Legal
Anti-money laundering and KYC policy
How we verify the businesses we onboard, watch the transactions we carry, keep records, and report.

Our position
Laitusneo Technologies Pvt. Ltd. builds and operates payment, onboarding and data technology for banks, non-banking financial companies, payment aggregators and merchants. The obligations to know a customer, monitor transactions and report suspicious activity arise under the Prevention of Money Laundering Act, 2002, the Prevention of Money Laundering (Maintenance of Records) Rules, 2005 and the Reserve Bank of India's Master Direction on Know Your Customer.
Where we act as a technology service provider, those obligations rest with the regulated entity we serve, and our systems are built so that it can meet them. Where Laitusneo is itself a reporting entity under the Act, we meet them directly. This page describes what we do in both cases.
Who we onboard, and how
Before a business is given access to a Laitusneo product that moves money or handles customer identity, we establish who it is. That means:
- Verifying the legal identity of the business — its registration, its registered address and its tax identity — against official records rather than against documents alone.
- Identifying the individuals who own or control it, and verifying their identity.
- Understanding what the business does, so that the transactions our technology later carries for it can be judged against what is normal for it.
- Screening the business and its controllers against the sanctions lists that apply in India and against public information on politically exposed persons.
- Declining to onboard a business whose identity cannot be established, or whose activity is unlawful in India or prohibited by the partner bank or payment network whose rails it would use.
No anonymous accounts
We do not open, operate or allow the use of an account or merchant identity that is anonymous, held in a fictitious name, or held on behalf of an undisclosed person. Where a business acts for others — a marketplace, an aggregator of smaller sellers — it must identify those others to the standard the regulated entity requires before they transact.
Ongoing monitoring
Verification at onboarding is a snapshot. Our platforms therefore monitor the transactions they carry against each business's expected pattern — volume, value, frequency, geography and counterparties — and flag what departs from it for review. Customer identity information is refreshed at the intervals the KYC Master Direction sets for the risk category concerned, and immediately if something changes.
Reporting and cooperation
Suspicious transactions, and the cash and cross-border transactions the Rules require to be reported, are reported to the Financial Intelligence Unit – India by the reporting entity in the form and within the time the Rules prescribe. We supply the regulated entities we serve with the data they need to file, and where we are the reporting entity we file ourselves.
We do not tell a customer that a report has been made about it, and we cooperate fully with lawful requests from FIU-IND, the Reserve Bank of India, law-enforcement agencies and courts.
Records
Identity records and transaction records are kept for at least five years — from the end of the business relationship for identity records, and from the date of the transaction for transaction records — as the Rules require, and for longer where a regulator, a partner bank or a proceeding requires it. Records are kept in a form that lets an individual transaction be reconstructed and produced to a competent authority when lawfully asked for.
How identity data is handled
Identity documents and the data extracted from them are collected only for the purpose of verification and the obligations above, encrypted in transit and at rest, stored in India, and accessible only to people whose role requires it. They are not used for marketing and are not shared except with the regulated entity on whose behalf they were collected and with authorities entitled to them.
How we store and protect data more generally is set out in our information security and data storage policy.
Responsibility and training
Responsibility for this policy sits with our compliance function, which reports to the board. Everyone at Laitusneo whose work touches onboarding, transactions or customer data is trained in it when they join and when it changes. The policy is reviewed at least once a year and whenever the law or a regulator's direction changes.
To raise a concern under this policy, or to report activity you believe should be looked at, use the escalation route in our grievance redressal policy and mark the message for the Nodal Officer.
Questions about this page? Write to info@laitusneo.com, or by post to Laitusneo Technologies Pvt. Ltd., NH2 Agra Road, Shanti Colony, Near ITI Chauraha, Etawah, Uttar Pradesh - 206001.
Still have a question?
Legal, privacy and data requests all reach the same inbox and get a reply.


