Org Registration Agreement

DEEP DIAGNOSTICS (PVT) LTD — CPDfy PLATFORM
ORGANISATION REGISTRATION AGREEMENT
Form Ref: CPDfy/ORG/v1.0  |  Effective 18 August 2026


INSTRUCTIONS. This Agreement is to be completed by an organisation applying to register as a CPD provider on the CPDfy platform. Complete all sections in BLOCK CAPITALS using black ink. The form must be signed by a person authorised to bind the organisation and bear the organisation's official seal. Return the signed Agreement with all supporting documents listed in Section G to cpdfy@deepdiagnostics.lk. The organisation workspace will not be activated until this Agreement is received, verified and approved.

SECTION A — ORGANISATION DETAILS

A1. Registered legal name: _________________________________________________________

A2. Trading name (if different): ___________________________________________________

A3. Company / society / institution registration no.: ______________________________

A4. Date of incorporation / establishment: ______ / ______ / __________

A5. Organisation type: [   ] Professional body   [   ] Hospital / healthcare   [   ] University / academic
    [   ] Training provider   [   ] Regulatory / accrediting body   [   ] Corporate   [   ] Other: ______________

A6. Registered address:
______________________________________________________________________________________
______________________________________________________________________________________

A7. Country: ______________________________    A8. Postal code: ____________________

A9. Official telephone: ____________________________________________________________

A10. Official email domain: ________________________________________________________

A11. Website: ______________________________________________________________________

A12. Tax identification no. (TIN / VAT): ___________________________________________

SECTION B — ACCREDITATION AND CPD AUTHORITY

B1. Is the Organisation accredited or authorised to award CPD credit?   [   ] Yes    [   ] No

B2. Accrediting / regulatory body: _________________________________________________

B3. Accreditation reference no.: ___________________________________________________

B4. Accreditation valid from ______ / ______ / __________ to ______ / ______ / __________

B5. Professional disciplines covered: ______________________________________________
______________________________________________________________________________________

B6. Anticipated number of CPD events per year: ________    B7. Anticipated certificates per year: ________

SECTION C — AUTHORISED REPRESENTATIVE

The person legally empowered to bind the Organisation and accountable for its compliance.

C1. Full name: _____________________________________________________________________

C2. Designation: ___________________________________________________________________

C3. NIC / Passport no.: ____________________________________________________________

C4. Official email: ________________________________________________________________

C5. Direct telephone: ______________________________________________________________

SECTION D — PRIMARY PLATFORM ADMINISTRATOR

The individual who will hold the initial Organisation Administrator account. If different from Section C, that individual must also submit an Organisation User Access Control Agreement.

D1. Full name: _____________________________________________________________________

D2. Designation: ___________________________________________________________________

D3. Official email (this will be the login): _______________________________________

D4. Contact telephone: _____________________________________________________________

SECTION E — DATA PROTECTION

E1. Data Protection Officer / responsible person: __________________________________

E2. Contact email: _________________________________________________________________

E3. The Organisation confirms it has a lawful basis under the Personal Data Protection Act No. 9 of 2022 for the personal data it will collect through the platform:   [   ] Yes    [   ] No

E4. Retention period the Organisation will apply to EXPIRED certificates and the participant data they contain (see clause F7A):

    [   ] Retain indefinitely, so the credential remains permanently verifiable

    [   ] Retain for ________ years after expiry, then delete or anonymise

    [   ] Other (specify): ____________________________________________________

E5. Certificate validity period the Organisation will apply: ________ years ________ months (default: 2 years from event date)

SECTION F — DECLARATIONS AND UNDERTAKINGS

The Organisation, acting through its Authorised Representative, declares, undertakes and agrees as follows:

F1. Binding terms. The Organisation has read, understood and agrees to be bound by the CPDfy Terms of Service, Platform Regulations and Privacy Policy, as amended from time to time, which are incorporated into this Agreement by reference.

F2. Accuracy of information. All information given in this Agreement and all supporting documents are true, accurate and complete. The Organisation will notify Deep Diagnostics in writing within fourteen (14) days of any material change, including any change, suspension, lapse or withdrawal of accreditation.

F3. Authority to bind. The signatory is duly authorised to execute this Agreement on behalf of the Organisation and to bind it to these obligations.

F4. Accreditation integrity. The Organisation holds all accreditations, approvals and authorisations it asserts, and will not represent on the platform any accreditation, verification or CPD authority it does not genuinely hold.

F5. Genuine activities. Every event published will be a genuine CPD activity, actually delivered, and accurately described as to date, duration, delivery mode, learning outcomes and CPD value. CPD credit will be assigned in accordance with the rules of the relevant accrediting body.

F6. Certificate integrity. Certificates will be issued only to individuals who genuinely attended, participated in or completed the activity concerned, in accordance with published criteria. The Organisation will not issue, procure, backdate, alter or facilitate any certificate that misrepresents attendance, participation, completion or CPD credit, and acknowledges that doing so may constitute a criminal offence under the Computer Crimes Act No. 24 of 2007.

F6A. Certificate validity and renewal. The Organisation will set a certificate validity period consistent with the requirements of its accrediting body, and understands that where none is set a default of two (2) years from the event date applies. The Organisation will not extend, re-date or reactivate an expired certificate, and will issue a renewal certificate only where the participant has genuinely completed a documented refresher, reassessment or update activity, cross-referenced to the superseded certificate and supported by evidence produced on audit.

