CYBERVED AI PRIVATE LIMITED
PPI & GIFT CARD
REGULATORY COMPLIANCE POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Regulatory Model | The Company does not represent itself as an independent PPI issuer unless separately authorised. Where PPI-regulated activities are involved, the Company shall operate through applicable authorised / regulated partners and within the scope of its agreements and applicable law. |
| Policy Owner | Compliance / Management / Partner Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the regulatory and governance framework for CYBERVED AI PRIVATE LIMITED in relation to gift cards, gift vouchers and related digital products offered or distributed through applicable authorised / regulated partners. It is designed to ensure that the Company's activities remain within the permitted scope of its business, contractual arrangements and applicable legal and regulatory requirements.
2. OBJECTIVES
- Maintain a documented regulatory compliance framework for gift-card and voucher activities.
- Clearly distinguish the Company's role from that of an authorised PPI issuer or regulated entity.
- Ensure regulated PPI functions are performed only by the applicable authorised partner where required.
- Control product onboarding, issuance, activation, redemption, refund and operational processes.
- Maintain appropriate customer-protection, fraud, information-security and record-keeping controls.
- Provide clear ownership, monitoring, escalation and review mechanisms.
3. SCOPE
This Policy applies to directors, management, employees, contractors, technology teams, operations, customer support, compliance personnel, vendors and partners involved in the Company's gift-card/voucher business, including activities performed through e-suvidha.com or connected systems.
4. REGULATORY ROLE & PARTNER MODEL
CYBERVED AI PRIVATE LIMITED shall not describe, market or conduct itself as a PPI issuer unless it holds the relevant authorisation. Where a product or service requires a regulated PPI issuer, bank or other authorised entity, the Company shall work through the applicable authorised partner under a written agreement and within the approved scope.
5. PARTNER DUE DILIGENCE
- Verify the partner's legal identity and relevant authorisation/licensing status where applicable.
- Review agreement, service scope, responsibilities and escalation contacts.
- Assess operational, security, fraud, data-protection and continuity requirements.
- Maintain evidence of due diligence and periodic review.
6. PRODUCT GOVERNANCE
Each gift-card or voucher product shall be subject to documented onboarding and approval covering product name, denomination, validity, redemption mechanism, issuer/partner, customer terms, restrictions, operational process and applicable compliance requirements.
7. CUSTOMER TERMS
Customer-facing terms shall clearly communicate applicable purchase, activation, redemption, expiry, refund/cancellation, restrictions and support conditions. Terms shall not incorrectly represent CYBERVED AI PRIVATE LIMITED as the regulated issuer where the issuer is a partner.
8. PPI / REGULATED ACTIVITY CONTROLS
Where an activity falls within the scope of regulated PPI or other regulated payment activity, the Company shall follow the applicable partner's approved process and contractual allocation of responsibilities. The Company shall not independently perform an activity reserved for an authorised entity.
9. KYC & CUSTOMER DUE DILIGENCE
Where KYC, customer identification or due diligence is required by applicable law, product structure or partner requirements, such controls shall be implemented through the responsible party and documented in accordance with the KYC & Customer Due Diligence Policy.
10. AML / CFT
The Company shall maintain risk-based controls appropriate to its role for prevention and detection of money laundering, terrorist financing, fraud and misuse. Where the regulated partner is responsible for statutory AML/CFT functions, CYBERVED AI PRIVATE LIMITED shall cooperate with the partner within the agreed scope.
11. FRAUD & TRANSACTION MONITORING
- Monitor relevant transaction and voucher activity for unusual patterns.
- Apply appropriate velocity, duplicate-use and abuse controls.
- Escalate suspected fraud or compromised voucher credentials.
- Coordinate with the authorised partner where transaction controls are partner-operated.
12. CUSTOMER PROTECTION
The Company shall maintain appropriate controls for customer support, complaints, unauthorised transactions, refunds, cancellations, disputes and protection of customer information.
13. INFORMATION SECURITY
Systems, APIs, credentials, voucher data and customer information shall be protected through access control, authentication, secure integration, logging, monitoring, vulnerability management and incident response controls.
14. DATA PROTECTION
Personal information shall be collected, used, shared, retained and disposed of only for legitimate and documented purposes and in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.
15. GIFT CARD / VOUCHER LIFECYCLE
- Product approval and configuration.
- Order and customer validation.
- Issuance through approved system/partner.
- Activation where applicable.
- Secure customer delivery.
- Redemption and balance/status management.
- Expiry, blocking, cancellation or reissue as applicable.
- Settlement and reconciliation.
- Record retention and closure.
16. PAYMENT, SETTLEMENT & RECONCILIATION
Financial and transaction records shall be reconciled with applicable partner records. Differences, failed transactions, refunds, reversals and outstanding amounts shall be documented and investigated.
17. CYBER & INCIDENT RESPONSE
Material cyber incidents, fraud, data compromise, API abuse or voucher-code compromise shall be escalated under the Cyber Incident Response & Cyber Fraud Policy, with appropriate partner coordination and evidence preservation.
18. THIRD-PARTY / VENDOR GOVERNANCE
Technology providers, vendors, merchants, PPI issuers, banks and other material partners shall be managed under the Third-Party / Vendor Risk Management Policy.
19. RECORD KEEPING
- Partner due-diligence records
- Product approvals
- Customer and transaction records where applicable
- Issuance and redemption records
- Refund/cancellation records
- Settlement and reconciliation records
- Complaints and dispute records
- Incident and fraud records
- Regulatory and contractual communications
20. REGULATORY REPORTING
The Company shall identify and fulfil regulatory or contractual reporting obligations applicable to its role. Where a report is the responsibility of the regulated PPI issuer or another authorised partner, the Company shall provide required information and cooperation within agreed timelines.
21. MARKETING & REPRESENTATION
Marketing material, website content, product descriptions and customer communications shall accurately describe the Company's role and the role of the applicable issuer/partner. The Company shall not make misleading claims regarding licensing, regulatory status or product issuance.
22. BUSINESS CONTINUITY
Critical gift-card/voucher operations, partner connectivity, transaction systems and customer-support processes shall be covered by appropriate business continuity and disaster recovery arrangements.
23. AUDIT & MONITORING
Compliance and management may review partner arrangements, product files, customer complaints, transaction exceptions, fraud trends, security controls, reconciliations and regulatory records to assess compliance.
24. NON-COMPLIANCE & ESCALATION
Any suspected regulatory breach, unauthorised activity, material partner failure, misleading representation or significant control failure shall be escalated promptly to Compliance and Management and, where applicable, to the relevant authorised partner.
25. POLICY EXCEPTIONS
Exceptions must be documented, risk-assessed and approved by authorised management. No internal exception may be used to bypass applicable law, regulatory requirements or binding partner obligations.
26. RESPONSIBILITY MATRIX
| Function | Key Responsibility | Escalation |
|---|---|---|
| Management | Overall governance, approvals and material risk decisions | Director / Authorised Management |
| Compliance | Regulatory mapping, policy oversight and escalation | Compliance Head |
| Partner Management | PPI/bank/regulated partner due diligence and coordination | Management |
| Operations | Gift-card/voucher operational controls | Operations Head |
| Technology / IT | Systems, APIs, access and security controls | Technology Head |
| Finance | Settlement, reconciliation and financial records | Finance Head |
| Customer Support | Customer complaints, support and approved disclosures | Operations / Compliance |
27. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in products, partner arrangements, technology, business model, regulatory requirements or significant incidents.
28. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations / Partner Management | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |