HARIPAY PRIVATE LIMITED
GIFT CARD / GIFT VOUCHER BUSINESS
POLICY NO. 03
KYC & CUSTOMER DUE DILIGENCE POLICY
| Particular | Details |
|---|---|
| Company | HARIPAY PRIVATE LIMITED |
| CIN | U72900UP2022PTC168527 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Business | Gift Cards, Gift Vouchers & Virtual Gift Products |
| Policy Owner | Management / Compliance / Risk / Operations |
| Version | 1.0 |
| Effective Date | 28 September 2026 |
| Review Frequency | At least annually and upon material legal, regulatory, product, partner or risk changes |
1. Purpose
This Policy establishes HARIPAY's framework for customer identification, verification and risk-based due diligence in connection with its gift card, gift voucher and virtual gift product business.
The controls shall be implemented according to applicable law and the contractual allocation of responsibilities with any authorised PPI issuer, bank or other regulated partner. Where a regulated partner has primary KYC responsibility, HARIPAY shall follow the approved partner process and shall not represent itself as the regulated entity.
2. Scope
- Retail customers purchasing or using gift products
- Corporate and institutional customers
- Bulk purchasers
- Merchant/brand partners where due diligence is required
- PPI issuer / bank / payment partners
- Employees and authorised personnel involved in customer verification
- Digital onboarding and transaction systems
3. KYC Governance
Management shall ensure that customer-verification responsibilities are clearly assigned. Compliance shall maintain oversight of the applicable KYC framework, while Operations shall implement approved procedures and retain required evidence.
- Documented responsibility matrix
- Approved onboarding process
- Escalation mechanism
- Periodic control review
- Staff training
4. Customer Identification
Where customer identification is required by applicable law, partner requirements or the Company's risk controls, HARIPAY shall collect appropriate information necessary to identify the customer and provide the relevant product/service.
- Name
- Contact information
- Address or other identifying information where required
- Account identifiers
- Transaction/order information
- Business information for corporate customers where applicable
5. Customer Verification
Verification shall be performed using appropriate and lawful methods proportionate to the risk and the applicable partner/regulatory requirements.
- Document-based verification where applicable
- Approved electronic verification where available
- Authentication of contact details
- Partner-provided verification results where contractually permitted
- Additional verification for higher-risk cases
6. Corporate / Bulk Customer Due Diligence
- Legal name and registration details
- Authorised representative
- Business purpose
- Beneficial ownership information where required
- Contact and billing details
- Expected transaction activity
- Source/payment information where required
- Risk indicators
7. Beneficial Ownership
Where a customer is a legal entity and beneficial ownership information is required, HARIPAY shall obtain and verify appropriate ownership/control information in accordance with applicable requirements and the relevant partner process.
8. Risk Categorisation
Customers may be categorised using a risk-based approach considering product, transaction, customer, geography, payment method, behaviour and other relevant risk indicators.
- Standard risk
- Higher risk
- Restricted / prohibited where applicable
Risk categorisation shall not be based on discriminatory characteristics unrelated to legitimate compliance or fraud risk.
9. Enhanced Due Diligence
Higher-risk relationships or transactions may require enhanced review proportionate to the identified risk.
- Additional identity information
- Additional business information
- Transaction-purpose review where appropriate
- Source-of-funds information where lawfully required
- Senior/compliance review
- Increased monitoring
10. Sanctions / PEP / Screening
Where applicable to HARIPAY's role or required by a regulated partner, relevant screening controls shall be applied using approved sources and processes. Potential matches shall be reviewed before adverse action is taken, with escalation to Compliance where required.
11. Customer Authentication
- Secure login/account authentication
- OTP or equivalent controls where applicable
- Transaction authentication
- Step-up verification for sensitive actions
- Credential protection
- No sharing of authentication credentials
12. KYC for Gift Card Transactions
The level of customer verification shall be proportionate to the product, transaction value, frequency, fraud indicators and applicable legal/partner requirements.
- High-value purchases
- Unusual purchase velocity
- Bulk/corporate orders
- Repeated failed attempts
- Suspicious redemption patterns
- Account takeover indicators
13. Ongoing Due Diligence
Where ongoing review is required, HARIPAY shall update customer information and risk assessment in accordance with applicable requirements and the partner responsibility matrix.
- Material customer-information change
- Unusual activity
- Risk trigger
- Expired verification where relevant
- Partner request
14. Incomplete or Failed Verification
Where required verification cannot be completed, HARIPAY may restrict onboarding, transaction processing, redemption or other activity as permitted by law, contract and product terms.
The reason for restriction shall be recorded appropriately without unnecessarily disclosing sensitive fraud or compliance controls to the customer.
15. Fraud & KYC Coordination
KYC controls shall operate alongside the Fraud Prevention & Transaction Monitoring Policy. Suspicious account behaviour, identity misuse, account takeover and fraudulent documentation shall be escalated for investigation.
16. PPI / Bank Partner Coordination
Where the PPI issuer or bank is responsible for customer KYC, HARIPAY shall use the partner's approved onboarding and verification mechanism where contractually and legally permitted.
- Do not duplicate unnecessarily collected information
- Follow partner-approved process
- Maintain responsibility matrix
- Escalate verification failures
- Protect shared KYC information
17. Data Protection & Privacy
KYC information is sensitive business/customer information and shall be collected, accessed, shared, retained and deleted according to applicable privacy requirements and HARIPAY's Data Protection, Privacy & Retention Policy.
- Purpose limitation
- Data minimisation
- Need-to-know access
- Secure storage
- Secure transmission
- Retention limits
- Controlled deletion
18. Record Keeping
- Customer verification records
- Verification result
- Date/time of verification
- Risk classification where applicable
- Review/escalation records
- Partner verification references
- Relevant transaction/order references
Records shall be retained for the applicable period under law, contractual requirements, disputes, investigations and the Company's approved retention schedule.
19. KYC Exceptions
Any exception to an approved KYC process shall be documented, risk-assessed and approved by the designated authority. Exceptions shall not be used to bypass mandatory legal or regulatory requirements.
20. Employee Training
Employees handling customer onboarding, verification, support, fraud review or partner operations shall receive appropriate training on KYC procedures, privacy, fraud indicators and escalation requirements.
21. Monitoring & Quality Assurance
- Sample verification reviews
- Data-quality checks
- Exception monitoring
- Failed-verification analysis
- Fraud/KYC trend analysis
- Partner process reviews
- Corrective action tracking
22. Customer Communication
Customer communications relating to verification shall be clear, accurate and proportionate. HARIPAY shall avoid unnecessarily revealing internal fraud-detection rules or sensitive security controls.
23. Management Reporting
- Verification volumes
- Failure rates
- Higher-risk reviews
- Material KYC exceptions
- Fraud-linked KYC cases
- Partner escalations
- Open corrective actions
24. Review & Amendment
This Policy shall be reviewed at least annually and after material changes to applicable requirements, product design, partner arrangements, technology or risk profile.
25. Approval
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Management / Risk / Compliance | |
| Approved By | Director / Authorised Signatory |

