📍 Built in India for the world. Your privacy comes first. The E1 CBDC platform is launching soon 🚀

Terms and Conditions

Last Modified: September 16, 2026

Introduction

The objectives of these terms of use ("Terms") are to inform you, the reader and user of E1 services, of the terms which apply to the access and use of the E1 Platform (defined below). E1 is also referred to in these Terms as "E1 Tech Finfrastructure".

The E1 Platform enables merchants and businesses to leverage technology to manage their invoicing, payments and collections, banking, accounting, payroll, tax and compliance from a unified dashboard.

These Terms are an electronic record in terms of the Information Technology Act, 2000 and the rules thereunder, as applicable and as amended from time to time. This electronic record is generated by a computer system and does not require any physical or digital signatures. These Terms governing the E1 Platform and Services are published in accordance with the provisions of Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 framed under the Information Technology Act, 2000 (as amended from time to time), and constitute a legally enforceable and binding contract between E1 and the User (as defined below), in line with applicable RBI guidelines.

These Terms consist of the following parts:

  • Part A contains the general terms and conditions which govern the access and use of the web link https://E1high.com and the mobile application by the name of "E1 Tech Finfrastructure" ("Website" or "E1 Platform", which includes any and all related mini-links and the Services provided thereunder), offered by E1 of 1M Global Business Services Private Limited (also referred to as "E1", "E1 Tech Finfrastructure", "Company", "We", "Us" and "Our" as the context requires, and includes its affiliates, including but not limited to E1 Tech Finfrastructure Private Limited and E1 Tech Finfrastructure Financial Technologies, Inc., assigns and Service Providers).
  • Part B contains specific terms and conditions that govern the use of each of the Services (defined below) to the extent such Services are availed by the User. The general terms and conditions provided under Part A ("General Terms") shall be read and understood in conjunction with the Service-specific terms and conditions provided under Part B ("Service Terms").
  • Part C sets out our Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) Policy.
  • Part D sets out our comprehensive declarations on security, data protection, ISO 20022 compliance and interoperability.

General Disclaimer

  • E1 is a technology service provider, a technology and marketing infrastructure provider and a neo-banking platform.
  • We are not a bank or a Non-Banking Financial Company (NBFC), and we do not hold or claim to hold a banking license. We are not a payment service provider, we do not hold a payment aggregator license nor claim to be one, and we are not a direct participant in Prepaid Payment Instruments.
  • We are a futuristic blockchain infrastructure combining centralised and decentralised ledgers, complemented with smart contracts, for easing routine financial activity of various kinds inside a programmable currency distributed by the central banks of various countries.
  • We manage data with futuristic and agentic infrastructure for distributing regulated financial products and services in a closed-loop wallet in the individual capacity of the organisation, and serve other prepaid instrument services and products of semi-closed-loop and open-loop payment services by integrating and through partnered association with Banks and other licensed channel partners and service providers.
  • The business current accounts, Visa, Mastercard and RuPay cards and allied corporate cards, business loans and other similar banking and financial services offered on the E1 Platform are provided by the Banks (defined below), in the centralised ledger handled and managed as per RBI regulations.
  • All funds in savings and current accounts, including a Business Current Account (defined below), are normally insured as per the limits prescribed by the Deposit Insurance and Credit Guarantee Corporation (DICGC). If in doubt, please make an enquiry with the concerned Bank.
  • Banking and financial services offered on the E1 Platform are subject to the security standards and legal requirements prescribed by the Bank, in accordance with extant RBI regulations.

PART A — General Terms and Conditions

These General Terms govern the User's use of and/or access to the Website. These Terms form an integral part of, and will be read in conjunction with:

  • the privacy policy governing the use of the Website, or provided to the User in any other manner or form, which is hosted at www.E1high.com/privacy/ ("Privacy Policy"); and
  • the terms and conditions stipulated by Service Providers (including Banks), which are specifically applicable to the Service(s) availed by You.

1. Definitions

Unless the context otherwise requires, the following capitalised words shall have the meanings assigned to them below.

  • "Admin Verified" refers to the approval provided by the administrator at E1 to the User to use a particular Service or set of Services, subject to the User information submitted, KYC, risk assessment and the execution of any other controls or protocols that may be required to verify and authenticate the User in accordance with applicable laws, including but not limited to the RBI Guidelines.
  • "Acquiring Bank" shall mean any bank which receives funds as sent by the User to the Customer.
  • "Bank" refers to any bank or financial institution that is licensed and regulated by the Reserve Bank of India ("RBI"), which E1 has partnered with towards offering the Services. It is hereby clarified that the term "Bank" also includes any sponsor banks that E1 has partnered with, by establishing software protocols and direct integrations via API.
  • "Business Days" means any day on which banks are open for business in Mumbai, New Delhi and Bengaluru, India.
  • "Business Current Account" refers to a bank account that is linked by the User to the E1 Platform for the settlement of proceeds. The Business Current Account can either be opened afresh with any Bank and linked to the E1 Platform for settlements, or be an existing bank account linked to the E1 Platform upon completion of KYC verification. Usage of the Business Current Account by any User is subject to the terms stipulated by the concerned Bank.
  • "Card Payment Network" includes Visa, Mastercard, the National Payments Corporation of India, American Express, Diners Club and any other card payment network designated as an authorised payment system as per the RBI Guidelines.
  • "Card Payment Network Rules" refers to the written rules, regulations, releases, guidelines, processes, interpretations and other requirements (whether contractual or otherwise) imposed and adopted by the Card Payment Network.
  • "Confirmation of Delivery" refers to the confirmation provided by the User to E1 confirming delivery of goods or services to the Customer, which also authorises E1 to settle funds collected in the Escrow Account to the Business Current Account belonging to the User in accordance with the RBI Guidelines. This authorisation will remain in full force and effect until specifically terminated by the User in writing.
  • "Customer" shall mean any individual or entity that transacts with the User, resulting in a transfer of funds to the User.
  • "Escrow Account" refers to the nodal account or escrow account maintained by E1 with the Bank in accordance with the RBI Guidelines.
  • "Know Your Customer" or "KYC" shall mean the various norms, orders, rules, regulations, laws and statutes as per applicable laws, including the RBI Guidelines issued from time to time, according to which E1 procures personal identification details from the User desiring to access or use the E1 Platform.
  • "E1 Pay" or "User Account" refers to the online account opened by the User in accordance with the onboarding requirements stipulated on the E1 Platform.
  • "Payee" means any person to whom a payment is made using the Services (and includes a User who uses the Services to receive payment).
  • "Payer" means any person who makes a payment using the Services (and includes a User who uses the Services to make payment).
  • "Prohibited Business" refers to any business, business activity or business practice that is expressly prohibited by Us and/or our Service Providers, or deemed illegal or unethical by applicable laws, regulations or commonly accepted business standards, and includes the business activities notified by Us from time to time.
  • "RBI Guidelines" refers to the extant rules, regulations, orders, directions, notifications and guidelines issued by the RBI, including but not limited to the Payment and Settlement Systems Act, 2007, the Guidelines on Regulation of Payment Aggregators and Payment Gateways dated March 17, 2020, and the Master Direction on Know Your Customer (KYC), 2016, as amended from time to time.
  • "Service(s)" means and includes the following services provided by E1 to the User at the request of the User:
    • E1 Pay for payment collections (including CPICBDC, UPI and Chainpay gateway collections);
    • Payment Gateway;
    • Automated Accounting;
    • Multi-Account Connect;
    • Tax Filing and compliance tools;
    • Co-branded prepaid cards;
    • Business Loans;
    • Apps such as E1 Tally, Business Connect, E1 Payroll and integrations; and
    • any other products or services offered by Us on the E1 Platform from time to time.
  • "Service Provider" refers to any entity, association of persons, facility provider, lender, card issuing institution, Bank, card processor or clearing house network whose facilities or services are utilised in the provision of the Services.
  • "Transaction" means a payment instruction that results in the successful transfer of funds (a) from a User to a Payee; or (b) from a Payer to a User, as the context requires.
  • "User", "You", "Your" and "Yourself", as the context requires, refers to and includes any natural person or legal person (sole proprietor, partnership firm, company, LLP, trust, society or HUF) that registers on the E1 Platform and/or transacts or avails Services. The term "User" shall also include such personnel of the User (including but not limited to any current or former officers, directors or employees of the User) who access the E1 Platform using the User Account credentials with either full rights or limited rights, as the case may be.

2. Eligibility

  • The E1 Platform must be accessed and used only by persons who can enter into legally binding contracts under the Indian Contract Act, 1872, by virtue of being "competent to contract" within the meaning of Section 11 of the Indian Contract Act, 1872.
  • The E1 Platform may be accessed and used by Users solely for their legitimate business requirements.

3. Registration and Access

  • To access and use the E1 Platform and Services, You must have a User Account registered on the E1 Platform. The User Account is provided to You by the Company in partnership with the Service Providers, subject to applicable laws (including the RBI Guidelines).
  • You will provide the Company and the Service Providers (as applicable) with all documents and information required to carry out KYC in accordance with the RBI Guidelines. You must provide true, accurate, current and complete information at all times, failing which E1 may at any time reject Your registration and terminate Your right to use or access the E1 Platform and/or Services. For the purpose of conducting KYC on the User, E1 has the right to seek self-attested copies of the documents submitted during or after the registration process.
  • You understand and unconditionally agree that even though You may be allowed to execute transactions on the E1 Platform, funds shall not be settled to Your account if any KYC obligations are pending on Your part, in accordance with the RBI Guidelines. Further, in the event of non-completion of Your KYC obligations, or breach or suspected breach of these Terms, to the satisfaction of E1, We, 1M Global Business Services Private Limited, reserve the right not to release the settlement amounts to You and eventually to reverse the funds to the account from which such payment originated.
  • When You register on the E1 Platform, a User Account will be created based on the information You have provided. You are advised to keep Your User credentials confidential, as You will be solely responsible for anything that happens through Your User Account. You will ensure that the User Account details provided and/or updated are correct and complete at all times. You shall inform E1 of any change in the User's email address, mobile number, address, authorisation, control or legal status, or the cessation of the User's business, by writing to Us within 30 (thirty) Business Days of such change or occurrence.
  • You shall be responsible at all times for maintaining the safety and confidentiality of the username, password and any other information pertaining to the User Account, and for preventing unauthorised access to the User Account and devices. E1 will not be liable for any mistake or misuse of the User Account by the User, by any person authorised by the User, or by any person gaining access to the Services through the User Account. Unauthorised access to or misuse of accounts is strictly prohibited.
  • It shall be Your responsibility to review these Terms periodically for updates and changes. Your continued use of the E1 Platform following any amendment of these Terms will be construed as deemed acceptance of such amendments. Subject to the User's continued compliance with these Terms, E1 grants the User a personal, non-exclusive, non-transferable, limited privilege to access and use the E1 Platform.
  • You will use the E1 Platform only for lawful business activities and will not carry out any activity which is banned, illegal or immoral, or in any manner facilitate the furtherance of any such activity which constitutes a violation of any law or regulation, including but not limited to the RBI Guidelines.
  • It is hereby clarified that any funds lying in the Business Current Account are held by the relevant Bank and shall be governed by the terms framed by that Bank. Funds in the Business Current Account shall belong to the account holder registered in the Bank's records and will be subject to applicable Bank charges.
  • You will be responsible for, and shall indemnify E1 against, any liability, costs or damages arising in connection with (a) the User providing false, incorrect or misleading information; and (b) compromise of the User Account credentials. E1 reserves the right to refuse access to the E1 Platform, terminate accounts, and remove or edit content at any time without notice to the User concerned if these Terms are violated.
  • The User unconditionally authorises E1 to generate Lightweight Directory Access Protocol (LDAP) credentials and User credentials, and to subscribe to the APIs on the sponsor Bank's web portal or software platform on behalf of the User, to facilitate the Services. The User authorises E1 to service the User's Business Current Account on its behalf with regard to queries and complaints raised by the User and/or third parties for the facilitation of the Services, including authorisation to raise queries with the Banks on the User's behalf.

4. Aadhaar Offline e-KYC Verification

There are a number of options for You to complete KYC on the E1 Platform. If You proceed to register on the E1 Platform using Aadhaar Offline e-KYC, You (the Aadhaar holder) hereby irrevocably:

  • place a request to E1 and Perfios Software Solutions Private Limited ("Perfios", formerly known as Karza Technologies Private Limited or "Karza") to access Your Aadhaar Information (defined below) from UIDAI to fetch and verify information regarding Your Aadhaar Number, Aadhaar XML, Virtual ID, e-Aadhaar, Masked Aadhaar, Aadhaar details, demographic information, identity information, Aadhaar-registered mobile number, face authentication details and/or biometric information (collectively, "Aadhaar Information");
  • explicitly authorise E1 and Perfios to fetch Your Aadhaar Information from UIDAI and make it available to E1 and/or any third party, as may be required for completing KYC verification;
  • agree to take all necessary actions required for the purpose of authenticating and verifying Your Aadhaar Information;
  • give a valid, binding, irrevocable and explicit authorisation and consent, as may be required under applicable laws, rules, regulations and guidelines, for availing the Aadhaar API services of Perfios, including but not limited to the transmission and storage of Your Aadhaar Information by E1 and Perfios;
  • understand and agree that this consent has been submitted by You voluntarily and without any coercion from E1, Perfios or any other party;
  • fully understand and accept sole and complete responsibility for any issues, legal suits, damages, losses, penalties, fines or liabilities ("Losses") arising out of Your sharing of Aadhaar Information and authorising E1 or Perfios to fetch Your Aadhaar Information, and agree that You will hold E1 and Perfios, and their representatives, employees and directors, fully harmless for any Losses arising out of such request and actions; and
  • understand and agree that E1 and Perfios do not store or retain any Aadhaar Information, including the Aadhaar number belonging to You, after processing Your request.

5. Fees and Taxes

  • Unless otherwise mutually agreed in writing, You will be charged fees on a case-to-case transaction basis and/or on a prepaid basis, depending on (a) the Services You have requested or availed; and (b) the pricing or subscription plan You have opted for on the E1 Platform (please refer to https://E1high.com/pricing for more details) ("Fee").
  • Subscription plans will be charged on a 30-day monthly or 360-day yearly basis. Your consumption of the Services will continue to be governed by the terms and Fee stipulated for the relevant subscription plan until You expressly upgrade or opt out of that subscription plan.
  • E1 will not refund any amounts charged as Fee unless explicitly agreed as per these Terms, or where a reasonable error is identified in the infrastructure framework.
  • You shall bear all taxes in connection with the levy of all Fees in accordance with applicable laws, including but not limited to goods and services tax (GST), unless exempted and provisioned by the Service Providers or the regulatory authority.

