CYBERVED AI PRIVATE LIMITED
UNAUTHORISED TRANSACTION POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Operations / Risk / Fraud / Compliance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Customer Protection & Risk Control Policy |
1. PURPOSE
This Policy establishes a controlled process for receiving, assessing, investigating and resolving reports of transactions that customers claim were not authorised by them, including relevant gift-card, voucher, payment, purchase, redemption and account activity.
2. OBJECTIVES
- Provide a clear process for reporting suspected unauthorised activity.
- Protect customers through prompt risk-based action.
- Coordinate with PPI, bank, payment and merchant partners.
- Prevent further misuse while preserving legitimate customer access.
- Maintain evidence, decisions and audit trails.
- Identify fraud patterns and improve preventive controls.
3. SCOPE
This Policy applies to relevant customer accounts, orders, payments, gift-card/voucher purchases, issuance, activation, redemption, refunds and related digital transactions handled by or through the Company.
4. RESPONSIBILITY MODEL
Where transaction processing or regulated payment/PPI functions are performed by a partner, the partner's applicable procedures and legal responsibilities shall apply. CYBERVED AI PRIVATE LIMITED shall act within its contractual and lawful role.
5. REPORTING CHANNELS
Customers may report suspected unauthorised activity through approved customer-support channels. The Company shall publish appropriate reporting/contact details for the relevant service.
6. COMPLAINT REGISTRATION
- Receive the report and create a reference/ticket.
- Record available transaction and customer information.
- Verify the customer through reasonable procedures.
- Classify the event and assess urgency.
- Escalate to Risk/Fraud and relevant partner where required.
7. CUSTOMER VERIFICATION
Reasonable verification may be required before disclosing transaction details, changing account information or taking account-restricted actions. Verification procedures shall not require unnecessary sensitive information.
8. IMMEDIATE RISK CONTROLS
- Temporarily restrict relevant account or transaction activity where permitted.
- Place an eligible voucher/order on hold where operationally possible.
- Escalate to the relevant PPI/payment/merchant partner.
- Preserve relevant transaction and system evidence.
- Apply fraud-monitoring rules to related activity.
9. INVESTIGATION
Investigations shall consider transaction references, timestamps, voucher status, payment information, account activity, device/session indicators where available, customer communications, system logs and partner records.
10. PARTNER COORDINATION
Cases involving an authorised PPI issuer, bank, payment processor, merchant or other partner shall be referred through approved escalation channels. Partner responses shall be recorded and tracked.
11. REFUND / REVERSAL
Where a transaction is determined or accepted as eligible for refund, reversal or other remedy, processing shall follow the Refund, Cancellation & Chargeback Policy and applicable partner rules.
12. CHARGEBACK
Where a payment dispute qualifies for chargeback, the case shall be handled through the applicable payment network or processor procedure and within relevant timelines.
13. FRAUD ASSESSMENT
Suspected fraudulent activity shall be assessed under the Fraud Prevention & Transaction Monitoring Policy. Related activity may be monitored or restricted based on risk.
14. CUSTOMER COMMUNICATION
Customers shall receive appropriate updates regarding acknowledgement, required information, status and resolution. Internal fraud-detection information shall not be disclosed where doing so could compromise security or legal obligations.
15. EVIDENCE PRESERVATION
- Transaction/order ID
- Payment reference / processor reference
- Voucher/card identifier where appropriate
- Activation/redemption status
- Relevant system and access logs
- Customer communications
- Partner correspondence
- Investigation and decision records
16. ESCALATION OF MATERIAL CASES
Material cases involving significant financial exposure, widespread impact, security compromise, suspected organised fraud, regulatory concern or repeated patterns shall be escalated to senior management and relevant control functions.
17. DATA PROTECTION
Information relating to unauthorised-transaction investigations shall be accessed only by authorised personnel and handled according to applicable privacy, security and retention requirements.
18. CUSTOMER LIABILITY / REMEDY
Responsibility for a disputed transaction and any remedy shall be determined based on applicable law, product terms, evidence, payment-network rules and the responsibilities of the relevant issuer/payment partner. This Policy does not predetermine liability.
19. CLOSURE
A case may be closed after appropriate investigation, partner response and resolution action. Closure shall record the outcome, reason, date and any follow-up action.
20. REOPENING
A closed case may be reopened where new material evidence, a partner update, a regulatory direction or a relevant customer submission warrants further review.
21. ROOT CAUSE & PREVENTION
Material or recurring unauthorised-transaction incidents shall be analysed for control weaknesses and may result in stronger authentication, monitoring, access controls, customer education or partner changes.
22. RECORD KEEPING
Records of reported unauthorised transactions, investigation, evidence, partner communications, decisions, refunds/reversals and closure shall be retained for the applicable period.
23. MANAGEMENT REPORTING
- Number and value of reported cases
- Confirmed/uncorroborated cases
- Resolution and ageing
- Fraud patterns
- Partner-related incidents
- Refund/reversal outcomes
- Recurring root causes
24. TRAINING
Relevant customer-support, operations, risk and fraud personnel shall receive role-appropriate training on verification, escalation, evidence preservation, customer communication and confidentiality.
25. EXCEPTIONS
Exceptions shall be documented and approved by authorised management. Applicable law, regulatory requirements and binding partner procedures shall not be bypassed.
26. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Customer Support | Receive reports, verify and communicate | Operations |
| Operations | Case coordination and closure | Operations Head |
| Risk / Fraud | Investigation, monitoring and fraud assessment | Risk/Fraud Head |
| Compliance / Legal | Regulatory/legal escalation | Compliance / Legal |
| Partner Management | PPI/bank/payment/merchant coordination | Management |
| Finance | Refund/reversal and reconciliation | Finance Head |
| Technology / IT | Logs, system evidence and technical controls | Technology Head |
27. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in products, payment methods, partner arrangements, fraud trends or applicable requirements.
28. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Operations / Risk / Fraud / Compliance | |
| Reviewed By | Legal / Management | |
| Approved By | Director / Authorised Signatory |