Org Registration Agreement
DEEP DIAGNOSTICS (PVT) LTD — CPDfy PLATFORM
ORGANISATION REGISTRATION AGREEMENT
Form Ref: CPDfy/ORG/v1.0 | Effective 18 August 2026
INSTRUCTIONS. This Agreement is to be completed by an organisation applying to register as a CPD provider on the CPDfy platform. Complete all sections in BLOCK CAPITALS using black ink. The form must be signed by a person authorised to bind the organisation and bear the organisation's official seal. Return the signed Agreement with all supporting documents listed in Section G to cpdfy@deepdiagnostics.lk. The organisation workspace will not be activated until this Agreement is received, verified and approved.
SECTION A — ORGANISATION DETAILS
A1. Registered legal name: _________________________________________________________
A2. Trading name (if different): ___________________________________________________
A3. Company / society / institution registration no.: ______________________________
A4. Date of incorporation / establishment: ______ / ______ / __________
A5. Organisation type: [ ] Professional body [ ] Hospital / healthcare [ ] University / academic
[ ] Training provider [ ] Regulatory / accrediting body [ ] Corporate [ ] Other: ______________
A6. Registered address:
______________________________________________________________________________________
______________________________________________________________________________________
A7. Country: ______________________________ A8. Postal code: ____________________
A9. Official telephone: ____________________________________________________________
A10. Official email domain: ________________________________________________________
A11. Website: ______________________________________________________________________
A12. Tax identification no. (TIN / VAT): ___________________________________________
SECTION B — ACCREDITATION AND CPD AUTHORITY
B1. Is the Organisation accredited or authorised to award CPD credit? [ ] Yes [ ] No
B2. Accrediting / regulatory body: _________________________________________________
B3. Accreditation reference no.: ___________________________________________________
B4. Accreditation valid from ______ / ______ / __________ to ______ / ______ / __________
B5. Professional disciplines covered: ______________________________________________
______________________________________________________________________________________
B6. Anticipated number of CPD events per year: ________ B7. Anticipated certificates per year: ________
SECTION C — AUTHORISED REPRESENTATIVE
The person legally empowered to bind the Organisation and accountable for its compliance.
C1. Full name: _____________________________________________________________________
C2. Designation: ___________________________________________________________________
C3. NIC / Passport no.: ____________________________________________________________
C4. Official email: ________________________________________________________________
C5. Direct telephone: ______________________________________________________________
SECTION D — PRIMARY PLATFORM ADMINISTRATOR
The individual who will hold the initial Organisation Administrator account. If different from Section C, that individual must also submit an Organisation User Access Control Agreement.
D1. Full name: _____________________________________________________________________
D2. Designation: ___________________________________________________________________
D3. Official email (this will be the login): _______________________________________
D4. Contact telephone: _____________________________________________________________
SECTION E — DATA PROTECTION
E1. Data Protection Officer / responsible person: __________________________________
E2. Contact email: _________________________________________________________________
E3. The Organisation confirms it has a lawful basis under the Personal Data Protection Act No. 9 of 2022 for the personal data it will collect through the platform: [ ] Yes [ ] No
E4. Retention period the Organisation will apply to EXPIRED certificates and the participant data they contain (see clause F7A):
[ ] Retain indefinitely, so the credential remains permanently verifiable
[ ] Retain for ________ years after expiry, then delete or anonymise
[ ] Other (specify): ____________________________________________________
E5. Certificate validity period the Organisation will apply: ________ years ________ months (default: 2 years from event date)
SECTION F — DECLARATIONS AND UNDERTAKINGS
The Organisation, acting through its Authorised Representative, declares, undertakes and agrees as follows:
F1. Binding terms. The Organisation has read, understood and agrees to be bound by the CPDfy Terms of Service, Platform Regulations and Privacy Policy, as amended from time to time, which are incorporated into this Agreement by reference.
F2. Accuracy of information. All information given in this Agreement and all supporting documents are true, accurate and complete. The Organisation will notify Deep Diagnostics in writing within fourteen (14) days of any material change, including any change, suspension, lapse or withdrawal of accreditation.
F3. Authority to bind. The signatory is duly authorised to execute this Agreement on behalf of the Organisation and to bind it to these obligations.
F4. Accreditation integrity. The Organisation holds all accreditations, approvals and authorisations it asserts, and will not represent on the platform any accreditation, verification or CPD authority it does not genuinely hold.
F5. Genuine activities. Every event published will be a genuine CPD activity, actually delivered, and accurately described as to date, duration, delivery mode, learning outcomes and CPD value. CPD credit will be assigned in accordance with the rules of the relevant accrediting body.
F6. Certificate integrity. Certificates will be issued only to individuals who genuinely attended, participated in or completed the activity concerned, in accordance with published criteria. The Organisation will not issue, procure, backdate, alter or facilitate any certificate that misrepresents attendance, participation, completion or CPD credit, and acknowledges that doing so may constitute a criminal offence under the Computer Crimes Act No. 24 of 2007.
F6A. Certificate validity and renewal. The Organisation will set a certificate validity period consistent with the requirements of its accrediting body, and understands that where none is set a default of two (2) years from the event date applies. The Organisation will not extend, re-date or reactivate an expired certificate, and will issue a renewal certificate only where the participant has genuinely completed a documented refresher, reassessment or update activity, cross-referenced to the superseded certificate and supported by evidence produced on audit.