6. Data, Audit and Security

  • E1 may monitor all Transactions to flag and prevent high-risk practices and fraudulent transactions. E1 may also engage Service Providers to assist in these efforts. In the event of any suspicious or unusual activity being carried out through a User Account, such account may be temporarily or permanently suspended.
  • The User and E1 each represent and covenant to the other that: (a) it does not store card information or any related data within its database or any servers accessed by it, except for limited lawful purposes compliant with the RBI Guidelines; (b) it will adhere to the data security protocols prescribed under the RBI Guidelines, including the procedures for incident management and reporting; and (c) its systems and infrastructure are compliant with the Payment Card Industry Data Security Standard ("PCI-DSS"). The User further represents and covenants to E1 that its systems and infrastructure are compliant with the Payment Application Data Security Standard ("PA-DSS"), as applicable.
  • E1 may, at its sole and absolute discretion and without prior notice, conduct inspections, risk and security assessments and audits of the User, and may impose additional conditions or restrictions on the User Account, including but not limited to: (a) establishing a reasonable reserve amount to cover potential Chargebacks (defined below) and related fees; and (b) withholding Services and directing the User to upgrade its infrastructure in compliance with applicable laws.
  • The User will not sell, provide, exchange or otherwise disclose to third parties, or use itself (other than for the purpose of completing a transaction, or as specifically required by law), any personal information about any third party (whether its Customer or otherwise), including financial details and any personal identification information, without obtaining the prior written consent of such third party.
  • We use cookies on the E1 Platform. Most interactive websites use cookies to enable the retrieval of User details for each visit. Cookies are used in some areas of the E1 Platform to enable and enhance functionality and ease of use for Users. By using the E1 Platform, the User consents to the use of cookies in accordance with the Privacy Policy. Some Service Providers may also use cookies.

7. Content

  • Unless specifically permitted by the User, usage of the Services does not grant E1 a license to use, reproduce, adapt, modify, publish or distribute the content created and/or stored in the User Account. Users retain ownership of their content. Notwithstanding the above, the User grants E1 permission to access, copy, distribute, store, transmit, reformat or disclose the data and content of the User Account for the purpose of providing the Services requested or availed by the User.
  • The User may transmit or publish content created by using any of the Services or otherwise. However, the User shall be solely responsible for such content and the consequences of its transmission or publication. Any content that the User may receive from third parties while using the Services is provided to the User "AS IS" for its information and personal use only, and the User agrees not to use, copy, reproduce, distribute, transmit, broadcast, display, sell, license or otherwise exploit such content for any purpose without the express written consent of the person who owns the rights to such content.
  • We are not responsible if information made available on the E1 Platform is not accurate, complete or current. The material on the E1 Platform is provided for general information only and should not be relied upon or used as the sole basis for making decisions without consulting primary, more accurate, more complete or more timely sources of information. Any reliance on the material on the E1 Platform is at the User's own risk. The E1 Platform may contain certain historical information, which is necessarily not current and is provided for the User's reference only. We reserve the right to modify the contents of the E1 Platform at any time, but we have no obligation to update any information on the E1 Platform. The User agrees that it is the User's responsibility to monitor changes on the E1 Platform.

8. Third-Party Links

The E1 Platform may refer to, or contain links to, third-party websites, applications, services and resources, but this does not mean that we endorse such channels. We provide these links only as a convenience to the User to avail certain services. The Company makes no representation or warranty of any kind regarding the accuracy, reliability, effectiveness or correctness of any aspect of any third-party services and, consequently, the Company is not responsible for the content, products or services available from third-party services. The User is responsible for reading and understanding the terms and conditions and privacy policy that apply to the User's use of any third-party services, and the User acknowledges sole responsibility for, and assumes all risks arising from, the User's use of any third-party services.

9. Intellectual Property Rights

All copyrights, patents, trade secrets, trademarks, service marks, trade names, moral rights and other intellectual property and proprietary rights ("IPR") in the E1 Platform and Services shall remain the sole and exclusive property of E1 and its licensors, as applicable. The IPR may not be copied, reproduced, distributed, transmitted, broadcast, displayed, sold, licensed, uploaded or otherwise exploited without the prior written consent of E1.

10. Relationship

  • You understand and agree that nothing contained in these Terms shall be deemed or construed as creating a partnership or joint venture between the User and E1, or as causing either party to be responsible in any way for the debts and obligations of the other party.
  • You will not describe Yourself (whether online or otherwise) as an agent or representative of E1, or make any representations to any User or third party, or give any warranties, which may require E1 or any Service Provider to undertake, or be liable for, whether directly or indirectly, any obligation and/or responsibility to the User or any third party.

11. Confidentiality

  • The User agrees not to disclose, or attempt to use or personally benefit from, any non-public information that it may learn or discover on the Website or through the Services. This obligation shall continue until such time as the non-public information has become publicly known through no action of the User. If the User is compelled by order of a court or other governmental or legal body (or has notice that such an order is being sought) to divulge any such non-public information, the User agrees to promptly and diligently notify E1 and cooperate fully with E1 in protecting such information to the extent possible under applicable law.
  • E1 may access, preserve and disclose any of the User's information if such information is required for the facilitation of any Services to the User as per the User's request, or to ensure compliance with applicable law or orders of regulatory authorities, or if We believe in good faith that it is reasonably necessary to (i) respond to claims asserted against E1 or comply with legal process; (ii) carry out fraud prevention, risk investigation, User support, product development and debugging; or (iii) protect the rights, property or safety of E1, its Users or members of the public.

12. Disclaimer of Warranties and Limitation of Liability

  • In processing Transactions, E1 shall be entitled to rely upon all electronic communications, orders or messages sent to E1 through the Service Providers, to the extent this is in compliance with the processing mechanism of the Service Providers, applicable laws and the RBI Guidelines. E1 shall not be obligated to verify or make further inquiry into the identity of the sender, or the message integrity, of any communications, orders or messages.
  • E1 will endeavour to ensure that access to and availability of the Services remain uninterrupted and error-free. However, access to the application may occasionally be suspended or restricted to allow for repairs, maintenance or the introduction of new facilities and Services, and in such cases E1 shall not be liable for any disruption of any Services. We reserve the right to determine the timing and content of software updates, which may be automatically downloaded and installed by an application at any time without prior notice to the User.
  • The Services are provided on an "as-is" and "as-available" basis. E1 expressly disclaims all warranties of any kind, whether express or implied, including but not limited to the implied warranties of merchantability and fitness for a particular purpose. E1 makes no warranty that the Services will be uninterrupted, timely, secure or error-free. To the maximum extent permitted by law, the entire risk arising out of the User's access to and use of the Website and Services remains with the User. Liability is limited to the extent permitted by law, and a separate limitation of liability shall be applicable to each of the Services.
  • E1 shall not be liable for any breach of these Terms due to any force majeure event that prevents or delays performance of its obligations under these Terms, such as lockdown, act of God, natural disaster, fire, lightning, explosion, flood, adverse weather conditions, power failures, failure in any communication systems, system failures, equipment breakdown, strikes, lock-outs or any other cause beyond the control of E1.

13. Indemnity

The User shall keep E1 indemnified from and against any and all liability (including but not limited to liabilities, judgments, damages, losses, claims, costs and expenses) or any other loss that may occur, arising from or relating to any claim, suit or proceeding brought against E1 by another User, a Service Provider or any third party for reasons including but not limited to: (i) a breach, non-performance, non-compliance or inadequate performance by the User of any of the terms, conditions, representations, obligations or warranties made by it; (ii) misuse of the Services or the provision of false information; and (iii) any acts, errors, misrepresentations, wilful misconduct or negligence of the User, or its employees, subcontractors and agents, in the performance of their obligations under these Terms.

14. Communication Policy

  • As part of the User's use of the Services, the User may receive notifications, offers, discounts, feedback requests and general information from E1 via text messages (SMS) or email.
  • The User understands that receipt of non-service-related communications can be deactivated from the User Account settings or by sending an email to connect@E1high.com, and the User consents ab initio to receive such communications.
  • The User acknowledges that the SMS service provided by E1 is an additional facility provided for the User's convenience and that it may be susceptible to error, omission and/or inaccuracy.

