INFORMATION TECHNOLOGY ACT COMPLIANCE POLICY
Last updated
INFORMATION TECHNOLOGY ACT COMPLIANCE POLICY
Compliance with the Information Technology Act, 2000 and Applicable Rules
Information Security · Cybersecurity · Data Protection · Lawful Digital Governance
Document Control
Document Title | Information Technology Act Compliance Policy |
Status | Final · Approved for Website Publication |
Applies To | Website, Mobile Applications, Customer Portals, Online Services, Communication Channels, Digital Content and Technology Platforms, and Information Systems and Databases |
Governing Law | Laws of the Republic of India |
Primary Statute | Information Technology Act, 2000 and Rules made thereunder, as amended |
Jurisdiction | Courts of Hyderabad, Telangana, India — Exclusive |
Platform |
Table of Contents
1. Introduction 3
2. Purpose of This Information Technology Act Compliance Policy 3
4. Definitions 4
5. Nature of Platform Services 5
7. Applicability of the Information Technology Act, 2000 and Applicable Rules 6
8. Electronic Records and Digital Communications 6
9. Electronic Consent and Acceptance 7
10. Information Security Practices 7
11. Reasonable Security Measures and Procedures 8
12. Data Protection and Confidentiality 8
13. User Account Security Responsibilities 9
14. Acceptable Use of Technology Systems 9
15. Prohibited Activities and Unlawful Conduct 9
16. Cybersecurity Measures 10
17. Monitoring and Incident Management 11
18. Fraud Prevention and Risk Management 11
19. Reporting Security Incidents 11
20. User-Generated Content and Digital Communications 12
21. Cooperation with Law Enforcement and Regulatory Authorities 12
22. Preservation of Electronic Records 12
23. Third-Party Technology Services and Dependencies 13
24. Intellectual Property Protection 13
25. Grievance Redressal Mechanism 13
26. Compliance Monitoring and Internal Reviews 14
27. Disclaimer 15
28. Amendments and Updates 15
29. Governing Law and Jurisdiction 15
30. Commitment and Conclusion 15
31. Contact Information 16
1. Introduction
PRNV Services (“PRNV Services”, “the Platform”, “we”, “us”, or “our”) operates a technology-enabled digital platform that connects independent service professionals, technicians, vendors, and business entities (collectively, “Service Professionals”) with customers and users (“Users”) through its website, mobile applications, customer portals, and associated online services accessible at www.prnvservices.com. As an organisation whose operations are delivered substantially through electronic and digital means, PRNV Services recognises that the lawful, secure, and responsible use of information technology is fundamental to maintaining the trust of its Users, Service Professionals, business partners, and regulatory authorities.
This Information Technology Act Compliance Policy (the “Policy”) sets out the framework, principles, commitments, and safeguards adopted by PRNV Services to ensure compliance with the Information Technology Act, 2000 and the rules, regulations, notifications, and directions issued thereunder, as amended from time to time, together with other applicable Indian cyber, data protection, and information-security laws. This Policy reflects the commitment of PRNV Services to operate its digital infrastructure in a manner that is lawful, secure, transparent, and accountable.
2. Purpose of This Information Technology Act Compliance Policy
The purpose of this Policy is to establish a clear, comprehensive, and enforceable framework for the lawful and secure operation of all digital platforms and information systems maintained by PRNV Services. In particular, this Policy is intended to:
• affirm the commitment of PRNV Services to full compliance with the Information Technology Act, 2000, the rules and regulations made thereunder, and all applicable Indian cyber and information-technology laws;
• define the manner in which electronic records, electronic communications, and digital transactions are created, processed, authenticated, transmitted, and preserved on the Platform;
• set out the reasonable security practices and procedures, technical and administrative safeguards, and cybersecurity measures implemented to protect digital systems and information assets;
• describe the responsibilities of Users and Service Professionals in safeguarding their credentials, devices, and digital communications;
• establish mechanisms for monitoring, incident management, fraud prevention, reporting of security incidents, and cooperation with lawful investigations; and
• provide an accessible grievance redressal mechanism and reaffirm the commitment of PRNV Services to responsible technology practices and continuous improvement of its compliance posture.
