Login or Create an account
Or Login Via

RECORD RETENTION & DATA PRESERVATION POLICY (RRP)

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Record Retention & Data Preservation Policy

ZESTFLOW INDIA PRIVATE LIMITED maintains a structured framework for the secure storage, preservation, retrieval and lawful disposal of business records. We retain records in accordance with applicable legal, regulatory, contractual and legitimate business requirements while ensuring appropriate confidentiality, data security and protection against unauthorised access or destruction.

1. Purpose and Policy Statement

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining appropriate standards for the creation, storage, preservation, retrieval and secure disposal of records generated or received in the course of its business.

This Policy establishes a structured framework to ensure that Company records are maintained for legitimate business, legal, regulatory, contractual, audit and operational purposes while protecting such records against unauthorised access, alteration, loss, misuse or destruction.

The Company shall retain records only for such period as may be required under applicable law, regulatory requirements, contractual obligations or legitimate business requirements, subject to any Legal Hold or preservation requirement.

2. Scope and Applicability

This Policy applies to:

  • the Board of Directors and Senior Management;
  • all departments and business functions;
  • employees, consultants and authorised representatives; and
  • vendors, service providers and other third parties handling or storing Company records, where applicable.

This Policy applies to records maintained in physical, electronic, digital or any other legally recognised form.

The extent and duration of record retention shall depend upon the nature of the record and the requirements applicable to the Company, including, where relevant:

  • applicable corporate, financial and taxation laws;
  • applicable AML, CFT and KYC requirements;
  • data protection and information technology laws;
  • regulatory or partner requirements;
  • contractual obligations; and
  • litigation, investigation or other legal requirements.

Where applicable law requires a longer retention period than this Policy, the applicable legal requirement shall prevail.

3. Governance and Responsibilities

The Board of Directors shall have overall oversight of the Company's record retention framework.

Senior Management and the appropriate Compliance, Legal, Finance, Technology or other responsible functions shall oversee implementation of this Policy within their respective areas.

Department Heads and designated record owners shall be responsible for ensuring that records generated or maintained within their functions are appropriately classified, stored, protected, retained and disposed of.

All employees and authorised persons shall:

  • create and maintain accurate records;
  • protect records from unauthorised access or disclosure;
  • comply with applicable retention requirements;
  • comply with Legal Hold and preservation instructions; and
  • promptly report any loss, unauthorised access, alteration or destruction of material records.

Where Company records are handled by a third-party service provider, appropriate contractual or operational safeguards may be implemented based on the nature and sensitivity of the records.

4. Categories and Retention of Records

The Company may create and maintain records including:

a. Customer and Merchant Records

KYC documents, onboarding information, due diligence records, business verification documents, agreements, communications and risk assessments.

b. Transaction and Operational Records

Transaction data, settlement records, refunds, reversals, chargebacks, system logs and other operational records.

c. AML/CFT and Compliance Records

Due diligence records, risk assessments, screening results, internal reviews, suspicious activity records and regulatory or partner communications.

d. Financial and Tax Records

Books of account, financial statements, invoices, bank records, tax records, audit reports and supporting documents.

e. Corporate and Legal Records

Board and shareholder records, statutory registers, licences, approvals, contracts, legal documents, policies and governance records.

f. Employee and Human Resource Records

Employment records, agreements, attendance, payroll, training, disciplinary and other employment-related records.

g. Technology and Security Records

System logs, access records, incident records, security reports, backup records and other relevant technology documentation.

Records shall be retained for the period required under applicable law, regulatory requirements, contractual obligations or legitimate business requirements.

Where no specific retention period is prescribed, the Company may determine an appropriate retention period considering:

  • the purpose for which the record was created;
  • legal and regulatory exposure;
  • applicable limitation periods;
  • operational and audit requirements;
  • contractual obligations;
  • data protection principles; and
  • the cost and risk associated with continued retention.

The Company may retain records for a longer period where reasonably necessary for legal, regulatory, security, fraud prevention, audit, dispute resolution or other legitimate purposes.

5. Storage, Security, Backup and Access

Records shall be maintained in a manner appropriate to their nature and sensitivity.

The Company shall implement reasonable administrative, technical and organisational safeguards designed to:

  • preserve the accuracy and integrity of records;
  • protect records against unauthorised access, alteration, loss or destruction;
  • enable timely retrieval where reasonably required;
  • restrict access based on roles and business requirements; and
  • maintain appropriate backup and recovery arrangements for critical electronic records.

Security measures may include, where appropriate:

  • role-based access controls;
  • authentication and password controls;
  • multi-factor authentication;
  • access logging;
  • encryption;
  • secure storage;
  • periodic backups; and
  • disaster recovery arrangements.

Access to confidential or sensitive records shall be limited to authorised persons on a need-to-know basis.

The Company may use third-party or cloud-based storage services subject to appropriate security, confidentiality and contractual safeguards.

6. Legal Hold and Preservation

Notwithstanding any normal retention period, records shall not be altered, deleted or destroyed where they are relevant to:

  • pending or reasonably anticipated litigation;
  • arbitration or other dispute resolution proceedings;
  • regulatory or governmental inquiry;
  • law enforcement investigation;
  • internal investigation;
  • audit;
  • legal notice, claim or complaint; or
  • any other matter requiring preservation.

The Company may issue a Legal Hold or preservation instruction identifying the records that must be preserved.

All employees, departments and relevant service providers shall comply with such instructions until the Legal Hold is formally released by the authorised function.

A Legal Hold shall override any routine deletion or disposal schedule applicable to the relevant records.

7. Retrieval, Disclosure and Secure Disposal

Records shall be maintained, where reasonably practicable, in a manner that enables retrieval for legitimate business, audit, legal, regulatory or operational requirements.

No Company record shall be disclosed to an external person or authority except:

  • in the ordinary and authorised course of business;
  • with appropriate internal approval;
  • pursuant to a valid contractual obligation; or
  • where required or permitted under applicable law.

Upon expiry of the applicable retention period, records may be securely deleted, destroyed, anonymised or otherwise disposed of, provided that:

  • no Legal Hold or preservation requirement applies;
  • no relevant litigation, investigation or regulatory proceeding is pending or reasonably anticipated; and
  • disposal is carried out in accordance with applicable internal procedures.

Disposal methods shall be appropriate to the nature and sensitivity of the information and may include secure deletion of electronic records or secure destruction of physical records.

The Company may maintain appropriate records of material disposal activities where considered necessary.

8. Confidentiality and Data Protection

All persons handling Company records shall maintain appropriate confidentiality.

Personal data and confidential information contained in Company records shall be collected, accessed, used, retained and disclosed only for legitimate purposes and in accordance with applicable law.

The Company shall endeavour to avoid retaining personal data for longer than reasonably necessary, except where continued retention is required or permitted for legal, regulatory, contractual, security, fraud prevention, dispute resolution or other legitimate purposes.

The confidentiality obligations applicable to Company records may continue even after termination of employment, engagement or business relationship.

9. Compliance, Review and Corrective Action

The Company may periodically review compliance with this Policy through internal assessments, audits or other appropriate mechanisms.

Such reviews may consider:

  • record maintenance practices;
  • compliance with retention requirements;
  • access and security controls;
  • backup and recovery arrangements;
  • Legal Hold compliance; and
  • disposal practices.

Any deficiency identified may be addressed through appropriate corrective measures.

Unauthorised destruction, alteration, falsification, disclosure or removal of Company records, failure to comply with a Legal Hold, deliberate circumvention of retention requirements or other material breach of this Policy may result in disciplinary, contractual or legal action, as appropriate.

10. Policy Review, Approval and Effective Date

This Policy shall be reviewed periodically and, where appropriate, upon:

  • changes in applicable laws or regulatory requirements;
  • material changes in the Company's business operations;
  • introduction of new products, services or technologies;
  • significant data, security or compliance incidents; or
  • findings arising from audits or compliance reviews.

This Record Retention & Data Preservation Policy has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.

The Board may amend or replace this Policy from time to time.

ANNEXURE I

INDICATIVE RECORD RETENTION SCHEDULE

The following schedule is indicative and shall remain subject to applicable law, regulatory requirements, contractual obligations and any Legal Hold:

Category of Record Indicative Retention Principle For the period required under applicable corporate Corporate and Statutory law; permanently where legally required or Records appropriate or upto 3 years which ever is higher. Books of Account and For the applicable statutory period or upto 3 years Financial Records which ever is higher. For the applicable statutory period, including any Tax and Related Records extended period required due to proceedings or assessments or upto 3 years which ever is higher. For the period required under applicable law or Customer and Merchant regulated partner requirements or upto 3 years KYC/CDD Records which ever is higher. For the period required under applicable law, Transaction and regulatory requirements or business arrangements Settlement Records or upto 3 years which ever is higher. AML/CFT and For the applicable statutory or regulatory period or Compliance Records upto 3 years which ever is higher. During the contractual relationship and thereafter Contracts and for the applicable limitation or legally required Agreements period or upto 3 years which ever is higher. Until final closure of the matter and completion of Litigation, Investigation any applicable preservation period or upto 3 years and Dispute Records which ever is higher. During employment or engagement and thereafter Employee and HR for the period required by applicable law or Records legitimate business requirements or upto 3 years which ever is higher.

For the applicable legal, regulatory or reasonable Audit and Compliance business retention period or upto 3 years which ever Review Records is higher. Based on security, operational, contractual and Technology, Security applicable legal requirements or upto 3 years which and Access Logs ever is higher. Until the business purpose has been fulfilled, unless Routine or Transitory otherwise required to be preserved or upto 3 years Records which ever is higher.

Where more than one retention period applies, the longest applicable mandatory retention period shall generally be followed.

No record shall be destroyed while subject to a Legal Hold, pending investigation, audit, regulatory requirement or reasonably anticipated legal proceeding.

CERTIFICATION

All Directors, officers, employees and authorised representatives of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________