Login or Create an account
Or Login Via

KNOW YOUR CUSTOMER (KYC) & CUSTOMER DUE DILIGENCE (CDD) POLICY

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Know Your Customer (KYC) & Customer Due Diligence (CDD) Policy

ZESTFLOW INDIA PRIVATE LIMITED follows a risk-based KYC and Customer Due Diligence framework to verify customers, merchants and relevant business relationships. We apply appropriate identity verification, beneficial ownership checks and ongoing due diligence to prevent fraud, money laundering and other unlawful activities, in accordance with applicable laws.

1. Purpose and Policy Statement

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining appropriate Know Your Customer ("KYC") and Customer Due Diligence ("CDD") measures to identify and verify customers, merchants and other relevant business relationships.

This Policy forms an integral part of the Company's Anti-Money Laundering ("AML") and Combating Financing of Terrorism ("CFT") framework and is intended to prevent the misuse of the Company's platform, services and business relationships for money laundering, terrorist financing, fraud, identity theft or other unlawful ac- tivities.

The Company shall adopt a risk-based approach to KYC and CDD in accordance with applicable laws, its business activities, regulatory status and arrangements with regu- lated partner institutions.

2. Scope and Regulatory Applicability

This Policy applies, as relevant, to:

  • customers and merchants;
  • proprietorships, partnerships, LLPs, companies, trusts, societies and other legal entities;
  • vendors, channel partners and service providers, where appropriate; and
  • Directors, officers, employees, consultants and authorised representatives re- sponsible for onboarding, verification or compliance.

This Policy shall be read together with the Company's AML and CFT Policies.

The extent of KYC and CDD requirements shall depend upon the nature of the rela- tionship, services provided, applicable law and the Company's arrangements with banks, financial institutions, payment service providers and other regulated entities.

This Policy shall be interpreted in accordance with, to the extent applicable:

  • the Prevention of Money Laundering Act, 2002;
  • the Prevention of Money Laundering (Maintenance of Records) Rules, 2005;
  • applicable directions and advisories issued by competent authorities;
  • applicable RBI KYC requirements, where relevant to the Company's business or regulated partner arrangements;
  • the Digital Personal Data Protection Act, 2023, to the extent applicable; and
  • other applicable laws and regulatory requirements.

Where any provision of this Policy conflicts with applicable law, the applicable law shall prevail.

3. Key Definitions

KYC: The process of identifying and verifying a customer or merchant using reliable documents, data or information.

Customer Due Diligence (CDD): The process of obtaining and evaluating infor- mation to understand the identity, ownership, business activities, expected transaction behaviour and associated risks of a customer or merchant.

Enhanced Due Diligence (EDD): Additional verification and monitoring measures applied where higher financial-crime risks are identified.

Beneficial Owner: The natural person who ultimately owns, controls or exercises effective control over a customer or entity, as determined under applicable law.

Officially Valid Document (OVD): A document recognised under applicable law for establishing identity or address.

4. KYC Governance and Responsibilities

The Board of Directors shall have overall oversight of the Company's KYC and CDD framework.

The Company shall designate an appropriate officer or compliance function respon- sible for:

  • implementation of this Policy;
  • overseeing customer and merchant verification;
  • reviewing higher-risk or exceptional cases;
  • maintaining appropriate KYC and due diligence records;
  • coordinating with regulated partner institutions and competent authorities, where required; and
  • periodically reviewing the effectiveness of KYC controls.

Where the Company is legally required to appoint a Designated Director, Principal Officer or other specified officer, such appointment shall be made in accordance with applicable law.

All employees and authorised persons involved in onboarding or verification shall comply with this Policy.

5. Customer Acceptance and Kyc/cdd

The Company shall establish a business relationship only after completing appropri- ate KYC and due diligence based on the nature and risk of the relationship.

The Company may obtain and verify, where applicable:

  • name and date of birth or incorporation;
  • PAN;
  • Aadhaar, where lawfully permitted and applicable, or other officially valid doc- uments;
  • address and contact details;
  • business registration and GST details, where applicable;
  • bank account details;
  • nature of business or occupation;
  • ownership and beneficial ownership information;
  • applicable regulatory registrations;
  • expected transaction profile; and
  • such other information as may reasonably be required.

The Company shall not knowingly establish or continue a relationship with:

  • anonymous or fictitious persons;
  • persons refusing to provide required KYC information;
  • persons providing false, forged or materially misleading information;
  • persons appearing on applicable sanctions or prohibited lists;
  • persons reasonably suspected of involvement in unlawful financial activities; or
  • entities whose identity, ownership or legitimate business purpose cannot rea- sonably be established.

