Haripay

Haripay INDIA PRIVATE LIMITED

PPI ISSUER / BANK PARTNER MANAGEMENT POLICY

POLICY NO. 02 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyHaripay INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
WebsiteHaripay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for identifying, onboarding, contracting, monitoring and reviewing PPI issuers, banks, payment providers and other regulated or critical partners engaged by Haripay in connection with its gift card, voucher, payment and related technology-enabled activities.

2. OBJECTIVES

  • Ensure appropriate partner due diligence before onboarding.
  • Verify relevant regulatory status and authorisations where applicable.
  • Clearly allocate responsibilities between Haripay and its partners.
  • Control operational, settlement, fraud, information-security and compliance risks.
  • Monitor partner performance and material changes.
  • Maintain evidence of due diligence and ongoing oversight.
  • Provide a controlled process for suspension, remediation and exit.

3. SCOPE

This Policy applies to PPI issuers, banks, payment service providers, payment facilitators, merchant/brand partners, technology providers and other third parties whose services are material to Haripay's covered products or regulated-partner model.

4. PARTNER CLASSIFICATION

Partners shall be classified based on their regulatory role, criticality, transaction exposure, data access, customer impact, settlement dependency and operational importance.

  • Regulated / PPI Issuer
  • Banking Partner
  • Payment / Processing Partner
  • Merchant / Brand Partner
  • Technology / API Partner
  • Critical Outsourced Service Provider
  • Other Material Vendor

5. PRE-ONBOARDING DUE DILIGENCE

No material partner shall be onboarded without documented due diligence appropriate to its risk level.

  • Corporate identity and incorporation details
  • Relevant licences/authorisations, where applicable
  • Registered office and key contacts
  • Ownership / control information where appropriate
  • Business model and service scope
  • Financial and operational capability
  • Information-security posture
  • Data-protection arrangements
  • Business continuity capability
  • Fraud and transaction-monitoring capability
  • Reputation and material adverse information checks where appropriate

6. REGULATORY AUTHORISATION VERIFICATION

Where a partner performs a regulated activity, Haripay shall verify the relevant authorisation or regulatory status through appropriate reliable evidence before relying on that partner for the relevant activity.

  • Capture authorisation details where applicable.
  • Record the verification date.
  • Retain supporting evidence.
  • Define the scope of the partner's authorised activity.
  • Re-verify material status changes or when required by risk assessment.

7. PARTNER ROLE & RESPONSIBILITY MATRIX

Each material partnership shall document who is responsible for issuance, payment processing, KYC, AML/CFT, fraud monitoring, customer support, refunds, chargebacks, settlement, reconciliation, data protection, incident response and regulatory reporting.

8. CONTRACTUAL REQUIREMENTS

  • Defined service scope
  • Roles and responsibilities
  • Service levels / SLAs
  • Settlement terms
  • Refund and dispute processes
  • Information-security requirements
  • Data-protection obligations
  • Confidentiality
  • Audit / inspection rights where appropriate
  • Incident notification
  • Business continuity
  • Regulatory cooperation
  • Subcontracting restrictions
  • Termination and exit provisions

9. CUSTOMER & PRODUCT GOVERNANCE

Partner arrangements shall support accurate customer disclosures and product terms. Where a regulated partner is the issuer or responsible entity, customer-facing materials shall not incorrectly represent Haripay as the issuer or licence holder.

10. INFORMATION SECURITY & DATA PROTECTION

Partners receiving or accessing Haripay or customer information shall be subject to appropriate security and data-protection requirements based on risk.

  • Access limitation
  • Encryption where appropriate
  • Secure API connectivity
  • Logging
  • Incident notification
  • Data retention and deletion
  • Confidentiality
  • Security assessment where appropriate

11. TRANSACTION, FRAUD & RISK CONTROLS

Material payment and PPI partners shall have appropriate controls for transaction processing, fraud detection, suspicious activity escalation and operational risk. Haripay shall define relevant monitoring and escalation responsibilities in the applicable agreement or SOP.