3. Scope and Applicability
3.1 Platforms Covered. This Policy applies to all digital platforms, products, services, systems, and technology infrastructure owned, operated, controlled, or maintained by PRNV Services, including without limitation the website, mobile applications, customer portals, online services, communication channels, digital content and technology platforms, and information systems and databases (collectively, the “Digital Platforms”).
3.2 Persons Covered. This Policy applies to all persons who access or interact with the Digital Platforms, including Users, customers, Service Professionals, technicians, vendors, business partners, visitors, authorised personnel of PRNV Services, contractors, and third-party service providers, in each case to the extent of their access to or use of the Digital Platforms.
3.3 Activities Covered. This Policy governs all electronic activities undertaken on or through the Digital Platforms, including account registration, listing and profile management, electronic communications, uploading and transmission of digital content, electronic acceptance of terms, and the storage and processing of electronic records.
3.4 Relationship with Other Policies. This Policy is supplementary to, and is to be read together with, the other terms, conditions, and policies published by PRNV Services, including its Privacy Policy, Terms and Conditions, Acceptable Use provisions, and Grievance Redressal mechanism. In the event of any inconsistency on matters specifically governed by this Policy, the provisions of this Policy shall prevail to the extent of compliance with the Information Technology Act, 2000 and applicable rules.
4. Definitions
For the purposes of this Policy, the following terms shall have the meanings assigned to them below. Terms not defined herein shall carry the meaning ascribed to them under the Information Technology Act, 2000 and the rules made thereunder.
Term | Meaning |
Information Technology Act | The Information Technology Act, 2000, together with all rules, regulations, notifications, directions, and amendments made thereunder, as in force from time to time. |
Electronic Record | Data, record, or information generated, sent, received, or stored in electronic form, as defined under Section 2(1)(t) of the Information Technology Act. |
Electronic Signature | Authentication of an electronic record by a subscriber by means of an electronic technique recognised under the Information Technology Act. |
Computer Resource | A computer, computer system, computer network, data, computer database, or software, as defined under the Information Technology Act. |
Intermediary | Any person who, on behalf of another person, receives, stores, or transmits an electronic record or provides any service with respect to that record, as defined under Section 2(1)(w) of the Information Technology Act. |
Term | Meaning |
Digital Platforms | Collectively, the website, mobile applications, customer portals, online services, communication channels, digital content and technology platforms, and information systems and databases operated by PRNV Services. |
User | Any person who accesses or uses the Digital Platforms, including customers, Service Professionals, business partners, and visitors. |
Personal Information | Information relating to an identified or identifiable natural person, including sensitive personal data or information as defined under applicable Indian law. |
Security Incident | Any actual or suspected unauthorised access, use, disclosure, disruption, modification, or destruction of information or information systems. |
5. Nature of Platform Services
5.1 Technology-Enabled Platform. PRNV Services functions as a technology-enabled intermediary platform that provides digital infrastructure, listing, advertising, visibility, and communication facilities enabling Service Professionals to present their services to Users. PRNV Services operates within the meaning of an “intermediary” under Section 2(1)(w) of the Information Technology Act and conducts its operations in accordance with the due-diligence obligations applicable to intermediaries.
5.2 Digital Delivery of Services. The services of the Platform are delivered through electronic and digital channels. Accordingly, the creation, transmission, authentication, and retention of electronic records and digital communications are central to the operation of the Platform and are governed by this Policy and by the Information Technology Act.
5.3 Responsible Technology Operations. PRNV Services is committed to operating its Digital Platforms responsibly, lawfully, and securely. PRNV Services adopts reasonable security practices, maintains appropriate technical and organisational safeguards, and endeavours to ensure that its technology operations remain consistent with applicable Indian law and recognised information-security standards.
6. Compliance Commitment
PRNV Services is firmly committed to lawful digital operations and to maintaining a robust culture of compliance across its technology functions. In furtherance of this commitment, PRNV Services undertakes to:
• comply with the Information Technology Act, 2000 and all applicable rules, regulations, notifications, directions, and amendments issued thereunder;
• handle electronic records and communications responsibly, ensuring their authenticity, integrity, and confidentiality so far as is reasonably practicable;
• implement and maintain reasonable security practices and procedures to protect Personal Information and digital systems against unauthorised access, misuse, and compromise;
• manage cybersecurity risks proactively through monitoring, detection, prevention, response, and recovery measures;
• prevent unauthorised access and misuse of its Digital Platforms, information systems, and information assets;
• cooperate with lawful investigations and with the requirements of regulatory and law-enforcement authorities in accordance with applicable law; and
• continuously review and improve its information-security and compliance measures in line with evolving legal requirements and technological developments.
7. Applicability of the Information Technology Act, 2000 and Applicable Rules
PRNV Services conducts its digital operations in accordance with the Information Technology Act, 2000 and the rules and regulations framed thereunder. Without limiting the generality of the foregoing, PRNV Services has regard to the following legal instruments to the extent applicable to its operations:
• the Information Technology Act, 2000, including provisions relating to legal recognition of electronic records and electronic signatures, attribution and authentication of electronic records, offences relating to computer resources, and the obligations of intermediaries;
• the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, governing reasonable security practices and the handling of sensitive personal data or information;
• the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, governing the due-diligence obligations of intermediaries, including grievance redressal and the removal of unlawful content;
• directions and guidelines issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act in relation to cybersecurity incident reporting and cyber hygiene; and
• other applicable Indian laws, including the Digital Personal Data Protection Act, 2023, the Indian Contract Act, 1872, the Consumer Protection Act, 2019 and the rules made thereunder, and the Bharatiya Nyaya Sanhita, 2023, to the extent they bear upon the lawful operation of the Digital Platforms.
References in this Policy to any statute, rule, or regulation shall be construed as references to such statute, rule, or regulation as amended, re-enacted, or replaced from time to time.
8. Electronic Records and Digital Communications
8.1 Legal Recognition. PRNV Services recognises the legal validity of electronic records and electronic communications in accordance with the Information Technology Act. Information, notices, terms, communications, and records generated, sent, received, or stored in electronic form on the Digital Platforms shall be treated as valid electronic records for all lawful purposes, subject to applicable law.
8.2 Authenticity and Integrity. PRNV Services endeavours to maintain the authenticity, accuracy, and integrity of electronic records created or maintained on its systems through appropriate technical controls, including access controls, logging, and secure storage. Users and Service Professionals are responsible for ensuring that information they submit electronically is accurate, current, and complete.
8.3 Electronic Communications. Communications between PRNV Services and Users may take place through electronic channels, including the Platform interface, in-application messaging, email, short messaging service, and notifications. Users consent to receiving service-related and legally required electronic communications. Such electronic communications shall be deemed to satisfy any legal requirement that information be provided in writing, to the extent permitted by the Information Technology Act.
8.4 Attribution. An electronic record or communication originating from a User’s registered account or verified contact details shall be attributable to that User, unless the User establishes that the record was sent or generated without authority and that the User exercised reasonable care to safeguard the relevant credentials.
9. Electronic Consent and Acceptance
9.1 Electronic Contracts. PRNV Services enables the formation of valid and enforceable agreements through electronic means. In accordance with the principles recognised under the Information Technology Act relating to the validity of contracts formed through electronic communication, a User’s electronic acceptance of any terms, conditions, or policies — whether by clicking an “I Agree” or equivalent button, ticking a checkbox, registering an account, or continuing to use the Digital Platforms — shall constitute a valid, binding, and enforceable acceptance.
9.2 Digital Acceptance Mechanisms. PRNV Services may implement digital acceptance mechanisms, including click-wrap and browse-wrap acceptance, electronic acknowledgements, and consent records, to evidence the agreement of Users to applicable terms. Records of such acceptance, including timestamps and associated metadata, may be retained as electronic evidence in accordance with this Policy.
9.3 Informed Consent. Where PRNV Services collects consent for the processing of Personal Information or for electronic communications, such consent shall be sought in a manner that is clear and capable of being recorded. Users may, subject to applicable law and to the continued availability of the relevant services, withdraw consent by contacting the Grievance Officer at the contact details set out in this Policy.
10. Information Security Practices
PRNV Services maintains an information-security framework designed to protect the confidentiality, integrity, and availability of information processed on its Digital Platforms. This framework is informed by recognised information-security standards and by the reasonable security practices contemplated under the Information Technology Act and the rules made thereunder. The framework comprises administrative, technical, and physical safeguards as described in this Policy.
10.1 Administrative Safeguards
• documented information-security policies, standards, and procedures that are periodically reviewed;
• defined roles and responsibilities for personnel handling information systems and Personal Information;
• confidentiality obligations binding personnel, contractors, and third-party service providers; and
• awareness measures designed to promote responsible handling of information and recognition of security risks.
10.2 Technical Safeguards
• encryption of data in transit and, where appropriate, at rest, using industry-recognised methods;
• secure configuration and hardening of servers, applications, and network infrastructure;
• protective controls such as firewalls, secure protocols, and malware-prevention measures; and
• regular application of security updates and patches to mitigate known vulnerabilities.
10.3 Physical and Environmental Safeguards
• reliance on reputable hosting and infrastructure providers maintaining appropriate physical and environmental controls; and
• restriction of physical and logical access to systems hosting sensitive information to authorised personnel only.
11. Reasonable Security Measures and Procedures
11.1 Reasonable Security Practices. PRNV Services implements reasonable security practices and procedures designed to protect information, in a manner consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and with internationally recognised information-security standards such as the ISO/IEC 27001 family of standards, or an equivalent framework appropriate to the nature, scale, and sensitivity of the information handled.
11.2 Risk-Based Approach. Security measures are applied on a risk-based and proportionate basis, having regard to the categories of information processed, the technologies deployed, the potential harm that may result from a security compromise, and the evolving threat landscape.
11.3 Review and Testing. PRNV Services endeavours to review, assess, and test its security measures from time to time, and to update them as reasonably necessary to address newly identified risks, vulnerabilities, or regulatory requirements.
12. Data Protection and Confidentiality
12.1 Protection of Information. PRNV Services treats Personal Information and other sensitive information processed on its Digital Platforms as confidential and protects such information through appropriate safeguards. The collection, use, storage, processing, and disclosure of Personal Information are governed by the Privacy Policy of PRNV Services, read together with this Policy and applicable Indian data-protection law.
12.2 Confidentiality Obligations. Personnel, contractors, and third-party service providers who are granted access to information are bound by confidentiality obligations and are permitted to access information only on a need-to-know basis and for legitimate, lawful purposes connected with the operation of the Platform.
12.3 Integrity of Information. PRNV Services adopts measures designed to preserve the integrity of information and to prevent its unauthorised alteration, corruption, or destruction. Any tampering with, or unauthorised modification of, computer source documents or electronic records is strictly prohibited and may attract liability under the Information Technology Act and other applicable laws.
12.4 Lawful Disclosure. PRNV Services shall not disclose Personal Information except in accordance with applicable law, the Privacy Policy, the consent of the relevant individual, or the lawful requirements of regulatory and law-enforcement authorities.
13. User Account Security Responsibilities
The security of the Digital Platforms is a shared responsibility. While PRNV Services implements security measures at the platform level, Users and Service Professionals bear important responsibilities for safeguarding their own accounts and credentials. Each User and Service Professional shall:
• maintain the confidentiality of their login credentials, passwords, one-time passwords, and authentication details, and not share them with any unauthorised person;
• use strong, unique passwords and enable any additional authentication mechanisms made available by PRNV Services;
• ensure that the devices used to access the Digital Platforms are secured with up-to-date security software and protections;
• take responsibility for all activities undertaken through their account, except to the extent arising from unauthorised access that occurs despite the exercise of reasonable care; and
• promptly notify PRNV Services of any suspected or actual unauthorised access to, or compromise of, their account or credentials.
14. Acceptable Use of Technology Systems
Users and Service Professionals shall use the Digital Platforms only for lawful purposes and in a manner consistent with this Policy, applicable terms, and applicable law. Acceptable use includes accessing the Platform through authorised means, providing accurate information, respecting the rights of other Users, and complying with all instructions and security requirements communicated by PRNV Services. PRNV Services reserves the right to restrict, suspend, or terminate access where use of the Digital Platforms is inconsistent with this Policy or applicable law.
15. Prohibited Activities and Unlawful Conduct
In order to maintain the security and lawful operation of the Digital Platforms, Users and Service Professionals shall not engage in any of the following prohibited activities. Several of these activities may constitute offences under the Information Technology Act and other applicable laws:
• gaining or attempting to gain unauthorised access to any computer resource, account, system, network, or data of PRNV Services or of any other person;
• introducing, transmitting, or distributing any virus, malware, ransomware, worm, trojan, or other malicious or harmful code;
• tampering with, damaging, disrupting, or destroying any computer source code, electronic record, or computer resource;
• engaging in identity theft, impersonation, or cheating by personation using a computer resource;
• intercepting, monitoring, or decrypting any information without lawful authority;
• uploading, publishing, or transmitting any unlawful, obscene, defamatory, infringing, harmful, or otherwise objectionable content;
• violating the privacy of any person, including capturing, publishing, or transmitting images or information in breach of applicable law;
• scraping, harvesting, reverse engineering, or extracting data from the Digital Platforms by unauthorised or automated means;
• circumventing, disabling, or interfering with any security feature, access control, or technical measure of the Digital Platforms; and
• using the Digital Platforms to commit, facilitate, or further any fraudulent, deceptive, or unlawful activity.
16. Cybersecurity Measures
PRNV Services adopts a layered approach to cybersecurity designed to protect its Digital Platforms and information assets against evolving cyber threats. These measures include:
16.1 Access Controls and Authentication
• role-based access controls that restrict access to systems and data on a need-to-know and least-privilege basis;
• authentication mechanisms, which may include passwords, one-time passwords, and additional verification measures; and
• session-management and access-revocation controls for personnel and Users.
16.2 Monitoring and Logging
• logging of relevant system and access events to support detection, investigation, and accountability; and
• monitoring of systems and networks for indicators of suspicious or malicious activity.
16.3 Incident Response and Recovery
• defined procedures for the identification, containment, eradication, and recovery from security incidents; and
• backup and recovery arrangements designed to restore the availability and integrity of critical information and services.
16.4 Confidentiality and Integrity Protections
• encryption, secure transmission protocols, and integrity controls designed to protect information against unauthorised access or alteration.
17. Monitoring and Incident Management
17.1 Lawful Monitoring. PRNV Services may, to the extent permitted by applicable law and for legitimate purposes, monitor, log, and analyse activity on its Digital Platforms in order to maintain security, detect and prevent fraud and misuse, ensure compliance with this Policy, and protect the rights and safety of Users and of PRNV Services. Such monitoring is conducted in a manner consistent with applicable law and the Privacy Policy.
17.2 Incident Management. PRNV Services maintains processes for the management of security incidents, including detection, assessment, containment, remediation, and post-incident review. Where a security incident occurs, PRNV Services endeavours to take prompt and appropriate corrective action to limit harm and to restore secure operations.
17.3 Regulatory Reporting. Where required by applicable law, including directions issued by CERT-In under Section 70B of the Information Technology Act, PRNV Services shall report cybersecurity incidents to the relevant authorities within the applicable timelines and shall cooperate with such authorities in the manner required by law.
18. Fraud Prevention and Risk Management
18.1 Fraud Prevention. PRNV Services is committed to preventing fraud, abuse, and misuse of its Digital Platforms. PRNV Services may deploy risk-detection tools, verification measures, and monitoring controls designed to identify and mitigate fraudulent, deceptive, or unlawful activity.
18.2 Risk Management. PRNV Services adopts a risk-management approach to the operation of its technology systems, identifying and assessing risks to information security and taking proportionate measures to mitigate them. This includes preventive controls, detective controls, and responsive measures appropriate to the nature of the risk.
18.3 Action on Suspected Fraud. Where PRNV Services identifies or reasonably suspects fraudulent or unlawful activity, it may take such action as it considers appropriate, including investigation, suspension or restriction of access, preservation of relevant records, and reporting to the appropriate authorities.
19. Reporting Security Incidents
PRNV Services encourages Users, Service Professionals, security researchers, and other stakeholders to report any actual or suspected security incident, vulnerability, unauthorised access, data breach, or unlawful activity affecting the Digital Platforms. Timely reporting assists PRNV Services in protecting its systems and the information of its Users.
Reports made in good faith will be treated with appropriate confidentiality. Users must not exploit any identified vulnerability, access data without authorisation, or disrupt the Digital Platforms while reporting a concern.
20. User-Generated Content and Digital Communications
20.1 Responsibility for Content. Users and Service Professionals are solely responsible for the content, information, listings, communications, and materials that they create, upload, publish, or transmit through the Digital Platforms. Such content must be lawful, accurate, and compliant with this Policy, applicable terms, and applicable law.
20.2 Prohibited Content. Users shall not publish or transmit any content that is unlawful, infringing, obscene, defamatory, misleading, harmful, or otherwise objectionable, or that violates the rights of any person or the provisions of the Information Technology Act and the rules made thereunder.
