Legal & Policy

SECURITY POLICY

Last updated

SECURITY POLICY

Information Security, Data Protection & Cybersecurity Resilience Framework

Applicable to all Digital Platforms, Systems and Services operated by PRNV Service

Document Control

Document Title

PRNV Services — Security Policy (Information Security, Data Protection & Cybersecurity Framework)

Document Owner

PRNV Services — Information Security Governance Function

Status

Approved & Publishing-Ready

Effective Date

As published on www.prnvservices.com

Applies To

Website, Mobile Applications, Customer Portals, Online Services, Communication Channels, Information Systems & Databases, Network Infrastructure, Cloud-Based Services, and Digital Content & Technology Resources

Intended Audience

Customers, Service Professionals, Business Partners, Regulatory Authorities and Legal Reviewers

Registered Office

PRNV Services, Flat No. 301, Sai Manor Apartment, H.No. 7-1-621/10, Near Umesh Chandra Statue, IAS Quarters Lane, SR Nagar, Hyderabad, Telangana – 500038, India

Governing Law

Laws of the Republic of India — including the Information Technology Act, 2000 and the DPDP Act, 2023

Jurisdiction

Courts of Hyderabad, Telangana, India (Exclusive)

Website

www.prnvservices.com

Review Cycle

Reviewed periodically and upon material change in technology, risk or regulation

CONFIDENTIALITY & LEGAL STATUS.  This Security Policy forms part of the official website content and legal framework of PRNV Services. It is published in the interest of transparency and regulatory compliance and should be read together with the PRNV Services Privacy Policy, Terms & Conditions, Cybersecurity & Digital Risk Disclosure and Grievance Redressal Policy. By accessing or using any PRNV Services digital platform, you acknowledge and agree to the security practices described herein.


Table of Contents


1.  Introduction

1.1   PRNV Services (“PRNV Services”, the “Company”, “we”, “us” or “our”) operates a technology-enabled digital advertising, listing, visibility and marketing platform that connects independent service professionals, skilled technicians and businesses directly with customers across India through its website, mobile applications and associated digital interfaces accessible at www.prnvservices.com.

1.2   As a technology-enabled platform, PRNV Services recognises that the trust placed in it by its Customers, Service Professionals, Business Partners and other stakeholders depends fundamentally on the security, confidentiality and integrity of the information and digital assets it processes. Information security is therefore a core operational priority and a foundation of responsible digital governance at PRNV Services.

1.3   This Security Policy (the “Policy”) sets out the principles, safeguards, controls and responsibilities adopted by PRNV Services to protect information, digital systems and technology resources against unauthorised access, disclosure, alteration, loss or destruction, and to ensure the resilience, availability and lawful operation of its digital platform.

1.4   This Policy has been prepared in accordance with applicable Indian information security, data protection and cyber laws, and is aligned with internationally recognised information security practices, including the ISO/IEC 27001 family of standards (or equivalent), to demonstrate PRNV Services’ commitment to information security, privacy protection, regulatory compliance and continuous improvement.

2.  Purpose of This Security Policy

The purpose of this Security Policy is to:

•      Establish a clear, structured and enforceable framework for the protection of information and digital assets across all PRNV Services platforms and systems;

•      Affirm PRNV Services’ commitment to the principles of confidentiality, integrity and availability of information;

•      Define the administrative, technical and physical safeguards implemented to prevent unauthorised access, disclosure, alteration, or destruction of information;

•      Define governance structures, roles and responsibilities for information security across the organisation and its service providers;

•      Promote a culture of cybersecurity awareness, responsible digital conduct and shared responsibility among all users and personnel;

•      Support cybersecurity risk management, incident response, business continuity and operational resilience; and

•      Demonstrate compliance with applicable Indian laws, regulatory requirements and recognised information security standards.

3.  Scope and Applicability

3.1   This Policy applies to all digital platforms, systems, services, environments and technology resources operated, owned, controlled or administered by PRNV Services, including, without limitation:

•      the PRNV Services Website;

•      PRNV Services Mobile Applications;

•      Customer Portals and user account environments;

•      Online Services and digital interfaces;

•      Communication Channels (including email, messaging, notifications and support channels);

•      Information Systems and Databases;

•      Network Infrastructure;

•      Cloud-Based Services and hosting environments; and

•      Digital Content and Technology Resources.

