REMPINDIA MULTITRADE PRIVATE LIMITED
POLICY NO. 02 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | REMPINDIA MULTITRADE PRIVATE LIMITED |
| CIN | U45202UP2021PTC143528 |
| Registered Office | C/O Rajesh Singh S/o Shree Shankar Singh, Karanpur Chauraha, Shamsabad Road, Sirathu, Kaushambi, Uttar Pradesh – 212217 |
| Website / Brand | giftvoucher.co.in |
| Business Model | Gift Card / Gift Voucher business operated through authorised PPI / bank / payment partners |
| Policy Owner | Compliance / Operations / Management |
| Review Frequency | At least annually and upon material change |
| Classification | Confidential – Partner Management Policy |
This Policy establishes the framework for selecting, onboarding, contracting, monitoring and exiting authorised PPI issuers, banks, payment processors and other critical regulated partners used by REMPINDIA MULTITRADE PRIVATE LIMITED for its gift-card and gift-voucher business.
This Policy applies to PPI issuers, banks, payment processors, settlement partners, technology providers supporting regulated flows and other material partners whose services affect gift-card/voucher issuance, payment, redemption, settlement, customer protection or regulatory compliance.
REMPINDIA shall use regulated services only through appropriately authorised partners and within the scope of the partner's authorisation and contractual arrangements. REMPINDIA shall not represent a partner's authorisation as its own.
Potential partners shall be evaluated on regulatory status, business capability, financial and operational stability, information security, compliance controls, service quality, settlement capability and contractual suitability.
Partners shall be classified according to the criticality and risk of their services. Partners supporting regulated, payment, PPI, settlement, customer-data or critical technology functions should receive enhanced due diligence and monitoring.
Material partner agreements should clearly define service scope, responsibilities, SLAs, settlement, fees, customer complaints, fraud, KYC/AML responsibilities, information security, data protection, confidentiality, incident notification, audit rights, regulatory cooperation, business continuity and termination.
For each material partner, REMPINDIA shall maintain a responsibility matrix identifying which party is responsible for issuance, activation, redemption, KYC/CDD, transaction monitoring, fraud, refunds, chargebacks, grievances, settlement, reconciliation, reporting, information security and customer communication.
Critical partners should be subject to measurable service levels covering availability, transaction processing, settlement, incident response, support, reconciliation and issue resolution, as applicable.
Compliance shall monitor material changes to a partner's regulatory status, licence/authorisation where relevant, regulatory restrictions or other developments that could affect the services provided to REMPINDIA.
Partners receiving access to systems or customer information shall be subject to appropriate security and privacy requirements. Access shall be limited to the agreed purpose and protected through appropriate technical and contractual controls.
Technology partners shall comply with applicable API-security, authentication, access-control, logging, vulnerability-management and change-management requirements. Material API incidents shall be escalated promptly.
Partner arrangements shall support accurate customer information, complaint handling, refunds, unauthorised transaction investigation, dispute handling and other applicable customer-protection processes.
REMPINDIA and relevant partners shall maintain appropriate information-sharing and escalation arrangements for fraud, suspicious activity, account compromise and other material risk indicators, subject to applicable law and contractual requirements.
Settlement processes shall be documented with clear cut-off times, settlement accounts, reports, reconciliation responsibilities, exception handling and escalation procedures.
Material cyber, fraud, operational, settlement, privacy or compliance incidents involving a partner shall be escalated according to the applicable incident-response process and partner agreement.
Critical partners should maintain appropriate business continuity and disaster recovery arrangements. REMPINDIA shall consider partner dependencies when planning continuity for gift-card, payment, settlement and customer-support services.
Material partners shall be reviewed periodically based on risk. Review may include regulatory status, performance, security, financial stability, incidents, complaints, SLA performance, audit findings and remediation.
Where appropriate, contracts should provide for audit, assessment, information requests or independent assurance relating to material services and controls, subject to confidentiality and applicable law.
Material subcontracting by a critical partner should be disclosed or controlled according to contractual requirements. Where subcontracting materially affects risk, REMPINDIA shall assess the impact and seek appropriate assurance.
A documented escalation matrix shall identify operational, security, fraud, settlement, compliance and senior-management contacts for critical partners.
Material non-compliance, repeated SLA failure, regulatory concern, security weakness or unresolved risk shall be documented and may result in remediation, enhanced monitoring, suspension or termination, subject to contractual rights and business continuity considerations.
Partner due diligence, approvals, contracts, risk assessments, reviews, SLA reports, incidents, audit evidence, correspondence and exit records shall be retained according to applicable requirements.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Material partner approval and risk decisions | Director / Management |
| Compliance / Legal | Due diligence, regulatory status, contracts and compliance oversight | Compliance Head |
| Operations | Partner performance, process and service monitoring | Operations Head |
| Technology / Security | API, system access, security assessment and incidents | Technology/Security Head |
| Finance | Settlement, reconciliation and financial controls | Finance Head |
| Risk / Fraud | Partner fraud-risk assessment and incident coordination | Risk/Fraud Head |
| Partner Owner | Day-to-day relationship and escalation management | Partner Owner |
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual requirements shall not be overridden.
This Policy shall be reviewed at least annually and whenever there is a material change in the partner model, product, regulatory requirements, technology or risk profile.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Legal / Risk / Technology / Finance | |
| Approved By | Director / Authorised Signatory |