Legal & Policy

DATA BREACH NOTIFICATION POLICY

Last updated

DATA BREACH NOTIFICATION POLICY

Document Title

Data Breach Notification Policy

Document Owner

PRNV Services

Applies To

All digital platforms, systems, and services operated by PRNV Services

Governing Law

Laws of the Republic of India

Jurisdiction

Courts of Hyderabad, Telangana, India — Exclusive

Website

www.prnvservices.com


Table of Contents

1.   Introduction.................................................................................................................................................................................. 3

2.   Purpose of this Policy.................................................................................................................................................................. 3

3.   Scope and Applicability............................................................................................................................................................... 4

4.   Definitions..................................................................................................................................................................................... 4

5.   Information Security and Privacy Commitment..................................................................................................................... 5

6.   Nature of Platform Services....................................................................................................................................................... 5

7.   Definition of a Data Breach........................................................................................................................................................ 6

8.   Types of Data Breaches and Security Incidents...................................................................................................................... 6

9.   Incident Detection and Identification Procedures................................................................................................................. 7

10.   Incident Reporting Procedures............................................................................................................................................... 8

11.   Internal Escalation Procedures............................................................................................................................................... 8

12.   Incident Classification and Severity Assessment.................................................................................................................. 9

13.   Investigation and Risk Assessment Procedures................................................................................................................... 9

14.   Containment and Mitigation Measures.............................................................................................................................. 10

15.   Preservation of Evidence and Records................................................................................................................................ 10

16.   Notification Principles............................................................................................................................................................ 10

17.   Notification to Affected Individuals, Where Required..................................................................................................... 11

18.   Notification to Regulatory Authorities and Law Enforcement, Where Required by Applicable Law....................... 11

19.   Communication Channels and Notification Methods...................................................................................................... 12

20.   Information Included in Notifications................................................................................................................................. 12

21.   Responsibilities of PRNV Services........................................................................................................................................ 12

22.   Responsibilities of Users........................................................................................................................................................ 13

23.   Responsibilities of Third-Party Service Providers.............................................................................................................. 13

24.   Incident Recovery and Service Restoration....................................................................................................................... 14

25.   Corrective and Preventive Actions....................................................................................................................................... 14

26.   Documentation and Record Retention............................................................................................................................... 14

27.   Training and Security Awareness......................................................................................................................................... 15

28.   Compliance Monitoring and Periodic Reviews.................................................................................................................. 15

29.   Amendments and Updates................................................................................................................................................... 15

30.   Governing Law and Jurisdiction........................................................................................................................................... 15

31.   Contact Information............................................................................................................................................................... 16

Incident Response and Notification Framework..................................................................................................................... 17

Disclaimer....................................................................................................................................................................................... 18

Conclusion....................................................................................................................................................................................... 18


1.   Introduction

PRNV Services (“PRNV Services”, “the Platform”, “we”, “us”, or “our”) operates a technology-enabled digital platform, accessible at www.prnvservices.com, together with its associated mobile applications, customer portals, online services, application programming interfaces (APIs), and connected digital systems. As a technology-driven platform, PRNV Services processes and safeguards information belonging to customers, service professionals, business partners, and other users in the ordinary course of operating its digital infrastructure.

This Data Breach Notification Policy (the “Policy”) sets out the principles, procedures, responsibilities, and commitments of PRNV Services with respect to the prompt identification, assessment, containment, management, notification, and remediation of data breaches and information security incidents affecting its digital platforms, systems, and services.

PRNV Services recognises that the security and confidentiality of information is fundamental to the trust placed in the Platform by its users. Accordingly, PRNV Services is committed to maintaining a robust, transparent, and accountable framework for detecting and responding to security incidents in a manner consistent with applicable Indian information technology, cybersecurity, privacy, and data protection laws.

2.   Purpose of this Policy

The purpose of this Policy is to establish a clear, structured, and legally compliant framework that governs how PRNV Services prevents, detects, evaluates, responds to, notifies, and learns from data breaches and information security incidents.

