BharatOne Services and Affiliates Pvt. Ltd. ("BharatOne", "Company", "we", "our", or "us") is committed to maintaining appropriate administrative, technical, organizational, and physical security measures to protect the confidentiality, integrity, availability, and resilience of its digital platforms, systems, applications, APIs, operational infrastructure, merchant ecosystem, and customer information.
This Security Policy ("Policy") outlines the general security principles and operational practices adopted by BharatOne to support secure platform operations, responsible information handling, and protection against unauthorized access, misuse, fraud, and cybersecurity threats.
This Policy applies to customers, merchants, retailers, franchisees, agents, distributors, API users, business partners, employees, contractors, vendors, service providers, and all users interacting with BharatOne's Services.
1. Purpose
The purpose of this Policy is to:
- Support secure and reliable platform operations.
- Protect customer, merchant, and operational information from unauthorized access, disclosure, misuse, alteration, or destruction.
- Maintain platform integrity, availability, and operational resilience.
- Promote responsible information security practices.
- Reduce risks associated with fraud, cyberattacks, unauthorized access, and operational disruptions.
- Support compliance with applicable Indian laws, regulatory requirements, and industry best practices.
2. Security Principles
BharatOne's security framework is guided by the following principles:
- Confidentiality of sensitive information.
- Integrity of systems and transaction data.
- Availability and resilience of critical services.
- Role-based access control.
- Accountability and auditability.
- Least privilege access.
- Risk-based security management.
- Continuous monitoring and improvement.
- Incident preparedness and response.
- Compliance with applicable legal and regulatory obligations.
3. Security Measures
BharatOne may implement commercially reasonable administrative, technical, and organizational safeguards, including:
- Strong authentication and access controls.
- Role-based user access management.
- Secure communication protocols.
- Encryption of sensitive information during transmission and storage where appropriate.
- Multi-factor authentication for privileged access where applicable.
- API authentication and security controls.
- Network and infrastructure security measures.
- Continuous monitoring and audit logging.
- Fraud detection and prevention mechanisms.
- Malware protection and endpoint security.
- Periodic vulnerability assessments and security reviews.
- Secure software development practices.
- Backup, disaster recovery, and business continuity procedures where applicable.
Security measures may be updated periodically in response to evolving technologies, emerging threats, operational requirements, regulatory developments, and partner security standards.
4. User Responsibilities
Users are responsible for:
- Maintaining the confidentiality of usernames, passwords, PINs, and One-Time Passwords (OTPs).
- Using secure devices, updated software, and trusted internet connections.
- Preventing unauthorized access to their accounts.
- Reviewing transactions before confirmation.
- Promptly reporting suspicious activities, fraud, or security concerns.
- Complying with BharatOne's Terms of Use and applicable laws.
Users should not:
- Share authentication credentials with unauthorized persons.
- Attempt unauthorized access to BharatOne systems.
- Circumvent security controls.
- Upload malicious software or harmful code.
- Misuse BharatOne's Services or digital infrastructure.
5. Data Protection and Localization
BharatOne follows responsible operational practices to protect personal information, merchant data, transaction records, and operational information.
Where required by applicable law or regulatory direction, regulated customer and payment-related information is stored and processed within the geographical boundaries of India.
Information may be shared with authorized banking partners, payment service providers, government authorities, technology providers, or other authorized ecosystem participants only where:
- Necessary for service delivery.
- Required by law.
- Required under contractual obligations.
- Necessary for fraud prevention or security.
- Required by competent regulatory authorities.
Additional information regarding privacy and information management is available in BharatOne's Privacy Policy and Data Protection & Localization Statement.
6. Monitoring and Risk Management
BharatOne may undertake reasonable monitoring activities to:
- Detect suspicious or fraudulent activity.
- Identify unauthorized access attempts.
- Protect platform integrity.
- Monitor operational health.
- Investigate service disruptions.
- Support regulatory compliance.
- Improve platform reliability.
Monitoring activities may include:
- Authentication monitoring.
- System and application logging.
- Transaction pattern analysis.
- Device and network monitoring.
- API usage monitoring.
- Infrastructure performance monitoring.
- Security event logging.
7. Third-Party Services and Infrastructure
BharatOne delivers various services through integrations with banks, payment aggregators, payment gateways, government departments, telecom operators, cloud infrastructure providers, API providers, identity verification agencies, and other technology partners.
While BharatOne endeavors to work with reputable service providers that maintain appropriate security standards, it cannot guarantee the continuous availability or security of third-party systems beyond its operational control.
8. Incident Response
BharatOne maintains incident response procedures designed to support:
- Detection of security incidents.
- Investigation of suspicious activities.
- Containment of security events.
- Mitigation of operational risks.
- Recovery of affected systems.
- Restoration of services where reasonably practicable.
- Notification to relevant partners or authorities where required by applicable law.
Users are encouraged to immediately report suspected fraud, unauthorized account access, security vulnerabilities, or cybersecurity incidents through BharatOne's official support channels.
9. Limitation of Security Guarantees
Although BharatOne employs commercially reasonable security measures, no digital platform, network, software application, or electronic communication system can guarantee absolute security or uninterrupted availability.
Users acknowledge that:
- Internet-based services involve inherent cybersecurity risks.
- Technical failures, cyberattacks, or external disruptions may occur.
- Users also play an essential role in protecting their own devices, credentials, and accounts.
10. Policy Updates
BharatOne may revise this Security Policy periodically to reflect:
- Changes in technology.
- Emerging cybersecurity threats.
- Operational improvements.
- Regulatory developments.
- Industry best practices.
- Partner security requirements.
The latest version of this Policy will be published on BharatOne's official website. Continued use of the Services after publication of any revised Policy constitutes acceptance of the updated version.
11. Contact Information
For security concerns, vulnerability reporting, fraud reporting, or information security matters, please contact:
- BharatOne Services and Affiliates Pvt. Ltd.
- Registered Office: Shree Durga, 10th B Cross, K.R. Puram, Hassan – 573201, Karnataka, India
- Email: support@mybharatone.com
- Website: www.mybharatone.com
12. Governing Law
This Security Policy shall be governed by and construed in accordance with the laws of India.
Any disputes arising out of or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Hassan, Karnataka, unless otherwise required by applicable law.