15. Customer Complaints

  • If We receive any general complaint against the User in connection with the use of the E1 Platform, We will forward the complaint to the User's registered email address. The User must respond to the complaint directly within 36 (thirty-six) hours of receiving the complaint as forwarded by E1, and copy E1 in its communications.
  • If the User does not respond to the complainant within 36 (thirty-six) hours from the time of E1's email to the User, We may, at our sole discretion, disclose the User's contact information to the complainant to enable the complainant to take legal action against the User. The User understands that its failure to respond to the forwarded complaint within the 36 (thirty-six) hour time limit will be construed as the User's consent to the disclosure of the User's name and contact information by E1.
  • Notwithstanding the foregoing, the User acknowledges and agrees that (a) E1 can disclose any information relating to the User if it deems, in its sole discretion, that such disclosure is required in the interest of justice; and (b) E1 can withhold or appropriate any settlements due to merchants on reasonable suspicion, to ensure compliance with applicable laws.
  • It is understood that a Transaction is solely between the User and its Customer, and E1 does not provide any guarantees, warranties or delivery-level commitments with respect to the User. Use of the E1 Platform by a User in no way represents any endorsement of that User by E1. E1 will facilitate the mediation of disputes between the User, the Customer and any payment participant concerning the Service(s) offered by E1 through its platform, but does not guarantee their outcome.

16. Suspension and Termination

  • E1 reserves the right to suspend or terminate a User's access to any or all of the E1 Platform and Services, without notice, in the event that:
    • the User breaches these Terms;
    • the User engages in, or is suspected of engaging in, any illegal, fraudulent or abusive activity;
    • the User provides any information that is untrue, inaccurate, not current or incomplete, or We have reasonable grounds to suspect that such information is untrue, inaccurate, not current, incomplete or not in accordance with these Terms; or
    • E1 receives orders to that effect from a competent authority.
  • Such suspension or termination will be without prejudice to E1's right to exercise any other remedy available to it under applicable law.
  • In the event E1 identifies any suspicious or unusual activity being carried out by the User on the E1 Platform, E1 may, at its discretion, temporarily or permanently suspend the User's access to the E1 Platform and/or take such actions as are necessary to mitigate risk, including but not limited to withholding settlements or funds to ensure compliance with laws, or refunding the funds to the source from which such payment originated.

17. Prohibited Services

The User acknowledges and agrees that the Services shall not be utilised in connection with, or to enable or meet the objectives of, any Prohibited Business or prohibited services ("Prohibited Services"). The User's utilisation of the Services is contingent upon the User refraining from the Prohibited Services as stipulated by the Service Providers specific to their offerings. If E1 reasonably suspects that the User is accessing or using the Services in connection with a Prohibited Service, the User agrees that E1 may take such action as it deems fit to mitigate the risk and/or likelihood of risk from such Prohibited Service, including but not limited to reporting the User, blocking the User's funds and refunding the funds collected by the User to source.

18. Governing Law, Jurisdiction and Disputes

  • Without prejudice to the provisions below, these Terms are subject to the laws of India, and any disputes arising out of or in connection with these Terms will be subject to the exclusive jurisdiction of the competent courts at Bengaluru, India.
  • E1 and the User acknowledge and agree that, in the event of any dispute or claim arising out of or in connection with these Terms: (a) the transaction logs maintained by E1 will be the only source of data to verify the accuracy of such transactions; (b) such logs will be fully binding as evidence for the purposes of adjudicating the said dispute or claim; and (c) the said dispute or claim shall be settled by binding arbitration in accordance with the Arbitration and Conciliation Act, 1996 (as amended) and the rules of the Conciliation and Arbitration Centre, Bengaluru, as amended from time to time, and the exclusive seat of arbitration shall be Bengaluru, India.
  • If any part of these Terms is determined to be invalid or unenforceable pursuant to applicable law, including but not limited to the warranty disclaimers and liability limitations set forth herein, the invalid or unenforceable provision will be deemed superseded by a valid, enforceable provision that most closely matches the intent of the original provision, and the remainder of these Terms shall continue in effect.

19. Customer Grievance Redressal

You may contact us with any enquiry, complaint or concern by writing to the Grievance Officer at the coordinates mentioned below:

  • Grievance Officer: Premjith
  • Entity: E1 Tech Finfrastructure or 1M E1 Fintechnologies Private Limited
  • Address: Bengaluru, Karnataka – 560010
  • Email: grievances@E1high.com

PART B — Service Terms and Conditions

The User represents and agrees that usage of the Services mentioned under this Part B will inherently subject the User to the General Terms governing use of the E1 Platform as set out under Part A.

1. E1 Pay

E1 Pay can be used to receive collections for any Transaction arising out of the normal course of business of the User.

By proceeding to use E1 Pay, the User (a) signifies its consent to be bound by these Terms; (b) will be contracting with E1; and (c) acknowledges and agrees that these Terms will constitute the User's binding obligations with E1 while using E1 Pay.

Eligibility

To use E1 Pay, You must: (i) be a tax resident of India; and (ii) be Admin Verified and registered to use E1 Pay on the E1 Platform.

Rights and Obligations

  • No interest is payable by E1 on the amounts maintained by the User in E1 Pay.
  • A User is permitted to operate only 1 (one) E1 Pay account.
  • Any amounts collected by the User into E1 Pay using Payment Gateway Services (defined below) will be subject to the provisions of these Terms governing Payment Gateway Services.
  • The availability of balance on E1 Pay to the User will be subject to receipt of funds into the Escrow Account and the User's continued compliance with these Terms and the RBI Guidelines at all times.
  • Subject to fulfilling the KYC requirements, the User may link its Business Current Account to its E1 Pay account in order to settle Transaction proceeds in accordance with the RBI Guidelines. Once linked, the Transaction amount (minus Fees, as applicable) will be settled to the User's Business Current Account from E1 Pay within T+1 days, where "T" is the date of Confirmation of Delivery by the User to E1. The User shall be solely responsible for providing updated and correct details of the Business Current Account so linked with the E1 Pay account.
  • Notwithstanding anything, the User acknowledges and agrees that where E1 has no control over incoming funds and any delay thereof, E1 will transfer the funds to the merchant in accordance with the RBI Guidelines, and the settlement clock of T+2 (or as the case may be) will commence only after realisation of funds in E1's Escrow Account.
  • Where, as a User, You require E1 to settle the monies collected by E1 in the Escrow Account on Your behalf to a third party, E1 will allow this feature and carry out the settlement solely on Your written instructions, and only if the following conditions and eligibility criteria are met:
    • You have an online presence with an annual turnover above ₹40,00,000 (Rupees Forty Lakhs only);
    • You have successfully completed the full KYC process as per the policy of E1;
    • the third party is the payee that interfaces with the payer for the purchase or delivery of goods, services or investment products for the underlying transaction; and
    • You ensure that complete KYC records of the third party are maintained by You and made available to E1 upon request.

Usage

  • The User authorises E1 to rely on and act upon any instructions provided by the User in respect of its E1 Pay account, and such instructions shall be conclusively presumed, for E1's benefit, to be duly authorised by and legally binding on the User.
  • The User will access and operate its E1 Pay account solely for the debits and credits permitted under the RBI Guidelines.
  • E1 shall be entitled to require any instruction or document in any form to be authenticated by the User by any password, identification code or authentication test as may be specified by E1 from time to time, and the User shall ensure the secrecy and security of such password, code or test. All payments made by the User will be subject to the two-factor authentication system envisaged under the RBI Guidelines.
  • The User acknowledges that there are inherent risks involved in sending instructions, communications or documents to E1 electronically, and accordingly agrees and confirms that all risks in this regard shall be fully borne by the User.

