e-suvidha

CYBERVED AI PRIVATE LIMITED

PPI & GIFT CARD
REGULATORY COMPLIANCE POLICY

POLICY NO. 01VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Regulatory ModelThe Company does not represent itself as an independent PPI issuer unless separately authorised. Where PPI-regulated activities are involved, the Company shall operate through applicable authorised / regulated partners and within the scope of its agreements and applicable law.
Policy OwnerCompliance / Management / Partner Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the regulatory and governance framework for CYBERVED AI PRIVATE LIMITED in relation to gift cards, gift vouchers and related digital products offered or distributed through applicable authorised / regulated partners. It is designed to ensure that the Company's activities remain within the permitted scope of its business, contractual arrangements and applicable legal and regulatory requirements.

2. OBJECTIVES

  • Maintain a documented regulatory compliance framework for gift-card and voucher activities.
  • Clearly distinguish the Company's role from that of an authorised PPI issuer or regulated entity.
  • Ensure regulated PPI functions are performed only by the applicable authorised partner where required.
  • Control product onboarding, issuance, activation, redemption, refund and operational processes.
  • Maintain appropriate customer-protection, fraud, information-security and record-keeping controls.
  • Provide clear ownership, monitoring, escalation and review mechanisms.

3. SCOPE

This Policy applies to directors, management, employees, contractors, technology teams, operations, customer support, compliance personnel, vendors and partners involved in the Company's gift-card/voucher business, including activities performed through e-suvidha.com or connected systems.

4. REGULATORY ROLE & PARTNER MODEL

CYBERVED AI PRIVATE LIMITED shall not describe, market or conduct itself as a PPI issuer unless it holds the relevant authorisation. Where a product or service requires a regulated PPI issuer, bank or other authorised entity, the Company shall work through the applicable authorised partner under a written agreement and within the approved scope.

5. PARTNER DUE DILIGENCE

  • Verify the partner's legal identity and relevant authorisation/licensing status where applicable.
  • Review agreement, service scope, responsibilities and escalation contacts.
  • Assess operational, security, fraud, data-protection and continuity requirements.
  • Maintain evidence of due diligence and periodic review.

6. PRODUCT GOVERNANCE

Each gift-card or voucher product shall be subject to documented onboarding and approval covering product name, denomination, validity, redemption mechanism, issuer/partner, customer terms, restrictions, operational process and applicable compliance requirements.

7. CUSTOMER TERMS

Customer-facing terms shall clearly communicate applicable purchase, activation, redemption, expiry, refund/cancellation, restrictions and support conditions. Terms shall not incorrectly represent CYBERVED AI PRIVATE LIMITED as the regulated issuer where the issuer is a partner.

8. PPI / REGULATED ACTIVITY CONTROLS

Where an activity falls within the scope of regulated PPI or other regulated payment activity, the Company shall follow the applicable partner's approved process and contractual allocation of responsibilities. The Company shall not independently perform an activity reserved for an authorised entity.

9. KYC & CUSTOMER DUE DILIGENCE

Where KYC, customer identification or due diligence is required by applicable law, product structure or partner requirements, such controls shall be implemented through the responsible party and documented in accordance with the KYC & Customer Due Diligence Policy.

10. AML / CFT

The Company shall maintain risk-based controls appropriate to its role for prevention and detection of money laundering, terrorist financing, fraud and misuse. Where the regulated partner is responsible for statutory AML/CFT functions, CYBERVED AI PRIVATE LIMITED shall cooperate with the partner within the agreed scope.

11. FRAUD & TRANSACTION MONITORING

  • Monitor relevant transaction and voucher activity for unusual patterns.
  • Apply appropriate velocity, duplicate-use and abuse controls.
  • Escalate suspected fraud or compromised voucher credentials.
  • Coordinate with the authorised partner where transaction controls are partner-operated.

12. CUSTOMER PROTECTION

The Company shall maintain appropriate controls for customer support, complaints, unauthorised transactions, refunds, cancellations, disputes and protection of customer information.

13. INFORMATION SECURITY

Systems, APIs, credentials, voucher data and customer information shall be protected through access control, authentication, secure integration, logging, monitoring, vulnerability management and incident response controls.

14. DATA PROTECTION

Personal information shall be collected, used, shared, retained and disposed of only for legitimate and documented purposes and in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.

15. GIFT CARD / VOUCHER LIFECYCLE

  1. Product approval and configuration.
  2. Order and customer validation.
  3. Issuance through approved system/partner.
  4. Activation where applicable.
  5. Secure customer delivery.
  6. Redemption and balance/status management.
  7. Expiry, blocking, cancellation or reissue as applicable.
  8. Settlement and reconciliation.
  9. Record retention and closure.

16. PAYMENT, SETTLEMENT & RECONCILIATION

Financial and transaction records shall be reconciled with applicable partner records. Differences, failed transactions, refunds, reversals and outstanding amounts shall be documented and investigated.

17. CYBER & INCIDENT RESPONSE

Material cyber incidents, fraud, data compromise, API abuse or voucher-code compromise shall be escalated under the Cyber Incident Response & Cyber Fraud Policy, with appropriate partner coordination and evidence preservation.

18. THIRD-PARTY / VENDOR GOVERNANCE

Technology providers, vendors, merchants, PPI issuers, banks and other material partners shall be managed under the Third-Party / Vendor Risk Management Policy.

19. RECORD KEEPING

  • Partner due-diligence records
  • Product approvals
  • Customer and transaction records where applicable
  • Issuance and redemption records
  • Refund/cancellation records
  • Settlement and reconciliation records
  • Complaints and dispute records
  • Incident and fraud records
  • Regulatory and contractual communications

20. REGULATORY REPORTING

The Company shall identify and fulfil regulatory or contractual reporting obligations applicable to its role. Where a report is the responsibility of the regulated PPI issuer or another authorised partner, the Company shall provide required information and cooperation within agreed timelines.

21. MARKETING & REPRESENTATION

Marketing material, website content, product descriptions and customer communications shall accurately describe the Company's role and the role of the applicable issuer/partner. The Company shall not make misleading claims regarding licensing, regulatory status or product issuance.

22. BUSINESS CONTINUITY

Critical gift-card/voucher operations, partner connectivity, transaction systems and customer-support processes shall be covered by appropriate business continuity and disaster recovery arrangements.

23. AUDIT & MONITORING

Compliance and management may review partner arrangements, product files, customer complaints, transaction exceptions, fraud trends, security controls, reconciliations and regulatory records to assess compliance.

24. NON-COMPLIANCE & ESCALATION

Any suspected regulatory breach, unauthorised activity, material partner failure, misleading representation or significant control failure shall be escalated promptly to Compliance and Management and, where applicable, to the relevant authorised partner.

25. POLICY EXCEPTIONS

Exceptions must be documented, risk-assessed and approved by authorised management. No internal exception may be used to bypass applicable law, regulatory requirements or binding partner obligations.

26. RESPONSIBILITY MATRIX

FunctionKey ResponsibilityEscalation
ManagementOverall governance, approvals and material risk decisionsDirector / Authorised Management
ComplianceRegulatory mapping, policy oversight and escalationCompliance Head
Partner ManagementPPI/bank/regulated partner due diligence and coordinationManagement
OperationsGift-card/voucher operational controlsOperations Head
Technology / ITSystems, APIs, access and security controlsTechnology Head
FinanceSettlement, reconciliation and financial recordsFinance Head
Customer SupportCustomer complaints, support and approved disclosuresOperations / Compliance

27. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in products, partner arrangements, technology, business model, regulatory requirements or significant incidents.

28. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations / Partner Management
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

This document is confidential and intended for authorised use only.