1. Purpose

The purpose of this Data Security Policy is to establish guidelines for protecting plantex e-commerce private limited information and data from unauthorised access, disclosure, alteration, loss, misuse or destruction.

Plantex e-commerce private limited recognises that information and data are critical business assets. This policy establishes the minimum security requirements that all employees and authorised users must follow while accessing, handling, storing, transmitting or sharing company information.

The policy aims to:

  • Protect confidential and sensitive business information.
  • Protect employee, customer, vendor and partner information.
  • Prevent unauthorised access to company systems and data.
  • Reduce the risk of data leakage, loss, theft or misuse.
  • Establish appropriate access and security controls.
  • Promote responsible use of company systems and devices.
  • Establish a framework for reporting and managing data security incidents.

2. Scope

This policy applies to:

  • All permanent and temporary employees.
  • Interns and trainees.
  • Consultants and contractors.
  • Vendors and service providers.
  • Third parties who are authorised to access Plantex e-commerce private limited information or systems.

This policy applies to all company information and data, irrespective of whether it is:

  • Stored electronically or physically.
  • Stored on company systems or authorised cloud platforms.
  • Accessed through company-owned or authorised personal devices.
  • Transmitted through email, messaging platforms or other communication channels.

3. Definition of Data

For the purpose of this policy, data includes, but is not limited to:

3.1 Employee Data

  • Personal information.
  • Contact details.
  • Employment information.
  • Salary and compensation information.
  • Bank and payroll information.
  • Identification and statutory documents.
  • Attendance and leave information.
  • Performance and appraisal information.

3.2 Business Data

  • Financial information.
  • Sales and revenue data.
  • Business plans.
  • Pricing information.
  • Product information.
  • Supplier and vendor information.
  • Marketing and customer information.
  • Internal reports and dashboards.
  • Strategic and operational information.

3.3 Confidential Information

Any information that is not publicly available and whose unauthorised disclosure may cause financial, operational, legal, reputational or competitive harm to Plantex e-commerce private limited.

4. Data Classification

Plantex e-commerce private limited may classify information based on its sensitivity and business impact.

4.1 Public

Information approved for public distribution.

Examples:

  • Public job postings.
  • Published company information.
  • Public marketing content.

4.2 Internal

Information intended for use within Plantex e-commerce private limited.

Examples:

  • Internal announcements.
  • Internal process documents.
  • General operational information.

4.3 Confidential

Information that should only be accessed by authorised employees or stakeholders.

Examples:

  • Business plans.
  • Financial information.
  • Internal reports.
  • Employee records.
  • Vendor information.

4.4 Highly Confidential / Restricted

Highly sensitive information requiring strict access controls.

Examples:

  • Salary information.
  • Bank details.
  • Passwords and credentials.
  • Sensitive employee information.
  • Customer information.
  • Strategic business information.
  • Critical financial or commercial information.

Employees must handle information according to its classification and applicable access restrictions.

5. Data Access Control

Access to company data and systems shall be provided based on business requirements.

Plantex e-commerce private limited shall follow the principle of least privilege, under which employees should receive only the level of access necessary to perform their assigned responsibilities.

Employees must:

  • Use only their authorised accounts.
  • Never share login credentials.
  • Never use another employee's account.
  • Lock their computer when leaving their workstation.
  • Immediately report suspected unauthorised access.
  • Request access through the designated process.
  • Ensure access is removed or modified when no longer required.

Access rights may be reviewed periodically and may be revoked when an employee changes roles or leaves the organisation.

6. Password & Credential Security

Employees are responsible for maintaining the confidentiality of their passwords and credentials.

Employees must:

  • Use strong and unique passwords.
  • Avoid using easily identifiable information as passwords.
  • Never share passwords with colleagues or third parties.
  • Avoid storing passwords in unsecured files or documents.
  • Change passwords when required by company systems or security procedures.
  • Use Multi-Factor Authentication (MFA) wherever enabled.
  • Report suspected credential compromise immediately.

Passwords must not be shared through email, messaging applications or other unsecured communication channels.

7. Company Devices & Systems

Company-provided laptops, desktops, mobile devices, storage devices and other IT assets must be used responsibly and securely.