3.2   This Policy applies to all individuals and entities who access, use, operate, support or interact with PRNV Services platforms, including Customers, Service Professionals, Business Partners, employees, contractors, consultants, vendors and authorised third-party service providers (collectively, “Users”).

3.3   This Policy governs all information processed by PRNV Services in any form — whether collected, stored, transmitted, displayed, archived or disposed of — across the entire information lifecycle and irrespective of the medium or location in which such information resides.

4.  Definitions

For the purposes of this Policy, the following terms shall have the meanings set out below:

4.1   “Information” / “Data” means any data, content, records or material in electronic or digital form that is processed by PRNV Services, including personal data, account data, transactional data, technical data and platform content.

4.2   “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as understood under the Digital Personal Data Protection Act, 2023 and applicable Indian law.

4.3   “Digital Assets” means PRNV Services’ websites, mobile applications, software, source code, databases, networks, servers, cloud environments, digital content and other technology resources.

4.4   “Confidentiality” means ensuring that information is accessible only to those authorised to have access.

4.5   “Integrity” means safeguarding the accuracy, completeness and reliability of information and processing methods.

4.6   “Availability” means ensuring that authorised users have reliable and timely access to information and systems when required.

4.7   “Security Incident” means any actual or suspected event that compromises, or threatens to compromise, the confidentiality, integrity or availability of information or digital assets, including unauthorised access, data breach, malware, phishing or system disruption.

4.8   “Access Control” means the administrative, technical and physical mechanisms that regulate who may access information and systems and to what extent.

4.9   “Third-Party Service Provider” means any external vendor, processor, hosting provider, payment partner, communication provider or contractor engaged to support PRNV Services’ operations.

5.  Information Security Objectives

PRNV Services’ information security objectives are to:

•      Protect the confidentiality, integrity and availability of information and digital assets;

•      Prevent unauthorised access, disclosure, alteration, destruction or misuse of information;

•      Ensure secure collection, storage, transmission, processing and disposal of information throughout its lifecycle;

•      Implement robust access control, authentication and authorisation mechanisms;

•      Detect, respond to, and recover from security incidents in a timely and effective manner;

•      Maintain business continuity and operational resilience against cyber threats and disruptions;

•      Comply with applicable Indian laws, regulatory requirements and recognised security standards; and

•      Continuously monitor, assess and improve security practices in response to evolving threats.

6.  Nature of Platform Services

6.1   PRNV Services is a technology-enabled digital advertising, listing, visibility and marketing platform that facilitates direct connections between independent Service Professionals and Customers. PRNV Services operates as an intermediary and technology-facilitation platform and is not a provider, employer, contractor or agent of the Service Professionals listed on its platform.

6.2   This Policy addresses the security of PRNV Services’ digital platforms, systems and information assets. It governs how PRNV Services protects information and technology resources within its operational control and does not extend to systems, devices, networks or environments controlled by Users or third parties outside PRNV Services’ direct control.

6.3   Communications, dealings and transactions that occur independently between Users outside the PRNV Services platform are beyond the operational and technical control of PRNV Services. Users remain responsible for the security of their own devices, credentials, networks and off-platform communications.

7.  Governance and Security Responsibilities

7.1   PRNV Services maintains an information security governance framework that defines clear roles, responsibilities and accountability for the protection of information and digital assets across the organisation.

7.2   Overall responsibility for information security governance vests with PRNV Services management, which establishes security objectives, approves this Policy, allocates appropriate resources, and oversees the implementation and effectiveness of security controls.

7.3   A designated security and compliance function is responsible for the day-to-day administration of security controls, monitoring of systems, coordination of incident response, management of vulnerabilities, and oversight of third-party security obligations.

7.4   All employees, contractors, consultants and authorised personnel are responsible for complying with this Policy, exercising due care in handling information, and promptly reporting any suspected security incidents or weaknesses.

7.5   PRNV Services has designated a Grievance Officer, in compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Act, 2023, who serves as a point of contact for security, privacy and data-protection grievances. Contact details are set out in the Contact Information section of this Policy.

8.  Information Security Principles

PRNV Services’ information security framework is guided by the following core principles:

•      Confidentiality, Integrity and Availability — protecting the security triad as the foundation of all controls;

•      Least Privilege — granting access strictly on a need-to-know and need-to-use basis;

•      Defence in Depth — applying multiple layers of administrative, technical and physical safeguards;

•      Accountability — ensuring actions on systems are traceable to identified, authorised individuals;

•      Security by Design and by Default — embedding security considerations into systems, applications and processes from inception;

•      Risk-Based Approach — prioritising controls according to the sensitivity of information and the level of risk;

•      Data Minimisation and Purpose Limitation — collecting and retaining only information necessary for legitimate purposes; and

•      Continuous Improvement — regularly reviewing and enhancing security practices to address evolving threats.

9.  Confidentiality, Integrity and Availability

9.1   Confidentiality. PRNV Services implements access controls, authentication mechanisms, encryption and confidentiality safeguards to ensure that information is accessible only to authorised individuals and is protected against unauthorised access or disclosure.

9.2   Integrity. PRNV Services employs validation controls, change management, audit logging and protective measures to safeguard the accuracy, completeness and reliability of information and to prevent unauthorised or undetected alteration.

9.3   Availability. PRNV Services maintains resilient infrastructure, redundancy, backup mechanisms and business continuity arrangements designed to ensure that information and services remain reliably available to authorised users, subject to maintenance, force majeure and circumstances beyond reasonable control.

10.  Information Classification and Handling

10.1   PRNV Services classifies information according to its sensitivity, value and the potential impact of unauthorised disclosure, loss or compromise, in order to apply proportionate handling and protection requirements.

10.2   Information is broadly classified into categories such as Public Information, Internal Information, Confidential Information and Sensitive Personal Information. Each category is subject to defined handling, storage, transmission, retention and disposal requirements.

10.3   Sensitive and personal information is afforded enhanced protection, including restricted access, encryption where appropriate, and secure handling throughout its lifecycle in accordance with applicable Indian data protection law.

10.4   Information is securely disposed of, deleted or anonymised when it is no longer required for the purposes for which it was collected, or as required by applicable law, using secure deletion and disposal methods.

11.  Access Control and User Authentication

11.1   PRNV Services implements role-based access controls to ensure that access to information and systems is granted strictly on the basis of authorised roles, responsibilities and the principles of least privilege and need-to-know.

11.2   Access to systems and information requires authentication of the identity of the requesting individual through approved authentication mechanisms before access is granted.

11.3   Access rights are provisioned, reviewed, modified and revoked through a controlled process, and are promptly withdrawn upon termination of employment, engagement or authorisation, or where access is no longer required.

11.4   Privileged and administrative access is restricted to a limited number of authorised personnel, subject to additional controls, monitoring and accountability.

11.5   Access activities are logged and subject to periodic review to detect and prevent unauthorised or inappropriate access.

12.  Password and Credential Management

12.1   PRNV Services enforces credential management practices designed to protect account credentials against compromise, including requirements for strong credentials and secure handling of authentication data.

12.2   Authentication credentials are stored using protective measures such as hashing and, where applicable, encryption, and are not stored or transmitted in plain, readable form where avoidable.

12.3   Where appropriate, PRNV Services may implement additional authentication safeguards, such as one-time passwords or multi-factor authentication mechanisms, to strengthen account protection.

12.4   Users are responsible for maintaining the confidentiality of their account credentials, for using strong and unique passwords, for not sharing credentials, and for promptly reporting any suspected compromise of their credentials.

13.  Identity and Access Management

13.1   PRNV Services operates identity and access management practices to govern the full lifecycle of user identities and access rights, including registration, authentication, authorisation, periodic review and de-provisioning.

13.2   Each user identity is, to the extent practicable, uniquely attributable to a specific individual to support accountability and traceability of actions performed on systems.

13.3   Authorisation rules ensure that authenticated users are able to access only the information and functions appropriate to their role and entitlements.

13.4   Access entitlements are reviewed periodically to confirm they remain appropriate, and excessive, redundant or dormant access is removed in a timely manner.