In particular, this Policy is intended to:

(a)    define what constitutes a data breach and a security incident across the digital platforms, systems, and services operated by PRNV Services;

(b)      set out the procedures for prompt detection, internal reporting, escalation, classification, and investigation of suspected and confirmed incidents;

(c)    describe the principles and procedures governing containment, mitigation, evidence preservation, and recovery;

(d)    explain the principles applicable to notification of affected individuals, regulatory authorities, and law-enforcement agencies, where and to the extent required by applicable law;

(e)   allocate responsibilities among PRNV Services, its users, and its third-party service providers in relation to incident prevention and response;

(f)      promote documentation, record retention, training, monitoring, periodic review, and continuous improvement of the Platform’s security posture; and


(g)     affirm the commitment of PRNV Services to information security, privacy protection, transparency, responsible incident management, and regulatory compliance.

3.   Scope and Applicability

This Policy applies to all digital platforms, systems, services, and information assets operated, controlled, hosted, or managed by PRNV Services, including but not limited to:

•       the PRNV Services website and any related web properties;

•       mobile applications published or operated by PRNV Services;

•       customer portals and user dashboards;

•       online services and digital features made available through the Platform;

•       communication channels, including in-platform messaging, notifications, email, and other electronic communication methods;

•       information systems and databases that store, process, or transmit information;

•       network infrastructure supporting the Platform;

•       cloud-based services and hosting environments engaged by PRNV Services;

•       APIs and integrated systems that exchange data with the Platform; and

•       digital content and technology resources used to deliver, secure, or administer the Platform.

This Policy applies to all information processed through the foregoing platforms, systems, and services, and to all personnel, contractors, and third-party service providers who access, process, or handle such information on behalf of PRNV Services, to the extent of their engagement with the Platform.

This Policy is applicable in addition to, and does not derogate from, the rights and obligations arising under the other policies and agreements published by PRNV Services, or under applicable law.

4.   Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below. Terms not defined here shall have the meaning ascribed to them under applicable Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, or as the context may require.

“Affected Individual” means any natural person whose information is, or is reasonably believed to be, compromised, accessed, disclosed, lost, altered, or otherwise affected by a data breach.

“Applicable Law” means all laws, rules, regulations, directions, notifications, and guidelines in force in the Republic of India that are applicable to PRNV Services in relation to information technology, cybersecurity, privacy, and data protection.

“Data Breach” means any unauthorised access to, acquisition of, disclosure of, loss of, alteration of, corruption of, or destruction of information that compromises the confidentiality, integrity, or availability of such information. The detailed meaning is set out in Section 7.

“Data Principal” means an individual to whom personal data relates, as defined under the Digital Personal Data Protection Act, 2023.


“Data Protection Board” means the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023.

“Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under applicable Indian data protection law.

“Security Incident” means any event or series of events that actually or potentially jeopardises the confidentiality, integrity, or availability of information or information systems, whether or not it amounts to a Data Breach.

“Security Officer” means the Data Protection Officer or Security Officer designated by PRNV Services as the responsible point of contact under this Policy, as identified in Section 31.

“Third-Party Service Provider” means any external vendor, processor, contractor, cloud or hosting provider, communication provider, or other party engaged by PRNV Services to provide services that involve access to, or processing of, information.

“User” means any customer, service professional, business partner, visitor, or other person who accesses or uses the Platform.

5.   Information Security and Privacy Commitment

PRNV Services is committed to protecting the information entrusted to it and to maintaining the confidentiality, integrity, and availability of its digital platforms, systems, and services. PRNV Services treats information security and privacy protection as continuing obligations that are integral to the responsible operation of a technology-enabled platform.

In furtherance of this commitment, PRNV Services endeavours to:

(a)   implement reasonable administrative, technical, and physical safeguards designed to protect information and digital assets against unauthorised access, disclosure, loss, alteration, and misuse;

(b)   align its security practices with applicable Indian law, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023, together with internationally recognised information-security standards as a matter of good practice;

(c)   promote a culture of security awareness, accountability, and responsible information handling among its personnel and service providers;

(d)       respond to security incidents promptly, responsibly, and transparently, consistent with legal requirements and the protection of affected individuals; and

(e)      continuously review and enhance its data breach prevention, detection, response, and recovery capabilities.

6.   Nature of Platform Services

PRNV Services operates as a technology-enabled digital platform that connects customers with independent service professionals and business entities through a unified digital interface. The Platform provides listing, visibility, communication, and related digital infrastructure that enables users to discover and connect with one another.


In operating the Platform, PRNV Services processes information through its websites, mobile applications, customer portals, online services, communication channels, information systems, databases, network infrastructure, cloud-based services, APIs, and integrated systems. The security of this information and of the underlying digital infrastructure is the subject of this Policy.

Nothing in this Policy alters the characterisation of PRNV Services as a technology platform and intermediary, nor does it create any obligation, representation, or warranty beyond those expressly set out herein or required under applicable law.

7.   Definition of a Data Breach

For the purposes of this Policy, a “Data Breach” means any security incident that leads to, or is reasonably likely to lead to, the unauthorised or unlawful access to, acquisition of, disclosure of, transmission of, loss of, alteration of, corruption of, or destruction of information processed, stored, or transmitted through the digital platforms, systems, or services operated by PRNV Services.

A Data Breach may involve a compromise of one or more of the following attributes of information:

(a)   Confidentiality — where information is accessed or disclosed to a person or system that is not authorised to receive it;

(b)   Integrity — where information is altered, corrupted, or tampered with in an unauthorised manner; and

(c)   Availability — where information or systems are rendered inaccessible, unusable, or destroyed, whether temporarily or permanently.

A Data Breach may arise from deliberate, accidental, internal, or external causes, and may affect personal data, business information, technical data, or other categories of information. An event may constitute a Data Breach whether or not it ultimately results in demonstrable harm to any individual.

8.   Types of Data Breaches and Security Incidents

Data breaches and security incidents may take various forms. The following non-exhaustive categories illustrate the types of incidents addressed by this Policy:

8.1  Unauthorised Access

Access to information, systems, accounts, or networks by any person or process that is not authorised to obtain such access, including through compromised credentials, exploitation of vulnerabilities, or circumvention of access controls.

8.2  Unauthorised Disclosure

The disclosure, transmission, publication, or sharing of information to any person or party not authorised to receive it, whether intentional or otherwise.

8.3  Loss of Information

The loss of information or of devices, media, or systems containing information, including misplacement, theft, or inability to locate or recover information.


8.4  Alteration or Corruption of Information

The unauthorised modification, alteration, corruption, or tampering of information that affects its accuracy, reliability, or integrity.

8.5  Accidental Disclosure

The inadvertent or unintended exposure of information, including misdirected communications, misconfigured systems, or human error.

8.6  Cybersecurity Incidents

Malicious or hostile activity directed at the Platform or its infrastructure, including hacking, phishing, malware, ransomware, denial-of-service attacks, account takeover, exploitation of vulnerabilities, and other forms of cyber-attack.

8.7  System Compromises

The compromise of one or more systems, servers, applications, or environments such that their security, integrity, or trustworthiness can no longer be assured.

8.8  Insider Threats

Incidents arising from the actions of personnel, contractors, or other authorised persons who misuse, exceed, or abuse their access, whether intentionally or through negligence.

8.9  Third-Party Security Incidents

Security incidents originating from, or affecting, third-party service providers, processors, integrated systems, or supply-chain components that handle information on behalf of, or in connection with, the Platform.

9.   Incident Detection and Identification Procedures

PRNV Services endeavours to detect and identify security incidents promptly through a combination of technical, procedural, and human measures. Detection and identification activities may include:

(a)    monitoring of systems, networks, applications, and access logs for unusual, anomalous, or unauthorised activity;

(b)   use of security tools and controls designed to detect intrusions, malware, and abnormal behaviour;

(c)   review of alerts, error reports, and system notifications generated by the Platform’s infrastructure;

(d)    receipt and assessment of reports from users, personnel, security researchers, and third-party service providers;

(e)   periodic vulnerability assessments and security reviews; and

(f)   verification procedures to confirm whether a suspected event constitutes an actual or potential security incident or data breach.

