Haripay INDIA PRIVATE LIMITED
REGULATORY REPORTING & RECORD-KEEPING POLICY
POLICY NO. 18 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | Haripay INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | Haripay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Legal / Operations / Finance |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for identifying, preparing, reviewing, approving, submitting, storing and retrieving regulatory, statutory, contractual and management records maintained by Haripay India Private Limited.
2. OBJECTIVES
- Maintain complete and reliable records.
- Support applicable legal and regulatory reporting obligations.
- Ensure reports are accurate, timely and properly approved.
- Preserve evidence for audits, disputes and investigations.
- Maintain controlled access and confidentiality.
- Enable prompt retrieval of records.
3. SCOPE
This Policy applies to regulatory submissions, statutory records, customer and transaction records, KYC/verification records, AML/CFT records, fraud records, settlement and reconciliation records, security records, grievances, contracts, partner records, audit records and other business records required to support Haripay's activities.
4. REPORTING PRINCIPLES
- Accuracy
- Completeness
- Timeliness
- Consistency
- Traceability
- Confidentiality
- Authorised approval
- Evidence-based reporting
5. REGULATORY OBLIGATION IDENTIFICATION
Compliance shall maintain an appropriate register of applicable reporting obligations based on Haripay's business model, contractual arrangements, applicable law, regulatory status and activities performed through authorised partners.
6. REPORTING CALENDAR
Where applicable, a reporting calendar shall identify the report, recipient, frequency, due date, responsible owner, reviewer and evidence of submission.
7. REPORT PREPARATION
- Identify applicable reporting requirement.
- Collect source data.
- Validate completeness and accuracy.
- Prepare report in required format.
- Obtain required review/approval.
- Submit through the approved channel.
- Retain submission evidence.
8. REVIEW & APPROVAL
Material regulatory or statutory reports shall be reviewed by the designated responsible function before submission. Where required, management or an authorised signatory shall approve the report.
9. SUBMISSION CHANNELS
Reports shall be submitted through authorised portals, email channels, partner processes or other officially designated mechanisms, as applicable.
10. SUBMISSION EVIDENCE
- Acknowledgement/reference number
- Submission date/time
- Submitted report
- Portal confirmation
- Official communication
- Approval evidence
11. CORRECTIONS / RE-SUBMISSION
If an error is identified in a submitted report, the responsible function shall assess the impact, escalate as appropriate and make correction or re-submission where required.
12. CUSTOMER & TRANSACTION RECORDS
Customer, transaction, order, redemption, refund, payment-reference and related records shall be retained according to applicable legal, contractual, operational and fraud-prevention requirements.
13. KYC / AML / FRAUD RECORDS
KYC/verification, customer due diligence, AML/CFT review, transaction monitoring, suspicious activity review and fraud investigation records shall be maintained according to applicable requirements and internal policies.
14. SETTLEMENT & RECONCILIATION RECORDS
- Settlement statements
- Bank/payment references
- Partner statements
- Reconciliation reports
- Exception records
- Refund/reversal records
- Approval and closure evidence
15. GRIEVANCE & DISPUTE RECORDS
Customer complaints, grievance correspondence, dispute records, chargeback records, unauthorised transaction investigations and resolution evidence shall be maintained for the applicable retention period.
16. INFORMATION SECURITY RECORDS
- Security logs where required
- Incident reports
- Access review evidence
- Vulnerability/security assessment records
- Backup/recovery test records
- Cyber incident evidence
17. CONTRACT & PARTNER RECORDS
Executed agreements, amendments, due diligence records, partner communications, SLA records, vendor reviews and termination/exit documentation shall be securely maintained.
18. RECORD CLASSIFICATION
- Public – approved for public disclosure
- Internal – business use
- Confidential – restricted business/customer information
- Restricted – highly sensitive security, fraud, legal or personal information
19. RECORD OWNERSHIP
Each material record category shall have a responsible business owner who ensures completeness, retention, accessibility and appropriate disposal.
20. RECORD INTEGRITY
Records shall be maintained in a manner that protects them from unauthorised alteration, deletion or destruction. Where appropriate, version control, access logs or other integrity mechanisms shall be used.
21. ELECTRONIC RECORDS
Electronic records shall be stored in approved systems with appropriate access control, backup, security and retention controls.
22. PHYSICAL RECORDS
Where physical records are maintained, they shall be stored securely and protected from unauthorised access, damage, loss or destruction.
23. RETENTION PERIODS
Records shall be retained for the period required by applicable law, regulatory requirements, contractual obligations, legitimate business needs and approved internal schedules. Where requirements differ, the longer applicable period may be followed unless otherwise determined by authorised legal/compliance advice.
24. LEGAL / REGULATORY HOLD
Records subject to litigation, investigation, audit, regulatory review, dispute or other authorised hold shall not be destroyed until the hold is formally released.
25. ACCESS & CONFIDENTIALITY
Access to records shall follow least-privilege and need-to-know principles. Confidential or restricted records shall only be shared with authorised persons or entities for legitimate purposes.
26. DATA PROTECTION
Personal and sensitive information contained in records shall be handled in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.
27. RECORD RETRIEVAL
Records shall be organised and indexed sufficiently to allow reasonable retrieval for audits, customer matters, partner reconciliation, investigations, legal requirements and management review.
28. AUDIT TRAIL
Material regulatory submissions and controlled records should maintain sufficient evidence to identify who prepared, reviewed, approved, submitted or amended the record, where practicable.
29. AUDIT & INSPECTION
Haripay shall provide appropriate records and evidence to authorised auditors, regulators, legal advisers or other authorised parties, subject to confidentiality and applicable law.
30. RECORD DISPOSAL
Records shall be securely deleted, destroyed or anonymised when the applicable retention period has expired and no legal, regulatory, contractual or business hold applies.
31. THIRD-PARTY RECORDS
Where records are maintained by a PPI issuer, bank, payment processor, cloud provider or other vendor, contractual arrangements shall address access, availability, confidentiality and retrieval requirements appropriate to the service.
32. BUSINESS CONTINUITY
Critical records shall have appropriate backup and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.
33. NON-COMPLIANCE
Missing, inaccurate, unauthorised, altered or improperly disclosed records shall be investigated and corrective action shall be taken as appropriate.
34. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal or regulatory record-keeping requirements shall not be overridden.
35. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Compliance | Regulatory obligation register, reporting oversight and evidence | Compliance Head |
| Legal | Legal interpretation, holds and legal record requirements | Legal / Management |
| Finance | Financial, settlement and accounting records | Finance Head |
| Operations | Customer, transaction and operational records | Operations Head |
| Information Security / IT | Security, access, system and technical records | Technology/Security Head |
| Vendor Management | Third-party record requirements | Management |
| Management | Material approvals and risk decisions | Director / Authorised Management |
36. TRAINING & AWARENESS
Relevant personnel shall receive appropriate awareness regarding reporting obligations, record accuracy, confidentiality, retention and secure handling.
37. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in Haripay's business model, partner arrangements, regulatory obligations, systems or applicable requirements.
38. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Legal / Operations / Finance | |
| Reviewed By | Risk / Management | |
| Approved By | Director / Authorised Signatory |