14.  Administrative Safeguards

PRNV Services implements administrative safeguards to manage the selection, development and execution of security measures, including:

•      documented security policies, standards and procedures;

•      defined roles, responsibilities and accountability for information security;

•      personnel security measures, including confidentiality undertakings and appropriate background checks where applicable;

•      security awareness and training programmes;

•      risk assessment and risk management processes;

•      third-party and vendor security management; and

•      incident management, review and continuous improvement processes.

15.  Technical Safeguards

PRNV Services implements technical safeguards to protect information and digital assets, including:

•      access control and authentication technologies;

•      encryption of data in transit and, where applicable, at rest;

•      firewalls, intrusion detection and prevention mechanisms;

•      anti-malware and endpoint protection;

•      secure configuration and hardening of systems;

•      logging, monitoring and audit-trail capabilities;

•      secure software development practices; and

•      patch and vulnerability management.

16.  Physical Safeguards

16.1   PRNV Services relies on data centre, cloud and hosting environments that maintain physical and environmental security controls designed to protect the underlying infrastructure on which information and digital assets reside.

16.2   Such physical safeguards typically include controlled physical access, surveillance, environmental monitoring, fire suppression and power-resilience measures provided by reputable infrastructure and cloud service providers.

16.3   Physical access to sensitive systems and equipment within PRNV Services’ control is restricted to authorised personnel, and devices used to access platform systems are subject to appropriate protection requirements.

17.  Network and Infrastructure Security

17.1   PRNV Services implements network and infrastructure security controls designed to protect its systems against unauthorised access, intrusion, disruption and misuse.

17.2   Controls include network segmentation where appropriate, firewalls, secure gateways, traffic monitoring, and protection against network-based attacks such as denial-of-service attempts.

17.3   Infrastructure components are securely configured, regularly maintained and updated, and protected through appropriate hardening and patch management practices.

17.4   Remote and administrative access to infrastructure is secured through authenticated, encrypted channels and restricted to authorised personnel.

18.  Application Security Measures

18.1   PRNV Services applies application security practices across the software development lifecycle to protect its website, mobile applications and online services against common application-level threats and vulnerabilities.

18.2   These practices include secure coding standards, input validation, protection against common web and application vulnerabilities, secure session and authentication handling, and security testing prior to and during deployment.

18.3   Application changes are subject to controlled change-management and review processes designed to maintain the integrity and security of platform services.

18.4   Applications are monitored, maintained and updated to address newly identified vulnerabilities and evolving threats.

19.  Data Protection and Confidentiality

19.1   PRNV Services is committed to protecting the confidentiality of information and to processing personal data lawfully, fairly and securely in accordance with applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made thereunder.

19.2   Information is collected, stored, transmitted, processed and disposed of using appropriate technical and organisational measures designed to protect it against unauthorised access, disclosure, alteration, loss or destruction throughout its lifecycle.

19.3   Access to personal and confidential information is restricted to authorised personnel and third-party processors bound by confidentiality obligations and engaged for legitimate, defined purposes.

19.4   PRNV Services applies data minimisation and retention principles, retaining information only for as long as necessary for the purposes for which it was collected or as required by applicable law, and disposing of it securely thereafter.

19.5   Further details regarding the collection, use, sharing and protection of personal data are set out in the PRNV Services Privacy Policy, which should be read together with this Policy.

20.  Encryption and Secure Communications

20.1   PRNV Services employs encryption and secure communication technologies to protect information in transit across its platforms and communication channels, including the use of industry-recognised secure transport protocols.

20.2   Where appropriate, sensitive information is protected through encryption at rest using recognised cryptographic methods.

20.3   Cryptographic mechanisms and keys are managed using controlled practices designed to protect their confidentiality, integrity and availability.

20.4   Secure communication safeguards are applied to authentication processes, data transfers and administrative access to reduce the risk of interception or compromise.

21.  Security Monitoring and Logging

21.1   PRNV Services implements security monitoring and logging mechanisms to record relevant security-related events across its systems and to support detection, investigation and accountability.

21.2   Logs and audit trails are generated, protected against unauthorised access and tampering, and retained for appropriate periods in accordance with operational and legal requirements.

