CYBERVED AI PRIVATE LIMITED
PPI ISSUER / BANK PARTNER
MANAGEMENT POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated partners |
| Regulatory Model | The Company does not operate as an independent PPI issuer unless separately authorised; regulated PPI activities shall be undertaken through applicable authorised / regulated partners within approved contractual scope. |
| Policy Owner | Partner Management / Compliance / Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Partner Governance Document |
1. PURPOSE
This Policy establishes the framework for selecting, onboarding, contracting, monitoring and managing PPI issuers, banks and other regulated or critical partners used by CYBERVED AI PRIVATE LIMITED for its gift-card and voucher business.
2. OBJECTIVES
- Ensure partners are appropriately identified and assessed before onboarding.
- Confirm relevant authorisation or regulatory status where applicable.
- Define clear contractual responsibilities and service boundaries.
- Protect customers, funds, data and transaction integrity.
- Monitor partner performance, security, fraud and operational risks.
- Maintain documented escalation, review and exit arrangements.
3. SCOPE
This Policy applies to PPI issuers, banks, payment processors, merchants, gift-card issuers, technology providers and other partners whose services are material to the Company's gift-card / voucher operations.
4. PARTNER CLASSIFICATION
- Regulated / PPI partner
- Banking partner
- Payment / transaction partner
- Gift-card / voucher issuer or merchant partner
- Technology / API partner
- Other critical service provider
5. DUE DILIGENCE
Before onboarding a material partner, the Company shall conduct risk-based due diligence appropriate to the relationship, including legal identity, business profile, regulatory status where relevant, ownership/control information where appropriate, operational capability, security, fraud controls and financial/settlement arrangements.
6. REGULATORY STATUS
Where a partner performs regulated PPI or payment activities, the Company shall verify the partner's applicable authorisation or regulatory status through appropriate official or contractual evidence and maintain records of the assessment.
7. COMMERCIAL & CONTRACTUAL REVIEW
- Defined services and scope
- Roles and responsibilities
- Settlement and reconciliation terms
- Customer support responsibilities
- Data protection and confidentiality
- Information-security requirements
- Incident notification
- Audit/assurance rights where appropriate
- Business continuity
- Termination and exit arrangements
8. RESPONSIBILITY ALLOCATION
Contracts shall clearly distinguish the responsibilities of CYBERVED AI PRIVATE LIMITED and the regulated/partner entity, including issuance, redemption, KYC where applicable, transaction processing, customer support, fraud monitoring, settlement and regulatory reporting.
9. PARTNER ONBOARDING
- Complete due diligence.
- Obtain required internal approvals.
- Complete contractual documentation.
- Complete technical/security assessment where applicable.
- Configure systems and access securely.
- Test critical transaction and reconciliation flows.
- Approve production activation.
10. PPI PARTNER CONTROLS
Where a PPI issuer provides the regulated product or wallet infrastructure, CYBERVED AI PRIVATE LIMITED shall operate only within the approved service model and shall not undertake functions reserved for the authorised issuer unless legally permitted and appropriately authorised.
11. BANK PARTNER CONTROLS
Bank relationships shall define payment, settlement, reconciliation, account/service responsibilities, operational contacts, security requirements, dispute handling and escalation procedures as applicable.
12. API / TECHNICAL INTEGRATION
- Use approved authentication and authorisation.
- Protect API credentials and certificates.
- Use secure communication.
- Maintain transaction and error logs.
- Apply appropriate timeout, retry and reconciliation controls.
- Review material API changes before production.
13. SETTLEMENT & RECONCILIATION
Partner settlement statements and transaction records shall be reconciled against internal records at appropriate intervals. Unmatched items, failed transactions, refunds and reversals shall be investigated and closed with evidence.
14. CUSTOMER PROTECTION
Partner arrangements shall support appropriate customer complaint handling, refund/cancellation processes, unauthorised transaction handling and protection of customer information.
15. FRAUD & AML COORDINATION
The Company shall coordinate with relevant partners for fraud monitoring, suspicious transaction escalation, account/voucher restrictions and other applicable financial-crime controls within the agreed responsibilities.
16. INFORMATION SECURITY & DATA PROTECTION
Partners handling Company or customer information shall be subject to appropriate confidentiality, information-security and data-protection requirements based on risk and contractual obligations.
17. SERVICE LEVELS & PERFORMANCE
Material partners may be monitored against availability, transaction success, settlement, incident response, customer support, reconciliation and other agreed service measures.
18. INCIDENT NOTIFICATION
Material security, fraud, data, transaction or service incidents affecting the Company's customers or operations shall be escalated promptly through agreed partner contacts.
19. PERIODIC PARTNER REVIEW
- Regulatory/authorisation status where applicable
- Service performance
- Security and incident history
- Fraud trends
- Settlement/reconciliation issues
- Complaints
- Material contractual or business changes
- Continuity and concentration risks
20. MATERIAL CHANGE MANAGEMENT
Changes in ownership, regulatory status, product scope, API architecture, settlement process, data flows or material service arrangements shall be assessed before implementation where appropriate.
21. SUBCONTRACTORS
Where a partner uses material subcontractors or sub-processors, appropriate disclosure, risk assessment, contractual controls and oversight shall be considered based on the risk of the service.
22. AUDIT & ASSURANCE
The Company may use contractual reports, certifications, assessments, audits, security reviews, service reports or other reasonable evidence to assess partner control effectiveness.
23. SUSPENSION / RESTRICTION
The Company may restrict or suspend a partner integration or product where there is a material security, fraud, regulatory, service, settlement or customer-protection concern, subject to contractual requirements and management approval.
24. EXIT & TERMINATION
Material partner relationships shall have appropriate exit arrangements addressing data return/deletion, customer impact, outstanding transactions, settlement, credential revocation, service transition and record retention.
25. RECORD KEEPING
- Due diligence documents
- Authorisation/regulatory evidence
- Contracts and amendments
- Partner assessments
- Service reports
- Incident communications
- Settlement/reconciliation records
- Review and approval records
- Termination/exit records
26. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Partner Management | Partner onboarding, relationship management and review | Management |
| Compliance | Regulatory assessment and compliance oversight | Compliance Head |
| Legal | Contractual and legal review | Legal / Management |
| Technology / IT | Technical integration and API controls | Technology Head |
| Information Security | Security due diligence and incident oversight | Security Head |
| Finance | Settlement and reconciliation | Finance Head |
| Operations | Service/customer operations and issue escalation | Operations Head |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in partner arrangements, products, technology, regulatory requirements or risk profile.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Partner Management / Compliance | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |