Privacy

Effective date: 18 August 2026
Last updated: 18 August 2026

This Privacy Policy explains how Deep Diagnostics (Pvt) Ltd ("we", "us", "our"), of No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka, collects, uses, discloses, retains and protects personal data through the CPDfy platform, including provider.cpdfy.com and form.cpdfy.com (the "Platform").

We process personal data in accordance with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka ("PDPA") and other applicable law.

1. Our Role: Controller and Processor

1.1. Where we are the controller. We act as data controller in respect of: account registration and authentication data; organisation registration and verification records; subscription and billing data; support correspondence; and security, audit and telemetry data generated by operation of the Platform.

1.2. Where we are the processor. When a Provider Organisation creates Forms, collects responses, manages Events and issues Certificates, that organisation is the data controller and we process personal data on its documented instructions as its processor. Questions about why particular data was collected, or requests to erase Event or response data, should be directed to the relevant Provider Organisation in the first instance.

1.3. We do not sell personal data, and we do not use Participant data submitted to Provider Organisations for our own marketing.

2. Personal Data We Collect

2.1. Account and identity data

  • Name, email address, and password (stored only as a salted cryptographic hash — we never store passwords in readable form);
  • Email verification status and account activation status;
  • Where you sign in using a third-party provider, the identifier, name, email address and profile image released by that provider under your authorisation.

2.2. Professional profile data

  • Institution or employer, occupation and designation, primary service type, professional credentials and qualifications;
  • Organisation membership, assigned role and permissions;
  • Mentor records where applicable.

2.3. Organisation data

  • Organisation name, tagline, biography, logo, social links, contact details and address;
  • Accreditation details, registration numbers and CPD provider verification status;
  • Authorised representative and administrator contact details;
  • Subscription tier, entitlements and usage against feature limits.

2.4. Event, Form and response data

  • Event details, and the content of Forms created by Provider Organisations;
  • Responses submitted to those Forms, whose fields are determined by the Provider Organisation and may include your name, email address, professional details, attendance confirmation and feedback;
  • Submission timestamp and identity verification method and status.

2.5. Technical and device data collected on form submission

To protect the integrity of CPD records, deter fraudulent or duplicate submissions, and provide an audit trail, we record with each Form response:

  • IP address;
  • Device identifier and device type;
  • Browser name, operating system and full user-agent string;
  • Screen resolution.

This data is collected on the basis of our and the Provider Organisation's legitimate interest in preventing certificate fraud and preserving the evidential value of CPD records.

2.6. Certificate and verification data

  • Certificate metadata, issuance records, cryptographic signature data, and revocation status;
  • Certificate access, download and verification logs, including timestamp and requesting IP address.

2.7. Communications data

  • Email delivery logs, including recipient address, subject, dispatch status, delivery outcome and failure reason;
  • Bulk email batch records;
  • Support correspondence with us.

2.8. Documentation submitted for activation

  • Completed Organisation Registration Agreements and Organisation User Access Control Agreements, and any supporting identity, authority or accreditation documentation you submit to us for verification.

3. Purposes and Lawful Bases

We process personal data for the following purposes:

  • To provide the Platform — creating and administering accounts, organisations, Events, Forms and Certificates. Basis: performance of a contract.
  • To verify identity and activate accounts — reviewing submitted agreements and supporting documents. Basis: performance of a contract; legitimate interests.
  • To issue, deliver and verify Certificates — including generation, cryptographic signing, email delivery and public verification. Basis: performance of a contract; legitimate interests.
  • To prevent fraud and protect record integrity — including device and IP telemetry, verification retry limits and audit logging. Basis: legitimate interests; compliance with legal obligation.
  • To secure the Platform — monitoring, logging, incident detection and investigation. Basis: legitimate interests; legal obligation.
  • To communicate with you — service notices, verification codes, certificate delivery and support responses. Basis: performance of a contract; legitimate interests.
  • To administer subscriptions and billing. Basis: performance of a contract; legal obligation.
  • To comply with law — responding to lawful requests from regulators, courts and authorities. Basis: legal obligation.
  • To improve the Platform — analysing aggregated and anonymised usage. Basis: legitimate interests.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

4. Disclosure of Personal Data

4.1. We disclose personal data only as follows:

  • To the relevant Provider Organisation — a Provider Organisation can access the responses, Participant records and Certificates within its own workspace. Organisation workspaces are logically isolated from one another.
  • To service providers acting on our instructions — including hosting and infrastructure providers, email delivery services, authentication providers, and document rendering components. These are bound by written confidentiality and data protection obligations and may process data only as instructed.
  • Publicly, where you or your organisation choose — public organisation profiles, published Event pages, and Certificate verification pages are accessible without login. A verification page discloses only what is necessary to confirm authenticity.
  • To authorities — where required by law, court order or regulatory direction, or to establish, exercise or defend legal claims.
  • In a corporate transaction — to a successor in the event of a merger, acquisition or transfer of assets, subject to equivalent protection.

4.2. We do not sell, rent or trade personal data.

5. International Transfers

5.1. Personal data is primarily stored and processed in Sri Lanka. Certain sub-processors, including email delivery and cloud infrastructure providers, may process data outside Sri Lanka.

