Org User Access Control Agreement

DEEP DIAGNOSTICS (PVT) LTD — CPDfy PLATFORM
ORGANISATION USER ACCESS CONTROL AGREEMENT
Form Ref: CPDfy/UAC/v1.0  |  Effective 18 August 2026


INSTRUCTIONS. This form is to be completed by an individual seeking access to an existing organisation workspace on the CPDfy platform. Complete all sections in BLOCK CAPITALS using black ink. Both the Applicant and the Organisation's Authorised Approver must sign. Return the signed form, together with proof of identity, to cpdfy@deepdiagnostics.lk. Access will not be granted until this form is received, verified and approved.

SECTION A — APPLICANT DETAILS

A1. Full name (as per NIC / passport): ______________________________________________

A2. NIC / Passport number: _________________________________________________________

A3. Designation / job title: ________________________________________________________

A4. Professional registration no. (if applicable): __________________________________

A5. Official email address (this will be the login): ________________________________

A6. Contact telephone: _____________________________________________________________

A7. Date of joining the Organisation: ______ / ______ / __________

SECTION B — ORGANISATION DETAILS

B1. Registered organisation name: ___________________________________________________

B2. CPDfy organisation ID / workspace name: _________________________________________

B3. Department / division: _________________________________________________________

SECTION C — ACCESS LEVEL REQUESTED

Tick one role. Access is granted on a least-privilege basis.

[   ] Organisation Administrator — full workspace control, including user management, billing and certificate issuance.

[   ] Event Manager — create and manage events, forms and participants; issue certificates.

[   ] Certificate Officer — manage certificate templates, issue and revoke certificates.

[   ] Data / Reporting User — view and export form responses and reports; no issuance rights.

[   ] Read Only — view access only.

[   ] Mentor — mentor functions only.

C2. Business justification for the access requested:
______________________________________________________________________________________
______________________________________________________________________________________

C3. Access required until (if fixed term): ______ / ______ / __________    or    [   ] Ongoing

SECTION D — APPLICANT DECLARATIONS AND UNDERTAKINGS

I, the Applicant named in Section A, in consideration of being granted access to the CPDfy platform, declare, undertake and agree as follows:

D1. Binding terms. I have read, understood and agree to be bound by the CPDfy Terms of Service, Platform Regulations and Privacy Policy, as amended from time to time.

D2. Accuracy. The information I have provided is true, accurate and complete. I understand that a false declaration is a material breach and may result in immediate revocation of access and referral to my professional regulator.

D3. Personal credentials. My account is personal to me. I will not share, disclose, transfer or permit any other person to use my username, password or authentication credentials under any circumstances. I accept responsibility for all activity carried out under my account.

D4. Authorised use only. I will access the platform and the personal data within it solely for the legitimate business purposes of the Organisation and solely to the extent necessary for my role. I will not browse, search or access records out of curiosity or for any personal, commercial or unauthorised purpose.

D5. Data protection. I will comply with the Personal Data Protection Act No. 9 of 2022 and the Organisation's data protection policies. I will not copy, extract, export, transmit, publish or retain participant personal data except as required for my role and as authorised by the Organisation, and I will keep any authorised export secure.

D6. Confidentiality. I will treat all participant data, organisation data and platform information as strictly confidential. This obligation continues indefinitely and survives the termination of my access, my role and my employment.

D7. Certificate integrity. I will not issue, procure, alter, backdate or facilitate any certificate that does not reflect genuine attendance, participation or completion. I understand that certificate fraud may constitute a criminal offence under the Computer Crimes Act No. 24 of 2007 and will result in immediate termination of access and referral to the relevant authorities.

D8. System integrity. I will not attempt to circumvent any access control, authentication mechanism, retry limit or subscription restriction, nor access any organisation workspace or data other than that which I am authorised to access.

D9. Incident reporting. I will report any suspected credential compromise, unauthorised access or personal data breach to the Organisation and to cpdfy@deepdiagnostics.lk immediately, and in any event within twenty-four (24) hours of becoming aware of it.

D10. Cessation of role. I will notify the Organisation immediately upon ceasing to hold the role for which access was granted, and I understand my access will be revoked. I will securely destroy or return any exported data in my possession.

D11. Monitoring. I acknowledge and consent to my access and actions on the platform being logged, monitored and audited for security, integrity and compliance purposes.

D12. Consequences. I understand that breach of these undertakings may result in revocation of access, disciplinary action by the Organisation, referral to my professional regulator or the Data Protection Authority, and civil or criminal liability.

Applicant signature: ____________________________________________

Name in block capitals: _________________________________________

Date: ______ / ______ / __________

SECTION E — AUTHORISATION BY THE ORGANISATION

To be completed by an Organisation Administrator or the Authorised Representative of the Organisation.

I confirm that: (a) the Applicant is a bona fide member of this Organisation; (b) the access level requested in Section C is appropriate and necessary for the Applicant's role; (c) the Applicant has been made aware of the Organisation's data protection obligations; and (d) the Organisation accepts responsibility for the Applicant's use of the platform and will notify Deep Diagnostics within seven (7) days should the Applicant cease to require access.

E1. Approver name: _________________________________________________________________

E2. Designation: ___________________________________________________________________

E3. Official email: ________________________________________________________________

E4. Contact telephone: _____________________________________________________________

Approver signature: ____________________________________________

Date: ______ / ______ / __________

Organisation stamp / seal:




______________________________


SECTION F — FOR OFFICIAL USE ONLY (Deep Diagnostics)

F1. Date received: ______ / ______ / __________    F2. Reference no.: ______________________

F3. Identity verified: [   ] Yes    [   ] No    F4. Organisation membership confirmed: [   ] Yes    [   ] No

F5. Access level granted: ___________________________________________________________

F6. Decision: [   ] Approved    [   ] Refused    [   ] Deferred pending further information

F7. Notes: _________________________________________________________________________

F8. Processed by: __________________________    Signature: __________________________    Date: ______ / ______ / __________


Deep Diagnostics (Pvt) Ltd — No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
cpdfy@deepdiagnostics.lk  |  +94 77 988 5043  |  https://provider.cpdfy.com