IT Policy

ZESSTBITES INTERNATIONAL PVT. LTD.

INFORMATION TECHNOLOGY (IT) POLICY

1. INTRODUCTION

ZesstBites International , we recognize that Information Technology (IT) is a critical component of our business operations, customer experience, supply chain, data security, and franchise management. This IT Policy outlines the standards, protocols, and practices that govern how we manage, protect, and use digital systems and information assets across all our platforms and operations.

This policy also reflects our commitment to protecting customer data, maintaining system integrity, and ensuring compliance with global standards of cybersecurity and technology use.

2. SCOPE & APPLICABILITY

This IT Policy applies to:

• All ZesstBites-managed websites, platforms, mobile applications, and backend systems

• Employees, franchise partners, consultants, contractors, and third-party vendors who access our systems

• All IT assets, including hardware, software, data, networks, applications, and cloud services used by ZesstBites

• Customers engaging with our digital services, including ordering platforms, loyalty apps, and support portals

3. OBJECTIVES

• To ensure the confidentiality, integrity, and availability of digital assets and information

• To prevent unauthorized access, loss, alteration, or misuse of data

• To define responsible digital behaviour for all users

• To secure business continuity through data backup and disaster recovery protocols

• To comply with local and international IT regulations (including India IT Act, GDPR, etc.)

4. ROLES & RESPONSIBILITIES
IT Department:

• Oversee implementation and compliance of all IT systems

• Regularly update and patch systems, monitor threats, and maintain backups

• Respond to cybersecurity threats and incidents

Employees & Franchise:

• Use systems responsibly and adhere to security protocols

• Report any IT-related issues or suspicious activity

• Avoid unauthorized downloads, installations, or data sharing

Vendors & Partners:

• Comply with our data handling and cybersecurity protocols

• Use secured channels and verified software for all transactions

5. ACCEPTABLE USE POLICY (AUP)

All users of ZesstBites digital resources must use them solely for authorized business or service purposes.

Unacceptable use includes but is not limited to:

• Accessing illegal content or engaging in unauthorized downloads

• Using IT resources for personal business, harassment, or political activity

• Sharing credentials or bypassing security controls

• Installing pirated or unauthorized software

6. IT ASSET MANAGEMENT

ZesstBites maintains detailed records of all IT assets, including:

• Servers, computers, POS machines, tablets, kiosks

• Licensed software, CRM, ERP, and analytics tools

• Cloud service providers and web hosting platforms

All assets must be registered, approved, and maintained under IT supervision.

7. DATA MANAGEMENT & BACKUP POLICY

• All critical operational and customer data is securely stored on cloud servers with multiple backup schedules

• Real-time and daily backup protocols are followed for POS, sales, and franchise systems

• Personal customer data is encrypted and only accessed by authorized personnel

• Backups are periodically tested for restoration integrity

8. EMAIL & COMMUNICATION POLICY

ZesstBites email systems are to be used for professional purposes only.

Users must:

• Avoid sending confidential data to external addresses without encryption

• Refrain from clicking on unknown links or downloading suspicious attachments

• Use corporate signatures and maintain tone and professionalism in communication

ZesstBites reserves the right to monitor emails for compliance and risk.

9. INTERNET USAGE POLICY

• Internet access is filtered and monitored for bandwidth use, browsing safety, and malware risk

• Social media access is limited to approved accounts for business use only

• Streaming, torrenting, and personal downloads are strictly prohibited on ZesstBites networks

10. CYBERSECURITY & THREAT PROTECTION

Our systems are protected by enterprise-grade security solutions:

• Firewalls, anti-malware, and intrusion detection systems (IDS)

• SSL-secured websites and encrypted data transfers

• Real-time monitoring of login attempts and device behaviors

• Regular security audits and ethical hacking simulations

Customers are also protected through HTTPS encryption and token-based transactions.

11. PASSWORD & ACCESS CONTROL POLICY

All access credentials must meet complexity requirements:

• Minimum 12 characters, including uppercase, lowercase, number, and symbol

• Changed every 60 days

• Two-Factor Authentication (2FA) enabled for admin access

Shared or default passwords are strictly forbidden.

12. REMOTE ACCESS & BYOD (BRING YOUR OWN DEVICE)

Remote access is permitted only under these conditions:

• Secure VPN connection must be used

• Device must have current antivirus and encryption

• Data should not be downloaded locally without approval

• Employees using personal devices for work must register them and comply with security standards

13. SOFTWARE USAGE & LICENSING

Only licensed and authorized software may be installed on ZesstBites devices. All applications must:

• Be verified for safety

• Have valid licensing and subscription

• Not be open-source unless approved by IT with sandboxing

Pirated, cracked, or trial-expired software is strictly prohibited.

14. MONITORING & SURVEILLANCE

ZesstBites reserves the right to:

• Monitor usage of its digital infrastructure

• Use CCTV, keylogging, and screen recording (in compliance with laws)

• Audit employee and franchisee digital behaviour for compliance and risk prevention

No personal information will be accessed without cause or justification.

15. INCIDENT REPORTING & BREACH RESPONSE

All IT-related incidents must be reported within 1 hour to:

mail to :

ithelp@zesstbites.com

+91 7805050523 (24/7 Support Hotline)

Examples of reportable incidents:

• Suspicious emails or files

• System crashes

• Data leaks or unusual logins

• Hardware theft

An immediate investigation and isolation protocol will be initiated.

16. THIRD-PARTY IT VENDOR POLICY

All IT vendors, developers, and integrators must:

• Sign a Non-Disclosure Agreement (NDA)

• Comply with ZesstBites‘ privacy and cybersecurity protocols

• Provide secure APIs, encrypted communications, and clear SLAs

Vendor systems may be subjected to periodic audits.

17. COMPLIANCE & LEGAL OBLIGATIONS

ZesstBites complies with:

• Information Technology Act 2000 (India)

• General Data Protection Regulation (GDPR) (for international operations)

• FSSAI’s Digital Compliance Norms

• Local e-commerce and cybersecurity laws in operating countries

Breaches will be dealt with according to legal provisions and may involve law enforcement.

18. VIOLATIONS & DISCIPLINARY ACTION

Any user found violating the IT Policy is subject to:

• Written warning

• Suspension of access

• Financial penalties for damages

• Termination of employment or franchise agreement

• Legal proceedings (for criminal offenses)

19. REVIEW & AMENDMENTS

This policy is reviewed every 12 months by our IT Governance Committee or sooner if required due to:

• Changes in technology

• Legal or compliance revisions

• Business expansion or franchise system changes

Updates will be published on the official ZesstBites website.

20. APPROVAL & ENFORCEMENT

This policy is authorized and enforced by:

ZesstBites International Pvt . Ltd. – IT Governance Board

Registered Office:

Hyderabad, India

+91 7805050523

www.zesstbites.com

mailto: hello@zesstbites.com

Last Updated: July 30, 2025

ZesstBites International Pvt . Ltd. – All Rights Reserved

ZESSTBITES INTERNATIONAL PVT. LTD.

INFORMATION TECHNOLOGY (IT) POLICY

1. INTRODUCTION

ZesstBites International , we recognize that Information Technology (IT) is a critical component of our business operations, customer experience, supply chain, data security, and franchise management. This IT Policy outlines the standards, protocols, and practices that govern how we manage, protect, and use digital systems and information assets across all our platforms and operations.

This policy also reflects our commitment to protecting customer data, maintaining system integrity, and ensuring compliance with global standards of cybersecurity and technology use.

2. SCOPE & APPLICABILITY

This IT Policy applies to:

• All ZesstBites-managed websites, platforms, mobile applications, and backend systems

• Employees, franchise partners, consultants, contractors, and third-party vendors who access our systems

• All IT assets, including hardware, software, data, networks, applications, and cloud services used by ZesstBites

• Customers engaging with our digital services, including ordering platforms, loyalty apps, and support portals

3. OBJECTIVES

• To ensure the confidentiality, integrity, and availability of digital assets and information

• To prevent unauthorized access, loss, alteration, or misuse of data

• To define responsible digital behaviour for all users

• To secure business continuity through data backup and disaster recovery protocols

• To comply with local and international IT regulations (including India IT Act, GDPR, etc.)

4. ROLES & RESPONSIBILITIES
IT Department:

• Oversee implementation and compliance of all IT systems

• Regularly update and patch systems, monitor threats, and maintain backups

• Respond to cybersecurity threats and incidents

Employees & Franchise:

• Use systems responsibly and adhere to security protocols

• Report any IT-related issues or suspicious activity

• Avoid unauthorized downloads, installations, or data sharing

Vendors & Partners:

• Comply with our data handling and cybersecurity protocols

• Use secured channels and verified software for all transactions

5. ACCEPTABLE USE POLICY (AUP)

All users of ZesstBites digital resources must use them solely for authorized business or service purposes.

Unacceptable use includes but is not limited to:

• Accessing illegal content or engaging in unauthorized downloads

• Using IT resources for personal business, harassment, or political activity

• Sharing credentials or bypassing security controls

• Installing pirated or unauthorized software

6. IT ASSET MANAGEMENT

ZesstBites maintains detailed records of all IT assets, including:

• Servers, computers, POS machines, tablets, kiosks

• Licensed software, CRM, ERP, and analytics tools

• Cloud service providers and web hosting platforms

All assets must be registered, approved, and maintained under IT supervision.