Termination

E1 reserves the right to suspend or discontinue E1 Pay for the User for any reason whatsoever. This includes the following grounds, based on suspicion or otherwise:

  • violation of the RBI Guidelines;
  • violation of any of these Terms;
  • discrepancy in the information and KYC documentation provided by the User;
  • to prevent potential fraud, sabotage, wilful destruction or threat to national security; or
  • where E1, in its sole opinion and discretion, believes that the cessation or suspension of E1 Pay is necessary to meet the ends of justice.

2. Payment Gateway

The E1 Platform enables the User to accept payments from multiple Customer sources, including credit and debit cards, net banking, e-wallets and UPI ("Payment Gateway Services"), subject to continued compliance with these Terms.

Authorisation

  • The User understands that the Payment Gateway Services are provided on the E1 Platform by integrating with various Service Providers in order to provide a single solution for all payment acceptance.
  • The User authorises E1 to hold, receive, disburse and settle funds on the User's behalf, subject to these Terms. This authorisation permits E1 to generate an electronic funds transfer between the payment system providers and the Escrow Account to process each Transaction. The User acknowledges that its continued use of the Payment Gateway Services will be subject to its compliance with the RBI Guidelines. The authorisations provided hereunder by the User will remain in full force and effect until the User Account is closed or terminated in accordance with these Terms.
  • All risk, loss or liability associated with delivery undertaken by the User to its Customers will be solely and absolutely attributable to the User. All disputes regarding quality, merchantability, non-delivery, delay in delivery or otherwise will be handled directly between the User and the Customer, without any reference to E1 as a party to such disputes.

Card Payment Network Rules

  • The Card Payment Networks have provided the infrastructure and processes to enable Transaction authorisation. The Card Payment Networks require the User to comply with the Card Payment Network Rules. The Card Payment Networks reserve the right to amend their guidelines, rules and regulations. We may be required to amend, modify or change these Terms pursuant to amendments to the Card Payment Network Rules, and such amendments, if any, shall be binding on Users with immediate effect.
  • Notwithstanding our assistance in understanding the Card Payment Network Rules, the User expressly acknowledges and agrees that it assumes the risk of compliance with all provisions of the Card Payment Network Rules, regardless of whether the User is aware of or has access to those provisions. RuPay, Mastercard, Visa and American Express make excerpts of their respective rules available on their websites.
  • If the User's non-compliance with the Card Payment Network Rules results in any fines, penalties or other amounts being levied on or demanded of Us by a Card Payment Network, then, without prejudice to Our other rights hereunder, the User shall forthwith reimburse Us an amount equal to the fines, penalties or other amounts so levied, demanded or spent by Us in any manner in relation to such fines, penalties and levies. If the User fails to comply with its obligations towards the Card Payment Network, We may suspend settlement, suspend or terminate the Services or any part thereof forthwith, or freeze and appropriate incoming funds to the User Account.

Settlement

  • All Transactions settled to the User shall be subject to the Fees payable to E1.
  • The availability of balance on E1 Pay to the User will be subject to receipt of funds into the Escrow Account and the User's continued compliance with the RBI Guidelines at all times.
  • Subject to fulfilling the KYC requirements, the User may link its Business Current Account to its E1 Pay account in order to settle Transaction proceeds in accordance with the RBI Guidelines. Once linked, the Transaction amount (minus Fees, as applicable) will be settled to the User's Business Current Account from E1 Pay within T+1 days, where "T" is the date of Confirmation of Delivery by the User to E1. The User shall be solely responsible for providing updated and correct details of the Business Current Account so linked. Notwithstanding anything, the User acknowledges and agrees that where E1 has no control over incoming funds and any delay thereof, E1 will transfer the funds to the merchant in accordance with the RBI Guidelines.
  • If the User so requests, E1 may, at its sole discretion, provide early settlement services with respect to the receivables of the User, to the E1 Pay account or Business Current Account as applicable, at such additional Fees as E1 informs the User in writing.
  • The User understands and unconditionally acknowledges that even if the User is allowed to receive payments using E1 Pay, funds from such transactions will not be settled to the User's E1 Pay account, Business Current Account or any other account until the User completes its KYC obligations in accordance with the RBI Guidelines. If the User continues to default on its KYC obligations, E1 may, at its sole and absolute discretion, refrain from releasing the settlement amounts to the User and reverse the funds to the source from which such payment originated.

Transaction Disputes

  • The User shall adhere to the refund policy stipulated on the User's website, as reviewed and approved by E1 (as applicable). The User agrees that transactions involving the Card Payment Networks may be disputed by the Customer at any time up to 180 (one hundred and eighty) days from the date of the transaction, as per the Card Payment Network Rules. Disputes resolved in favour of the Customer may result in reversal of payments to the Customer ("Chargeback").
  • In the event of rejection or suspension of payments to the User, Chargebacks, refunds and/or any other dispute relating to the Transactions contemplated under these Terms, on any grounds whatsoever ("Transaction Dispute"), E1 will forthwith notify the User of the same.
  • On such notification, the User will conduct an internal review of the matter and will, within the time frame prescribed by E1 in the notification, revert to Us in writing either:
    • requesting Us to refund ("Refund Request") the payment received from the Customer in respect of such Transaction Dispute ("Refund Monies"); or
    • providing Us with a statement explaining why the Transaction Dispute is not warranted, together with all documentary evidence in support of contesting such Transaction Dispute.
  • If the User provides a Refund Request to Us, fails to contest the Transaction Dispute within the timeframe prescribed by E1, or contests the Transaction Dispute without providing supporting documentation to the satisfaction of E1, the Service Provider, the Card Payment Network and/or the issuing Bank, E1 will be entitled to recover the Refund Monies from settlements subsequently made to the User Account.
  • The User will be liable to pay forthwith any Refund Monies, or part thereof, that have not been returned to E1. The parties agree and acknowledge that the Fees charged by E1 in respect of a Transaction Dispute will not be refunded, compensated or paid by us to the User, the Customer or any other person. Further, a Chargeback will be effected within 1 (one) week of the Transaction, and the maximum amount of the Chargeback payable by us to the Customer will be the value of the transaction only.
  • The User also acknowledges and agrees that E1 may route failed Chargeback or refund amounts back to the concerned Customer outside the payment aggregator escrow account, using such payment mechanisms as it deems fit, subject to ensuring compliance with applicable laws at all times.

Fees and Charges

The User acknowledges and agrees that the operation of the Payment Gateway Services includes the deduction, by the Service Provider offering Payment Gateway Services, of amounts owed for service fees and/or Refund Monies (if applicable). Consequently, the amounts receivable by a User from a Customer for a card transaction will be reduced by the deducted fees and refunds.

Miscellaneous

  • If the User acts in violation of applicable laws or breaches these Terms, the Service Provider offering Payment Gateway Services reserves the right to discontinue the availability of Payment Gateway Services to the User, or take such other action as it deems fit in its sole discretion, without prior notice or intimation to the User.
  • The User acknowledges and agrees to prominently display on its website(s) any policies, notices, disclaimers, warranties and indemnities as may be requested in writing, periodically and at its sole discretion, by the Service Provider offering Payment Gateway Services. Failure to adhere to these requirements may result in such Service Provider exercising its discretion to cease providing Payment Gateway Services to the User.
  • Should the User engage in Prohibited Services while utilising the Services, the Service Provider offering Payment Gateway Services reserves the right, without prejudice to its other rights under these Terms, to instruct the User through E1 to promptly discontinue the Prohibited Services. Additionally, such Service Provider may impose such fines for such violations as it deems appropriate, at its sole discretion. This action is independent of such Service Provider's right to cease providing Services to the User if E1 has not terminated the User's access to the E1 Platform and Services.
  • The User acknowledges and agrees that the Service Provider offering Payment Gateway Services may, during the User onboarding process and continuously thereafter, request and acquire necessary details pertaining to the User, including but not limited to information regarding the User's turnover and any other details deemed essential by such Service Provider.
  • The User agrees to incorporate the following elements on its website: (a) privacy statements; (b) identifiers that clearly associate the User's website with the User's trade name for easy recognition; and (c) a statement encouraging its Customers to retain a copy of the transaction record for their records.

3. Multi-Account Connect, Automated Accounting and Tax Filing

Scope

  • This Service allows the User to track its Customer payments and transaction history across various banks under a unified dashboard ("Multi-Account Connect"), and equips the User with automatically generated book-keeping records and reports ("Automated Accounting").
  • You note and agree that E1 is acting only as a technology aggregator for these purposes, and the role of E1 is limited to providing the E1 Platform to You.
  • E1 has partnered with Service Providers who are authorised e-Return Intermediaries (ERI) and Application Service Providers (ASP) under the Electronic Furnishing of Return of Income Scheme, 2007 and the Goods and Services Tax Act, 2017, and may offer ERI Services and ASP Services in the near future.
    • "ERI Services" include (i) income tax return filing and ancillary activities, by adding You as a client on the Income Tax Department's web portal to submit Your Income Tax Return ("ITR") and retrieve information such as Your ITR-V, refund status, Form 26AS, etc.; (ii) easy filing of ITRs by automatically recognising the data from the Form 16 uploaded by You; and (iii) manual filing of ITRs by allowing You to fill in the requisite data in the ITR.
    • "ASP Services" include taking the User's raw data on sales and purchases and converting it into GST returns ("GSTR"). These GSTRs will then be filed on behalf of the filer with GSTN via the GST Suvidha Provider.
  • The User agrees to such terms as are stipulated by E1 and its Service Providers from time to time, if the User undertakes ERI Services and ASP Services from the E1 Platform. The provision of ERI Services through the E1 Platform, and the display of information received from the Service Provider, shall not in any manner constitute any recommendation, advice, opinion or service given by E1.

Exclusion of Liability

The User understands, covenants and confirms that E1 shall not be liable if any unauthorised or incorrect instruction is executed by the User or the concerned Service Provider, resulting in any wrongful amount being debited from or credited to the User. Consequently, E1 expressly excludes any and all direct as well as indirect liability whatsoever which may arise in this regard.

Internet Frauds and Technology Risks

The internet is susceptible to a number of frauds, misuses, hacking and other actions which could affect the use of these Services. While E1 shall aim to provide security to prevent the same, it does not guarantee the User complete protection from such internet frauds, hacking and other actions. There may be instances where the Services require maintenance, during which it may not be possible to process the requests of Users. This could result in delays in, or failure of, the processing of requisite instructions. The User understands and acknowledges that E1 disclaims any and all liability arising out of any failure or inability by E1 to honour any Customer instruction.

Collection of User Data

The information collected for performing these Services ("Data") will be based on the details submitted by the User. The User must provide true, accurate, current and complete Data at all times, failing which the output from this Data may be false, inaccurate, redundant or incomplete.

Use of User Data

The information collected may be used to personalise the User's experience and better match Our responses to the User's requirements wherever possible, and to improve the E1 Platform and/or application based on the information, the User's exact requirements and feedback.

Request for Consent

Consent for the collection of Data, and for the subsequent use of the Data, is deemed to be given by the User when the User decides to avail the Services.

Malicious Behaviour

The E1 Platform shall not allow any party and/or entity that steals data, secretly monitors or harms Users, or is otherwise malicious. Accordingly, the following are expressly prohibited:

  • viruses, trojan horses, malware, spyware or any other malicious software;
  • apps or websites that link to or facilitate the distribution or installation of malicious software;
  • apps or websites that introduce or exploit security vulnerabilities;
  • apps or websites that steal Users' authentication information (such as usernames or passwords), or that mimic other apps or websites to trick Users into disclosing personal or authentication Data;
  • apps or websites that install other apps on a device without the User's prior consent; and
  • apps or websites designed to secretly collect device usage, such as commercial spyware apps.

4. E1 Credit

The terms and conditions published by E1 for credit facilities ("E1 Credit Terms") shall govern the credit and business loan facilities offered on the E1 Platform, as part of the Services, by E1's partner banks and financial institutions regulated by the RBI ("E1 Credit"). By proceeding to use E1 Credit, the User signifies its consent to be bound by the E1 Credit Terms, which shall be read in conjunction with these Terms and the Privacy Policy.

5. Business Connect

The terms and conditions published by E1 for Business Connect ("Business Connect Terms") shall govern the marketplace offered on the E1 Platform as part of the Services ("Business Connect"). By proceeding to use Business Connect, the User signifies its consent to be bound by the Business Connect Terms, which shall be read in conjunction with these Terms and the Privacy Policy.

6. E1 Payroll

E1 offers Users payroll management solutions on the E1 Platform ("E1 Payroll"). The terms and conditions published by E1 for E1 Payroll ("E1 Payroll Terms") shall govern access to and usage of E1 Payroll and any services provided thereunder. By proceeding to use E1 Payroll, the User signifies its consent to be bound by the E1 Payroll Terms, which shall be read in conjunction with these Terms at all times.


PART C — AML / CFT Policy

1. Policy Statement and Commitment

At E1, we are committed to the highest standards of compliance with all applicable laws and regulations relating to Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT).

We recognise that money laundering and terrorist financing pose significant threats to the integrity of the financial system, national security and global economic stability. As a responsible fintech payment platform operating in India, we adhere to the Prevention of Money Laundering Act (PMLA), 2002, the rules framed thereunder, the Reserve Bank of India's (RBI) KYC Directions, and the global compliance standards expected by our payment partners, including ICICI and SBI.

Our policy is designed to:

  • prevent our platform from being exploited by criminals or malicious actors;
  • comply with all regulatory obligations under Indian law and international sanctions frameworks; and
  • protect our customers, partners and the broader financial ecosystem.

2. Scope and Applicability

This policy applies to:

  • E1 and all its subsidiaries;
  • all products and services offered on our platform; and
  • all directors, officers, employees, contractors and agents of E1.

This policy is subject to regulatory oversight, and we are required to maintain effective controls proportionate to our risk exposure. We recognise that non-compliance with relevant laws could expose our company to civil and criminal liability, reputational damage, business restrictions and other serious consequences.

Where differences exist between local Indian regulatory requirements and global policies, the stricter requirements shall be followed.

3. Legal and Regulatory Framework

Our AML/CFT compliance programme is built upon the following key legal and regulatory frameworks:

  • India: Prevention of Money Laundering Act (PMLA), 2002; PML Rules; RBI KYC Master Directions; Unlawful Activities (Prevention) Act (UAPA), 1967.
  • International: Financial Action Task Force (FATF) Recommendations; United Nations Security Council (UNSC) Sanctions.
  • Partner Requirements: ICICI Bank Global Financial Crimes Standards; ICICI Bank AML/KYC Compliance Terms.

We are committed to complying with all applicable AML, CFT, sanctions and export control laws in every jurisdiction where we operate.

4. Our Financial Crimes Programme

Our AML/CFT programme is based on a Risk-Based Approach (RBA) and utilises controls at both the user level and the transaction level.

4.1 Customer Due Diligence (CDD) and KYC

We maintain robust Know Your Customer (KYC) standards and procedures, including:

  • Identification: We verify the identity of our customers using reliable, independent source documents, data or information.
  • Verification: We conduct Video KYC (V-CIP) and Aadhaar-based authentication as permitted by the RBI.
  • Beneficial Ownership: For legal entities, we identify and verify the natural person who ultimately owns or controls the customer (25% ownership threshold for companies; 15% for partnerships and trusts).
  • Customer Risk Categorisation: We classify customers into risk categories (Low, Medium, High) based on their profile, geography, transaction behaviour and nature of business.

4.2 Transaction Monitoring

We maintain continuous transaction monitoring systems designed to:

  • detect suspicious or unusual patterns of activity;
  • identify structuring (smurfing) or attempts to avoid reporting thresholds;
  • flag transactions involving high-risk jurisdictions or sanctioned entities; and
  • monitor Non-Profit Organisations (NPOs) for potential terror financing risks.

4.3 Sanctions Screening

We conduct continuous screening of all customers and transactions against:

  • United Nations Security Council (UNSC) Sanctions Lists (1267/1989 Committee);
  • U.S. Office of Foreign Assets Control (OFAC) lists;
  • European Union, United Kingdom and Canadian sanctions lists; and
  • the RBI's list of designated individuals and entities under the UAPA, 1967.

Any match to a designated terrorist or sanctioned entity will result in the immediate freezing of funds without prior notice to the customer, as required under Section 51A of the UAPA, 1967.

4.4 Prohibited Jurisdictions and Activities

We do not support businesses or transactions directly or indirectly involving:

  • High-risk jurisdictions: Cuba, Iran, North Korea, Syria, and the regions of Crimea, Donetsk and Luhansk.
  • Restricted persons: individuals or entities appearing on any sanctions list maintained by the UN, US, UK, EU or Canada.
  • Prohibited goods and services: any trade with Russia or Belarus involving goods prohibited by law (e.g., luxury goods), or the export of certain professional services to Russia.

E1 reserves the right to decline services to any individual, entity or jurisdiction deemed high-risk, even if such activity is not explicitly prohibited by local law.

5. Reporting Obligations

We are registered as a Reporting Entity under the PMLA, 2002, and adhere to all reporting requirements of the Financial Intelligence Unit – India (FIU-IND).

  • STR (Suspicious Transaction Report): triggered by any transaction (attempted or executed) involving proceeds of crime, regardless of amount. Filed within 7 days of suspicion.
  • CTR (Cash Transaction Report): triggered by cash receipts or payments aggregating more than ₹10 lakh in a single month. Filed by the 15th of the following month.
  • NTR (Non-Profit Transaction Report): triggered by transactions involving registered Non-Profit Organisations. Filed monthly or as prescribed.

Confidentiality: All information furnished to FIU-IND is strictly confidential. "Tipping-off" (informing a customer that they are being reported) is a criminal offence under the PMLA.

6. Politically Exposed Persons (PEPs)

If a customer is identified as a Politically Exposed Person (PEP), meaning a current or former senior foreign or domestic public official, their family members or close associates, we will:

  • obtain senior management approval before establishing or continuing the business relationship;
  • conduct Enhanced Due Diligence (EDD), including establishing the source of funds and source of wealth; and
  • implement enhanced ongoing monitoring of the relationship.

7. Record Keeping

We maintain all records (transaction data, CDD documents, account files and STR evidence) for a minimum period of 5 years from the date of the transaction, or 5 years after the business relationship ends, whichever is later, as required under Section 12 of the PMLA.

Records are stored securely, with access restricted to authorised personnel only.

8. Employee Training and Awareness

All employees of 1M Global Business Services Private Limited must complete mandatory AML/CFT training:

  • Induction Training: for all new hires, covering PMLA obligations, KYC norms and red flag indicators.
  • Annual Refresher: updates on regulatory changes, emerging typologies and case studies.
  • Specialised Training: for compliance and risk teams, on advanced transaction monitoring and STR filing.

Employees are protected from retaliation for reporting suspicious activity in good faith.

9. Role of the Principal Officer

We have designated a Principal Officer as required under Rule 2 of the PML Rules. The Principal Officer is:

  • an officer at the managerial level (Head of Compliance/Risk);
  • the central point of contact with law enforcement agencies (FIU-IND, Police, Enforcement Directorate); and
  • responsible for receiving and reporting Suspicious Transaction Reports (STRs).

Contact for AML/CFT enquiries: compliance@e1high.com

10. Policy Review and Updates

This policy is effective immediately and will be reviewed:

  • annually by the Compliance Department;
  • upon any material change in Indian regulations (PMLA/RBI updates) or partner requirements (ICICI/SBI policy changes); and
  • following any enforcement action or regulatory finding.

We reserve the right to amend this policy without prior notice to customers; however, updated versions will be posted on this page with a new effective date.


PART D — Comprehensive Declarations: Security and Data Protection

1. Banking-Grade Security Commitment

M/s 1M Global Business Services Private Limited ("the Company", "we", "us") is committed to protecting the confidentiality, integrity and availability of all client data, financial transactions and digital assets. We implement and maintain security measures that meet or exceed the standards required of licensed banking and financial institutions globally.

2. Regulatory and Compliance Frameworks

Our security infrastructure is designed in alignment with the following internationally recognised standards and regulatory frameworks:

  • PCI-DSS Level 1: All payment card data is processed, stored and transmitted in strict compliance with the Payment Card Industry Data Security Standard (PCI-DSS) Level 1, the highest level of certification available in the payments industry.
  • ISO/IEC 27001 and 27017: Our Information Security Management System (ISMS) is architected in accordance with ISO/IEC 27001 (Information Security Management) and ISO/IEC 27017 (Cloud Security Controls).
  • SOC 2 Type II: Our operational processes, system availability, processing integrity, confidentiality and privacy are subject to independent third-party audits under the Service Organization Control (SOC) 2 Type II framework.
  • GDPR and DPDP Compliance: We adhere to the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act (DPDP), ensuring lawful processing, data minimisation and the protection of personal data for all users.
  • FIPS 140-2 Level 3: Cryptographic key generation, storage and management are secured using Hardware Security Modules (HSMs) certified to FIPS 140-2 Level 3 standards.

3. Encryption and Data Protection

  • Data in Transit: All data transmitted between users, servers and third-party financial institutions is encrypted using Transport Layer Security (TLS) 1.3 or higher. No sensitive data is transmitted over unencrypted channels.
  • Data at Rest: All sensitive client data, transaction records and digital asset metadata are encrypted at rest using AES-256 (Advanced Encryption Standard) or equivalent military-grade encryption algorithms.
  • Key Management: Cryptographic keys are generated, stored and rotated using secure Hardware Security Modules (HSMs). Private keys controlling digital assets are never stored in plaintext, on hot servers or in a single geographic location.

4. Digital Asset and Wallet Security

For clients utilising our digital asset custody, wallet infrastructure and programmable asset services, we implement the following additional safeguards:

  • Multi-Party Computation (MPC): Private keys are fragmented using Multi-Party Computation protocols. No single entity, server or employee has access to a complete private key. Transactions require collaborative cryptographic signing across multiple secure nodes.
  • Deep Cold Storage: The majority of client digital assets are held in air-gapped, geographically distributed cold storage facilities. Physical access to these facilities requires multi-factor biometric authentication and is restricted to authorised personnel only.
  • Programmable Security Rules: Where applicable, digital assets are secured using programmable smart contract logic, including transaction time-locks, address whitelisting and multi-signature authorisation requirements at the asset layer, rendering unauthorised access mathematically ineffective.
  • Regular Penetration Testing: Our wallet infrastructure, cross-chain bridges and smart contracts undergo regular, independent penetration testing and security audits by reputable third-party blockchain security firms.