F7. Controller responsibility. The Organisation is the data controller in respect of participant personal data it collects through the platform, and Deep Diagnostics acts as its processor. The Organisation warrants that it has a lawful basis for all collection and processing it directs, has issued all required privacy notices, and has obtained all necessary consents.
F7A. Retention of expired certificates. The Organisation acknowledges that expiry of a certificate does not delete it or the personal data it contains, and that an expired certificate remains stored and publicly verifiable with an expired status until the Organisation instructs otherwise. As data controller, the Organisation undertakes to: (a) define and document a retention period for expired certificates, as stated in Section E4; (b) disclose that period in its own privacy notice to participants; (c) instruct Deep Diagnostics in writing where expired records are to be deleted or anonymised; and (d) review its expired certificate holdings at least annually. The Organisation accepts that responsibility for compliance with the storage limitation requirements of the Personal Data Protection Act No. 9 of 2022 in respect of expired certificates rests with it as controller, and not with Deep Diagnostics as processor.
F8. User access control. The Organisation will grant workspace access on a least-privilege basis, only to individuals who have executed an Organisation User Access Control Agreement; will revoke access within seven (7) days of a person ceasing to be authorised; and will review its user access list at least annually. The Organisation is liable for the acts and omissions of its users as if they were its own.
F9. Breach notification. The Organisation will notify Deep Diagnostics at cpdfy@deepdiagnostics.lk of any personal data breach or suspected unauthorised access affecting platform data within twenty-four (24) hours of becoming aware of it.
F10. Acceptable use. The Organisation will not use the platform for any unlawful purpose, will not send unsolicited bulk communications, will not attempt to circumvent access controls or subscription limits, and will not access data belonging to any other organisation.
F11. Intellectual property. The Organisation warrants that it holds all rights necessary in any logo, seal, signature image, template or content it uploads, and grants Deep Diagnostics the licence set out in the Terms of Service for the sole purpose of operating the platform.
F12. Cooperation with audit. The Organisation will cooperate fully with any compliance audit or investigation, and will provide requested evidence — including proof of accreditation, attendance records or evidence of event delivery — within fourteen (14) days of request.
F13. Fees. The Organisation will pay all applicable subscription fees when due and acknowledges that access may be suspended or downgraded where fees remain unpaid.
F14. Indemnity. The Organisation will indemnify and hold harmless Deep Diagnostics against all claims, losses, fines, penalties and reasonable costs arising from its breach of this Agreement or applicable law, from its content or certificates, or from any claim by a participant or regulator relating to its CPD activities or its processing of personal data.
F15. Sanctions. The Organisation acknowledges that breach may result in warning, feature restriction, revocation of certificates, withdrawal of verified provider status, suspension or termination of access, and referral to the relevant professional regulator, the Data Protection Authority or law enforcement, and that no refund of fees is payable in respect of any period of suspension or termination for breach.
F16. Governing law. This Agreement is governed by the laws of the Democratic Socialist Republic of Sri Lanka, and the parties submit to the exclusive jurisdiction of the competent courts of Colombo.
F17. No guarantee of registration. The Organisation acknowledges that submission of this Agreement does not guarantee registration or activation, and that Deep Diagnostics may approve, refuse, defer or revoke any application at its sole discretion.
SECTION G — SUPPORTING DOCUMENTS CHECKLIST
The following must be enclosed. Incomplete applications will not be processed.
[ ] Certificate of incorporation / registration of the Organisation
[ ] Evidence of accreditation or CPD-awarding authority (if claimed in Section B)
[ ] Board resolution or letter of authority empowering the Section C signatory
[ ] Copy of NIC / passport of the Authorised Representative
[ ] Organisation logo in high resolution (PNG or SVG)
[ ] Completed Organisation User Access Control Agreement for the Section D administrator
[ ] Tax registration certificate (if applicable)
SECTION H — EXECUTION
Signed for and on behalf of the Organisation by its duly Authorised Representative:
Signature: ____________________________________________
Name in block capitals: _________________________________________
Designation: ____________________________________________________
Date: ______ / ______ / __________
Official seal / rubber stamp of the Organisation:
______________________________
WITNESS
Signature: ____________________________________________
Name in block capitals: _________________________________________
NIC no.: ________________________________________________________
Address: ________________________________________________________
Date: ______ / ______ / __________
SECTION I — FOR OFFICIAL USE ONLY (Deep Diagnostics)
I1. Date received: ______ / ______ / __________ I2. Application ref.: __________________
I3. Documents complete: [ ] Yes [ ] No I4. Accreditation verified: [ ] Yes [ ] No [ ] N/A
I5. Authority of signatory verified: [ ] Yes [ ] No
I6. Subscription tier assigned: ____________________________________________________
I7. Verified CPD provider status: [ ] Granted [ ] Not granted
I8. Decision: [ ] Approved [ ] Refused [ ] Deferred pending further information
I9. Notes: _________________________________________________________________________
I10. Approved by: __________________________ Signature: _________________________ Date: ______ / ______ / __________
Deep Diagnostics (Pvt) Ltd — No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
cpdfy@deepdiagnostics.lk | +94 77 988 5043 | https://provider.cpdfy.com