Guidelines for appropriate corporate email access, transmission restrictions, and communications audit logs.
E-MAIL USAGE POLICY
| DOCUMENT CONTROL | |
| Reference No. | DJTMPLMPL/IT/POL/EMUS |
| Document Name | E-mail Usage Policy |
| Version No. | 2.0 |
| Document Status | Definitive |
| Review Date | 01-04-2026 |
| Next Review Date | 01-04-2027 |
| Compliance Status | Mandatory – Applicable to All Employees |
| Review Period | Annually or earlier if required due to regulatory changes |
| Security Classification | Internal Use Only |
| Policy Owner | Chief Operation Officer |
| Policy Approving Authority | Board Of Directors |
| Distribution | All Employees – Head Office & Micro Centers |
| DOCUMENT REVISION HISTORY | ||
| Version | Release Date | Change Description |
| 1.0 | 01-06-2024 | First Version – Baseline Document |
| 2.0 | 01-04-2026 | Second revision – Comprehensive |
Table of Content
| S. No | Particulars |
| 1 | Definition, Purpose and Scope |
| 2 | Policy |
| 3 | E-mail Account Provisioning and Access Management |
| 4 | Acceptable Use of Company E-mail |
| 5 | Prohibited Use and Unacceptable Behaviour |
| 6 | Data Privacy, Confidentiality, and Record Retention |
| 7 | Guidelines for Micro Centre Staff |
| 8 | Monitoring, Compliance Measurement, and Audit |
| 9 | Security Incidents and Breach Reporting |
| 10 | Training, Awareness, and Employee Acknowledgement |
| 11 | Non-Compliance and Disciplinary Action |
| 12 | Policy Review, Ownership, and Amendments |
1. Definition, Purpose and Scope
1.1 Definition
E-mail is pervasively used in almost all industry verticals and is often the primary communication and awareness method inside/outside the organization. At the same time, misuse of e-mail can pose many legal, privacy and security risks, thus users need to understand the appropriate use of electronic communications.
1.2 Purpose
The purpose of this E-mail Usage Policy is to establish clear, enforceable standards for the use of the Company's official e-mail system. It aims to ensure that all electronic communications are consistent with the Company's ethical standards, applicable laws. The purpose of this e-mail policy is to ensure the proper use of DJTMPL e-mail system and make users aware of what DJTMPL deems as acceptable and unacceptable use of its e-mail system. This policy outlines the minimum requirements for the use of e-mail within DJTMPL Network. and establish an auditable record of electronic communications to support regulatory inspections, legal proceedings, and internal investigations.
1.3 Scope
This Policy applies to all individuals who are assigned an official DJTMPL e-mail account or who communicate on behalf of the Company using electronic mail. This includes permanent and contractual employees at the Head Office; all Micro Centre staff, including Centre Managers, Field Officers, Loan Officers, and Collection Agents across all states; vendors, consultants, interns, and third-party agents authorized to use DJTMPL e-mail; and any individual accessing DJTMPL e-mail systems remotely via mobile devices, laptops, or web browsers. Compliance with this Policy is mandatory and non-negotiable for all covered individuals.
2. Policy
- All use of e-mail must be consistent with DJTMPL policies and procedures of ethical conduct, safety, compliance with applicable laws and proper business practices.
- DJTMPL e-mail account should be used primarily for DJTMPL business-related purpose and non- DJTMPL related commercial or personal uses are prohibited.
- All DJTMPL data contained within an e-mail message or an attachment must be secured according to the Data Protection Standard.
- E-mail should be retained only if it qualifies as a DJTMPL business record. E-mail is a DJTMPL business record if there exists a legitimate and ongoing business reason to preserve the information contained in the e-mail.
- E-mail that is identified as a DJTMPL business record shall be retained according to DJTMPL Record Retention Schedule.
- The DJTMPL e-mail system shall not to be used for the creation or distribution of any disruptive or offensive messages, including offensive comments about race, gender, hair colour, disabilities, age, sexual orientation, pornography, religious beliefs and practice, political beliefs, or national origin. Employees who receive any e-mails with this content from any DJTMPL employee should report the matter to their supervisor immediately.
- Users are prohibited from automatically forwarding DJTMPL e-mail to a third-party e-mail system. Individual messages which are forwarded by the user must not contain DJTMPL confidential or above information.
- Users are prohibited from using third-party e-mail systems and storage servers such as Google, Yahoo, and MSN Hotmail etc. to conduct DJTMPL business, to create or memorialize any binding transactions, or to store or retain e-mail on behalf of DJTMPL. Such communications and transactions should be conducted through proper channels using DJTMPL-approved documentation.
- Non-work-related e-mail shall be saved in a separate folder from work related e mail. Sending chain letters or joke e-mails from a DJTMPL e-mail account is prohibited.
