e-suvidha

CYBERVED AI PRIVATE LIMITED

PPI ISSUER / BANK PARTNER
MANAGEMENT POLICY

POLICY NO. 02VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated partners
Regulatory ModelThe Company does not operate as an independent PPI issuer unless separately authorised; regulated PPI activities shall be undertaken through applicable authorised / regulated partners within approved contractual scope.
Policy OwnerPartner Management / Compliance / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Partner Governance Document

1. PURPOSE

This Policy establishes the framework for selecting, onboarding, contracting, monitoring and managing PPI issuers, banks and other regulated or critical partners used by CYBERVED AI PRIVATE LIMITED for its gift-card and voucher business.

2. OBJECTIVES

  • Ensure partners are appropriately identified and assessed before onboarding.
  • Confirm relevant authorisation or regulatory status where applicable.
  • Define clear contractual responsibilities and service boundaries.
  • Protect customers, funds, data and transaction integrity.
  • Monitor partner performance, security, fraud and operational risks.
  • Maintain documented escalation, review and exit arrangements.

3. SCOPE

This Policy applies to PPI issuers, banks, payment processors, merchants, gift-card issuers, technology providers and other partners whose services are material to the Company's gift-card / voucher operations.

4. PARTNER CLASSIFICATION

  • Regulated / PPI partner
  • Banking partner
  • Payment / transaction partner
  • Gift-card / voucher issuer or merchant partner
  • Technology / API partner
  • Other critical service provider

5. DUE DILIGENCE

Before onboarding a material partner, the Company shall conduct risk-based due diligence appropriate to the relationship, including legal identity, business profile, regulatory status where relevant, ownership/control information where appropriate, operational capability, security, fraud controls and financial/settlement arrangements.

6. REGULATORY STATUS

Where a partner performs regulated PPI or payment activities, the Company shall verify the partner's applicable authorisation or regulatory status through appropriate official or contractual evidence and maintain records of the assessment.

7. COMMERCIAL & CONTRACTUAL REVIEW

  • Defined services and scope
  • Roles and responsibilities
  • Settlement and reconciliation terms
  • Customer support responsibilities
  • Data protection and confidentiality
  • Information-security requirements
  • Incident notification
  • Audit/assurance rights where appropriate
  • Business continuity
  • Termination and exit arrangements

8. RESPONSIBILITY ALLOCATION

Contracts shall clearly distinguish the responsibilities of CYBERVED AI PRIVATE LIMITED and the regulated/partner entity, including issuance, redemption, KYC where applicable, transaction processing, customer support, fraud monitoring, settlement and regulatory reporting.

9. PARTNER ONBOARDING

  1. Complete due diligence.
  2. Obtain required internal approvals.
  3. Complete contractual documentation.
  4. Complete technical/security assessment where applicable.
  5. Configure systems and access securely.
  6. Test critical transaction and reconciliation flows.
  7. Approve production activation.

10. PPI PARTNER CONTROLS

Where a PPI issuer provides the regulated product or wallet infrastructure, CYBERVED AI PRIVATE LIMITED shall operate only within the approved service model and shall not undertake functions reserved for the authorised issuer unless legally permitted and appropriately authorised.

11. BANK PARTNER CONTROLS

Bank relationships shall define payment, settlement, reconciliation, account/service responsibilities, operational contacts, security requirements, dispute handling and escalation procedures as applicable.

12. API / TECHNICAL INTEGRATION

  • Use approved authentication and authorisation.
  • Protect API credentials and certificates.
  • Use secure communication.
  • Maintain transaction and error logs.
  • Apply appropriate timeout, retry and reconciliation controls.
  • Review material API changes before production.

13. SETTLEMENT & RECONCILIATION

Partner settlement statements and transaction records shall be reconciled against internal records at appropriate intervals. Unmatched items, failed transactions, refunds and reversals shall be investigated and closed with evidence.

14. CUSTOMER PROTECTION

Partner arrangements shall support appropriate customer complaint handling, refund/cancellation processes, unauthorised transaction handling and protection of customer information.

15. FRAUD & AML COORDINATION

The Company shall coordinate with relevant partners for fraud monitoring, suspicious transaction escalation, account/voucher restrictions and other applicable financial-crime controls within the agreed responsibilities.

16. INFORMATION SECURITY & DATA PROTECTION

Partners handling Company or customer information shall be subject to appropriate confidentiality, information-security and data-protection requirements based on risk and contractual obligations.

17. SERVICE LEVELS & PERFORMANCE

Material partners may be monitored against availability, transaction success, settlement, incident response, customer support, reconciliation and other agreed service measures.

18. INCIDENT NOTIFICATION

Material security, fraud, data, transaction or service incidents affecting the Company's customers or operations shall be escalated promptly through agreed partner contacts.

19. PERIODIC PARTNER REVIEW

  • Regulatory/authorisation status where applicable
  • Service performance
  • Security and incident history
  • Fraud trends
  • Settlement/reconciliation issues
  • Complaints
  • Material contractual or business changes
  • Continuity and concentration risks

20. MATERIAL CHANGE MANAGEMENT

Changes in ownership, regulatory status, product scope, API architecture, settlement process, data flows or material service arrangements shall be assessed before implementation where appropriate.

21. SUBCONTRACTORS

Where a partner uses material subcontractors or sub-processors, appropriate disclosure, risk assessment, contractual controls and oversight shall be considered based on the risk of the service.

22. AUDIT & ASSURANCE

The Company may use contractual reports, certifications, assessments, audits, security reviews, service reports or other reasonable evidence to assess partner control effectiveness.

23. SUSPENSION / RESTRICTION

The Company may restrict or suspend a partner integration or product where there is a material security, fraud, regulatory, service, settlement or customer-protection concern, subject to contractual requirements and management approval.

24. EXIT & TERMINATION

Material partner relationships shall have appropriate exit arrangements addressing data return/deletion, customer impact, outstanding transactions, settlement, credential revocation, service transition and record retention.

25. RECORD KEEPING

  • Due diligence documents
  • Authorisation/regulatory evidence
  • Contracts and amendments
  • Partner assessments
  • Service reports
  • Incident communications
  • Settlement/reconciliation records
  • Review and approval records
  • Termination/exit records

26. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory or contractual requirements shall not be bypassed.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Partner ManagementPartner onboarding, relationship management and reviewManagement
ComplianceRegulatory assessment and compliance oversightCompliance Head
LegalContractual and legal reviewLegal / Management
Technology / ITTechnical integration and API controlsTechnology Head
Information SecuritySecurity due diligence and incident oversightSecurity Head
FinanceSettlement and reconciliationFinance Head
OperationsService/customer operations and issue escalationOperations Head

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in partner arrangements, products, technology, regulatory requirements or risk profile.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByPartner Management / Compliance
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED PARTNER GOVERNANCE DOCUMENT

This document is confidential and intended for authorised use only.