PPI & Gift Card Regulatory Compliance Policy
Defines regulatory governance for the partner-led PPI / gift-card model, product responsibilities, compliance mapping and partner obligations.
PRIVATE LIMITED
Gift Card / Gift Voucher & PPI Partner Business
Consolidated governance, compliance, risk, security, operational and customer-protection framework governing CYBERVED AI PRIVATE LIMITED's gift-card, gift-voucher and related digital-services business.
18
Policies
01
Framework
2026
Effective Year
Customer protection and fair treatment
Lawful and risk-based operations
KYC / AML / CFT and fraud-risk controls where applicable
Information security and cyber resilience
Data protection and confidentiality
Transparent payment, settlement and reconciliation controls
Third-party and partner oversight
Regulatory cooperation and accurate record keeping
Business continuity and disaster recovery
Documented accountability, approvals and audit trails
CYBERVED AI Framework
Explore the policies forming the CYBERVED AI compliance, governance, security, customer-protection and operational control framework.
Defines regulatory governance for the partner-led PPI / gift-card model, product responsibilities, compliance mapping and partner obligations.
Governs onboarding, due diligence, contractual responsibilities, operational coordination, escalation and monitoring of authorised PPI / bank partners.
Provides customer identification, verification, risk-based due diligence, record and escalation controls where applicable to the Company's role and partner process.
Provides the framework for AML/CFT risk management, monitoring, escalation, sanctions-related controls and cooperation with relevant regulated partners where applicable.
Covers fraud-risk assessment, transaction monitoring, suspicious patterns, rule management, escalation, blocking/review and fraud reporting.
Controls product approval, issuance, activation, lifecycle, limits, reconciliation, partner dependencies, customer protection and product changes.
Sets the customer-facing contractual framework for purchase, use, validity, redemption, restrictions, liability, refunds and other applicable terms.
Governs refund, cancellation, reversal, chargeback, dispute handling, evidence, approvals, settlement impact and customer communication.
Defines complaint intake, acknowledgement, investigation, escalation, resolution, records, turnaround management and management reporting.
Provides controls for suspected unauthorised transactions, customer reporting, verification, investigation, partner coordination, refunds/reversals where applicable and closure.
Controls payment processing, settlement, daily/periodic reconciliation, unmatched transactions, refunds, fees, holds, adjustments and financial controls.
Establishes security governance covering systems, data, access, applications, APIs, endpoints, monitoring, vulnerabilities and security awareness.
Defines incident detection, classification, containment, investigation, evidence preservation, cyber-fraud response, partner/authority escalation and recovery.
Controls personal/confidential data collection, use, sharing, access, security, retention, disposal, privacy requests and breach handling.
Governs vendor due diligence, risk classification, contracts, security/privacy requirements, monitoring, incidents, continuity and exit.
Controls user access, privileged access, authentication, service accounts, API authentication/authorisation, secrets, logging, rate limits and API testing.
Provides continuity and recovery arrangements for critical processes, technology, partners, backups, cyber incidents, testing and emergency communication.
Governs regulatory/partner reporting, source-data validation, approvals, submission evidence, retention, legal holds, audits and secure disposal.
Company
CYBERVED AI PRIVATE LIMITED
CIN
U62090UP2024PTC201257
Version
Version 1.0
Effective Date
29 September 2026
Registered Office
Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platform
e-suvidha.com
Policy Owner
Board / Management / Compliance
Review Frequency
At least annually and upon material regulatory, business or technology change
Classification
Confidential – Master Compliance Policy
PPI Position
The Company does not itself operate as a PPI issuer under this framework; regulated PPI activities are undertaken through applicable authorised partners, subject to contracts and law.
Approval
Prepared By
Compliance / Operations
Reviewed By
Risk / Information Security / Legal
Approved By
Director / Authorised Signatory