- DJTMPL employees shall have no expectation of privacy in anything they store, send or receive on the company’s e-mail system.
- IT Department may monitor messages of any user without prior notice to him/her but on the direction/approval of DJTMPL Management.
- Subscription on official e-mail id for Horoscopes, News is prohibited.
3. E-mail Account Provisioning and Access Management
3.1 Account Creation
Every eligible employee shall be issued an official Company e-mail account by the IT Department within two (2) working days of completing onboarding formalities. The standard naming convention for Head Office employees is firstname.lastname@DJTMPL.com. For Branch staff, the format shall be statecode.firstname.lastname@DJTMPL.com, as approved by the IT Head. No employee shall use a personal or third-party e-mail account (such as Gmail, Yahoo, Outlook Personal, Rediff mail, or any other service) for any official Company communication, including communication with customers, regulators, or partners. Use of personal e-mail for business purposes constitutes a violation of this Policy and may result in disciplinary action.
3.2 Password Management and Multi-Factor Authentication
Each employee is solely responsible for the security of their e-mail login credentials. Passwords must be a minimum of 10 characters in length and must include a combination of uppercase and lowercase letters, numerals, and at least one special character. Passwords must be changed every 90 days and must not be recycled from the previous five passwords. Employees must never share their password with any colleague, supervisor, family member, or third party under any circumstance. The Company enforces Multi-Factor Authentication (MFA) for all e-mail access from outside the Company's secured office network.
3.3 Account Deactivation and Exit Procedures
Upon an employee's separation from the Company — whether through resignation, retirement, termination, contract expiry, or any other reason — the IT Department shall deactivate the employee's official e-mail account within 24 hours of the last working day, as intimated by the HR Department. Prior to deactivation, all business-critical e-mails in the departing employee's account shall be archived and transferred to the relevant Department Head or Reporting Manager. The departing employee must not access, copy, forward, or delete any Company e-mails after receipt of a separation notice.
4. Acceptable Use of Company E-mail
The Company's official e-mail system is provided exclusively for legitimate business purposes and must be used responsibly and professionally at all times. All use of e-mail must be consistent with DJTMPL's policies and procedures of ethical conduct, safety, compliance with applicable laws, and sound business practices. Acceptable uses of the Company e-mail system include the following.
Internal communications between employees at the Head Office and Micro Centres related to loan processing, credit appraisal, disbursement, repayment, collections, and day-to-day operational coordination are appropriate uses of the e-mail system. External communications with borrowers, guarantors, or co-applicants for the purposes of loan status updates, repayment reminders, disbursement confirmations, NOC issuance, and grievance responses are permitted. All customer-facing e-mails must be courteous, factual, and free from coercive, misleading, or threatening language.
Submission of statutory reports, regulatory filings, audit confirmations, and compliance certificates via e-mail is permitted and must follow the formats prescribed by the respective regulatory authority. Internal dissemination of approved circulars, HR notifications, policy updates, training material, and official announcements through the Company e-mail system is acceptable and encouraged.
Micro Centre staff may use official e-mail to communicate loan-related information to the Head Office, such as daily collection reports, field visit summaries, customer grievance escalations, and centre performance data.
Non-work-related e-mail shall be saved in a separate folder from work related e mail. Sending chain letters or joke e-mails from a DJTMPL e-mail account is prohibited.
IT Department may monitor messages of any user without prior notice to him/her but on the direction/approval of DJTMPL Management.
5. Prohibited Use and Unacceptable Behaviour
The following categories of e-mail use are strictly prohibited and constitute unacceptable conduct. Violations may result in disciplinary action up to and including termination of employment, and in serious cases, civil or criminal proceedings.
5.1 Misuse of Customer and Confidential Data
Employees are strictly prohibited from sharing, forwarding, or transmitting any customer Non-Public Personal Information (NPPI) — including Aadhaar numbers, PAN details, bank account numbers, loan account numbers, credit scores, or repayment histories — to personal e-mail accounts, unauthorized third parties, or external platforms. All DJTMPL data contained within an e-mail or attachment must be handled in accordance with the Company's Data Protection Standard. Sharing of confidential business information such as internal credit policies, interest rate structures, board resolutions, RBI inspection reports, or risk assessment frameworks via e-mail without proper authorization is strictly forbidden. Employees found to have transmitted such information for personal gain or to a competitor shall be referred to law enforcement authorities.
5.2 Personal and Non-Business Use
DJTMPL e-mail accounts must be used primarily for Company business. Use of the official e-mail account for personal commercial activities, freelance work, personal subscriptions (including but not limited to horoscopes, entertainment newsletters, personal news feeds, or shopping offers), chain letters, joke forwards, political campaigns, religious promotions, or social activism is prohibited. Non-work-related e-mails, if unavoidably received, shall be stored in a separate folder and must not be replied to or forwarded using the official account. Employees must not subscribe to any mailing list, newsletter, or forum using their official DJTMPL e-mail ID unless explicitly required for job-related purposes and approved by their Department Head.
