Information Security Policy & Cybersecurity Framework
1. PURPOSE
-
This Information Security Policy & Cybersecurity Framework ("Policy") sets out the principles, controls, roles and responsibilities that Plantex E-Commerce Private Limited ("Company") applies to protect the confidentiality, integrity and availability of its information assets, including personal data processed on behalf of its customers, employees and other stakeholders.
-
This Policy is designed to support the Company's compliance with the Information Technology Act, 2000 and rules made thereunder (including the SPDI Rules and the Intermediary Guidelines), the Digital Personal Data Protection Act, 2023 and rules made thereunder, the Cyber Security Directions issued by CERT-In under Section 70B of the IT Act, and, to the extent applicable, internationally recognised standards and frameworks.
-
This Policy is a statement of the Company's information security governance framework. It does not, by itself, constitute a warranty, guarantee or representation that the Company's systems are or will remain impervious to unauthorised access, cyberattack, or data breach. The Company reserves the right to amend, supplement or replace this Policy, in whole or in part, at its sole discretion.
2. SCOPE AND APPLICABILITY
-
This Policy applies to all employees, directors, officers, contractors, consultants, interns, and temporary staff of the Company ("Personnel"), and, to the extent specified in the relevant contract, to third-party vendors, service providers and Data Processors who access, process, store or transmit information on behalf of the Company ("Third Parties").
-
This Policy applies to all information assets owned, leased, licensed or otherwise controlled by the Company, including but not limited to: information systems, applications, networks, databases, cloud infrastructure, endpoints (laptops/mobiles/tablets), removable media, physical records, and any personal data or confidential/business information processed through the Company's website https://www.plantex.in/ or any related mobile application (collectively, the "Platform").
-
Where this Policy conflicts with a more specific technical standard, operating procedure, or contractual obligation, the more stringent requirement shall prevail, unless expressly stated otherwise by the Information Security Team.
3. INFORMATION SECURITY GOVERNANCE
3.1 Governance Structure
-
The Board of Directors holds ultimate accountability for information security and cybersecurity risk oversight at the Company.
-
Day-to-day ownership of this Policy rests with the Information Security In-Charge (currently Mr. Abhishek Shaileshkumar Chauhan), who is responsible for implementation, monitoring, incident response coordination, and periodic review of this Policy.
-
The Information Security Team (which may comprise designated IT, engineering, legal and compliance personnel, and may be constituted on a virtual/cross-functional basis appropriate to the Company's size) supports the CISO in operationalising this Policy.
3.2 Roles and Responsibilities
|
Role |
Key Responsibilities |
|
Board of Directors |
Overall accountability for information security risk; approval of this Policy and material changes; oversight of significant incidents. |
|
Information Security In-Charge |
Policy ownership, risk assessments, incident response coordination, vendor security oversight, regulatory reporting (e.g., CERT-In), Policy review. |
|
IT / Engineering Team |
Implementation of technical controls (access management, encryption, network security, patching, backups, monitoring). |
|
Data Protection / Grievance Officer |
Coordination on personal data-related aspects, including breach notification to affected Data Principals and the Data Protection Board of India, as applicable. |
|
All Personnel |
Compliance with this Policy, completion of mandatory security training, and prompt reporting of suspected incidents. |
|
Third-Party Vendors/Processors |
Compliance with contractual security requirements and applicable law; prompt breach notification to the Company. |
4. RISK ASSESSMENT AND MANAGEMENT
-
The Company undertakes periodic information security risk assessments, at a frequency and scope determined by the CISO based on the Company's risk profile, to identify, evaluate and prioritise risks to its information assets.
-
Identified risks are treated through a combination of risk mitigation (implementing controls), risk transfer (e.g., insurance, contractual indemnities from vendors), risk avoidance, or documented risk acceptance by an appropriately authorised individual.
-
Material new systems, products, features or third-party integrations that involve the processing of personal data or other sensitive information are subject to a security/privacy review prior to go-live, at the discretion of the CISO.
