e-suvidha

CYBERVED AI PRIVATE LIMITED

UNAUTHORISED TRANSACTION POLICY

POLICY NO. 10VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerOperations / Risk / Fraud / Compliance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Customer Protection & Risk Control Policy

1. PURPOSE

This Policy establishes a controlled process for receiving, assessing, investigating and resolving reports of transactions that customers claim were not authorised by them, including relevant gift-card, voucher, payment, purchase, redemption and account activity.

2. OBJECTIVES

  • Provide a clear process for reporting suspected unauthorised activity.
  • Protect customers through prompt risk-based action.
  • Coordinate with PPI, bank, payment and merchant partners.
  • Prevent further misuse while preserving legitimate customer access.
  • Maintain evidence, decisions and audit trails.
  • Identify fraud patterns and improve preventive controls.

3. SCOPE

This Policy applies to relevant customer accounts, orders, payments, gift-card/voucher purchases, issuance, activation, redemption, refunds and related digital transactions handled by or through the Company.

4. RESPONSIBILITY MODEL

Where transaction processing or regulated payment/PPI functions are performed by a partner, the partner's applicable procedures and legal responsibilities shall apply. CYBERVED AI PRIVATE LIMITED shall act within its contractual and lawful role.

5. REPORTING CHANNELS

Customers may report suspected unauthorised activity through approved customer-support channels. The Company shall publish appropriate reporting/contact details for the relevant service.

6. COMPLAINT REGISTRATION

  1. Receive the report and create a reference/ticket.
  2. Record available transaction and customer information.
  3. Verify the customer through reasonable procedures.
  4. Classify the event and assess urgency.
  5. Escalate to Risk/Fraud and relevant partner where required.

7. CUSTOMER VERIFICATION

Reasonable verification may be required before disclosing transaction details, changing account information or taking account-restricted actions. Verification procedures shall not require unnecessary sensitive information.

8. IMMEDIATE RISK CONTROLS

  • Temporarily restrict relevant account or transaction activity where permitted.
  • Place an eligible voucher/order on hold where operationally possible.
  • Escalate to the relevant PPI/payment/merchant partner.
  • Preserve relevant transaction and system evidence.
  • Apply fraud-monitoring rules to related activity.

9. INVESTIGATION

Investigations shall consider transaction references, timestamps, voucher status, payment information, account activity, device/session indicators where available, customer communications, system logs and partner records.

10. PARTNER COORDINATION

Cases involving an authorised PPI issuer, bank, payment processor, merchant or other partner shall be referred through approved escalation channels. Partner responses shall be recorded and tracked.

11. REFUND / REVERSAL

Where a transaction is determined or accepted as eligible for refund, reversal or other remedy, processing shall follow the Refund, Cancellation & Chargeback Policy and applicable partner rules.

12. CHARGEBACK

Where a payment dispute qualifies for chargeback, the case shall be handled through the applicable payment network or processor procedure and within relevant timelines.

13. FRAUD ASSESSMENT

Suspected fraudulent activity shall be assessed under the Fraud Prevention & Transaction Monitoring Policy. Related activity may be monitored or restricted based on risk.

14. CUSTOMER COMMUNICATION

Customers shall receive appropriate updates regarding acknowledgement, required information, status and resolution. Internal fraud-detection information shall not be disclosed where doing so could compromise security or legal obligations.

15. EVIDENCE PRESERVATION

  • Transaction/order ID
  • Payment reference / processor reference
  • Voucher/card identifier where appropriate
  • Activation/redemption status
  • Relevant system and access logs
  • Customer communications
  • Partner correspondence
  • Investigation and decision records

16. ESCALATION OF MATERIAL CASES

Material cases involving significant financial exposure, widespread impact, security compromise, suspected organised fraud, regulatory concern or repeated patterns shall be escalated to senior management and relevant control functions.

17. DATA PROTECTION

Information relating to unauthorised-transaction investigations shall be accessed only by authorised personnel and handled according to applicable privacy, security and retention requirements.

18. CUSTOMER LIABILITY / REMEDY

Responsibility for a disputed transaction and any remedy shall be determined based on applicable law, product terms, evidence, payment-network rules and the responsibilities of the relevant issuer/payment partner. This Policy does not predetermine liability.

19. CLOSURE

A case may be closed after appropriate investigation, partner response and resolution action. Closure shall record the outcome, reason, date and any follow-up action.

20. REOPENING

A closed case may be reopened where new material evidence, a partner update, a regulatory direction or a relevant customer submission warrants further review.

21. ROOT CAUSE & PREVENTION

Material or recurring unauthorised-transaction incidents shall be analysed for control weaknesses and may result in stronger authentication, monitoring, access controls, customer education or partner changes.

22. RECORD KEEPING

Records of reported unauthorised transactions, investigation, evidence, partner communications, decisions, refunds/reversals and closure shall be retained for the applicable period.

23. MANAGEMENT REPORTING

  • Number and value of reported cases
  • Confirmed/uncorroborated cases
  • Resolution and ageing
  • Fraud patterns
  • Partner-related incidents
  • Refund/reversal outcomes
  • Recurring root causes

24. TRAINING

Relevant customer-support, operations, risk and fraud personnel shall receive role-appropriate training on verification, escalation, evidence preservation, customer communication and confidentiality.

25. EXCEPTIONS

Exceptions shall be documented and approved by authorised management. Applicable law, regulatory requirements and binding partner procedures shall not be bypassed.

26. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Customer SupportReceive reports, verify and communicateOperations
OperationsCase coordination and closureOperations Head
Risk / FraudInvestigation, monitoring and fraud assessmentRisk/Fraud Head
Compliance / LegalRegulatory/legal escalationCompliance / Legal
Partner ManagementPPI/bank/payment/merchant coordinationManagement
FinanceRefund/reversal and reconciliationFinance Head
Technology / ITLogs, system evidence and technical controlsTechnology Head

27. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in products, payment methods, partner arrangements, fraud trends or applicable requirements.

28. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByOperations / Risk / Fraud / Compliance
Reviewed ByLegal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CUSTOMER PROTECTION & RISK CONTROL POLICY

This document is confidential and intended for authorised use only.