Upon detection of a suspected incident, PRNV Services undertakes preliminary verification to determine the nature, scope, and credibility of the event before initiating the applicable reporting, escalation, and response procedures set out in this Policy.


10.  Incident Reporting Procedures

Prompt internal reporting is essential to effective incident response. Any person who becomes aware of, or reasonably suspects, a security incident or data breach involving the Platform is encouraged or required, as applicable, to report it without undue delay through the designated reporting channels.

10.1  Security Incident Reporting Channels

Suspected or confirmed security incidents may be reported to the Security Officer of PRNV Services through the contact details set out in Section 31. Reports may be submitted by personnel, contractors, users, third-party service providers, and external parties such as security researchers.

A report should, where possible, include:

(a)   a description of the suspected incident and how it was identified;

(b)   the date and time of discovery and, if known, of occurrence;

(c)   the systems, services, or information believed to be affected;

(d)   any actions already taken; and

(e)   the contact details of the person making the report.

11.  Internal Escalation Procedures

Upon receipt of a report or detection of a suspected incident, PRNV Services follows internal escalation procedures designed to ensure that incidents are assessed and managed by appropriately authorised personnel in a timely manner.

Internal escalation generally proceeds as follows:

(a)     Initial Receipt — the report or alert is received and logged by the relevant personnel or the Security Officer;

(b)   Preliminary Triage — the Security Officer or designated personnel undertake a preliminary assessment to confirm whether an incident has occurred and to estimate its potential severity;

(c)     Escalation to Incident Response Function — confirmed or credible incidents are escalated to the personnel responsible for coordinating the response, who may convene additional internal or external resources as required;

(d)   Management and Legal Escalation — incidents that are significant, that involve personal data, or that may give rise to legal or regulatory obligations are escalated to senior management and, where appropriate, to legal advisors; and

(e)    Notification Decision-Making — where escalation indicates that notification obligations may arise, the matter is handled in accordance with Sections 16 to 20 of this Policy.


12.  Incident Classification and Severity Assessment

PRNV Services classifies confirmed incidents according to their nature and severity in order to prioritise response activities and to inform decisions regarding containment, investigation, and notification. Severity is assessed having regard to factors including the sensitivity and volume of information involved, the number of individuals potentially affected, the likelihood and potential extent of harm, the criticality of the affected systems, and the status of containment.

The following illustrative classification may be applied. The categories are indicative and may be adapted to the circumstances of a particular incident:

Severity Level

General Description

Illustrative Response Priority

Low

Limited or no impact on the confidentiality, integrity, or availability of information; readily contained.

Routine handling and monitoring.

Medium

Moderate impact; potential exposure of a limited set of information or systems.

Prompt investigation and containment.

High

Significant impact; potential exposure of sensitive information or a larger population of individuals.

Urgent, coordinated response and escalation.

Critical

Severe or widespread impact on information, systems, or individuals.

Immediate, prioritised response and senior escalation.

Classification is provisional and may be revised as further information becomes available during investigation. The severity assessment informs, but does not by itself determine, whether any notification is required under applicable law.

13.  Investigation and Risk Assessment Procedures

PRNV Services conducts a responsible investigation of confirmed incidents that is proportionate to their nature and severity. The objectives of the investigation are to understand the incident, to assess the associated risks, to support containment and remediation, and to determine any notification obligations.

Investigation and risk assessment activities may include:

(a)   establishing the nature, cause, timeline, and scope of the incident;

(b)   identifying the categories and approximate volume of information involved;

(c)   identifying, so far as reasonably practicable, the individuals who may be affected;

(d)   evaluating the likelihood and potential severity of harm to affected individuals and to information assets;

(e)    assessing the effectiveness of any security measures that were in place, such as encryption or access controls;

(f)   determining whether the incident is ongoing or has been contained; and

(g)   assessing legal, regulatory, and contractual implications, including any notification obligations.

Where appropriate, PRNV Services may engage qualified internal personnel, external security specialists, forensic experts, or legal advisors to assist with the investigation and risk assessment.