5.2. Where personal data is transferred outside Sri Lanka, we take reasonable steps to ensure an adequate level of protection consistent with the PDPA, including contractual safeguards with the recipient.

6. Retention

6.1. We retain personal data only as long as necessary for the purposes for which it was collected:

  • Account and profile data — for the life of the account, and up to twenty-four (24) months after closure to handle disputes and satisfy legal obligations.
  • Form responses and Event records — for as long as the Provider Organisation maintains them, subject to its own retention policy and instructions.
  • Certificates and issuance records — retained so long as the Certificate remains verifiable, as verifiability is fundamental to its purpose. Revoked Certificates retain a revocation record.
  • Expired Certificates — Certificates carry a validity period set by the issuing Provider Organisation, being by default two (2) years from the Event date. Expiry does not delete the record. An expired Certificate remains stored, and its verification page remains publicly accessible showing an expired status, so that it continues to evidence past attendance. The retention period for expired Certificates is determined by the Provider Organisation as data controller, which is required to define that period, disclose it in its own privacy notice, and instruct us in writing where records are to be deleted or anonymised. We retain expired Certificate records until we receive such an instruction. If you wish an expired Certificate to be erased, contact the issuing organisation in the first instance, or contact us and we will refer your request to it.
  • Certificate access and verification logs — automatically pruned ninety (90) days after creation.
  • Email delivery logs — retained for up to twelve (12) months for deliverability and dispute resolution.
  • Security and audit logs — retained for up to twelve (12) months, or longer where required for an active investigation.
  • Activation documentation — retained for the life of the relationship and seven (7) years thereafter, consistent with statutory record-keeping obligations.
  • Financial records — retained as required by Sri Lankan tax and company law.

6.2. On expiry of the applicable period, data is deleted or irreversibly anonymised.

7. Security

7.1. We implement appropriate technical and organisational measures, including:

  • encryption of data in transit using TLS;
  • passwords stored only as salted cryptographic hashes;
  • cryptographic signing of Certificates to detect tampering;
  • role-based access control and organisation-level data isolation;
  • email verification and retry limits on verification codes to deter brute-force attempts;
  • audit logging of administrative and certificate actions;
  • restriction of sensitive administrative functions to authorised personnel;
  • regular backups.

7.2. No method of transmission or storage is completely secure. Whilst we work to protect your data, we cannot guarantee absolute security.

7.3. In the event of a personal data breach likely to result in risk to affected individuals, we will notify the Data Protection Authority and affected individuals as required by the PDPA and without undue delay.

8. Your Rights

8.1. Subject to the conditions and exemptions in the PDPA, you have the right to:

  • Access — obtain confirmation of whether we process your personal data, and a copy of it;
  • Rectification — have inaccurate or incomplete data corrected;
  • Erasure — request deletion where the data is no longer necessary or was processed unlawfully;
  • Withdraw consent — where processing is based on consent;
  • Object — object to processing based on legitimate interests, on grounds relating to your particular situation;
  • Restriction — request that processing be restricted in defined circumstances;
  • Data portability — receive certain data in a structured, commonly used, machine-readable format;
  • Not be subject to a decision based solely on automated processing producing legal or similarly significant effects.

8.2. How to exercise your rights. Contact us at cpdfy@deepdiagnostics.lk. We will respond within twenty-one (21) days, and where a request is complex we may extend that period and will tell you why.

8.3. We may need to verify your identity before acting on a request.

8.4. Important limitation. Erasure of an issued Certificate record may not be possible where retention is necessary for the integrity of a professional CPD record, to comply with a legal obligation, or to establish or defend legal claims. We will explain our reasoning if we cannot fully comply. This limitation applies to expired Certificates as well as current ones — an expired Certificate remains evidence that you attended the activity at the time, and the issuing organisation may have a legitimate or legal basis for continuing to hold that record. Where erasure is granted, it is irreversible: the Certificate can no longer be verified by anyone, and you will lose the ability to evidence that credential through the Platform.

8.5. Where your data was collected by a Provider Organisation, we will refer your request to that organisation as controller and assist it in responding.

9. Complaints

9.1. If you are dissatisfied with how we have handled your personal data, please contact us first at cpdfy@deepdiagnostics.lk so we can attempt to resolve the matter.

9.2. You have the right to lodge a complaint with the Data Protection Authority of Sri Lanka established under the Personal Data Protection Act No. 9 of 2022.

10. Cookies and Similar Technologies

10.1. We use strictly necessary cookies to maintain your session, keep you signed in, and protect against cross-site request forgery. These are essential and cannot be disabled without impairing the Platform.

10.2. We use limited functional storage to remember interface preferences.

10.3. We do not use third-party advertising or cross-site tracking cookies.

10.4. Blocking essential cookies through your browser will prevent you from signing in or submitting Forms.

11. Children

11.1. The Platform is intended for professionals and is not directed at persons under eighteen (18). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it.

12. Changes to this Policy

12.1. We may update this Policy. The effective date above will be revised, and material changes will be notified by email or in-platform notice not less than fourteen (14) days before taking effect.

13. Contact

Deep Diagnostics (Pvt) Ltd — Data Protection
No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
Email: cpdfy@deepdiagnostics.lk
Telephone: +94 77 988 5043