5. ASSET MANAGEMENT AND DATA CLASSIFICATION
-
The Company maintains, on a best-efforts basis, an inventory of critical information assets, including systems, applications and repositories that store or process personal data or other confidential information.
|
Classification |
Description |
Illustrative Examples |
|
Restricted |
Highly sensitive data; unauthorised disclosure could cause severe harm. |
Payment credentials (where applicable), authentication secrets, encryption keys, SPDI. |
|
Confidential |
Sensitive business or personal data; access restricted to a need-to-know basis. |
Customer PII, employee records, contracts, financial statements. |
|
Internal |
Information intended for internal use; not for public disclosure. |
Internal policies, internal reports, non-public product plans. |
|
Public |
Information approved for public disclosure. |
Marketing material, published policies, public website content. |
-
Personnel must handle each category of information in accordance with the controls applicable to its classification, including restrictions on storage, transmission (e.g., encrypted channels for Restricted/Confidential data), printing and disposal.
6. ACCESS CONTROL
-
Access to Company information systems is granted on the principle of least privilege and need-to-know, and is role-based wherever technically feasible.
-
All Personnel are assigned unique user credentials; shared or generic accounts are discouraged and, where used, are subject to additional monitoring.
-
Multi-factor authentication (MFA) is implemented for access to critical systems, administrative accounts, and remote access, wherever technically and commercially feasible.
-
User access rights are reviewed periodically, and access is revoked promptly upon a Personnel's change in role or separation from the Company.
-
Privileged/administrative access is restricted to authorised personnel and subject to enhanced logging and monitoring.
7. CRYPTOGRAPHY AND DATA PROTECTION
-
Where technically and commercially feasible, Restricted and Confidential data is encrypted in transit (e.g., via TLS/HTTPS) and at rest (e.g., via disk/database-level encryption).
-
Cryptographic keys are managed through access-controlled key-management practices, with access restricted to authorised personnel/systems.
-
Payment-related data, where collected, is processed through RBI-authorised payment gateway partners; the Company does not, as a general practice, store full card numbers or CVV on its own systems.
8. NETWORK, ENDPOINT AND OPERATIONS SECURITY
-
The Company's network and hosting infrastructure is protected through industry-standard controls, which may include firewalls, intrusion detection/prevention systems, network segmentation, and secure configuration baselines.
-
Anti-malware, endpoint protection and device-management controls are deployed on Company-managed endpoints, as commercially reasonable.
-
Change management procedures apply to material changes to production systems, including testing and, where appropriate, rollback planning.
-
System and security event logs are retained for a period determined by the Information Security Team, consistent with applicable law (including the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021), to support monitoring, investigation and audit.
9. VULNERABILITY AND PATCH MANAGEMENT
-
The Company undertakes vulnerability assessments and, where appropriate, penetration testing of critical systems at a frequency determined by the CISO based on risk, resource availability and materiality of the system.
-
Critical security patches are prioritised for deployment within a risk-based timeframe determined by the Information Security Team; the Company does not warrant that all vulnerabilities will be identified or remediated within any specific period.
10. CYBERSECURITY INCIDENT MANAGEMENT
10.1 Detection and Reporting
-
All Personnel and Third Parties are required to report any suspected or confirmed information security incident (including suspected unauthorised access, malware infection, phishing attempt, or data loss) to the Information Security Team immediately upon discovery, through the Company's designated internal reporting channel.
10.2 Response and Escalation
-
The Information Security Team follows an internal incident-response procedure comprising: (a) identification and triage; (b) containment; (c) eradication of the root cause; (d) recovery of affected systems; and (e) post-incident review, with escalation to the CISO and, where warranted, to senior management/the Board, based on the severity of the incident.
10.3 Regulatory and Data Principal Notification
-
Where an incident constitutes a reportable cybersecurity incident under the CERT-In Directions, the Company will report the same to CERT-In within the timelines prescribed under applicable law (currently within 6 hours of noticing/being brought to notice of such incident, as applicable).
-
Where an incident constitutes a "Personal Data Breach" under the Digital Personal Data Protection Act, 2023, the Company will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and DPDP Rules, once the relevant provisions are in force.
-
Notification of an incident is not, and shall not be construed as, an admission of fault, negligence or liability on the part of the Company. The Company's liability in connection with any incident remains governed by, and subject to the limitations set out in, its Privacy Policy and applicable Terms of Use.
11. BUSINESS CONTINUITY AND DISASTER RECOVERY
-
The Company maintains backup and recovery arrangements for critical systems and data, designed to support restoration of operations following a disruptive event, in accordance with a backup schedule determined by the Information Security/IT Team.