21.3   Monitoring activities are conducted on a continuous or periodic basis to identify anomalous, suspicious or unauthorised activity and to support timely response.

21.4   Monitoring and logging are conducted in a manner consistent with applicable law and the PRNV Services Privacy Policy.

22.  Threat Detection and Prevention

22.1   PRNV Services deploys controls and tools designed to detect, prevent and mitigate cyber threats, including malware, phishing, intrusion attempts, fraud and other malicious activity.

22.2   Threat detection mechanisms may include intrusion detection and prevention, anti-malware controls, anomaly detection, and automated and manual analysis of security events.

22.3   PRNV Services takes proactive measures to reduce the likelihood and impact of threats, including hardening of systems, restriction of access, and ongoing assessment of the evolving threat landscape.

23.  Vulnerability Management

23.1   PRNV Services maintains a vulnerability management process to identify, assess, prioritise and remediate security vulnerabilities across its systems, applications and infrastructure.

23.2   This process includes periodic vulnerability assessments and, where appropriate, security testing such as penetration testing, conducted internally or by qualified third parties.

23.3   Identified vulnerabilities are assessed according to risk and remediated, mitigated or otherwise addressed within reasonable, risk-based timeframes.

23.4   Security patches and updates are applied through a controlled patch-management process to reduce exposure to known vulnerabilities.

24.  Incident Detection and Response

24.1   PRNV Services maintains an incident detection and response capability designed to identify, contain, investigate, mitigate and recover from security incidents in a timely and structured manner.

24.2   Upon detection of a suspected or confirmed security incident, PRNV Services takes appropriate steps to contain the incident, assess its scope and impact, mitigate harm and restore affected systems and services.

24.3   Where a security incident or personal data breach is notifiable under applicable law, PRNV Services shall notify the relevant authorities — which may include the Indian Computer Emergency Response Team (CERT-In) and the Data Protection Board of India — and affected individuals, in the manner and within the timelines prescribed by applicable Indian law.

24.4   PRNV Services reviews security incidents to identify root causes and lessons learned, and to implement corrective and preventive measures that strengthen its security posture.

25.  Business Continuity and Disaster Recovery

25.1   PRNV Services maintains business continuity and disaster recovery arrangements designed to support the resilience of its critical systems and services and to enable timely recovery following a disruptive event.

25.2   These arrangements address scenarios such as system failures, cyber incidents, infrastructure outages and force majeure events, and aim to minimise the impact of disruption on the availability of platform services.

25.3   Business continuity and disaster recovery measures are reviewed and, where appropriate, tested periodically to validate their effectiveness.

25.4   While PRNV Services takes reasonable measures to maintain availability and continuity, it does not warrant uninterrupted or error-free operation, and certain disruptions may arise from causes beyond its reasonable control.

26.  Backup and Recovery Procedures

26.1   PRNV Services implements backup procedures designed to protect against the loss of critical information and to support restoration of systems and data following an incident.

26.2   Backups are performed at appropriate intervals, protected through access controls and, where appropriate, encryption, and stored securely to preserve their confidentiality, integrity and availability.

26.3   Recovery procedures are maintained to enable the restoration of information and services from backups, and are reviewed and tested periodically to confirm their reliability.

27.  Third-Party Security Management

27.1   PRNV Services engages third-party service providers — including hosting and cloud providers, payment partners, communication providers and other processors — to support the operation of its platform, and requires such providers to maintain appropriate security safeguards.

27.2   Third-party service providers are engaged under contractual arrangements that include obligations relating to confidentiality, data protection, security and lawful processing of information.

27.3   PRNV Services applies due diligence and, where appropriate, ongoing oversight in selecting and managing third-party providers, commensurate with the sensitivity of the information involved and the nature of the services provided.

27.4   Access by third parties to PRNV Services’ information and systems is limited to what is necessary for the performance of their contracted services and is subject to appropriate controls.

