HariPay

HARIPAY PRIVATE LIMITED

GIFT CARD / GIFT VOUCHER BUSINESS

POLICY NO. 03

KYC & CUSTOMER DUE DILIGENCE POLICY

ParticularDetails
CompanyHARIPAY PRIVATE LIMITED
CINU72900UP2022PTC168527
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
BusinessGift Cards, Gift Vouchers & Virtual Gift Products
Policy OwnerManagement / Compliance / Risk / Operations
Version1.0
Effective Date28 September 2026
Review FrequencyAt least annually and upon material legal, regulatory, product, partner or risk changes

1. Purpose

This Policy establishes HARIPAY's framework for customer identification, verification and risk-based due diligence in connection with its gift card, gift voucher and virtual gift product business.

The controls shall be implemented according to applicable law and the contractual allocation of responsibilities with any authorised PPI issuer, bank or other regulated partner. Where a regulated partner has primary KYC responsibility, HARIPAY shall follow the approved partner process and shall not represent itself as the regulated entity.

2. Scope

  • Retail customers purchasing or using gift products
  • Corporate and institutional customers
  • Bulk purchasers
  • Merchant/brand partners where due diligence is required
  • PPI issuer / bank / payment partners
  • Employees and authorised personnel involved in customer verification
  • Digital onboarding and transaction systems

3. KYC Governance

Management shall ensure that customer-verification responsibilities are clearly assigned. Compliance shall maintain oversight of the applicable KYC framework, while Operations shall implement approved procedures and retain required evidence.

  • Documented responsibility matrix
  • Approved onboarding process
  • Escalation mechanism
  • Periodic control review
  • Staff training

4. Customer Identification

Where customer identification is required by applicable law, partner requirements or the Company's risk controls, HARIPAY shall collect appropriate information necessary to identify the customer and provide the relevant product/service.

  • Name
  • Contact information
  • Address or other identifying information where required
  • Account identifiers
  • Transaction/order information
  • Business information for corporate customers where applicable

5. Customer Verification

Verification shall be performed using appropriate and lawful methods proportionate to the risk and the applicable partner/regulatory requirements.

  • Document-based verification where applicable
  • Approved electronic verification where available
  • Authentication of contact details
  • Partner-provided verification results where contractually permitted
  • Additional verification for higher-risk cases

6. Corporate / Bulk Customer Due Diligence

  • Legal name and registration details
  • Authorised representative
  • Business purpose
  • Beneficial ownership information where required
  • Contact and billing details
  • Expected transaction activity
  • Source/payment information where required
  • Risk indicators

7. Beneficial Ownership

Where a customer is a legal entity and beneficial ownership information is required, HARIPAY shall obtain and verify appropriate ownership/control information in accordance with applicable requirements and the relevant partner process.

8. Risk Categorisation

Customers may be categorised using a risk-based approach considering product, transaction, customer, geography, payment method, behaviour and other relevant risk indicators.

  • Standard risk
  • Higher risk
  • Restricted / prohibited where applicable

Risk categorisation shall not be based on discriminatory characteristics unrelated to legitimate compliance or fraud risk.

9. Enhanced Due Diligence

Higher-risk relationships or transactions may require enhanced review proportionate to the identified risk.

  • Additional identity information
  • Additional business information
  • Transaction-purpose review where appropriate
  • Source-of-funds information where lawfully required
  • Senior/compliance review
  • Increased monitoring

10. Sanctions / PEP / Screening

Where applicable to HARIPAY's role or required by a regulated partner, relevant screening controls shall be applied using approved sources and processes. Potential matches shall be reviewed before adverse action is taken, with escalation to Compliance where required.

11. Customer Authentication

  • Secure login/account authentication
  • OTP or equivalent controls where applicable
  • Transaction authentication
  • Step-up verification for sensitive actions
  • Credential protection
  • No sharing of authentication credentials

12. KYC for Gift Card Transactions

The level of customer verification shall be proportionate to the product, transaction value, frequency, fraud indicators and applicable legal/partner requirements.

  • High-value purchases
  • Unusual purchase velocity
  • Bulk/corporate orders
  • Repeated failed attempts
  • Suspicious redemption patterns
  • Account takeover indicators

13. Ongoing Due Diligence

Where ongoing review is required, HARIPAY shall update customer information and risk assessment in accordance with applicable requirements and the partner responsibility matrix.

  • Material customer-information change
  • Unusual activity
  • Risk trigger
  • Expired verification where relevant
  • Partner request

14. Incomplete or Failed Verification

Where required verification cannot be completed, HARIPAY may restrict onboarding, transaction processing, redemption or other activity as permitted by law, contract and product terms.

The reason for restriction shall be recorded appropriately without unnecessarily disclosing sensitive fraud or compliance controls to the customer.

15. Fraud & KYC Coordination

KYC controls shall operate alongside the Fraud Prevention & Transaction Monitoring Policy. Suspicious account behaviour, identity misuse, account takeover and fraudulent documentation shall be escalated for investigation.

16. PPI / Bank Partner Coordination

Where the PPI issuer or bank is responsible for customer KYC, HARIPAY shall use the partner's approved onboarding and verification mechanism where contractually and legally permitted.

  • Do not duplicate unnecessarily collected information
  • Follow partner-approved process
  • Maintain responsibility matrix
  • Escalate verification failures
  • Protect shared KYC information

17. Data Protection & Privacy

KYC information is sensitive business/customer information and shall be collected, accessed, shared, retained and deleted according to applicable privacy requirements and HARIPAY's Data Protection, Privacy & Retention Policy.

  • Purpose limitation
  • Data minimisation
  • Need-to-know access
  • Secure storage
  • Secure transmission
  • Retention limits
  • Controlled deletion

18. Record Keeping

  • Customer verification records
  • Verification result
  • Date/time of verification
  • Risk classification where applicable
  • Review/escalation records
  • Partner verification references
  • Relevant transaction/order references

Records shall be retained for the applicable period under law, contractual requirements, disputes, investigations and the Company's approved retention schedule.

19. KYC Exceptions

Any exception to an approved KYC process shall be documented, risk-assessed and approved by the designated authority. Exceptions shall not be used to bypass mandatory legal or regulatory requirements.

20. Employee Training

Employees handling customer onboarding, verification, support, fraud review or partner operations shall receive appropriate training on KYC procedures, privacy, fraud indicators and escalation requirements.

21. Monitoring & Quality Assurance

  • Sample verification reviews
  • Data-quality checks
  • Exception monitoring
  • Failed-verification analysis
  • Fraud/KYC trend analysis
  • Partner process reviews
  • Corrective action tracking

22. Customer Communication

Customer communications relating to verification shall be clear, accurate and proportionate. HARIPAY shall avoid unnecessarily revealing internal fraud-detection rules or sensitive security controls.

23. Management Reporting

  • Verification volumes
  • Failure rates
  • Higher-risk reviews
  • Material KYC exceptions
  • Fraud-linked KYC cases
  • Partner escalations
  • Open corrective actions

24. Review & Amendment

This Policy shall be reviewed at least annually and after material changes to applicable requirements, product design, partner arrangements, technology or risk profile.

25. Approval

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByManagement / Risk / Compliance
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – INTERNAL COMPLIANCE DOCUMENT