7. DATA MANAGEMENT & BACKUP POLICY

• All critical operational and customer data is securely stored on cloud servers with multiple backup schedules

• Real-time and daily backup protocols are followed for POS, sales, and franchise systems

• Personal customer data is encrypted and only accessed by authorized personnel

• Backups are periodically tested for restoration integrity

8. EMAIL & COMMUNICATION POLICY

ZesstBites email systems are to be used for professional purposes only.

Users must:

• Avoid sending confidential data to external addresses without encryption

• Refrain from clicking on unknown links or downloading suspicious attachments

• Use corporate signatures and maintain tone and professionalism in communication

ZesstBites reserves the right to monitor emails for compliance and risk.

9. INTERNET USAGE POLICY

• Internet access is filtered and monitored for bandwidth use, browsing safety, and malware risk

• Social media access is limited to approved accounts for business use only

• Streaming, torrenting, and personal downloads are strictly prohibited on ZesstBites networks

10. CYBERSECURITY & THREAT PROTECTION

Our systems are protected by enterprise-grade security solutions:

• Firewalls, anti-malware, and intrusion detection systems (IDS)

• SSL-secured websites and encrypted data transfers

• Real-time monitoring of login attempts and device behaviors

• Regular security audits and ethical hacking simulations

Customers are also protected through HTTPS encryption and token-based transactions.

11. PASSWORD & ACCESS CONTROL POLICY

All access credentials must meet complexity requirements:

• Minimum 12 characters, including uppercase, lowercase, number, and symbol

• Changed every 60 days

• Two-Factor Authentication (2FA) enabled for admin access

Shared or default passwords are strictly forbidden.

12. REMOTE ACCESS & BYOD (BRING YOUR OWN DEVICE)

Remote access is permitted only under these conditions:

• Secure VPN connection must be used

• Device must have current antivirus and encryption

• Data should not be downloaded locally without approval

• Employees using personal devices for work must register them and comply with security standards

13. SOFTWARE USAGE & LICENSING

Only licensed and authorized software may be installed on ZesstBites devices. All applications must:

• Be verified for safety

• Have valid licensing and subscription

• Not be open-source unless approved by IT with sandboxing

Pirated, cracked, or trial-expired software is strictly prohibited.

14. MONITORING & SURVEILLANCE

ZesstBites reserves the right to:

• Monitor usage of its digital infrastructure

• Use CCTV, keylogging, and screen recording (in compliance with laws)

• Audit employee and franchisee digital behaviour for compliance and risk prevention

No personal information will be accessed without cause or justification.

15. INCIDENT REPORTING & BREACH RESPONSE

All IT-related incidents must be reported within 1 hour to:

mail to :

ithelp@ZesstBitesinternational.com

+91 7805050523 (24/7 Support Hotline)

Examples of reportable incidents:

• Suspicious emails or files

• System crashes

• Data leaks or unusual logins

• Hardware theft

An immediate investigation and isolation protocol will be initiated.

16. THIRD-PARTY IT VENDOR POLICY

All IT vendors, developers, and integrators must:

• Sign a Non-Disclosure Agreement (NDA)

• Comply with ZesstBites‘ privacy and cybersecurity protocols

• Provide secure APIs, encrypted communications, and clear SLAs

Vendor systems may be subjected to periodic audits.

17. COMPLIANCE & LEGAL OBLIGATIONS

ZesstBites complies with:

• Information Technology Act 2000 (India)

• General Data Protection Regulation (GDPR) (for international operations)

• FSSAI’s Digital Compliance Norms

• Local e-commerce and cybersecurity laws in operating countries

Breaches will be dealt with according to legal provisions and may involve law enforcement.

18. VIOLATIONS & DISCIPLINARY ACTION

Any user found violating the IT Policy is subject to:

• Written warning

• Suspension of access

• Financial penalties for damages

• Termination of employment or franchise agreement

• Legal proceedings (for criminal offenses)

19. REVIEW & AMENDMENTS

This policy is reviewed every 12 months by our IT Governance Committee or sooner if required due to:

• Changes in technology

• Legal or compliance revisions

• Business expansion or franchise system changes

Updates will be published on the official ZesstBites website.

20. APPROVAL & ENFORCEMENT

This policy is authorized and enforced by:

ZesstBites International Pvt . Ltd. – IT Governance Board

Registered Office:

Hyderabad, India

+91 7805050523

www.zesstbitesinternational.com

mailto: hello@zesstbitesinternational.com

Last Updated: July 30, 2025

ZesstBites International Pvt . Ltd. – All Rights Reserved