Information Security Policy

Finunique Small Private Limited is committed to protecting the confidentiality, integrity, and availability of customer and organizational data.

Introduction

This Information Security Policy outlines our security principles, infrastructure practices, and regulatory compliance approach. It applies to all employees, contractors, service providers, and third-party partners.

This Policy ensures compliance with:

  • DPDP Act, 2023
  • IT Act, 2000 & IT Rules, 2011
  • RBI Guidelines for Payment Aggregators and Fintech Entities
  • PCI-DSS standards
Objectives
  • Protect user data and financial transactions
  • Prevent unauthorized access, data breaches, and fraud
  • Establish a robust secure infrastructure
  • Ensure legal, regulatory, and contractual compliance
Data Classification and Handling

All data is categorized and protected as:

  • Confidential: Personal, financial, KYC, and payment data
  • Internal: Business operations and internal communications
  • Public: Approved marketing or regulatory disclosures

Sensitive personal data is encrypted both at rest and in transit as per DPDP Act.

Encryption and Secure Data Transmission
  • AES-256 encryption for data at rest
  • SSL/TLS 1.2+ for data in transit
  • HTTPS-only enforcement on all platforms
  • Tokenization of card details per RBI & PCI-DSS
  • Secure key vault management and rotation
Access Control and Authentication
  • Role-Based Access Control (RBAC) with least privilege
  • Multi-Factor Authentication (MFA) enforced internally
  • Immediate deprovisioning upon employee exit
  • Secure identity & access management tools
Infrastructure and Network Security
  • Cloud infrastructure hosted in compliant Indian data centers
  • VPC segmentation, firewalls, and intrusion prevention
  • DDoS protection, rate-limiting, Zero Trust architecture
  • On-premise systems follow same standards
PCI-DSS Compliance
  • No storage of full card numbers or CVV post-authorization
  • Annual assessments by Qualified Security Assessors (QSAs)
  • Secure development practices for payment systems
Data Storage, Monitoring & Logging

Data is stored encrypted in certified data centers in India. Backup copies are distributed geographically. We operate a 24/7 SOC with real-time monitoring and SIEM tools, centralized logs, and automated alerts for anomalies or breaches.

Vulnerability Management & Audits
  • Regular vulnerability assessments & automated patching
  • Quarterly internal audits and annual third-party testing
  • Data protection impact assessments (DPIAs)
  • Audit logs securely retained and reviewed
Incident Response and Breach Notification

We follow a documented IRP, including identification, containment, eradication, recovery, and post-incident review. Notifications to regulators and users are sent as per legal obligations. A dedicated Incident Response Team coordinates all actions.

Employee Security Protocols
  • Quarterly security awareness training & background checks
  • Endpoint encryption and mobile device management
  • Mandatory reporting of phishing or suspicious activity
Compliance & Review
  • Annual policy reviews and updates
  • Compliance with DPDP Act, IT Act, RBI, and CERT-In guidelines
  • Approval by senior management and stakeholders

Contact Information

Chief Information Security Officer (CISO)
Email: security@finunique.in
Phone: [+91- 9284748299]
Address: Plot No 97, Dakshinpuri - I, Shrikishan, Sanganer, Jagatpura, Jaipur Rajasthan, India, 302017