14.  Containment and Mitigation Measures

On confirming an incident, PRNV Services takes reasonable steps to contain the incident and to mitigate its impact, with the objective of limiting further unauthorised access, disclosure, loss, alteration, or damage. Containment and mitigation measures are selected according to the nature and severity of the incident and may include:

(a)   isolating, disabling, or restricting access to affected systems, accounts, or services;

(b)   revoking or resetting compromised credentials and access privileges;

(c)   applying security patches, configuration changes, or additional controls;

(d)   blocking malicious activity, addresses, or processes;

(e)   removing malware or unauthorised components;

(f)   preserving relevant evidence in accordance with Section 15; and

(g)   coordinating with third-party service providers where the incident involves their systems or services.

Containment measures may, where necessary, result in the temporary restriction or unavailability of certain features or services. PRNV Services endeavours to balance the need for containment against the continuity of services for users.

15.  Preservation of Evidence and Records

PRNV Services takes reasonable steps to preserve evidence and records relevant to an incident, in order to support investigation, remediation, legal compliance, and cooperation with lawful investigations. Such evidence may include system and security logs, access records, audit trails, communications, and other digital records.

PRNV Services endeavours to preserve relevant evidence in a manner that maintains its integrity and, where appropriate, its admissibility, including as electronic records under applicable Indian law. Personnel and service providers are required to refrain from destroying, altering, or tampering with information that may be relevant to an incident, except as directed in the course of authorised containment or remediation activities.

16.  Notification Principles

PRNV Services is committed to making timely and meaningful notifications where required by applicable law, and to communicating responsibly in relation to data breaches. Notification decisions are guided by the following principles:

(a)     Legal Compliance — notifications are made to affected individuals, regulatory authorities, and law-enforcement agencies where, and to the extent, required under applicable Indian law;

(b)   Timeliness — notifications are made within the timelines prescribed by applicable law and, in the absence of a prescribed timeline, without undue delay following confirmation and assessment of the relevant facts;

(c)   Accuracy — notifications are based on the information reasonably available at the relevant time, and may be supplemented or updated as the investigation progresses;


(d)   Clarity — notifications are expressed in clear and plain language, so far as practicable, to enable recipients to understand the incident and any recommended steps;

(e)    Proportionality — the form, content, and recipients of notifications are appropriate to the nature, severity, and circumstances of the incident; and

(f)   Confidentiality and Integrity of Investigation — notifications are made in a manner that does not unduly prejudice ongoing investigations, security measures, or the rights of affected individuals.

17.  Notification to Affected Individuals, Where Required

Where required under applicable law, or where PRNV Services otherwise considers it appropriate, PRNV Services notifies affected individuals of a data breach that affects, or is reasonably likely to affect, their information. Such notification is made through appropriate communication channels and within applicable timelines.

In accordance with applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023 and the rules made thereunder, where a personal data breach is notifiable, PRNV Services endeavours to intimate each affected individual in a concise and plain-language manner, using available and appropriate communication channels.

Notifications to affected individuals may include the information described in Section 20, to the extent applicable and available, including a description of the nature of the breach, its likely consequences, the measures taken or proposed, and recommended steps that individuals may take to protect their interests.

18.  Notification to Regulatory Authorities and Law Enforcement, Where Required by Applicable Law

Where required under applicable Indian law, PRNV Services notifies and cooperates with the relevant regulatory authorities and, where appropriate, law-enforcement agencies in relation to a data breach or security incident.

Such authorities may include, depending on the nature of the incident and the requirements of applicable law:

(a)     the Data Protection Board of India, in respect of notifiable personal data breaches under the Digital Personal Data Protection Act, 2023 and the rules made thereunder;

(b)    the Indian Computer Emergency Response Team (CERT-In), in respect of reportable cyber security incidents under the Information Technology Act, 2000 and the directions and rules issued thereunder;

(c)   other competent regulatory, governmental, or supervisory authorities having jurisdiction; and

(d)   law-enforcement agencies, where the incident involves suspected criminal conduct or where cooperation is required by law.

PRNV Services cooperates with lawful investigations and with the directions of competent authorities, and may disclose information to such authorities to the extent permitted or required by law.

