Org User Access Control Agreement
DEEP DIAGNOSTICS (PVT) LTD — CPDfy PLATFORM
ORGANISATION USER ACCESS CONTROL AGREEMENT
Form Ref: CPDfy/UAC/v1.0 | Effective 18 August 2026
INSTRUCTIONS. This form is to be completed by an individual seeking access to an existing organisation workspace on the CPDfy platform. Complete all sections in BLOCK CAPITALS using black ink. Both the Applicant and the Organisation's Authorised Approver must sign. Return the signed form, together with proof of identity, to cpdfy@deepdiagnostics.lk. Access will not be granted until this form is received, verified and approved.
SECTION A — APPLICANT DETAILS
A1. Full name (as per NIC / passport): ______________________________________________
A2. NIC / Passport number: _________________________________________________________
A3. Designation / job title: ________________________________________________________
A4. Professional registration no. (if applicable): __________________________________
A5. Official email address (this will be the login): ________________________________
A6. Contact telephone: _____________________________________________________________
A7. Date of joining the Organisation: ______ / ______ / __________
SECTION B — ORGANISATION DETAILS
B1. Registered organisation name: ___________________________________________________
B2. CPDfy organisation ID / workspace name: _________________________________________
B3. Department / division: _________________________________________________________
SECTION C — ACCESS LEVEL REQUESTED
Tick one role. Access is granted on a least-privilege basis.
[ ] Organisation Administrator — full workspace control, including user management, billing and certificate issuance.
[ ] Event Manager — create and manage events, forms and participants; issue certificates.
[ ] Certificate Officer — manage certificate templates, issue and revoke certificates.
[ ] Data / Reporting User — view and export form responses and reports; no issuance rights.
[ ] Read Only — view access only.
[ ] Mentor — mentor functions only.
C2. Business justification for the access requested:
______________________________________________________________________________________
______________________________________________________________________________________
C3. Access required until (if fixed term): ______ / ______ / __________ or [ ] Ongoing
SECTION D — APPLICANT DECLARATIONS AND UNDERTAKINGS
I, the Applicant named in Section A, in consideration of being granted access to the CPDfy platform, declare, undertake and agree as follows:
D1. Binding terms. I have read, understood and agree to be bound by the CPDfy Terms of Service, Platform Regulations and Privacy Policy, as amended from time to time.
D2. Accuracy. The information I have provided is true, accurate and complete. I understand that a false declaration is a material breach and may result in immediate revocation of access and referral to my professional regulator.
D3. Personal credentials. My account is personal to me. I will not share, disclose, transfer or permit any other person to use my username, password or authentication credentials under any circumstances. I accept responsibility for all activity carried out under my account.
D4. Authorised use only. I will access the platform and the personal data within it solely for the legitimate business purposes of the Organisation and solely to the extent necessary for my role. I will not browse, search or access records out of curiosity or for any personal, commercial or unauthorised purpose.
D5. Data protection. I will comply with the Personal Data Protection Act No. 9 of 2022 and the Organisation's data protection policies. I will not copy, extract, export, transmit, publish or retain participant personal data except as required for my role and as authorised by the Organisation, and I will keep any authorised export secure.
D6. Confidentiality. I will treat all participant data, organisation data and platform information as strictly confidential. This obligation continues indefinitely and survives the termination of my access, my role and my employment.
D7. Certificate integrity. I will not issue, procure, alter, backdate or facilitate any certificate that does not reflect genuine attendance, participation or completion. I understand that certificate fraud may constitute a criminal offence under the Computer Crimes Act No. 24 of 2007 and will result in immediate termination of access and referral to the relevant authorities.
D8. System integrity. I will not attempt to circumvent any access control, authentication mechanism, retry limit or subscription restriction, nor access any organisation workspace or data other than that which I am authorised to access.
D9. Incident reporting. I will report any suspected credential compromise, unauthorised access or personal data breach to the Organisation and to cpdfy@deepdiagnostics.lk immediately, and in any event within twenty-four (24) hours of becoming aware of it.
D10. Cessation of role. I will notify the Organisation immediately upon ceasing to hold the role for which access was granted, and I understand my access will be revoked. I will securely destroy or return any exported data in my possession.
D11. Monitoring. I acknowledge and consent to my access and actions on the platform being logged, monitored and audited for security, integrity and compliance purposes.
D12. Consequences. I understand that breach of these undertakings may result in revocation of access, disciplinary action by the Organisation, referral to my professional regulator or the Data Protection Authority, and civil or criminal liability.
Applicant signature: ____________________________________________
Name in block capitals: _________________________________________
Date: ______ / ______ / __________
SECTION E — AUTHORISATION BY THE ORGANISATION
To be completed by an Organisation Administrator or the Authorised Representative of the Organisation.
I confirm that: (a) the Applicant is a bona fide member of this Organisation; (b) the access level requested in Section C is appropriate and necessary for the Applicant's role; (c) the Applicant has been made aware of the Organisation's data protection obligations; and (d) the Organisation accepts responsibility for the Applicant's use of the platform and will notify Deep Diagnostics within seven (7) days should the Applicant cease to require access.
E1. Approver name: _________________________________________________________________
E2. Designation: ___________________________________________________________________
E3. Official email: ________________________________________________________________
E4. Contact telephone: _____________________________________________________________
Approver signature: ____________________________________________
Date: ______ / ______ / __________
Organisation stamp / seal:
______________________________
SECTION F — FOR OFFICIAL USE ONLY (Deep Diagnostics)
F1. Date received: ______ / ______ / __________ F2. Reference no.: ______________________
F3. Identity verified: [ ] Yes [ ] No F4. Organisation membership confirmed: [ ] Yes [ ] No
F5. Access level granted: ___________________________________________________________
F6. Decision: [ ] Approved [ ] Refused [ ] Deferred pending further information
F7. Notes: _________________________________________________________________________
F8. Processed by: __________________________ Signature: __________________________ Date: ______ / ______ / __________
Deep Diagnostics (Pvt) Ltd — No. 68, Jaya Mawatha, Pannipitiya 10230, Sri Lanka
cpdfy@deepdiagnostics.lk | +94 77 988 5043 | https://provider.cpdfy.com