TOTP Authentication (FedMobile) - Terms and Conditions

TOTP Authentication (FedMobile) - Terms and Conditions

  1. Introduction
    These Terms and Conditions ("Terms") govern the use of the Time-Based One-Time Password ("TOTP") authentication mechanism as a dynamic, time-sensitive authentication factor made available by the Federal Bank Limited (“the Bank”) through its mobile application FedMobile, in accordance with applicable regulatory directions governing authentication mechanisms for digital payment transactions. By accessing, enabling, or using the TOTP authentication mechanism within FedMobile, the Customer acknowledges having read, understood, and agreed to be legally bound by these Terms in their entirety and further acknowledges that TOTP constitutes an additional layer of security intended to enhance the integrity and reliability of transaction authentication and agrees to be bound by its usage as prescribed by the Bank from time to time.
  1. Definition of TOTP
    “TOTP” refers to a time-bound, system-generated one-time password created for validating a specific transaction. TOTP is unique to each transaction and has a limited validity period, after which it expires automatically.
  1. Applicability
    TOTP mechanism shall be applicable for all financial transactions initiated by the Customer through the FedMobile. Each transaction shall be authenticated and processed only upon successful validation of the TOTP, in conjunction with the Customer’s MPIN/UPIN or such other static or additional authentication credential as may be prescribed by the Bank. The Customer acknowledges and agrees that completion of such multi-factor authentication shall constitute valid and binding authorisation for the transaction, and the Bank shall be entitled to rely upon the same for processing the transaction.
  1. Customer Responsibilities
    The Customer acknowledges, agrees and undertakes that:
    1. Customer shall be solely responsible for maintaining the confidentiality and security of the device, FedMobile application, credentials, authentication factors and any information used for generation of the TOTP.
    2. The TOTP displayed within FedMobile shall be used only for the intended transaction.
    3. Customer shall not share, transmit, display, photograph, disclose or otherwise make available the TOTP to any third party, including Bank officials under any circumstances whatsoever.
    4. Customer shall ensure that the transaction is completed within the TOTP validity time window.
    5. Any access to FedMobile or any transaction, instruction, request or activity authenticated using a valid TOTP made through customer’s registered device or authentication mechanism shall be deemed to have been undertaken by the customer and shall be binding upon the customer.
       
  2. Timely Reporting of Compromise
    The Customer shall exercise due diligence in monitoring the use of FedMobile and shall promptly review all transactions undertaken using such services. The Customer shall immediately notify the Bank, through the prescribed channels, upon becoming aware of or having any reasonable suspicion regarding (i) any unauthorised use or access, (ii) any abnormal or suspicious transaction behaviour, or (iii) any irregularity in the operation of the account.
    Without prejudice to the foregoing, the Customer shall, without delay, inform the Bank in the event that the Customer’s registered device, authentication credentials, etc is lost, stolen, compromised, or accessed by any unauthorised person.
    The Customer acknowledges that timely reporting of such events is critical for preventing misuse and mitigating potential losses and agrees that any delay or failure in notifying the Bank may affect the Customer’s rights, including eligibility for protection against unauthorised transactions, in accordance with applicable laws, regulatory guidelines, and the Bank’s policies.
    Notification shall be made through the official customer support channels of the Bank using below details.
    Email: contact@federalbank.co.in
    Resident Customers: 1800 - 425 - 1199 Or 1800 - 420 – 1199
    Non Resident Customers: 0484 - 2630994 or 0484-2630995 or 080-61991199
  1. Transaction Authentication & Flow
    For each transaction initiated where TOTP authentication is prescribed by the Bank, a TOTP will be generated by the Bank’s backend system and presented within the FedMobile application interface. Customer shall be required to acknowledge the TOTP generated through the authentication mechanism and proceed to enter MPIN/UPIN. The Bank will validate both TOTP and MPIN/UPIN before processing the transaction.
  1. TOTP Validity, Expiry and Failure Scenarios
    The TOTP issued by the Bank for the purpose of authenticating a transaction is time-sensitive and shall remain valid only for such limited duration as may be prescribed by the Bank from time to time. The Customer acknowledges and agrees that any TOTP that is invalid, incorrect, or expired at the time of submission shall be automatically rejected, resulting in decline of the transaction, which shall not be processed further. The Customer further understands that an expired TOTP cannot be reused under any circumstances and that any delay in submitting the TOTP within the stipulated validity period may lead to automatic failure or non-processing of the transaction. In such cases, the Customer may, subject to applicable system controls, security protocols, and limits prescribed by the Bank from time to time, initiate a fresh authentication request to obtain a new TOTP for retrying the transaction.
    The Bank reserves the right to impose restrictions on the number of TOTP generation requests and/or transaction retry attempts in order to safeguard against unauthorized access, fraud, or misuse. The Bank shall not be liable for any loss, delay, or inconvenience arising from the Customer’s failure to complete the authentication process within the prescribed validity period or in accordance with the Bank’s security requirements.
     