19.  Communication Channels and Notification Methods

PRNV Services selects communication channels and notification methods appropriate to the nature of the incident, the recipients, and the requirements of applicable law. Such channels and methods may include:

•       direct electronic communication, such as email or in-platform notifications, to registered users;

•       messages or notices displayed within the website, mobile applications, or customer portals;

•       public notices or website statements, where individual notification is not reasonably practicable or where a broader communication is appropriate;

•       formal communications to regulatory authorities and law-enforcement agencies through prescribed or appropriate channels; and

•       communications to third-party service providers and partners, where relevant to the incident.

Where direct notification of every affected individual is not reasonably feasible, PRNV Services may employ alternative or supplementary methods of communication that are reasonably designed to reach affected individuals, consistent with applicable law.

20.  Information Included in Notifications

To the extent applicable, available, and permitted by law, a notification concerning a data breach may include the following information:

(a)   a description of the nature of the data breach, including, where known, its timing and circumstances;

(b)   a description of the categories of information involved or likely to be involved;

(c)   the likely consequences of the data breach, so far as they can be assessed;

(d)   the measures taken or proposed by PRNV Services to address the data breach and to mitigate its possible adverse effects;

(e)   recommended steps, if any, that affected individuals may take to protect their interests; and

(f)   contact details through which recipients may obtain further information, as set out in Section 31.

The specific content of any notification is determined having regard to the requirements of applicable law, the circumstances of the incident, and the information reasonably available at the relevant time. Notifications may be issued on a preliminary basis and supplemented as further information becomes available.

21.  Responsibilities of PRNV Services

In relation to data breaches and security incidents, PRNV Services endeavours to:


(a)     implement and maintain reasonable administrative, technical, and physical safeguards to protect information and digital assets;

(b)    maintain procedures for the detection, reporting, escalation, classification, investigation, containment, and remediation of incidents;

(c)   assess incidents responsibly and determine notification obligations in accordance with applicable law;

(d)    make timely notifications to affected individuals, regulatory authorities, and law-enforcement agencies where required by applicable law;

(e)   preserve relevant evidence and maintain appropriate documentation and records;

(f)   cooperate with lawful investigations and the directions of competent authorities;

(g)     designate a Data Protection Officer or Security Officer as the responsible point of contact under this Policy; and

(h)   review and continuously improve its incident prevention, detection, response, and recovery capabilities.

22.  Responsibilities of Users

The security of information is a shared responsibility. Users contribute to the protection of information by exercising reasonable care in their use of the Platform. Users are encouraged or required, as applicable, to:

(a)   use strong, unique credentials and keep them confidential;

(b)    refrain from sharing passwords, one-time passwords, or other authentication details with any person, including any person claiming to represent PRNV Services;

(c)   keep their devices, software, and applications reasonably secure and up to date;

(d)   remain alert to phishing, social engineering, and fraudulent communications;

(e)   promptly report any suspected unauthorised access, security incident, or data breach to PRNV Services through the contact details in Section 31; and

(f)   comply with the applicable policies and terms published by PRNV Services.

23.  Responsibilities of Third-Party Service Providers

Third-party service providers that access, process, host, or handle information on behalf of, or in connection with, PRNV Services are expected to maintain appropriate security measures and to cooperate in incident response. In particular, such providers are expected to:

(a)     implement and maintain reasonable security safeguards consistent with applicable law and their contractual obligations;

(b)    promptly notify PRNV Services of any actual or suspected security incident or data breach affecting information connected with the Platform;


(c)     cooperate with PRNV Services in the investigation, containment, remediation, and notification of incidents;

(d)   preserve relevant evidence and records; and

(e)   comply with applicable law and lawful directions of competent authorities.

PRNV Services engages third-party service providers under arrangements that include appropriate confidentiality, security, and incident-handling obligations, consistent with applicable law and good practice. PRNV Services is not responsible for security failures attributable solely to the independent acts or omissions of third parties beyond its reasonable control, except to the extent provided under applicable law.