28.  User Responsibilities and Security Practices

Information security is a shared responsibility. Users are expected to:

•      safeguard their account credentials and use strong, unique passwords;

•      protect the devices, networks and systems they use to access PRNV Services platforms;

•      not share credentials or allow unauthorised use of their accounts;

•      remain vigilant against phishing, fraudulent communications and social-engineering attempts;

•      use the platform only for lawful and authorised purposes, and not attempt to gain unauthorised access, probe, scan or test systems except under an authorised programme;

•      not introduce malicious code or interfere with the security or operation of the platform; and

•      promptly report any suspected security incident, vulnerability or unauthorised activity to PRNV Services.

29.  Reporting Security Incidents

29.1   PRNV Services encourages Users and personnel to promptly report any suspected or actual security incident, vulnerability, data breach or unauthorised activity affecting PRNV Services platforms or information.

29.2   Security concerns may be reported to PRNV Services through the contact channels set out in the Contact Information section of this Policy, including the designated Grievance Officer.

29.3   Reports are reviewed and handled in a timely manner, and reporters are encouraged to provide relevant details to assist investigation while refraining from any unauthorised action.

29.4   Users are also encouraged to report suspected criminal cyber activity to the appropriate law-enforcement authorities, including the national cybercrime reporting channels.

30.  Security Awareness and Training

30.1   PRNV Services promotes a culture of security awareness and provides appropriate guidance and training to its personnel on information security responsibilities, secure practices and emerging threats.

30.2   Personnel are made aware of this Policy and related security procedures, and of their obligations to protect information and report security concerns.

30.3   PRNV Services may publish security guidance and best-practice information to help Users protect their accounts, devices and communications.

31.  Detailed Security Controls Framework

PRNV Services maintains a layered set of security controls spanning administrative, technical and physical safeguards. The following provides a consolidated overview of the principal control domains:

Control Domain

Representative Controls

Access Management & Authentication

Role-based access control, least privilege, authentication and authorisation mechanisms, privileged-access restrictions, periodic access reviews.

Encryption & Confidentiality

Encryption of data in transit and, where applicable, at rest; secure protocols; cryptographic key management; confidentiality safeguards.

Monitoring, Logging & Audit

Security event logging, protected audit trails, continuous or periodic monitoring, and review of access and activity.

Threat Detection & Incident Response

Intrusion detection/prevention, anti-malware, anomaly detection, structured incident detection, containment, response and lawful breach notification.

Backup, Restoration & Recovery

Regular backups, secure storage, encryption where appropriate, and tested restoration and recovery procedures.

Vulnerability Management & Assessments

Vulnerability assessments, periodic security testing including penetration testing, risk-based remediation and patch management.

Business Continuity & Disaster Recovery

Continuity planning, resilience measures, redundancy, and periodic review and testing of recovery arrangements.

Security Awareness & User Responsibilities

Personnel awareness and training, published user guidance, and shared-responsibility expectations for Users.

These controls are applied on a risk-based basis, proportionate to the sensitivity of information and the nature of the systems concerned, and are reviewed and enhanced as part of PRNV Services’ commitment to continuous improvement.

32.  Compliance with Applicable Indian Laws and Regulatory Requirements

32.1   PRNV Services is committed to operating in compliance with applicable Indian information security, data protection, privacy and cyber laws, and conducts its information security practices accordingly.

32.2   PRNV Services’ security and data-protection practices are designed to be consistent with, among others, the following Indian legal and regulatory instruments, as applicable and as amended from time to time:

•      the Information Technology Act, 2000 (including the Information Technology (Amendment) Act, 2008);

•      the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;

•      the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;

•      the Digital Personal Data Protection Act, 2023;

•      directions and guidelines issued by the Indian Computer Emergency Response Team (CERT-In);

•      the Bharatiya Nyaya Sanhita, 2023 and other applicable laws relating to cyber offences; and

•      other applicable laws, rules, regulations and regulatory directions of the Republic of India.

32.3   PRNV Services aligns its information security framework with internationally recognised standards, such as the ISO/IEC 27001 family of standards (or equivalent), to support a structured and benchmarked approach to information security management.

32.4   PRNV Services cooperates with lawful requests from regulators, courts, law-enforcement agencies and cybercrime authorities to the extent required by applicable law.

33.  Compliance Monitoring and Internal Reviews

33.1   PRNV Services monitors compliance with this Policy and its related security procedures through internal reviews, assessments and oversight activities.