-
Business continuity and disaster-recovery arrangements are reviewed periodically and updated as the Company's systems and risk profile evolve; the Company does not guarantee any specific recovery time or recovery point objective, except where separately agreed in writing with a customer or partner.
12. CYBERSECURITY FRAMEWORK
-
The Company's cybersecurity programme is organised, in relevant part, with reference to the widely recognised NIST Cybersecurity Framework function areas, adapted to the Company's scale of operations, as illustrated below:
|
Function |
Illustrative Company Practices |
|
Identify |
Asset inventory, data classification, periodic risk assessments, vendor risk reviews. |
|
Protect |
Access control and MFA, encryption, secure configuration, employee security training, vendor contracts. |
|
Detect |
Security monitoring/logging, anti-malware and endpoint alerts, periodic vulnerability scanning. |
|
Respond |
Documented incident-response procedure, escalation matrix, regulatory notification (CERT-In/DPB). |
|
Recover |
Backups, disaster-recovery arrangements, post-incident review and remediation tracking. |
-
The Company also has regard to the Cyber Security Directions and guidance issued by CERT-In under Section 70B of the IT Act, and to sectoral guidance issued by applicable regulators, to the extent relevant to its business.
-
This description is illustrative of the Company's approach and is not a certification, representation or warranty of compliance with any specific external framework or standard, unless expressly stated as a certified status in Clause 15 (Certifications) below.
13. SECURITY AWARENESS, TRAINING AND ACCEPTABLE USE
-
All Personnel are required to complete information security and data-protection awareness training upon onboarding and periodically thereafter, at a frequency determined by the Information Security Team.
-
Personnel are required to comply with the Company's acceptable use requirements in respect of Company systems and devices, including restrictions on unauthorised software installation, use of unapproved cloud storage/personal devices for Confidential/Restricted data, and sharing of credentials.
-
Non-compliance with this Policy by Personnel may result in disciplinary action, up to and including termination of employment/engagement, in accordance with the Company's HR policies and applicable law. Non-compliance by a Third Party may result in suspension or termination of the relevant contract.
14. LEGAL AND REGULATORY COMPLIANCE
-
This Policy is intended to support compliance with, among others: the Information Technology Act, 2000 and rules thereunder (including the SPDI Rules and the Intermediary Guidelines Rules, 2021); the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025; the Cyber Security Directions issued by CERT-In under Section 70B of the IT Act; and other sector-specific or general laws applicable to the Company's business, as amended from time to time.
-
Internal audits/reviews of compliance with this Policy may be conducted periodically, at the discretion of the CISO or the Board, and findings reported to senior management.
15. POLICY REVIEW AND AMENDMENT
-
This Policy is reviewed annually, or earlier upon a material change in risk, technology, or applicable law, and may be amended by the Company at its sole discretion to reflect changes in technology, risk, business operations, or Applicable Law. The then-current version of this Policy, as published on the Company's internal repository and/or the Platform, shall govern.
16. DISCLAIMER
-
THIS POLICY DESCRIBES THE COMPANY'S INFORMATION SECURITY GOVERNANCE FRAMEWORK AS OF THE EFFECTIVE DATE. IT IS PROVIDED FOR INFORMATIONAL PURPOSES AND DOES NOT CONSTITUTE A WARRANTY, GUARANTEE OR REPRESENTATION THAT THE COMPANY'S SYSTEMS, NETWORKS OR PLATFORM ARE OR WILL REMAIN FREE FROM VULNERABILITY, UNAUTHORISED ACCESS, OR CYBERSECURITY INCIDENTS. THE COMPANY'S LIABILITY IN RESPECT OF ANY SECURITY INCIDENT SHALL BE GOVERNED BY, AND IS SUBJECT TO THE LIMITATIONS OF LIABILITY SET OUT IN, ITS PRIVACY POLICY AND APPLICABLE TERMS OF USE.
17. CONTACT
For questions regarding this Policy, or to report a suspected security incident or vulnerability, please contact the Information Security Team at abhishek@plantex.in.
For and on Behalf of
Plantex E-Commerce Private Limited
Abhishek Shaileshkumar Chauhan
(Director)
DIN: 08817542