24.  Incident Recovery and Service Restoration

Following containment of an incident, PRNV Services undertakes reasonable steps to recover affected systems and to restore normal service in a secure and controlled manner. Recovery and restoration activities may include:

(a)   validating that the cause of the incident has been addressed and that affected systems are secure before restoration;

(b)   restoring information and systems from secure backups or trusted sources, where appropriate;

(c)   rebuilding, reconfiguring, or replacing compromised components;

(d)   applying additional safeguards to reduce the risk of recurrence; and

(e)   monitoring restored systems for signs of residual or recurring compromise.

PRNV Services endeavours to restore services as promptly as is consistent with maintaining security and integrity. Recovery timelines may vary depending on the nature and severity of the incident and the operational circumstances.

25.  Corrective and Preventive Actions

PRNV Services treats incidents as opportunities to strengthen its security posture. Following an incident, and as part of its continuous improvement practices, PRNV Services may undertake corrective and preventive actions, including:

(a)   addressing the root cause and any contributing factors identified during investigation;

(b)   enhancing technical controls, monitoring, and detection capabilities;

(c)   updating policies, procedures, and configurations;

(d)   reinforcing training and security awareness; and

(e)   reviewing and, where appropriate, strengthening arrangements with third-party service providers.

26.  Documentation and Record Retention

PRNV Services maintains appropriate documentation of security incidents and data breaches, including records of detection, assessment, classification, investigation, containment, remediation, notification, and recovery


activities. Such documentation supports accountability, legal compliance, cooperation with authorities, and continuous improvement.

Records relating to incidents are retained for such period as is necessary for the purposes for which they were created, or as required under applicable law, including any retention obligations relating to logs, audit trails, and electronic records. On expiry of the applicable retention period, records are disposed of, anonymised, or archived in accordance with applicable law and the internal data-handling standards of PRNV Services.

27.  Training and Security Awareness

PRNV Services promotes security awareness among its personnel and, where relevant, its service providers. PRNV Services endeavours to provide appropriate training and guidance to enable relevant persons to recognise, prevent, report, and respond to security incidents and data breaches.

Security awareness initiatives may address topics such as safe handling of information, recognition of phishing and social-engineering attempts, secure use of systems and credentials, and the procedures set out in this Policy. PRNV Services reviews and updates its awareness initiatives from time to time to reflect evolving threats and good practice.

28.  Compliance Monitoring and Periodic Reviews

PRNV Services monitors compliance with this Policy and reviews its effectiveness on a periodic basis and as circumstances require. Monitoring and review activities may include assessment of incident-handling practices, review of security controls and logs, evaluation of lessons learned from incidents, and consideration of developments in applicable law, technology, and threat landscape.

Periodic reviews are intended to confirm that this Policy remains accurate, effective, and aligned with applicable Indian information technology, cybersecurity, privacy, and data protection laws, and to identify opportunities for enhancement of the Platform’s security and incident-response capabilities.

29.  Amendments and Updates

PRNV Services may amend, revise, supplement, or update this Policy from time to time to reflect changes in applicable law, technology, operational practices, or the threat landscape, or for any other lawful reason. Material changes will be reflected in an updated version of this Policy published on the PRNV Services website.

The version of this Policy in force at any given time is the version published on www.prnvservices.com. Continued use of the Platform following the publication of an updated Policy constitutes acceptance of the updated Policy, to the extent permitted by applicable law. Users are encouraged to review this Policy periodically.

30.  Governing Law and Jurisdiction

This Policy is governed by and shall be construed in accordance with the laws of the Republic of India, including, as applicable, the Information Technology Act, 2000 and the rules and directions made thereunder; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Digital Personal Data Protection Act, 2023 and the rules made thereunder; and


other applicable Indian information technology, cybersecurity, privacy, and data protection laws in force from time to time.

Subject to any applicable statutory dispute-resolution mechanism, the courts at Hyderabad, Telangana, India shall have exclusive jurisdiction over any matter arising out of or in connection with this Policy.

31.  Contact Information

Questions, reports, or requests concerning this Policy, or any suspected or confirmed data breach or security incident, may be addressed to the designated Data Protection Officer / Security Officer of PRNV Services using the details below:

Data Protection Officer / Security Officer

[Insert Name]

Email Address

[Insert Email]

Contact Number

[Insert Number]

Business Address

[Insert Address]

Website

www.prnvservices.com

PRNV Services endeavours to acknowledge and respond to communications received under this Policy within a reasonable time, consistent with applicable law and the circumstances of the matter.