5.3 Use of Third-Party E-mail Systems
Employees are prohibited from using third-party e-mail systems or cloud storage services — including Google Gmail, Yahoo Mail, MSN Hotmail, Rediffmail, or any other personal or free e-mail platform — to conduct Company business, store Company records, or create binding transactions on behalf of DJTMPL. All official communications and transactions must be conducted through the Company's own secure e-mail infrastructure. Automatic forwarding of Company e-mails to any third-party or personal e-mail system is strictly prohibited. Individually forwarded messages must not contain DJTMPL confidential or above-classified information.
5.4 Offensive, Discriminatory, and Illegal Content
The DJTMPL e-mail system must not be used to create, store, forward, or distribute any content that is offensive, discriminatory, pornographic, obscene, indecent, or illegal. This includes messages containing offensive comments about race, gender, caste, religion, nationality, disability, age, sexual orientation, or political beliefs, as well as any content that constitutes personal harassment or constitutes a hostile work environment. Employees who receive such content from any colleague must report the matter to their supervisor or the HR Department immediately. Broadcasting unsolicited personal views on social, political, or religious matters using the Company's e-mail system is equally prohibited. Distributing, disseminating, or storing materials that might be considered abusive, sexist, or racially offensive — whether text, image, audio, or video — is a serious disciplinary offence.
5.5 Impersonation and Fraud
Impersonating another employee, a Company officer, or any external authority via e-mail is a grave misconduct. Sending e-mails under a false name or with a misleading identity, creating unauthorized e-mail aliases, or spoofing the Company's e-mail domain constitutes fraud. Employees must never send communications on behalf of a senior official without prior written authorization. Any attempt to manipulate, alter, or forge e-mail headers, timestamps, or content for any purpose is strictly prohibited.
5.6 Cyber Security Threats
Introducing any form of computer virus, malware, ransomware, spyware, or other malicious code into the Company's e-mail system or corporate network is strictly prohibited. Employees must not open attachments or click links in suspicious e-mails from unknown senders. Undertaking deliberate activities that waste staff effort, consume networked resources, or disrupt the performance of the e-mail system is also prohibited. Employees must not attempt to bypass or disable any e-mail security controls, spam filters, or content monitoring tools deployed by the IT Department.
6. Data Privacy, Confidentiality, and Record Retention
As an RBI-registered NBFC, DJTMPL operates under a comprehensive regulatory framework that imposes specific obligations on the handling of customer data, financial records, and electronic communications. This section sets out the e-mail-specific requirements arising from these obligations.
6.1 Encryption and Secure Transmission
All e-mails containing customer data, loan account information, or any classified business information must be transmitted over encrypted connections. Employees must not send unencrypted spreadsheets, databases, or document files containing customer Aadhaar, PAN, bank account numbers, or credit details as e-mail attachments. Where operational necessity requires sharing such data within the organization, it must be done through the Company's approved secure document-sharing platform with the prior approval of the Department Head. Loan sanction letters, repayment schedules, and NOC documents sent to borrowers must be transmitted as password-protected or encrypted PDF files from the designated customer-communication e-mail ID only.
6.2 Data Confidentiality
Where a Lending Service Provider (LSP) or Digital Lending Application (DLA) is involved, this must be disclosed in the communication. No recovery agents, direct-selling agents (DSAs), or field staff are permitted to communicate with borrowers on loan recovery matters using personal e-mail or unauthorized channels. All such communications must flow from official Company accounts. E-mail communications to borrowers must never contain threatening, abusive, or misleading language, and must be in a language understandable to the borrower where practicable.
6.3 Record Retention and Archival
E-mail shall be retained only if it qualifies as a Company business record — that is, if there exists a legitimate and ongoing business reason to preserve the information it contains. E-mail that qualifies as a business record shall be retained in accordance with the DJTMPL Record Retention Schedule. The IT Department shall configure automatic server-level e-mail archiving to ensure completeness and tamper-proof storage. Employees must not manually delete or move e-mails related to active loan accounts, pending litigation, regulatory correspondence, or any matter under investigation. A legal hold shall be placed on relevant accounts when required, and employees must cooperate fully with legal and compliance processes.
7. Guidelines for Micro Centre Staff
Given DJTMPL's distributed operations across multiple states through its network of Micro Centers, specific responsibilities apply to field-level employees. All official communication from Micro Centers — including loan application forwarding, disbursement confirmations, collection reports, customer complaint escalations, and center performance data — must be conducted exclusively through official Company e-mail accounts. Use of personal WhatsApp, personal e-mail accounts, or any unauthorized messaging platform for official business communication with the Head Office, customers, or any external party is strictly prohibited.
