Regulations

Effective date: 18 August 2026
Last updated: 18 August 2026

These Platform Regulations (the "Regulations") are issued by Deep Diagnostics (Pvt) Ltd and govern the conduct of all Provider Organisations, organisation users, mentors and Participants on the CPDfy platform. They are incorporated into, and form a binding part of, the Terms of Service. Capitalised terms have the meanings given in the Terms of Service.

Breach of these Regulations is a material breach of the Terms of Service and may result in suspension, revocation of Certificates, termination of access, and referral to professional regulators or law enforcement.

1. Purpose and Scope

1.1. These Regulations exist to protect the integrity of continuing professional development records issued through the Platform, to safeguard personal data, and to maintain the trustworthiness of CPDfy Certificates and verification records.

1.2. They apply to every User, in every organisation workspace, in respect of every Event, Form, Certificate and communication made through the Platform.

2. Provider Organisation Standards

2.1. A Provider Organisation must at all times:

  • hold and maintain the accreditations, registrations and professional authorisations it asserts on its public profile;
  • ensure that every Event it publishes is genuine, is actually delivered, and is described accurately as to date, duration, venue or delivery mode, learning outcomes and CPD value;
  • assign CPD points or credits in accordance with the rules of the relevant accrediting or regulatory body, and not inflate them;
  • ensure that any organisation seal, signature image, logo or accreditation mark it uploads is authentic and lawfully used;
  • maintain a designated Authorised Representative accountable for compliance; and
  • respond to reasonable compliance enquiries from Deep Diagnostics within seven (7) working days.

2.2. Claims of "verified CPD provider" status may only be displayed where that status has been granted by Deep Diagnostics. Verification status is granted, withheld and withdrawn at our sole discretion and does not constitute accreditation.

3. Event and Form Conduct

3.1. Forms must collect only data that is adequate, relevant and limited to what is necessary for the stated purpose of the Event.

3.2. Forms must not request national identity card numbers, passwords, payment card data, biometric data, or health data unless there is a clear lawful basis and a demonstrable necessity, and appropriate safeguards are in place.

3.3. The Participant email field is a mandatory, protected field and must not be removed, disabled or circumvented. Email verification controls must not be bypassed.

3.4. Events and Forms must not be used to collect data for marketing or any purpose unrelated to the CPD activity without separate, informed and freely given consent.

3.5. Content published on Events, Forms and organisation profiles must be lawful, accurate, professional, and free from discriminatory, defamatory or misleading material.

4. Certificate Integrity

4.1. A Certificate may be issued only to a Participant who genuinely attended, participated in, or completed the activity to which it relates, in accordance with the criteria published for that Event.

4.2. The following are strictly prohibited and constitute Certificate Fraud:

  • issuing a Certificate for an Event that did not take place;
  • issuing a Certificate to a person who did not meet the published attendance or completion criteria;
  • backdating a Certificate or misstating the date, duration or CPD value of an activity;
  • altering, forging or reproducing a Certificate, digital signature, badge or verification record outside the Platform;
  • issuing Certificates in bulk to individuals who did not individually participate;
  • selling, or offering to sell, Certificates or CPD credit divorced from genuine participation;
  • extending, re-dating, reactivating or otherwise circumventing the expiry of an expired certificate, save by issuing a renewal certificate strictly in accordance with clause 4.7; or
  • knowingly permitting or concealing any of the above.

4.3. Certificates carry cryptographic signatures and verification records. Any attempt to defeat, strip, spoof or reproduce these mechanisms is a serious breach and may constitute a criminal offence under the Computer Crimes Act No. 24 of 2007.

4.4. Where a Certificate has been issued in error, the issuing Provider Organisation must revoke it through the Platform without delay and notify the affected Participant.

4.5. Validity period. Every certificate carries an expiry date derived from the event date and the validity period configured by the issuing Provider Organisation. Where no period is configured, a default of two (2) years from the event date applies. Provider Organisations must set a validity period consistent with the requirements of the relevant accrediting or regulatory body, and must not set an artificially long period in order to inflate the apparent currency of a credential.