Incident Response and Notification Framework

This Framework consolidates and illustrates the end-to-end approach of PRNV Services to managing data breaches and security incidents. It is intended to be read together with Sections 9 to 25 of this Policy and does not create obligations additional to, or inconsistent with, those Sections or applicable law.

A.  Identification and Verification

PRNV Services monitors its systems and receives reports in order to identify suspected incidents, and undertakes preliminary verification to confirm whether an event constitutes an actual or potential security incident or data breach, as described in Section 9.

B.  Severity Assessment Methodology

Confirmed incidents are classified by severity having regard to the sensitivity and volume of information involved, the number of individuals potentially affected, the likelihood and potential extent of harm, the criticality of affected systems, and the status of containment, as described in Section 12. Classification is provisional and may be revised as the investigation progresses.

C.  Containment and Remediation Activities

PRNV Services takes reasonable steps to contain incidents and to mitigate their impact, and subsequently to remediate underlying causes, as described in Sections 14 and 25. Containment may result in the temporary restriction or unavailability of certain features or services.

D.  Notification Decision-Making Principles

PRNV Services determines whether, when, how, and to whom notification is required, applying the principles in Section 16 and the requirements of applicable law. Notification obligations to affected individuals, regulatory authorities, and law-enforcement agencies are addressed in Sections 17 to 20.

E.  Communication with Affected Individuals and Authorities

Where notification is required or appropriate, PRNV Services communicates through suitable channels and methods, as described in Section 19, and includes the information described in Section 20, to the extent applicable, available, and permitted by law.

F.  Recovery and Service Restoration

PRNV Services validates security, restores affected systems and services in a controlled manner, and monitors for residual or recurring compromise, as described in Section 24.

G.  Post-Incident Review and Continuous Improvement

Following resolution, PRNV Services conducts post-incident review to capture lessons learned, implement corrective and preventive actions, and enhance its prevention, detection, response, and recovery capabilities, as described in Sections 25 and 28.

This Policy is provided for general informational purposes and to describe the approach of PRNV Services to data breach notification. It does not constitute legal advice, and it does not create rights or obligations beyond those required under applicable law or expressly set out herein. To the maximum extent permitted by applicable law, PRNV Services shall not be liable for incidents or losses arising from causes beyond its reasonable control, including sophisticated cyber-attacks, previously unknown vulnerabilities, the acts or omissions of third parties, user negligence, or force majeure events.

Conclusion

PRNV Services reaffirms its commitment to operating as a responsible, technology-enabled platform that places information security and privacy protection at the centre of its operations. Through this Data Breach Notification Policy, PRNV Services seeks to ensure the prompt identification and management of security incidents, the responsible investigation and evaluation of risk, the protection of affected individuals and information assets, and the making of timely notifications wherever legally required.

PRNV Services remains committed to:

•       information security;

•       privacy protection;

•       transparency;

•       responsible incident management;

•       regulatory compliance;

•       cybersecurity resilience; and

•       the continuous enhancement of its data breach prevention, detection, response, and recovery capabilities.

By maintaining and continually improving this framework, PRNV Services seeks to uphold the trust placed in it by its customers, service professionals, business partners, and the wider community, and to discharge its responsibilities in a manner consistent with applicable Indian information technology, cybersecurity, privacy, and data protection laws.

PRNV Services

PRNV Services

Modern local service discovery platform.

Customers find verified local professionals quickly. Service professionals grow with subscription-based lead access. PRNV keeps the model direct, trustworthy, and commission-free.

Contact

6TH FLOOR, 7-1-28/4/4, SWATHI PLAZA, Shyam Karan Road, Ameerpet, Hyderabad, Hyderabad, Telangana, 500016

96035583699059789177

Policies & Information

Browse platform policies, agreements, user guidance, and other important documents maintained by PRNV Services.

© 2026 PRNV Services. All rights reserved.