33.2   Security controls, processes and arrangements are reviewed periodically and following material changes in technology, risk, operations or applicable law, to confirm their continued adequacy and effectiveness.

33.3   Findings from reviews and assessments are used to identify areas for improvement and to drive corrective and preventive measures as part of a continuous-improvement cycle.

33.4   Non-compliance with this Policy by personnel or third parties may result in appropriate remedial, disciplinary or contractual action, consistent with applicable agreements and law.

34.  Security Disclaimer

Important Security Disclaimer

PRNV Services implements reasonable administrative, technical and physical safeguards designed to protect information and digital assets against unauthorised access, disclosure, alteration, loss or destruction.

However, no technology system, software application, electronic communication method, or internet-based service can guarantee absolute or complete security. Despite the implementation of robust security measures, the transmission and storage of information over the internet and digital systems carry inherent risks, and PRNV Services cannot warrant or guarantee absolute security.

Users share responsibility for information security. Users are responsible for protecting their own devices, credentials, networks and communications, for exercising caution against fraudulent or malicious activity, and for promptly reporting any suspected security incidents or unauthorised activities to PRNV Services.

To the maximum extent permitted by applicable law, and as further set out in the PRNV Services Terms & Conditions and related policies, PRNV Services shall not be liable for any security breach, unauthorised access, hacking, data theft, malware, or similar event occurring despite the implementation of reasonable security measures, except to the extent directly attributable to PRNV Services as required under applicable law.

35.  Amendments and Updates

35.1   PRNV Services may review, amend, update or revise this Security Policy from time to time to reflect changes in technology, security practices, operational requirements, threats or applicable law.

35.2   The most current version of this Policy will be published on the PRNV Services website at www.prnvservices.com. The date or version of the Policy in effect will be indicated on the website.

35.3   Continued access to or use of PRNV Services platforms following the publication of any amendment constitutes acceptance of the updated Policy.

36.  Governing Law and Jurisdiction

36.1   This Security Policy shall be governed by and construed in accordance with the laws of the Republic of India.

36.2   Subject to any applicable dispute-resolution provisions in the PRNV Services Terms & Conditions, the courts at Hyderabad, Telangana, India shall have exclusive jurisdiction over any matter arising out of or in connection with this Policy.

36.3   This Policy is intended to be read together with the PRNV Services Terms & Conditions, Privacy Policy and related policies. In the event of any inconsistency on matters of information security, this Policy shall be read harmoniously with such documents to give effect to the protection of information and digital assets.

37.  Conclusion and Reaffirmation of Commitment

37.1   PRNV Services reaffirms its unwavering commitment to information security, privacy protection, responsible digital governance, transparency, regulatory compliance, cybersecurity resilience and the continuous improvement of its security management practices.

37.2   As a technology-enabled platform, PRNV Services regards the protection of information and digital assets, and the trust of its Customers, Service Professionals, Business Partners and stakeholders, as central to its operations and long-term integrity.

37.3   PRNV Services will continue to invest in, monitor and enhance its administrative, technical and physical safeguards, to uphold the principles of confidentiality, integrity and availability, and to respond responsibly to the evolving cybersecurity landscape, in furtherance of a secure, trustworthy and compliant digital platform.

38.  Contact Information

For any questions, concerns, reports or grievances relating to this Security Policy, information security, data protection or the reporting of a security incident, please contact:

Entity

PRNV Services

Website

www.prnvservices.com

Grievance Officer

Designation

Grievance Officer

Email

grievance@prnvservices.com

Support Email

support@prnvservices.com

Telephone

+91 96035 58369

Registered Office

PRNV Services, Flat No. 301, Sai Manor Apartment, H.No. 7-1-621/10, Near Umesh Chandra Statue, IAS Quarters Lane, SR Nagar, Hyderabad, Telangana – 500038, India

Grievance Acknowledgement & Resolution.  In accordance with applicable Indian law, the designated Grievance Officer shall acknowledge security, privacy and data-protection grievances within forty-eight (48) hours of receipt and endeavour to resolve them within the timelines prescribed under applicable law. Suspected criminal cyber activity may also be reported to the national cybercrime reporting portal and local law-enforcement authorities.