4.6. Effect of expiry. On expiry the certificate is automatically marked EXPIRED on its verification page and no longer returns a valid verification result. A Provider Organisation must not represent an expired certificate as current, and must not state or imply that an expired certificate continues to carry CPD credit.

4.7. Renewal. An expired certificate may not be extended, re-dated or reactivated. A Provider Organisation may issue a renewal certificate only where the participant has genuinely completed a documented refresher, reassessment or update activity. A renewal certificate must:

  1. be issued as a new certificate, with its own issuance record, verification entry and validity period;
  2. record the date of the refresher activity actually completed, and not the date of the original activity;
  3. cross-reference the superseded certificate so that the credential history is traceable; and
  4. be supported by attendance or assessment evidence, retained by the Provider Organisation and produced on audit.

4.8. Issuing a renewal certificate without a genuine, documented refresher activity, or renewing solely on the basis that the previous certificate has lapsed, constitutes Certificate Fraud under clause 4.2 and will be dealt with under clause 10.2.

5. Account and Access Discipline

5.1. Accounts are personal to the named individual. Credential sharing, shared logins, and generic or role-based accounts used by multiple people are prohibited.

5.2. Access to an organisation workspace must be granted on a least-privilege basis and only to individuals with a genuine operational need.

5.3. Every organisation user must have executed the Organisation User Access Control Agreement before access is granted.

5.4. Access must be revoked within seven (7) days of a person ceasing to hold their role.

5.5. Organisation administrators must review their user access list not less than once every twelve (12) months and record that review.

5.6. Suspected credential compromise must be reported to cpdfy@deepdiagnostics.lk immediately and in any event within twenty-four (24) hours of discovery.

6. Data Protection Obligations

6.1. Each Provider Organisation is the data controller for Participant data it collects and is responsible for compliance with the Personal Data Protection Act No. 9 of 2022 and all other applicable law.

6.2. Personal data accessed through the Platform must be used only for the purposes of the CPD activity concerned, must not be exported or retained beyond what is necessary, and must not be disclosed to any third party without a lawful basis.

6.3. Bulk export of Participant data must be authorised, logged, and stored securely by the exporting organisation. The exporting organisation remains responsible for that data once it leaves the Platform.

6.4. Any personal data breach affecting Platform data must be notified to Deep Diagnostics at cpdfy@deepdiagnostics.lk within twenty-four (24) hours of the organisation becoming aware of it, with sufficient detail to allow assessment and regulatory notification.

6.5. Participant requests to exercise data protection rights must be actioned by the responsible Provider Organisation within the statutory period, and Deep Diagnostics will provide reasonable technical assistance.

Expired certificates

6.6. Expiry does not delete personal data. When a certificate reaches the end of its validity period under clause 4.5, it is marked EXPIRED and ceases to verify as valid, but the certificate record and the participant personal data it contains — including the participant's name, email address, the event attended and the associated issuance and verification records — remain stored on the Platform. Provider Organisations must not treat expiry as satisfying any retention or erasure obligation.

6.7. Retention of expired certificates is determined by the Provider Organisation in its capacity as data controller. Deep Diagnostics does not impose a fixed post-expiry retention period and will retain expired certificate records indefinitely until instructed otherwise, so that the certificate remains verifiable as evidence of past attendance. Each Provider Organisation must:

  1. define and document a retention period for expired certificates and their associated participant data, proportionate to the requirements of its accrediting body and applicable law;
  2. disclose that period in its own privacy notice to participants, before or at the point of data collection;
  3. issue written instructions to Deep Diagnostics at cpdfy@deepdiagnostics.lk where expired certificate records are to be deleted or anonymised, identifying the records concerned; and
  4. review its expired certificate holdings not less than once every twelve (12) months and act on that review.

6.8. A Provider Organisation that fails to define a post-expiry retention period, or that retains expired certificate data indefinitely without a documented justification, may be in breach of the storage limitation requirements of the Personal Data Protection Act No. 9 of 2022. That compliance failure rests with the Provider Organisation as controller, not with Deep Diagnostics as processor.

6.9. Continued public verifiability. Unless deleted on the written instruction of the Provider Organisation, the verification page of an expired certificate remains publicly accessible and displays the expired status together with the expiry date. Provider Organisations must ensure their privacy notices inform participants that this page remains reachable after expiry.