20.3 Removal of Unlawful Content. Consistent with the due-diligence obligations of an intermediary, PRNV Services may remove, disable access to, or restrict any content that is found to be unlawful or in breach of this Policy, upon obtaining actual knowledge, receiving a valid complaint, or being directed to do so by a competent authority in accordance with applicable law.
21. Cooperation with Law Enforcement and Regulatory Authorities
21.1 Lawful Cooperation. PRNV Services is committed to cooperating with law-enforcement agencies, regulatory authorities, courts, and other competent authorities in accordance with applicable law. PRNV Services may provide information, electronic records, or assistance in response to lawful requests, summons, orders, directions, or notices issued by such authorities.
21.2 Lawful Requests. PRNV Services shall act on requests for information or assistance only where such requests are made in accordance with applicable law and through proper legal process. PRNV Services may verify the authenticity and lawfulness of any request before responding.
21.3 Preservation on Request. Where required by law or directed by a competent authority, PRNV Services may preserve relevant electronic records and information for the purposes of investigation or legal proceedings.
22. Preservation of Electronic Records
22.1 Retention. PRNV Services retains electronic records, logs, and information for such periods as are necessary for the purposes for which they were collected, or as required under applicable law, including obligations relating to record retention, evidence preservation, taxation, and regulatory compliance.
22.2 Electronic Evidence. Electronic records maintained by PRNV Services, including transaction records, consent records, communication logs, and access logs, may be relied upon as electronic evidence in accordance with applicable law. PRNV Services endeavours to maintain such records in a manner that supports their integrity and admissibility.
22.3 Secure Disposal. Upon expiry of the applicable retention period, and where no overriding legal obligation requires continued retention, electronic records shall be securely deleted, anonymised, or archived in accordance with the data-handling standards of PRNV Services and applicable law.
23. Third-Party Technology Services and Dependencies
23.1 Use of Third-Party Services. The operation of the Digital Platforms may rely upon third-party technology services, including hosting and cloud-infrastructure providers, communication-service providers, analytics providers, and other technology vendors. PRNV Services endeavours to engage reputable providers who maintain appropriate security and confidentiality standards.
23.2 Third-Party Obligations. Third-party providers engaged by PRNV Services are expected to comply with applicable law and with contractual obligations relating to data protection, confidentiality, and information security commensurate with the services they provide.
23.3 Third-Party Limitations. While PRNV Services takes reasonable steps to ensure that third-party providers maintain appropriate safeguards, PRNV Services does not control the systems of independent third parties and shall not be responsible for failures, breaches, or disruptions arising solely from the acts, omissions, or systems of such third parties beyond its reasonable control.
24. Intellectual Property Protection
24.1 Ownership. All content, software, source code, design, layout, graphics, text, databases, trademarks, logos, and other materials comprising the Digital Platforms are owned by or licensed to PRNV Services and are protected under applicable intellectual-property laws, including the Copyright Act, 1957, the Trade Marks Act, 1999, and other applicable laws, read together with the protections afforded to computer resources under the Information Technology Act.
24.2 Restrictions. No person shall reproduce, copy, distribute, modify, reverse engineer, or create derivative works from the Digital Platforms or their underlying technology, in whole or in part, without the prior written consent of PRNV Services, except as expressly permitted by law.
24.3 Protection of Source Documents. Any unauthorised access to, alteration of, or tampering with the computer source code or source documents of the Digital Platforms is strictly prohibited and may attract liability under the Information Technology Act and other applicable laws.
25. Grievance Redressal Mechanism
In accordance with the due-diligence obligations applicable to intermediaries under the Information Technology Act and the rules made thereunder, PRNV Services has established a grievance redressal mechanism for the receipt and resolution of complaints relating to information security, unlawful content, data protection, or any contravention of this Policy. Complaints may be submitted to the designated Grievance Officer / Compliance Officer using the contact details below.