  2. Security & Confidentiality
    The Customer acknowledges and agrees that the security of TOTP-based authentication is contingent upon the confidentiality and integrity of the Customer’s mobile device, credentials, and access environment. Accordingly, the Bank shall not be liable for any loss, unauthorised transaction, or damage arising directly or indirectly from (i) any negligence, default, or failure on the part of the Customer to safeguard their device, credentials, or TOTP, or failure to adhere to prescribed security practices, or (ii) any compromise, unauthorised access, malware, or security breach affecting the Customer’s mobile device or associated systems.
     
  3. Logging, Monitoring & Audit
    The Customer acknowledges and agrees that the Bank shall be entitled to access, retain and utilise records and system logs in connection with TOTP-based authentication, including but not limited to (i) details of TOTP generation and validation events, (ii) transaction reference numbers along with corresponding timestamps, and (iii) records evidencing Customer authentication and acknowledgements, for legitimate purposes including, without limitation, audit, forensic investigation, fraud detection and prevention, dispute resolution, and compliance with applicable legal and regulatory obligations. The Customer further agrees that such records and logs shall constitute valid and admissible evidence of authentication and transaction processing for all purposes.
     
  4. System Availability, Force Majeure & Liability
    In the event of any failure, delay, or disruption in the generation, transmission, or validation of the TOTP, arising from system limitations, technological issues, network interruptions, or device incompatibility, the relevant transaction shall not be processed or shall stand declined.
    The Customer acknowledges and agrees that the Bank shall not be liable for any loss, delay, or non-execution of any transaction arising directly or indirectly from the unavailability, failure, or malfunction of the TOTP mechanism due to such circumstances, provided that the Bank has acted in accordance with applicable laws and its internal systems and security protocols.
    Further, the Bank shall not be liable for any failure or delay in the performance of its obligations under these Terms to the extent that such failure or delay is caused by events beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemic, war, civil unrest, acts of government, power failures, telecommunications failures, or cyberattacks.
     
  5. Amendments
    The Bank reserves the right to modify, suspend, withdraw or replace the TOTP authentication mechanism, or prescribe additional or alternative authentication requirements, at any time, as may be considered necessary for security, operational, regulatory or risk management process. The Bank further reserves the right to amend, revise, or update these Terms and Conditions from time to time to ensure compliance with applicable laws, regulatory directions, and prevailing security standards. Any such modification or update shall become effective in accordance with the Bank’s prescribed notification or dissemination process, and the continued use of the Bank’s services by the Customer shall be deemed as acceptance of the revised Terms and Conditions.
  1. Customer Consent
     The Customer  provides free, specific, informed, and unambiguous consent to the Bank for the collection, processing, storage, monitoring, and logging of authentication-related data, including but not limited to TOTP authentication events, device identifiers, and associated event logs, for the purposes of security, fraud prevention, regulatory compliance, audit, and service improvement, in accordance with these Terms, the Bank’s Privacy Policy, and the provisions of the Digital Personal Data Protection Act, 2023.
    The Customer further expressly acknowledges and consents to the use of the TOTP mechanism as a valid, secure, and binding mode of transaction authentication. The Customer agrees that successful authentication using TOTP shall constitute sufficient and conclusive proof of the Customer’s identity and authorization for the relevant transaction.
    The Customer furthermore hereby agrees to comply with and be bound by all terms, conditions, instructions, and security requirements governing the use of TOTP as set out herein and as may be prescribed by the Bank from time to time. Continued use of such services shall be deemed to constitute the Customer’s ongoing acceptance of these Terms and Conditions.
     
  2.  Governing Law and Jurisdiction
    These terms shall be governed by the laws of India. Any disputes arising from services shall be subject to the jurisdiction of courts at Ernakulam.