and legal requirementsCustomer Support / Compliance
Security/incident recordsFor security, audit, legal and incident-management requirementsInformation Security
Vendor recordsFor contractual, audit and risk-management requirementsVendor Management / Compliance

18. DATA DISPOSAL

When information is no longer required and no legal or operational hold applies, it shall be securely deleted, anonymised, destroyed or otherwise disposed of using methods appropriate to the medium and sensitivity.

19. LEGAL / LITIGATION HOLD

Deletion shall be suspended where records are subject to a legal, regulatory, audit, dispute, investigation or other authorised hold.

20. CUSTOMER DATA REQUESTS

Where applicable, customer requests relating to access, correction, deletion, consent or other privacy rights shall be received, verified, assessed and handled according to applicable law and RanaPay's documented procedures.

21. IDENTITY VERIFICATION

Reasonable verification shall be completed before disclosing, modifying or deleting sensitive customer information to reduce the risk of social engineering or unauthorised access.

22. DATA BREACH / INCIDENT

Suspected loss, unauthorised access, disclosure or compromise of personal or confidential information shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and applicable legal/contractual procedures.

23. DATA MINIMISATION

Systems and processes should avoid collecting or retaining unnecessary information. Where possible, data fields and access should be limited to the minimum required.

24. MASKING / REDACTION

Sensitive information should be masked or redacted in reports, screenshots, support communications and test environments where full values are not required.

25. TEST / DEVELOPMENT DATA

Production customer or sensitive data should not be used in development or testing unless specifically authorised and appropriately protected.

26. EMPLOYEE RESPONSIBILITIES

  • Use data only for authorised purposes
  • Protect credentials and devices
  • Do not disclose confidential data without authority
  • Report suspected data incidents
  • Follow retention and disposal procedures
  • Complete required privacy/security training

27. TRAINING & AWARENESS

Personnel handling customer or confidential information shall receive appropriate privacy, data-handling and information-security awareness.

28. RECORD OF PROCESSING / DATA INVENTORY

Where appropriate to the scale and nature of processing, RanaPay shall maintain an inventory or documented description of major data categories, purposes, systems, recipients, retention requirements and responsible owners.

29. MONITORING & AUDIT

Compliance with this Policy may be assessed through access reviews, vendor reviews, data-retention checks, security assessments, internal audits or other assurance activities.

30. NON-COMPLIANCE

Actual or suspected non-compliance shall be investigated and may result in corrective action, access restriction, disciplinary measures or contractual action, subject to applicable requirements.

31. POLICY EXCEPTIONS

Exceptions shall be documented, risk-assessed, time-bound where appropriate and approved by an authorised person. Mandatory legal or regulatory requirements shall not be overridden.

32. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
CompliancePrivacy governance, legal/regulatory oversight and data-risk reviewManagement
Information Security / ITTechnical data security, access, logging and incident supportSecurity Head
OperationsData collection, customer processes and recordsOperations Head
Customer SupportPrivacy-related customer requests and communicationCompliance
FinanceFinancial record retention and accounting recordsFinance Head
Third-Party ManagementVendor due diligence and contractual data controlsCompliance / Management
All UsersSecure and lawful handling of informationManager / Compliance

33. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in applicable privacy requirements, products, systems, partners or data-processing activities.

34. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Information Security / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED