CYBERVED AI PRIVATE LIMITED
GIFT CARD ISSUANCE & PRODUCT
GOVERNANCE POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Regulatory Model | Gift-card/PPI product issuance shall be performed only within the approved role of CYBERVED AI PRIVATE LIMITED and applicable authorised/regulated partner arrangements. |
| Policy Owner | Operations / Product / Compliance / Partner Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Product Governance Document |
1. PURPOSE
This Policy establishes governance and operational controls for onboarding, approving, configuring, issuing, activating, delivering, monitoring and retiring gift-card and voucher products handled by CYBERVED AI PRIVATE LIMITED.
2. OBJECTIVES
- Ensure every gift-card/voucher product has documented ownership and approval.
- Prevent unauthorised or incorrectly configured products.
- Ensure product terms and customer disclosures are accurate.
- Maintain controlled issuance, activation and lifecycle processes.
- Manage product, fraud, operational, customer and partner risks.
- Maintain evidence of approvals, configuration and changes.
3. SCOPE
This Policy applies to all gift cards, gift vouchers, digital vouchers, virtual products, related product configurations, issuer/partner integrations and supporting systems operated by or for the Company.
4. PRODUCT GOVERNANCE PRINCIPLES
- Regulatory alignment
- Customer transparency
- Partner approval
- Security by design
- Controlled configuration
- Traceability
- Risk-based controls
- Periodic review
5. PRODUCT ONBOARDING
- Identify the product and responsible owner.
- Confirm issuer/partner and contractual basis.
- Assess regulatory and compliance requirements.
- Document denomination, validity and redemption rules.
- Complete technology and operational assessment.
- Obtain required approvals before production launch.
6. PRODUCT MASTER DATA
- Product name and unique product ID
- Issuer / partner
- Denomination(s)
- Currency
- Validity / expiry
- Activation requirements
- Redemption channel
- Restrictions
- Refund/cancellation conditions
- Customer support process
7. PARTNER / ISSUER APPROVAL
Products provided by a PPI issuer, bank, merchant or other partner shall be activated only after appropriate partner confirmation and contractual/operational approval.
8. REGULATORY ASSESSMENT
Before launch, the responsible function shall assess whether the product or activity involves any regulated function and confirm that the operating model uses the applicable authorised/regulated entity where required.
9. CUSTOMER TERMS
Customer-facing terms shall accurately state applicable purchase, activation, redemption, expiry, restrictions, refund/cancellation and support conditions.
10. PRICING & DENOMINATION
Denominations, pricing, fees and applicable restrictions shall be approved and configured accurately. Changes shall follow the change-management process.
11. ISSUANCE CONTROLS
- Validate authorised product status.
- Validate order and applicable customer information.
- Generate/obtain voucher credentials through approved systems.
- Record issuance reference and status.
- Apply applicable fraud/risk controls.
- Deliver through approved channels.
12. ACTIVATION
Where activation is required, activation shall be performed through an authorised process and the activation event shall be recorded.
13. INVENTORY / VALUE CONTROL
Where applicable, product inventory, voucher credentials and outstanding value shall be controlled to prevent duplicate issuance, unauthorised creation or value mismatch.
14. REDEMPTION GOVERNANCE
Redemption shall occur through the authorised issuer, merchant or partner mechanism and shall follow product-specific rules and balance/validity controls.
15. PRODUCT CHANGE MANAGEMENT
- Document proposed change.
- Assess customer, regulatory, fraud, technology and settlement impact.
- Obtain required approval.
- Test the change where appropriate.
- Deploy through controlled procedures.
- Maintain change evidence.
16. SUSPENSION / WITHDRAWAL
A product may be suspended or withdrawn due to fraud, regulatory concerns, partner termination, security incidents, technical defects, commercial closure or other material risk.
17. FRAUD CONTROLS
Products shall be assessed for fraud risks including code compromise, duplicate redemption, automated abuse, refund abuse and unusual purchase/redemption patterns.
18. CUSTOMER PROTECTION
Product design and operations shall consider customer transparency, support, dispute handling, refunds/cancellations and appropriate treatment of failed transactions.
19. SETTLEMENT & RECONCILIATION
Issued, redeemed, refunded, cancelled and outstanding product values shall be reconciled with relevant partner records as appropriate.
20. TECHNOLOGY & API CONTROLS
Product integrations shall use approved APIs, secure authentication, access controls, logging, error handling, monitoring and controlled deployment.
21. DATA PROTECTION
Customer and transaction information used in product operations shall be handled in accordance with the Data Protection, Privacy & Retention Policy.
22. INCIDENT MANAGEMENT
Product-related security incidents, material fraud, widespread transaction errors or partner failures shall be escalated under the applicable incident-response policies.
23. PRODUCT REVIEW
Products shall be periodically reviewed for performance, complaints, fraud, redemption issues, reconciliation exceptions, partner performance and regulatory changes.
24. RECORD KEEPING
- Product approval records
- Product master data
- Partner/issuer approvals
- Terms and customer disclosures
- Configuration/change records
- Issuance and activation records
- Redemption/refund records
- Reconciliation records
- Product review and withdrawal records
25. THIRD-PARTY / VENDOR CONTROLS
Material vendors supporting product issuance, delivery, redemption or technology shall be managed under the Third-Party / Vendor Risk Management Policy.
26. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Regulatory, contractual or customer- protection requirements shall not be bypassed.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Product / Operations | Product onboarding, configuration and lifecycle management | Operations Head |
| Compliance | Regulatory and policy review | Compliance Head |
| Partner Management | Issuer/partner approvals and coordination | Management |
| Technology / IT | Product systems, APIs and deployment controls | Technology Head |
| Risk / Fraud | Product fraud-risk assessment and monitoring | Risk/Fraud Head |
| Finance | Pricing/settlement/reconciliation controls | Finance Head |
| Customer Support | Customer communication and product issue handling | Operations / Compliance |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in product design, issuer/partner arrangement, technology, customer journey or applicable requirements.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Product / Operations / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |