e-suvidha

CYBERVED AI PRIVATE LIMITED

GIFT CARD ISSUANCE & PRODUCT
GOVERNANCE POLICY

POLICY NO. 06VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Regulatory ModelGift-card/PPI product issuance shall be performed only within the approved role of CYBERVED AI PRIVATE LIMITED and applicable authorised/regulated partner arrangements.
Policy OwnerOperations / Product / Compliance / Partner Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Product Governance Document

1. PURPOSE

This Policy establishes governance and operational controls for onboarding, approving, configuring, issuing, activating, delivering, monitoring and retiring gift-card and voucher products handled by CYBERVED AI PRIVATE LIMITED.

2. OBJECTIVES

  • Ensure every gift-card/voucher product has documented ownership and approval.
  • Prevent unauthorised or incorrectly configured products.
  • Ensure product terms and customer disclosures are accurate.
  • Maintain controlled issuance, activation and lifecycle processes.
  • Manage product, fraud, operational, customer and partner risks.
  • Maintain evidence of approvals, configuration and changes.

3. SCOPE

This Policy applies to all gift cards, gift vouchers, digital vouchers, virtual products, related product configurations, issuer/partner integrations and supporting systems operated by or for the Company.

4. PRODUCT GOVERNANCE PRINCIPLES

  • Regulatory alignment
  • Customer transparency
  • Partner approval
  • Security by design
  • Controlled configuration
  • Traceability
  • Risk-based controls
  • Periodic review

5. PRODUCT ONBOARDING

  1. Identify the product and responsible owner.
  2. Confirm issuer/partner and contractual basis.
  3. Assess regulatory and compliance requirements.
  4. Document denomination, validity and redemption rules.
  5. Complete technology and operational assessment.
  6. Obtain required approvals before production launch.

6. PRODUCT MASTER DATA

  • Product name and unique product ID
  • Issuer / partner
  • Denomination(s)
  • Currency
  • Validity / expiry
  • Activation requirements
  • Redemption channel
  • Restrictions
  • Refund/cancellation conditions
  • Customer support process

7. PARTNER / ISSUER APPROVAL

Products provided by a PPI issuer, bank, merchant or other partner shall be activated only after appropriate partner confirmation and contractual/operational approval.

8. REGULATORY ASSESSMENT

Before launch, the responsible function shall assess whether the product or activity involves any regulated function and confirm that the operating model uses the applicable authorised/regulated entity where required.

9. CUSTOMER TERMS

Customer-facing terms shall accurately state applicable purchase, activation, redemption, expiry, restrictions, refund/cancellation and support conditions.

10. PRICING & DENOMINATION

Denominations, pricing, fees and applicable restrictions shall be approved and configured accurately. Changes shall follow the change-management process.

11. ISSUANCE CONTROLS

  • Validate authorised product status.
  • Validate order and applicable customer information.
  • Generate/obtain voucher credentials through approved systems.
  • Record issuance reference and status.
  • Apply applicable fraud/risk controls.
  • Deliver through approved channels.

12. ACTIVATION

Where activation is required, activation shall be performed through an authorised process and the activation event shall be recorded.

13. INVENTORY / VALUE CONTROL

Where applicable, product inventory, voucher credentials and outstanding value shall be controlled to prevent duplicate issuance, unauthorised creation or value mismatch.

14. REDEMPTION GOVERNANCE

Redemption shall occur through the authorised issuer, merchant or partner mechanism and shall follow product-specific rules and balance/validity controls.

15. PRODUCT CHANGE MANAGEMENT

  1. Document proposed change.
  2. Assess customer, regulatory, fraud, technology and settlement impact.
  3. Obtain required approval.
  4. Test the change where appropriate.
  5. Deploy through controlled procedures.
  6. Maintain change evidence.

16. SUSPENSION / WITHDRAWAL

A product may be suspended or withdrawn due to fraud, regulatory concerns, partner termination, security incidents, technical defects, commercial closure or other material risk.

17. FRAUD CONTROLS

Products shall be assessed for fraud risks including code compromise, duplicate redemption, automated abuse, refund abuse and unusual purchase/redemption patterns.

18. CUSTOMER PROTECTION

Product design and operations shall consider customer transparency, support, dispute handling, refunds/cancellations and appropriate treatment of failed transactions.

19. SETTLEMENT & RECONCILIATION

Issued, redeemed, refunded, cancelled and outstanding product values shall be reconciled with relevant partner records as appropriate.

20. TECHNOLOGY & API CONTROLS

Product integrations shall use approved APIs, secure authentication, access controls, logging, error handling, monitoring and controlled deployment.

21. DATA PROTECTION

Customer and transaction information used in product operations shall be handled in accordance with the Data Protection, Privacy & Retention Policy.

22. INCIDENT MANAGEMENT

Product-related security incidents, material fraud, widespread transaction errors or partner failures shall be escalated under the applicable incident-response policies.

23. PRODUCT REVIEW

Products shall be periodically reviewed for performance, complaints, fraud, redemption issues, reconciliation exceptions, partner performance and regulatory changes.

24. RECORD KEEPING

  • Product approval records
  • Product master data
  • Partner/issuer approvals
  • Terms and customer disclosures
  • Configuration/change records
  • Issuance and activation records
  • Redemption/refund records
  • Reconciliation records
  • Product review and withdrawal records

25. THIRD-PARTY / VENDOR CONTROLS

Material vendors supporting product issuance, delivery, redemption or technology shall be managed under the Third-Party / Vendor Risk Management Policy.

26. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Regulatory, contractual or customer- protection requirements shall not be bypassed.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Product / OperationsProduct onboarding, configuration and lifecycle managementOperations Head
ComplianceRegulatory and policy reviewCompliance Head
Partner ManagementIssuer/partner approvals and coordinationManagement
Technology / ITProduct systems, APIs and deployment controlsTechnology Head
Risk / FraudProduct fraud-risk assessment and monitoringRisk/Fraud Head
FinancePricing/settlement/reconciliation controlsFinance Head
Customer SupportCustomer communication and product issue handlingOperations / Compliance

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in product design, issuer/partner arrangement, technology, customer journey or applicable requirements.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByProduct / Operations / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED PRODUCT GOVERNANCE DOCUMENT

This document is confidential and intended for authorised use only.