F7. Controller responsibility. The Organisation is the data controller in respect of participant personal data it collects through the platform, and Deep Diagnostics acts as its processor. The Organisation warrants that it has a lawful basis for all collection and processing it directs, has issued all required privacy notices, and has obtained all necessary consents.

F7A. Retention of expired certificates. The Organisation acknowledges that expiry of a certificate does not delete it or the personal data it contains, and that an expired certificate remains stored and publicly verifiable with an expired status until the Organisation instructs otherwise. As data controller, the Organisation undertakes to: (a) define and document a retention period for expired certificates, as stated in Section E4; (b) disclose that period in its own privacy notice to participants; (c) instruct Deep Diagnostics in writing where expired records are to be deleted or anonymised; and (d) review its expired certificate holdings at least annually. The Organisation accepts that responsibility for compliance with the storage limitation requirements of the Personal Data Protection Act No. 9 of 2022 in respect of expired certificates rests with it as controller, and not with Deep Diagnostics as processor.

F8. User access control. The Organisation will grant workspace access on a least-privilege basis, only to individuals who have executed an Organisation User Access Control Agreement; will revoke access within seven (7) days of a person ceasing to be authorised; and will review its user access list at least annually. The Organisation is liable for the acts and omissions of its users as if they were its own.

F9. Breach notification. The Organisation will notify Deep Diagnostics at cpdfy@deepdiagnostics.lk of any personal data breach or suspected unauthorised access affecting platform data within twenty-four (24) hours of becoming aware of it.

F10. Acceptable use. The Organisation will not use the platform for any unlawful purpose, will not send unsolicited bulk communications, will not attempt to circumvent access controls or subscription limits, and will not access data belonging to any other organisation.

F11. Intellectual property. The Organisation warrants that it holds all rights necessary in any logo, seal, signature image, template or content it uploads, and grants Deep Diagnostics the licence set out in the Terms of Service for the sole purpose of operating the platform.

F12. Cooperation with audit. The Organisation will cooperate fully with any compliance audit or investigation, and will provide requested evidence — including proof of accreditation, attendance records or evidence of event delivery — within fourteen (14) days of request.

F13. Fees. The Organisation will pay all applicable subscription fees when due and acknowledges that access may be suspended or downgraded where fees remain unpaid.

F14. Indemnity. The Organisation will indemnify and hold harmless Deep Diagnostics against all claims, losses, fines, penalties and reasonable costs arising from its breach of this Agreement or applicable law, from its content or certificates, or from any claim by a participant or regulator relating to its CPD activities or its processing of personal data.

F15. Sanctions. The Organisation acknowledges that breach may result in warning, feature restriction, revocation of certificates, withdrawal of verified provider status, suspension or termination of access, and referral to the relevant professional regulator, the Data Protection Authority or law enforcement, and that no refund of fees is payable in respect of any period of suspension or termination for breach.

F16. Governing law. This Agreement is governed by the laws of the Democratic Socialist Republic of Sri Lanka, and the parties submit to the exclusive jurisdiction of the competent courts of Colombo.

F17. No guarantee of registration. The Organisation acknowledges that submission of this Agreement does not guarantee registration or activation, and that Deep Diagnostics may approve, refuse, defer or revoke any application at its sole discretion.

SECTION G — SUPPORTING DOCUMENTS CHECKLIST

The following must be enclosed. Incomplete applications will not be processed.

[   ] Certificate of incorporation / registration of the Organisation

[   ] Evidence of accreditation or CPD-awarding authority (if claimed in Section B)

[   ] Board resolution or letter of authority empowering the Section C signatory

[   ] Copy of NIC / passport of the Authorised Representative

[   ] Organisation logo in high resolution (PNG or SVG)

[   ] Completed Organisation User Access Control Agreement for the Section D administrator

[   ] Tax registration certificate (if applicable)

SECTION H — EXECUTION

Signed for and on behalf of the Organisation by its duly Authorised Representative:

Signature: ____________________________________________

Name in block capitals: _________________________________________

Designation: ____________________________________________________

Date: ______ / ______ / __________

Official seal / rubber stamp of the Organisation:




______________________________

WITNESS

Signature: ____________________________________________

Name in block capitals: _________________________________________

NIC no.: ________________________________________________________

Address: ________________________________________________________

Date: ______ / ______ / __________


SECTION I — FOR OFFICIAL USE ONLY (Deep Diagnostics)

I1. Date received: ______ / ______ / __________    I2. Application ref.: __________________

I3. Documents complete: [   ] Yes    [   ] No    I4. Accreditation verified: [   ] Yes    [   ] No    [   ] N/A

I5. Authority of signatory verified: [   ] Yes    [   ] No

I6. Subscription tier assigned: ____________________________________________________

I7. Verified CPD provider status: [   ] Granted    [   ] Not granted

I8. Decision: [   ] Approved    [   ] Refused    [   ] Deferred pending further information

I9. Notes: _________________________________________________________________________

I10. Approved by: __________________________    Signature: _________________________    Date: ______ / ______ / __________


Deep Diagnostics (Pvt) Ltd — No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
cpdfy@deepdiagnostics.lk  |  +94 77 988 5043  |  https://provider.cpdfy.com