Login or Signup
and Grab Exclusive deals
Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009
ZESTFLOW INDIA PRIVATE LIMITED maintains a structured framework for the secure storage, preservation, retrieval and lawful disposal of business records. We retain records in accordance with applicable legal, regulatory, contractual and legitimate business requirements while ensuring appropriate confidentiality, data security and protection against unauthorised access or destruction.
ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining appropriate standards for the creation, storage, preservation, retrieval and secure disposal of records generated or received in the course of its business.
This Policy establishes a structured framework to ensure that Company records are maintained for legitimate business, legal, regulatory, contractual, audit and operational purposes while protecting such records against unauthorised access, alteration, loss, misuse or destruction.
The Company shall retain records only for such period as may be required under applicable law, regulatory requirements, contractual obligations or legitimate business requirements, subject to any Legal Hold or preservation requirement.
This Policy applies to:
This Policy applies to records maintained in physical, electronic, digital or any other legally recognised form.
The extent and duration of record retention shall depend upon the nature of the record and the requirements applicable to the Company, including, where relevant:
Where applicable law requires a longer retention period than this Policy, the applicable legal requirement shall prevail.
The Board of Directors shall have overall oversight of the Company's record retention framework.
Senior Management and the appropriate Compliance, Legal, Finance, Technology or other responsible functions shall oversee implementation of this Policy within their respective areas.
Department Heads and designated record owners shall be responsible for ensuring that records generated or maintained within their functions are appropriately classified, stored, protected, retained and disposed of.
All employees and authorised persons shall:
Where Company records are handled by a third-party service provider, appropriate contractual or operational safeguards may be implemented based on the nature and sensitivity of the records.
The Company may create and maintain records including:
a. Customer and Merchant Records
KYC documents, onboarding information, due diligence records, business verification documents, agreements, communications and risk assessments.
b. Transaction and Operational Records
Transaction data, settlement records, refunds, reversals, chargebacks, system logs and other operational records.
c. AML/CFT and Compliance Records
Due diligence records, risk assessments, screening results, internal reviews, suspicious activity records and regulatory or partner communications.
d. Financial and Tax Records
Books of account, financial statements, invoices, bank records, tax records, audit reports and supporting documents.
e. Corporate and Legal Records
Board and shareholder records, statutory registers, licences, approvals, contracts, legal documents, policies and governance records.
f. Employee and Human Resource Records
Employment records, agreements, attendance, payroll, training, disciplinary and other employment-related records.
g. Technology and Security Records
System logs, access records, incident records, security reports, backup records and other relevant technology documentation.
Records shall be retained for the period required under applicable law, regulatory requirements, contractual obligations or legitimate business requirements.
Where no specific retention period is prescribed, the Company may determine an appropriate retention period considering:
The Company may retain records for a longer period where reasonably necessary for legal, regulatory, security, fraud prevention, audit, dispute resolution or other legitimate purposes.
Records shall be maintained in a manner appropriate to their nature and sensitivity.
The Company shall implement reasonable administrative, technical and organisational safeguards designed to:
Security measures may include, where appropriate:
Access to confidential or sensitive records shall be limited to authorised persons on a need-to-know basis.
The Company may use third-party or cloud-based storage services subject to appropriate security, confidentiality and contractual safeguards.
Notwithstanding any normal retention period, records shall not be altered, deleted or destroyed where they are relevant to:
The Company may issue a Legal Hold or preservation instruction identifying the records that must be preserved.
All employees, departments and relevant service providers shall comply with such instructions until the Legal Hold is formally released by the authorised function.
A Legal Hold shall override any routine deletion or disposal schedule applicable to the relevant records.
Records shall be maintained, where reasonably practicable, in a manner that enables retrieval for legitimate business, audit, legal, regulatory or operational requirements.
No Company record shall be disclosed to an external person or authority except:
Upon expiry of the applicable retention period, records may be securely deleted, destroyed, anonymised or otherwise disposed of, provided that:
Disposal methods shall be appropriate to the nature and sensitivity of the information and may include secure deletion of electronic records or secure destruction of physical records.
The Company may maintain appropriate records of material disposal activities where considered necessary.
All persons handling Company records shall maintain appropriate confidentiality.
Personal data and confidential information contained in Company records shall be collected, accessed, used, retained and disclosed only for legitimate purposes and in accordance with applicable law.
The Company shall endeavour to avoid retaining personal data for longer than reasonably necessary, except where continued retention is required or permitted for legal, regulatory, contractual, security, fraud prevention, dispute resolution or other legitimate purposes.
The confidentiality obligations applicable to Company records may continue even after termination of employment, engagement or business relationship.
The Company may periodically review compliance with this Policy through internal assessments, audits or other appropriate mechanisms.
Such reviews may consider:
Any deficiency identified may be addressed through appropriate corrective measures.
Unauthorised destruction, alteration, falsification, disclosure or removal of Company records, failure to comply with a Legal Hold, deliberate circumvention of retention requirements or other material breach of this Policy may result in disciplinary, contractual or legal action, as appropriate.
This Policy shall be reviewed periodically and, where appropriate, upon:
This Record Retention & Data Preservation Policy has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.
The Board may amend or replace this Policy from time to time.
ANNEXURE I
INDICATIVE RECORD RETENTION SCHEDULE
The following schedule is indicative and shall remain subject to applicable law, regulatory requirements, contractual obligations and any Legal Hold:
Category of Record Indicative Retention Principle For the period required under applicable corporate Corporate and Statutory law; permanently where legally required or Records appropriate or upto 3 years which ever is higher. Books of Account and For the applicable statutory period or upto 3 years Financial Records which ever is higher. For the applicable statutory period, including any Tax and Related Records extended period required due to proceedings or assessments or upto 3 years which ever is higher. For the period required under applicable law or Customer and Merchant regulated partner requirements or upto 3 years KYC/CDD Records which ever is higher. For the period required under applicable law, Transaction and regulatory requirements or business arrangements Settlement Records or upto 3 years which ever is higher. AML/CFT and For the applicable statutory or regulatory period or Compliance Records upto 3 years which ever is higher. During the contractual relationship and thereafter Contracts and for the applicable limitation or legally required Agreements period or upto 3 years which ever is higher. Until final closure of the matter and completion of Litigation, Investigation any applicable preservation period or upto 3 years and Dispute Records which ever is higher. During employment or engagement and thereafter Employee and HR for the period required by applicable law or Records legitimate business requirements or upto 3 years which ever is higher.
For the applicable legal, regulatory or reasonable Audit and Compliance business retention period or upto 3 years which ever Review Records is higher. Based on security, operational, contractual and Technology, Security applicable legal requirements or upto 3 years which and Access Logs ever is higher. Until the business purpose has been fulfilled, unless Routine or Transitory otherwise required to be preserved or upto 3 years Records which ever is higher.
Where more than one retention period applies, the longest applicable mandatory retention period shall generally be followed.
No record shall be destroyed while subject to a Legal Hold, pending investigation, audit, regulatory requirement or reasonably anticipated legal proceeding.
CERTIFICATION
All Directors, officers, employees and authorised representatives of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.
For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________