6.10. Erasure requests concerning expired certificates. Where a participant requests erasure of an expired certificate, the Provider Organisation as controller is responsible for determining whether the request must be granted or whether an exemption applies — in particular where retention remains necessary for the integrity of a professional CPD record, to comply with a legal obligation, or to establish, exercise or defend legal claims. The Provider Organisation must respond to the participant within the statutory period, and Deep Diagnostics will give effect to any lawful documented instruction it receives.

6.11. Deletion is irreversible. Deleting an expired certificate permanently removes its verification record. The certificate can no longer be verified by any third party, and the participant loses the ability to evidence that credential through the Platform. Provider Organisations must weigh this consequence, and should ordinarily inform the participant, before instructing deletion.

7. Communications and Bulk Email

7.1. Bulk email functionality may be used only to communicate with Participants about Events they registered for or attended, and to deliver Certificates and related administrative notices.

7.2. Unsolicited marketing, mass promotional campaigns to non-Participants, and use of Participant lists obtained outside the Platform are prohibited.

7.3. Communications must accurately identify the sending Provider Organisation and must not be sent in a manner that impersonates Deep Diagnostics or CPDfy.

7.4. We monitor sending volumes and deliverability, and may impose rate limits or suspend sending privileges to protect Platform reputation.

8. System Integrity

8.1. Users must not attempt to circumvent authentication, authorisation, subscription quotas, retry limits or rate limits.

8.2. Automated scraping, bulk extraction, load testing, vulnerability scanning and penetration testing are prohibited without our prior express written authorisation.

8.3. Security vulnerabilities discovered in good faith should be reported responsibly and confidentially to cpdfy@deepdiagnostics.lk and must not be publicly disclosed or exploited.

9. Monitoring, Audit and Investigation

9.1. Deep Diagnostics maintains audit logs of access, issuance, verification and administrative actions for security, integrity and compliance purposes.

9.2. We may audit a Provider Organisation's use of the Platform where we have reasonable grounds to suspect a breach. The organisation shall cooperate and provide requested evidence within fourteen (14) days.

9.3. We may request documentary proof of accreditation, attendance records, or delivery of any Event.

10. Sanctions

10.1. Where a breach is established, Deep Diagnostics may apply any one or more of the following, proportionate to the seriousness of the breach:

  1. Written warning and a required remediation plan;
  2. Feature restriction, including suspension of Certificate issuance or bulk email;
  3. Revocation or annotation of affected Certificates;
  4. Withdrawal of verified provider status;
  5. Suspension of the organisation workspace or individual account;
  6. Termination of access and deletion of the workspace in accordance with the Privacy Policy;
  7. Referral to the relevant professional regulator, accrediting body, the Data Protection Authority, or law enforcement.

10.2. Certificate Fraud under clause 4.2 will ordinarily result in immediate suspension and referral, without prior warning.

10.3. No refund of fees is payable in respect of any period during which access is suspended or terminated for breach.

11. Complaints and Appeals

11.1. Complaints concerning a Provider Organisation, an Event or a Certificate should be submitted to cpdfy@deepdiagnostics.lk with supporting particulars. We will acknowledge within five (5) working days.

11.2. Complaints regarding the substantive content or educational quality of an Event are, in the first instance, a matter for the Provider Organisation and its accrediting body.

11.3. A party subject to a sanction under clause 10 may appeal in writing within fourteen (14) days of notification, setting out the grounds of appeal and any supporting evidence.

11.4. Appeals will be determined by a person not involved in the original decision, ordinarily within thirty (30) days. The determination is final as a matter of internal process and does not affect any legal right.

11.5. A sanction remains in effect pending appeal unless we determine otherwise.

12. Amendment

12.1. These Regulations may be amended from time to time. Material amendments take effect not less than fourteen (14) days after notification, save where an immediate change is required by law or to address a security or integrity risk.

13. Contact

Deep Diagnostics (Pvt) Ltd — Compliance
No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
Email: cpdfy@deepdiagnostics.lk
Telephone: +94 77 988 5043