Skip to main content

    Legal

    Regulatory Disclosure Addendum

    Banking & Payment Infrastructure Partner Version. This document provides a technical and regulatory overview of ArosaPay's transaction model for banking institutions, payment service providers, mobile money operators, card networks, and regulatory bodies.

    Last updated: February 2026

    1. Purpose

    This document provides a technical and regulatory overview of ArosaPay's transaction model for banking institutions, payment service providers (PSPs), mobile money operators, card networks, and regulatory bodies.

    This document clarifies:

    • Funds flow structure and transaction lifecycle
    • Operational safeguards and ledger isolation
    • Role separation between ArosaPay and regulated PSP partners
    • Risk controls, reserve policies, and monitoring mechanisms
    • Compliance alignment with applicable regulatory frameworks

    2. Role Classification

    ArosaPay operates as:

    • A transaction orchestration layer
    • A conditional release engine
    • A ledger-based funds routing system

    ArosaPay does not:

    • Hold itself out as a deposit-taking institution
    • Represent itself as a bank
    • Extend credit to any party
    • Provide custody services outside applicable regulatory framework

    ArosaPay integrates with regulated PSP partners for payment collection and payout execution. All funds movement occurs through licensed payment infrastructure.

    3. Funds Flow Summary

    Funds move through defined stages within the ArosaPay transaction lifecycle. Detailed flow documentation is available in the Funds Flow Overview.

    Transaction stages:

    • Buyer Funding Source — Payment initiated by buyer
    • PSP Collection — Funds received by regulated payment service provider
    • Secured Transaction Ledger — Funds recorded and isolated at ledger level
    • Conditional Release — Release triggered upon buyer confirmation or policy resolution
    • Merchant Payable Ledger — Approved amount allocated to merchant
    • PSP Payout Execution — Funds disbursed to merchant via regulated payout rails

    Funds are not:

    • Released at checkout
    • Available to merchant prior to buyer approval
    • Used for platform operating expenses

    Funds are segregated at ledger level throughout the transaction lifecycle.

    4. Segregation & Safeguarding Model

    ArosaPay maintains strict ledger-level segregation between transaction funds, platform revenue, and reserve balances. Full safeguarding methodology is documented in Security & Funds Safeguarding.

    Secured Funds:

    • Are isolated from platform operating balances
    • Are transaction-bound and ledger-restricted
    • Are not commingled with fee revenue

    Merchant Payable Funds:

    • Are derived only upon transaction approval
    • May be subject to reserve retention per risk policy
    • Are eligible for payout per defined schedule

    Reserve Funds:

    • Are retained solely for risk mitigation purposes
    • Are not treated as revenue
    • Are automatically released per applicable reserve policy

    5. Dispute Mechanism

    ArosaPay administers conditional release disputes internally through a structured resolution process. Dispute governance is detailed in the Dispute Resolution Policy.

    During an active dispute:

    • Funds remain in Secured Transaction Ledger
    • No payout occurs to any party
    • Evidence is requested from both buyer and merchant
    • Determination is documented with written rationale

    Possible outcomes:

    • Full refund to buyer
    • Full release to merchant
    • Partial allocation as determined by evidence review

    No funds are moved during an active dispute. Funds remain isolated until determination is issued.

    6. Risk Management Controls

    ArosaPay employs a multi-layered risk management framework. Complete tier methodology is documented in the Merchant Risk & Tier Policy.

    Controls include:

    • Tier-based reserve policies (Tiers 1–4)
    • Dynamic per-transaction and daily volume limits
    • Velocity monitoring across transaction frequency and amount
    • Dispute rate monitoring with automatic tier adjustment
    • Late delivery rate monitoring
    • Identity verification requirements per tier

    Merchant classification is recalculated using rolling 90-day transaction data. Suspicious activity triggers review, restriction, or account suspension.

    7. AML & Fraud Monitoring

    ArosaPay maintains transaction monitoring and fraud detection controls in cooperation with regulated PSP partners.

    Monitoring includes:

    • Transaction pattern analysis
    • Suspicious activity detection and flagging
    • Escalation procedures for high-risk transactions
    • Cooperation protocols with PSP compliance teams

    Where required by law:

    • Suspicious activity reports (SARs) may be filed with relevant authorities
    • Transactions may be frozen pending investigation
    • Information may be disclosed to regulatory or law enforcement authorities

    ArosaPay does not bypass PSP compliance screening. All transaction monitoring operates in conjunction with, not in replacement of, PSP-level controls.

    8. Payout Controls

    Payouts are executed through regulated PSP payout rails following ledger reconciliation and provider confirmation.

    Payout execution requires:

    • Batch processing per defined schedule
    • Ledger reconciliation confirming approved amounts
    • Provider confirmation of recipient account validity

    Payout may be paused if:

    • Account is under investigation
    • Regulatory hold has been issued
    • Risk threshold has been exceeded
    • Active dispute exists on pending payout amount

    9. Incident Response

    ArosaPay maintains documented incident response procedures for operational disruptions. Full incident response framework is documented in the Incident Response & Security Commitment.

    Covered incidents include:

    • Ledger anomaly or reconciliation discrepancy
    • PSP outage or integration failure
    • Security breach or unauthorized access
    • Data compromise affecting transaction records

    Response actions may include:

    • Pause of conditional release logic
    • Suspension of payout execution
    • Initiation of reconciliation audit
    • Notification of relevant PSP and banking partners

    10. Data Sharing & Audit Cooperation

    ArosaPay supports audit cooperation with PSP and banking partners subject to applicable confidentiality obligations.

    Data available to partners may include:

    • Transaction IDs and lifecycle status
    • Funding references and payment confirmations
    • Payout batch reports and settlement records
    • Reserve calculations and retention schedules
    • Risk tier classification and merchant scoring data

    Data sharing is governed by applicable data protection laws and partnership agreements. ArosaPay's data handling practices are documented in the Privacy Policy.

    11. Limitation of Operational Scope

    ArosaPay:

    • Does not independently settle card transactions
    • Does not issue stored value instruments unless separately licensed
    • Does not provide custody of funds outside PSP structure
    • Does not operate as a money transmitter outside applicable licensing

    All funds remain within regulated payment rails. ArosaPay's role is limited to transaction orchestration, conditional release logic, and ledger-based routing between regulated infrastructure providers.

    12. Partner Integration Model

    ArosaPay integrates with PSP partners through standardized APIs and webhook-based event confirmation.

    Integration components:

    • STK push / API-based payment collection
    • Webhook confirmation of payment receipt
    • Payout API for merchant disbursement
    • Settlement reconciliation for batch verification

    No funds are released absent PSP confirmation. All release logic is contingent upon verified payment receipt and buyer confirmation state.

    13. Regulatory Alignment

    ArosaPay operates in alignment with applicable regulatory frameworks across the jurisdictions in which it operates.

    Alignment includes:

    • Applicable consumer protection laws
    • Payment processing regulations and licensing requirements
    • Anti-money laundering (AML) reporting obligations
    • Data protection and privacy laws

    Where required, ArosaPay's licensing or partnership model will align with jurisdictional mandates. ArosaPay cooperates with regulatory authorities and maintains documentation to support compliance verification.

    14. Contact

    For inquiries related to this Regulatory Disclosure Addendum:

    Compliance Inquiries

    compliance@arosapay.com

    Legal Inquiries

    legal@arosapay.com

    This document should be read in conjunction with the Funds Flow Overview, Security & Funds Safeguarding, Merchant Risk & Tier Policy, and Incident Response & Security Commitment.