Employees must:

  • Keep company devices secure.
  • Install only authorised software.
  • Not disable antivirus, firewall or other security controls.
  • Not modify security configurations without authorisation.
  • Avoid connecting unauthorised external storage devices.
  • Report lost or stolen devices immediately.
  • Return company assets upon separation or when requested.

Employees must not use company devices for activities that may compromise company systems or data.

8. Email & Communication Security

Employees must exercise caution while using email and other communication platforms.

Employees should:

  • Verify the sender before opening attachments or clicking links.
  • Be alert to phishing and fraudulent emails.
  • Avoid sharing confidential information through unsecured channels.
  • Verify unusual requests for sensitive information.
  • Use official company communication channels for business information.
  • Report suspicious emails or messages to the appropriate IT/Security team.

Employees must not forward confidential company information to personal email accounts without prior authorisation.

9. Data Storage

Company information should only be stored on authorised systems, applications and cloud platforms approved by Plantex e-commerce private limited.

Employees must not:

  • Store confidential company information on unauthorised personal cloud storage.
  • Upload company information to unauthorised applications or websites.
  • Store sensitive information on personal devices without authorisation.
  • Maintain unnecessary copies of confidential information.

Employees should periodically review and remove unnecessary data in accordance with applicable retention requirements.

10. Data Sharing & Transfer

Confidential and restricted information may only be shared with individuals who have a legitimate business requirement to access it.

Before sharing sensitive information, employees must ensure:

  • The recipient is authorised to receive the information.
  • The information is relevant to the stated business purpose.
  • Appropriate security measures are used.
  • The information is not shared through unauthorised channels.

Employees must exercise additional caution when sharing information with external parties, vendors, consultants or business partners.

Where required, appropriate confidentiality agreements or contractual safeguards should be in place before confidential information is shared.

11. Personal Data Protection

Employees who have access to personal information must handle such information responsibly and only for legitimate business purposes.

Personal information must:

  • Be accessed only when required for work.
  • Not be unnecessarily copied or downloaded.
  • Not be disclosed to unauthorised individuals.
  • Be stored securely.
  • Be disposed of securely when no longer required, subject to applicable retention requirements.

Employees must immediately report any suspected loss, unauthorised disclosure or misuse of personal information.

12. Use of Cloud Services & Third-Party Applications

Employees must use only authorised cloud platforms and software applications for storing or processing company information.

Employees must not upload confidential or restricted company data to:

  • Personal cloud storage.
  • Unauthorised AI tools.
  • Unapproved file-sharing platforms.
  • Unauthorised third-party applications.
  • Personal email accounts.

Any business requirement for a new application or platform should be reviewed and approved through the appropriate internal process.

13. Use of AI Tools

Employees must exercise caution while using Artificial Intelligence tools for business purposes.

Confidential, restricted or sensitive company information must not be entered into publicly available AI tools unless the tool has been formally approved by Plantex e-commerce private limited for such use and appropriate safeguards are in place.

Employees should not upload or disclose:

  • Employee personal data.
  • Customer information.
  • Passwords or credentials.
  • Financial information.
  • Confidential business plans.
  • Proprietary information.
  • Sensitive commercial information.

Employees remain responsible for ensuring that the use of AI tools complies with Plantex e-commerce private limited' confidentiality and information security requirements.

14. Remote Work & Public Networks

Employees working remotely must take reasonable measures to protect company information.

Employees should:

  • Use secure and trusted internet connections.
  • Avoid accessing confidential information through unsecured public networks where possible.
  • Keep company devices physically secure.
  • Avoid leaving devices unattended in public places.
  • Ensure that confidential conversations cannot be overheard by unauthorised persons.
  • Follow company VPN and security requirements, where applicable.

15. Physical Data Security

Physical documents containing confidential or restricted information must be appropriately protected.

Employees must:

  • Avoid leaving confidential documents unattended.
  • Store sensitive documents in secure locations.
  • Dispose of confidential documents through appropriate means.
  • Avoid taking confidential documents outside the workplace unless authorised.

16. Data Retention & Disposal

Data shall be retained only for as long as required for legitimate business, legal, regulatory or contractual purposes.

When data is no longer required, it should be securely deleted, destroyed or disposed of in accordance with applicable retention requirements.