5. Access Control and Monitoring

  • Principle of Least Privilege: Employee and system access to sensitive data and infrastructure is granted on a strict need-to-know basis. All access rights are reviewed and recertified quarterly.
  • Multi-Factor Authentication (MFA): MFA is mandatory for all internal systems, administrative panels and client-facing account access.
  • 24/7 Security Operations Center (SOC): Our infrastructure is monitored continuously by a dedicated Security Operations Center using AI-driven anomaly detection, intrusion detection systems (IDS) and intrusion prevention systems (IPS).
  • Immutable Audit Logs: All administrative actions, transaction events and system changes are recorded in tamper-evident, immutable audit logs to ensure full traceability and accountability.

6. Business Continuity and Disaster Recovery

  • Redundancy: All critical systems are deployed across multiple, geographically separated data centres to ensure there is no single point of failure.
  • Disaster Recovery: We maintain a comprehensive Disaster Recovery Plan (DRP) with defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets for critical financial and operational data.
  • Regular Testing: Disaster recovery and incident response plans are tested, reviewed and updated at least annually.

7. Incident Response and Notification

In the unlikely event of a security breach or data incident that may affect client data or digital assets, the Company will:

  • immediately activate its Incident Response Plan to contain, investigate and remediate the breach;
  • notify affected clients and relevant regulatory authorities within the timeframes mandated by applicable law (e.g., within 72 hours under the GDPR); and
  • provide transparent communication regarding the nature of the incident, the data affected and the steps being taken to resolve the issue.

8. Limitation of Liability and Shared Responsibility

While the Company undertakes all commercially reasonable and industry-standard measures to secure client data and digital assets, clients acknowledge that:

  • Credential Security: Clients are responsible for maintaining the confidentiality of their own login credentials, API keys and multi-factor authentication devices. The Company shall not be liable for losses resulting from a client's failure to protect its own access credentials.
  • Blockchain Irreversibility: Transactions executed on public or private blockchain networks are immutable. Once a transaction is confirmed on the ledger, it cannot be reversed, frozen or recovered by the Company. Clients are solely responsible for verifying wallet addresses and transaction details prior to execution.
  • Standardisation: Our systems are audited bi-quarterly under the STQC Directorate, and maintain standard compatibility and adherence to ISO/IEC 27001 by undergoing bi-quarterly vulnerability assessments.
  • Programmable Asset Rules: For programmable digital assets, clients are responsible for correctly configuring and reviewing their own security rules (e.g., whitelists, time-locks, multi-signature thresholds) prior to deployment. The Company provides the infrastructure but does not assume liability for losses resulting from client-configured smart contract logic.
  • Force Majeure: The Company shall not be directly or indirectly liable for security failures or service interruptions caused by events beyond its reasonable control, including but not limited to natural disasters, acts and consequences of war, government sanctions or global internet infrastructure failures.

9. ISO 20022 Compliance and Interoperability

9.1 Commitment to Global Financial Messaging Standards

1M Global Business Services Private Limited ("the Company", "we", "us", "our") is committed to building institutional-grade infrastructure that seamlessly bridges decentralised networks, Central Bank Digital Currencies (CBDCs) and traditional global finance. To ensure maximum interoperability, transparency and straight-through processing (STP), our payment orchestration engines, settlement layers and cross-chain data protocols are architected in alignment with the ISO 20022 international standard for electronic data interchange.

9.2 Structured Data and Message Formats

Our platform utilises structured, data-rich messaging formats (including ISO 20022 XML and JSON) to facilitate the exchange of financial information between our infrastructure and external financial institutions. Depending on the service utilised, our systems are designed to generate, parse and transmit standard ISO 20022 message types, including but not limited to:

  • pain.001 (Customer Credit Transfer Initiation): for corporate payment initiation and automated fiat on/off-ramp routing via our Chainpay Gateway.
  • pacs.008 (Financial Institution to Financial Institution Customer Credit Transfer): for high-value, interbank and wholesale CBDC (wCBDC) settlement routing.
  • camt.052 / camt.053 (Bank to Customer Account Report / Statement): for real-time reconciliation, providing clients with structured end-of-day or intraday ledger reports that integrate directly with core banking and ERP systems (e.g., SAP, Oracle, Finacle).

9.3 Straight-Through Processing (STP) and Reconciliation

By utilising ISO 20022 data envelopes, our infrastructure ensures that payment instructions, remittance data, purpose codes and ultimate beneficiary details travel alongside the transaction value. This enables automated straight-through processing, significantly reducing manual intervention, minimising reconciliation errors and accelerating settlement times across both fiat and blockchain rails.

9.4 Enhanced Compliance and AML Screening

We recognise that structured data is critical for modern financial compliance. Our ISO 20022-compliant payloads are designed to carry comprehensive originator and beneficiary information. This allows for highly accurate, automated Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF) and international sanctions screening in real time, without delaying the finality of the underlying asset transfer or smart contract execution.

9.5 Interoperability with Legacy and Central Bank Networks

As the global financial system migrates to ISO 20022, our platform is designed to act as a translation and routing layer between heterogeneous systems. Our architecture supports interoperability with:

  • The SWIFT Network: facilitating the transition from legacy MT (unstructured text) messages to MX (ISO 20022) structured messaging.
  • Central Bank Settlement Systems: ensuring compatibility with national Real-Time Gross Settlement (RTGS) systems, including but not limited to the Reserve Bank of India (RBI) SFMS/NEFT/RTGS networks, the Bank of Japan (BOJ-NET) and other major central bank infrastructures.
  • Datachain Interoperability Protocols: wrapping cross-chain smart contract events in ISO 20022 data envelopes to ensure that value moving between disparate ledgers (e.g., Hyperledger Fabric, Corda, public chains) maintains institutional-grade data integrity and auditability.

9.6 Limitation of Liability and Third-Party Network Dependencies

While the Company employs commercially reasonable efforts to maintain ISO 20022 compliance, clients acknowledge and agree that:

  • Third-Party Bank Rejection: The Company is not liable for transaction delays, failures or rejections caused by a receiving bank, intermediary bank or central bank failing to correctly parse, accept or process ISO 20022 messages due to its own legacy system limitations or configuration errors.
  • Standard Evolution: The ISO 20022 standard is maintained by the ISO 20022 Registration Authority (RA) and is subject to continuous updates, versioning changes and regional implementation guidelines (e.g., HVPS+ for high-value payments). The Company reserves the right to update its APIs and message schemas to comply with new versions of the standard. We will provide reasonable notice of any breaking changes, but we shall not be held liable for service interruptions required to maintain compliance with evolving global standards.
  • Data Accuracy: Clients are solely responsible for ensuring the accuracy, completeness and legality of the data fields (including remittance information, tax details and purpose codes) they input into the Chainpay Gateway or sovereign currency infrastructure prior to the generation of the ISO 20022 message.

9.7 Continuous Certification and Auditing

The Company actively monitors updates from the ISO 20022 Registration Authority, SWIFT and regional central banks. Where applicable, our integration partners and payment processors undergo regular compliance testing to ensure ongoing adherence to global messaging standards.

10. Third-Party Services

Our platform may integrate with third-party services, including but not limited to payment processors, blockchain networks, cloud infrastructure providers and identity verification vendors. While we conduct rigorous security due diligence on all third-party partners, the Company is not responsible for the security practices or data handling policies of these external providers. Clients are encouraged to review the security policies of any third-party services integrated with their account.

11. Updates to This Security Policy

The Company reserves the right to update, modify or enhance this Security Clause at any time to reflect changes in our security infrastructure, regulatory requirements or industry best practices. Material changes will be communicated to clients via email or a prominent notice on our website at least 30 days prior to taking effect. Continued use of our services following the effective date of any changes constitutes acceptance of the updated Security Policy.