1. Purpose

IDYC360 Private Limited (“IDYC360”) is a B2B FinTech/RegTech technology provider offering real-time entity-centric Fraud & AML Intelligence to financial institutions.

This Fair Practices Code (“Code”) sets out the principles IDYC360 follows in its dealings with customers, prospective customers, partners, vendors and other stakeholders.

This Code is an organisational conduct framework for a technology provider. IDYC360 does not currently undertake lending, deposit-taking or other regulated credit activities, and this Code should not be interpreted as an RBI Fair Practices Code applicable to an NBFC/lender unless such requirements become applicable to IDYC360 in the future.

2. Core Principles

IDYC360 will conduct business with integrity, transparency, fairness, confidentiality and accountability. The Company will seek to:

  • Communicate product capabilities and limitations accurately;
  • Avoid misleading, exaggerated or unsubstantiated claims;
  • Provide clear commercial and contractual terms;
  • Protect confidential and personal information;
  • Support responsible use of fraud/AML intelligence;
  • Provide reasonable channels for queries, complaints and escalation;
  • Avoid unfair discrimination, conflicts of interest, bribery or improper inducements.

3. Fair and Transparent Product Representation

IDYC360 will describe its platform, integrations, deployment options, performance and validation status accurately.

Demonstrations, proposals and marketing material must distinguish laboratory/synthetic validation from production financial-institution results.

IDYC360 will not represent a model score, graph indicator, alert or AI/ML output as conclusive proof of fraud or wrongdoing.

Risk intelligence is intended to support authorised financial-institution decisioning, investigation and governance.

4. Responsible AI, FPSM and Risk Decisioning

IDYC360 uses proprietary FPSM, AI/ML, behavioural analytics, geo intelligence and graph/network scoring.

These capabilities will be deployed with appropriate explainability, traceability and customer-defined governance.

Where a financial institution uses IDYC360 outputs for customer-impacting actions, the institution remains responsible for its approved policies, legal/regulatory obligations, human oversight and final decisions unless responsibilities are expressly agreed otherwise.

IDYC360 will support review of relevant risk rationale and evidence generated by the platform.

5. Customer Engagement and Contracting

Before deployment, IDYC360 will seek to clearly communicate the agreed scope, use cases, integration responsibilities, service levels, security responsibilities, support arrangements, fees and material limitations.

Changes that materially affect agreed scope, pricing, data processing or service obligations should be documented and communicated through the applicable commercial/change-control process.

Confidential customer information will not be used to unfairly advantage another customer or competitor.

6. Pricing and Commercial Fairness

Pricing will be communicated transparently through proposals, order forms or agreements and may vary according to deployment model, transaction volume/TPS, modules, implementation effort, support requirements and other agreed commercial factors.

IDYC360 will not impose undisclosed charges.

Taxes, third-party costs, implementation charges or usage-based components, where applicable, should be identified in the relevant commercial documentation.

Material pricing changes for an existing engagement will follow the applicable contract.

7. Data Privacy and Confidentiality

IDYC360 will process customer and financial-institution data only for authorised purposes and in accordance with applicable agreements, its Data Privacy Policy and applicable law.

The platform is designed to support data minimisation and pseudonymised/tokenised entity identifiers where feasible.

IDYC360 will not sell FI customer data or disclose one institution’s confidential data to another institution without appropriate authority.

Access will be restricted on a need-to-know and least-privilege basis.

8. Information Security and Operational Integrity

IDYC360 will maintain proportionate technical and organisational safeguards for systems and data under its control, including:

  • Authenticated access;
  • Role-based access control;
  • Encryption controls;
  • Audit logging;
  • Environment segregation;
  • Monitoring;
  • Backup and recovery;
  • Controlled administrative access as applicable to the deployment.

Security incidents affecting customer data or service integrity will be handled through defined investigation, containment, remediation and notification processes consistent with contractual and applicable legal requirements.

9. Fair Access and Non-Discrimination

IDYC360 will not discriminate unfairly in business dealings on grounds unrelated to legitimate commercial, security, regulatory or risk considerations.

Access to product functions and data will be governed by authorised roles, contractual scope and security requirements rather than arbitrary treatment.

10. Conflicts of Interest, Gifts and Improper Influence

Employees and representatives must avoid situations in which personal interests improperly influence business decisions.

Bribery, kickbacks, facilitation payments and improper inducements are prohibited.

Gifts or hospitality, if any, must be reasonable, lawful, transparent and must not be offered or accepted with the intent of influencing procurement, evaluation, regulatory interaction or other business decisions.

11. Intellectual Property and Competitive Fairness

IDYC360 will respect third-party intellectual property, contractual restrictions and confidential information.

Likewise, proprietary IDYC360 algorithms, scoring logic, source code, models and technical know-how will be disclosed only to the extent contractually required and appropriately protected.

The Company will compete on product capability, service quality, innovation and value and will not knowingly make false or disparaging statements about competitors.

12. Complaints and Grievance Handling

Customers and stakeholders may raise concerns regarding commercial conduct, privacy, service, security or other matters through IDYC360’s designated business channel at [email protected] .

Complaints will be acknowledged, assessed and routed to the appropriate responsible person.

Material complaints should be documented, investigated fairly and resolved or escalated within a reasonable timeframe based on severity and contractual obligations.

Retaliation against a person raising a good-faith concern is prohibited.

13. Financial-Institution and Regulatory Cooperation

IDYC360 will cooperate in good faith with authorised customer due diligence, audits, investigations and regulatory/supervisory requests applicable to services provided, subject to legal authority, confidentiality, security and contractual requirements.

Information supplied to banks, financial institutions, RBIH or other authorised ecosystem stakeholders will be accurate to the best of the Company’s knowledge and will distinguish current capabilities from roadmap items or planned certifications.

14. Business Continuity and Customer Protection

IDYC360 will maintain proportionate continuity, backup and recovery arrangements for services under its control.

For pilots or production deployments, exit, data return/deletion, support transition and service discontinuation responsibilities will be governed by the applicable agreement and data-retention requirements.

15. Third Parties and Partners

IDYC360 expects contractors, implementation partners and approved service providers acting on its behalf to maintain standards consistent with this Code.

Third-party access to confidential or production data must be authorised, necessary for the service and subject to appropriate confidentiality and security obligations.

16. Governance, Training and Review

Management is responsible for promoting and overseeing this Code. Relevant personnel should be made aware of the principles applicable to their roles.

Suspected breaches must be reported and may result in corrective or disciplinary action as appropriate.

This Code will be reviewed at least annually and earlier where material changes occur in IDYC360’s business model, products, applicable law, regulatory expectations or customer requirements.

17. Contact

Questions or concerns relating to this Fair Practices Code may be addressed to:

IDYC360 Private Limited
Email: [email protected]

Adoption note: This Code should be formally approved by IDYC360 management/Board- authorised authority and communicated to relevant personnel before being represented as an implemented organisational policy.