Employees must not independently delete records that are required for legal, audit, regulatory or business purposes.

17. Data Security Incidents

A data security incident may include:

  • Unauthorised access.
  • Data leakage.
  • Accidental disclosure.
  • Phishing or malware attack.
  • Lost or stolen company device.
  • Compromised password.
  • Unauthorised download or transfer of data.
  • Sending information to the wrong recipient.
  • Unauthorised use of company information.
  • Any suspected breach of confidentiality.

Employees must report suspected or actual security incidents immediately to the designated IT/Information Security team and/or HR, as applicable.

Employees must not attempt to conceal, delete evidence of, or independently investigate a suspected security incident unless specifically authorised to do so.

18. Incident Response

Upon receiving a security incident report, the designated team may:

  1. Assess the incident.
  2. Identify affected systems or information.
  3. Contain the incident.
  4. Investigate the cause.
  5. Take corrective and preventive action.
  6. Restore affected systems or data where required.
  7. Escalate the incident to relevant management/legal/compliance stakeholders.
  8. Maintain appropriate incident records.

Where legally or contractually required, relevant notifications may be made to appropriate authorities or affected stakeholders.

19. Third-Party Data Security

Third parties who have access to Plantex e-commerce private limited information or systems are expected to comply with applicable security and confidentiality requirements.

Where appropriate, third-party agreements should include:

  • Confidentiality obligations.
  • Data protection requirements.
  • Security requirements.
  • Access restrictions.
  • Incident reporting obligations.
  • Data return/deletion requirements.

Third-party access may be reviewed, restricted or revoked based on business requirements or security concerns.

20. Employee Responsibilities

Every employee and authorised user is responsible for protecting the information they access or handle.

Employees are expected to:

  • Follow this policy and applicable information security procedures.
  • Protect company and personal information.
  • Maintain confidentiality.
  • Use authorised systems and applications.
  • Report suspected security incidents promptly.
  • Complete mandatory security awareness training.
  • Cooperate with security investigations where required.

21. HR Responsibilities

HR shall support data security by:

  • Ensuring employee data is handled confidentially.
  • Restricting access to employee information based on job requirements.
  • Coordinating access changes during employee transfers.
  • Ensuring relevant access is revoked during employee separation.
  • Communicating applicable confidentiality obligations.
  • Supporting awareness of data protection requirements.
  • Maintaining employee records in authorised systems.

22. IT / Information Security Responsibilities

The IT/Information Security function shall be responsible for implementing and maintaining appropriate technical and administrative security controls, including where applicable:

  • Access management.
  • Device security.
  • Network security.
  • Security monitoring.
  • Backup and recovery.
  • Vulnerability management.
  • Security awareness.
  • Incident management.
  • System access reviews.

23. Confidentiality

All employees and authorised users are required to maintain confidentiality of Plantex e-commerce private limited information during and after their employment or engagement, subject to applicable contractual and legal obligations.

Unauthorised disclosure or misuse of company information may result in disciplinary or legal action.

24. Policy Violations

Violation of this policy may result in appropriate disciplinary action, depending on the nature and severity of the violation.

Actions may include:

  • Counselling or warning.
  • Restriction or suspension of system access.
  • Disciplinary action.
  • Termination of employment or engagement.
  • Recovery of losses, where applicable.
  • Legal action, where warranted.

Nothing in this policy limits Plantex e-commerce private limited right to take action under applicable law, contractual obligations or other organisational policies.

25. Training & Awareness

Plantex e-commerce private limited may conduct periodic data security and information security awareness programmes.

Employees may be required to complete mandatory training relating to:

  • Password security.
  • Phishing awareness.
  • Data protection.
  • Confidentiality.
  • Secure use of devices.
  • Information handling.
  • Cybersecurity best practices.

Employees are expected to participate in mandatory training within the prescribed timelines.

26. Exceptions

Any exception to this policy must be formally approved by the designated authority.

Exceptions should be:

  • Business justified.
  • Documented.
  • Risk assessed where required.
  • Time-bound wherever practicable.

27. Policy Review & Amendment

This policy shall be reviewed at least annually or whenever there are significant changes in business operations, technology, applicable laws, regulations or information security requirements.

Plantex e-commerce private limited reserves the right to modify, amend or withdraw this policy as required.