12. SETTLEMENT & RECONCILIATION

Settlement arrangements shall define settlement cycles, accounts, transaction references, reconciliation responsibilities, exceptions, reversals, refunds and escalation.

  • Daily/periodic reconciliation where applicable
  • Settlement statement review
  • Exception tracking
  • Unmatched transaction investigation
  • Refund/reversal matching
  • Escalation of settlement discrepancies

13. ONGOING PARTNER MONITORING

Partners shall be monitored proportionately to their risk and criticality.

  • Regulatory status
  • Service performance
  • Transaction failure rates
  • Settlement performance
  • Fraud incidents
  • Security incidents
  • Customer complaints
  • SLA performance
  • Material ownership/control changes
  • Business continuity status

14. PERIODIC REVIEW

High-risk or critical partners shall be reviewed more frequently based on risk. Review results shall be documented with identified gaps, action owners and target dates.

15. PARTNER INCIDENT MANAGEMENT

Partners shall notify Haripay of material security, fraud, service, regulatory or operational incidents within the timeframe specified in the agreement. Haripay shall coordinate containment, customer impact assessment, evidence preservation, partner escalation and recovery.

16. SUBCONTRACTING

Material subcontracting by a critical partner shall be subject to contractual controls and, where appropriate, prior notification or approval. The primary partner shall remain responsible for agreed services and oversight of its subcontractors.

17. PARTNER ACCESS CONTROL

Partner access to Haripay systems, APIs, data or operational interfaces shall be granted only on a need-to-use basis and shall be reviewed periodically.

  • Unique credentials
  • Role-based access
  • Least privilege
  • MFA where appropriate
  • API authentication
  • Credential/secrets management
  • Logging and monitoring
  • Timely access revocation

18. PERFORMANCE & SLA MANAGEMENT

Material partners shall be monitored against agreed service levels, including availability, transaction processing, settlement timelines, incident response, customer support and resolution timelines where applicable.

19. REMEDIATION & ESCALATION

Material partner deficiencies shall be documented and assigned for remediation. Serious or repeated failures may result in enhanced monitoring, suspension of affected activity or termination, subject to contractual and legal requirements.

  1. Identify issue.
  2. Risk-assess issue.
  3. Agree corrective action.
  4. Set owner and target date.
  5. Monitor closure.
  6. Escalate overdue/material issues.

20. SUSPENSION & TERMINATION

Haripay may suspend or terminate a partner relationship in accordance with contractual terms where there is material regulatory, security, fraud, operational, settlement or customer-protection risk.

21. EXIT MANAGEMENT

  • Transition planning
  • Data return/deletion
  • Credential revocation
  • Settlement closure
  • Customer-impact management
  • Open complaint/dispute handling
  • Contractual record preservation
  • Alternative provider readiness where appropriate

22. RECORD KEEPING

  • Due diligence files
  • Regulatory verification evidence
  • Contracts and amendments
  • SLA records
  • Review reports
  • Incident records
  • Settlement/reconciliation records
  • Risk assessments
  • Remediation records
  • Exit records

Records shall be maintained according to applicable law, contracts and Haripay's Data Protection, Privacy & Retention Policy.

23. AUDIT & ASSURANCE

Haripay may conduct or commission risk-based reviews of material partners, including document reviews, control assessments, security questionnaires, audits or other assurance activities where appropriate and contractually permitted.

24. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementApprove material partnerships and risk decisionsDirector / Authorised Management
ComplianceRegulatory due diligence and monitoringManagement
Partner ManagementOnboarding, contracts and performanceManagement / Compliance
OperationsOperational monitoring and reconciliationManagement
Technology/SecurityAPI, access and security assessmentManagement / Security
FinanceSettlement and financial reconciliationManagement
LegalContractual and legal reviewManagement

25. POLICY EXCEPTIONS

Any exception shall be documented, risk-assessed and approved by the authorised function. Exceptions shall not override mandatory legal or regulatory requirements.

26. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in Haripay's business model, regulated partner structure, product, technology, applicable requirements or risk profile.

27. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

Haripay INDIA PRIVATE LIMITED