The Company may reject, restrict, suspend or terminate a relationship where satisfac- tory KYC or CDD cannot be completed, subject to applicable law and contractual obligations.

6. Risk-based Due Diligence and Customer Classification

The Company shall apply a risk-based approach to KYC and CDD.

Risk assessment may consider:

  • customer or merchant profile;
  • nature and location of business;
  • ownership and beneficial ownership structure;
  • products and services used;
  • expected transaction volume and behaviour;
  • geographical exposure;
  • mode of onboarding;
  • source of funds, where relevant;
  • regulatory or compliance history; and
  • any other relevant risk factor.

Customers and merchants may be classified as Low, Medium or High Risk based on the overall risk assessment.

Higher-risk relationships may be subject to Enhanced Due Diligence, including:

  • additional documents or information;
  • enhanced verification of identity and beneficial ownership;
  • verification of source of funds or source of wealth, where appropriate;
  • senior management approval;
  • enhanced monitoring; and
  • more frequent review.

No person shall be classified as high-risk solely on the basis of nationality, wealth or legal constitution without considering the overall risk profile.

7. Beneficial Ownership

For non-individual customers, the Company shall take reasonable measures to iden- tify and verify the beneficial owner(s) in accordance with applicable law.

The Company may obtain information relating to:

  • ownership and shareholding;
  • directors or partners;
  • trustees, settlors or beneficiaries, where applicable;
  • persons exercising effective control; and
  • authorised signatories.

Where beneficial ownership cannot be satisfactorily established, the Company may decline or discontinue the relationship, subject to applicable law and contractual ob- ligations.

8. Merchant, Vendor and Partner Due Diligence

The Company shall undertake proportionate due diligence before onboarding mer- chants and, where relevant, material vendors, channel partners or service providers.

Due diligence may include verification of:

  • identity and business registration;
  • PAN and GST registration, where applicable;
  • business address;
  • bank account details;
  • nature of business;
  • ownership and beneficial ownership;
  • website or digital presence, where relevant;
  • applicable regulatory registrations; and
  • other information reasonably required based on the nature and risk of the rela- tionship.

The Company may undertake additional verification where necessary, including dig- ital, telephonic, physical or independent verification, subject to applicable law.

9. Digital and Non-face-to-face Onboarding

Where onboarding is conducted through digital or non-face-to-face channels, the Company shall implement appropriate safeguards to mitigate identity theft, imper- sonation and other relevant risks.

The Company may use legally permissible verification mechanisms, including, where applicable and operationally available:

  • CKYC;
  • DigiLocker;
  • Aadhaar Offline Verification;
  • Digital KYC;
  • Video-based verification;
  • OTP or other secure authentication methods; and
  • other legally permissible verification technologies.

The use of any verification method shall remain subject to applicable law and, where relevant, the requirements of regulated partner institutions.

Additional verification may be undertaken where higher risks are identified.

10. Ongoing Due Diligence and KYC Updation

KYC and CDD shall be an ongoing process.

The Company may review or update customer and merchant information:

  • periodically based on risk;
  • upon material changes in identity, ownership or business activities;
  • where unusual transaction activity is observed;
  • where existing information appears inaccurate or outdated; or
  • where required under applicable law or partner arrangements.

The Company may monitor relevant activities to determine whether they remain con- sistent with the known customer or merchant profile.

Where suspicious activity is identified, appropriate action shall be taken in accord- ance with the Company's AML and CFT Policies.

11. Records, Confidentiality and Compliance

The Company shall maintain appropriate records relating to KYC, customer and mer- chant due diligence, beneficial ownership, risk classification and periodic reviews for the period required under applicable law and contractual obligations.

KYC and personal information shall be handled in accordance with applicable data protection and confidentiality requirements and shall be accessible only to authorised persons on a need-to-know basis.

Employees involved in relevant functions shall receive appropriate KYC and compli- ance training.

The Company shall periodically review the effectiveness of its KYC and CDD con- trols and implement appropriate corrective measures where deficiencies are identi- fied.

Failure to comply with this Policy may result in appropriate disciplinary, contractual or legal action depending upon the nature and seriousness of the violation.

12. Policy Review, Approval and Effective Date

This Policy shall be reviewed periodically and, where appropriate, upon:

  • changes in applicable laws or regulatory requirements;
  • material changes in the Company's business model;
  • introduction of new products or services;
  • significant compliance developments; or
  • findings arising from compliance reviews or audits.

This KYC & CDD Policy has been approved by the Board of Directors of ZEST- FLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.

The Board may amend or replace this Policy from time to time.

CERTIFICATION

All Directors, officers, employees and authorised representatives of ZESTFLOW IN- DIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________