Particulars | Details |
Grievance Officer / Compliance Officer | Rokalla Sri Saran Sai |
Designation | Grievance Officer (Compliance) |
Email Address | |
Contact Number | +91 96035 58369 |
Business Address | PRNV Services, Flat No. 301, Sai Manor Apartment, H. No. 7-1-621/10, Near Umesh Chandra Statue, IAS Quarters Lane, SR Nagar, Hyderabad, Telangana – 500038, India |
Communication Hours | Monday to Saturday, 10:00 a.m. to 6:00 p.m. (IST), excluding public holidays |
25.1 Communication Procedures
• Complaints should be submitted in writing to the Grievance Officer at the email address specified above, with sufficient particulars to enable identification and assessment of the matter, including the nature of the grievance, the content or activity complained of, and any supporting information.
• PRNV Services shall endeavour to acknowledge receipt of a complaint within forty-eight (48) hours of receipt.
• PRNV Services shall endeavour to dispose of and resolve the complaint within thirty (30) days of receipt, or within such timelines as may be prescribed under applicable law.
• PRNV Services may require the complainant to provide additional information or verification of identity in order to process the complaint, and may decline to act upon complaints that are frivolous, vexatious, incomplete, or unlawful.
26. Compliance Monitoring and Internal Reviews
26.1 Internal Compliance. PRNV Services maintains internal processes to monitor and promote compliance with this Policy and with applicable information-technology and cyber laws. These processes may include internal reviews, assessments, and audits of its technology systems, security controls, and compliance practices.
26.2 Continuous Improvement. PRNV Services is committed to the continuous improvement of its compliance and information-security posture. The findings of internal reviews and audits may be used to identify and implement enhancements to controls, processes, and safeguards.
26.3 Accountability. PRNV Services endeavours to maintain appropriate documentation and records to demonstrate its compliance efforts and to support accountability towards Users, business partners, and regulatory authorities.
27. Disclaimer
28. Amendments and Updates
PRNV Services reserves the right to amend, revise, update, or modify this Policy at any time in order to reflect changes in law, regulatory requirements, technology, business practices, or security considerations. Any amendment shall be effective upon publication of the revised Policy on the Digital Platforms, unless a later effective date is specified. Users and Service Professionals are encouraged to review this Policy periodically. Continued use of the Digital Platforms after the publication of any amendment constitutes acceptance of the amended Policy, to the extent permitted by applicable law.
29. Governing Law and Jurisdiction
29.1 Governing Law. This Policy shall be governed by and construed in accordance with the laws of the Republic of India, including the Information Technology Act, 2000 and the rules, regulations, and amendments made thereunder, and other applicable Indian laws.
29.2 Jurisdiction. Subject to any applicable provisions relating to dispute resolution contained in the terms and conditions of PRNV Services, the courts at Hyderabad, Telangana, India shall have exclusive jurisdiction over any dispute, controversy, or claim arising out of or in connection with this Policy or its subject matter.
29.3 Severability. If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court or authority of competent jurisdiction, such provision shall, to the extent of the invalidity or unenforceability, be deemed severable, and the remaining provisions of this Policy shall continue in full force and effect.
30. Commitment and Conclusion
PRNV Services reaffirms its steadfast commitment to lawful digital governance, information security, and regulatory compliance. As a technology-enabled platform, PRNV Services recognises that the trust of its Users, Service Professionals, business partners, and regulatory authorities depends upon the responsible, secure, and lawful operation of its Digital Platforms. PRNV Services is committed to upholding the highest practicable standards of transparency, accountability, and responsible technology practices, and to the continuous
improvement of its cybersecurity and compliance measures in line with evolving legal requirements and technological developments.
Through the framework set out in this Policy, PRNV Services seeks to ensure compliance with the Information Technology Act, 2000 and applicable rules, the responsible handling of electronic records and communications, the protection of data and digital systems, the prevention of unauthorised access and misuse, and full cooperation with lawful investigations and regulatory requirements. PRNV Services remains dedicated to operating as a secure, trustworthy, and compliant digital service platform for all of its stakeholders.
31. Contact Information
For any questions, concerns, or communications relating to this Information Technology Act Compliance Policy, please contact PRNV Services using the details below:
Particulars | Details |
Entity | PRNV Services |
Compliance / Grievance Officer | |
Grievance Email | |
Support Email | |
Contact Number | +91 96035 58369 |
Registered / Business Address | PRNV Services, Flat No. 301, Sai Manor Apartment, H. No. 7-1-621/10, Near Umesh Chandra Statue, IAS Quarters Lane, SR Nagar, Hyderabad, Telangana – 500038, India |
Website |