Where Company-issued smartphones or laptops are provided to Micro Centre staff, e-mail access on such devices shall be configured and managed through the Company's Mobile Device Management (MDM) system. Employees must not install unauthorized e-mail clients or configure Company e-mail on personal devices without prior IT Department approval. In areas with limited internet connectivity.
Micro Centre Managers are responsible for ensuring that all staff under their supervision comply with this Policy. Any e-mail policy violation observed at a Micro Center must be reported to the Regional Manager and the HR Department within 48 hours of discovery.
8. Monitoring, Compliance Measurement, and Audit
DJTMPL employees shall have no expectation of privacy in anything they store, send, or receive on the Company's e-mail system. The Company reserves the right to monitor, access, and review e-mail communications transmitted through its official systems for the purposes of security, compliance verification, fraud investigation, regulatory inspection, and performance management. The IT Department may monitor messages of any user without prior notice to the individual, but strictly on the direction and approval of DJTMPL Management. Such monitoring is for legitimate business and regulatory purposes only and is conducted in compliance with applicable Indian law.
The IT team, in coordination with the Compliance Department, will verify adherence to this Policy through various methods including, but not limited to, periodic system audits, automated content monitoring tools (software and/or hardware), business tool reports, internal audits, external audits, and feedback to the Policy Owner. Quarterly e-mail audits shall be conducted to detect anomalies such as large-volume data transfers, e-mails forwarded to personal accounts containing business attachments, or communication with unauthorized external domains. All findings shall be reported to the Chief Compliance Officer and, where material, escalated to the Managing Director.
9. Security Incidents and Breach Reporting
Any suspected e-mail security incident must be reported immediately to the IT Helpdesk and the Compliance Officer. Reportable incidents include phishing attacks, suspicious links or attachments, e-mail spoofing or impersonation, unauthorized account access, accidental transmission of customer data to incorrect recipients, and any communication that appears to be a social engineering attempt. Employees who inadvertently open a suspicious attachment or click a malicious link must immediately disconnect from the network and notify the IT Helpdesk without delay. The IT Department shall isolate the affected device and initiate the Company's Incident Response Plan in accordance with the Cyber Security Framework for NBFCs.
In the event of a data breach involving customer information transmitted via e-mail, the Company is required to notify the RBI within the timelines mandated by the RBI Cyber Security Framework and to communicate with affected customers as prescribed under the DPDP Act 2023. All regulatory notifications and customer communications arising from a breach shall be managed exclusively by the Compliance Department in consultation with the Legal team.
10. Training, Awareness, and Employee Acknowledgement
All new employees — at both the Head Office and Micro Centres — shall complete mandatory e-mail usage and cyber security awareness training as part of their induction program before their official e-mail accounts are activated. Training shall cover acceptable and prohibited e-mail use, data handling and privacy obligations, phishing and social engineering awareness, e-mail etiquette standards, RBI regulatory requirements, grievance redressal protocols, and incident reporting procedures. Existing employees shall attend annual refresher training sessions conducted by the IT and Compliance Departments.
11. Non-Compliance and Disciplinary Action
Where it is believed or found that an employee has failed to comply with this Policy, the Company shall take disciplinary action proportionate to the nature, intent, frequency, and impact of the breach. Disciplinary action may range from a formal written warning, mandatory retraining, and temporary suspension of e-mail access for minor infractions, to suspension from employment, termination of service, and referral to law enforcement authorities for serious violations such as unauthorized disclosure of customer data, impersonation, fraud, or deliberate introduction of malware.
The Company shall not be liable for any regulatory penalties, fines, or reputational harm arising from an employee's willful or negligent non-compliance with this Policy, and may seek financial indemnification from the responsible employee to the extent permissible by Indian law. Disciplinary decisions shall consider the employee's overall service record, the seriousness of the breach, and whether the offence was repeated.
12. Policy Review, Ownership, and Amendments
This Policy is jointly owned by the IT Department and the Compliance Department of DJTMPL. It shall be reviewed annually from the date of issue, or earlier if required by changes in RBI guidelines, amendments to applicable Indian laws, material changes in the Company's technology infrastructure, or significant operational developments. Proposed amendments shall be drafted by the Policy Owner, reviewed by the Legal team and the Chief Compliance Officer, and approved by the Board of Directors or the Board-level Risk and Compliance Committee before implementation.
All employees shall be formally notified of any amendments through the Company's official e-mail and intranet. Employees will be required to acknowledge the updated Policy within 15 working days of notification. The most current version of this Policy shall always be available on the Company's internal document management system. For any queries, clarifications, or concerns about this Policy, employees may write to the IT Helpdesk or to the Compliance Department Concerns about potential misuse or violations may also be raised confidentially through the Company's Whistleblower Mechanism.