The Subscriber is responsible for using BlockchainCert in a properly configured, lawful, and authorised manner consistent with the Service Documentation.
(a) Where API access is included, the Subscriber is responsible for implementing and maintaining its integration, including proper configuration, authentication, request formatting, and secure credential handling.
(b) The Subscriber shall submit valid requests and implement appropriate error handling, retry, backoff, timeout, and reconciliation controls for its integrations.
(c) The Subscriber shall maintain compatibility of its systems with supported interfaces, browsers, file formats, and protocols.
(d) The Service Provider is not responsible for issues caused by incorrect implementation, malformed requests, unsupported environments, or improper use by the Subscriber.
The Subscriber is responsible for its systems, networks, devices, browsers, email access, and internet connectivity required to use BlockchainCert.
(a) The Subscriber shall secure its administrator accounts, passwords, API keys, credentials, and access tokens; apply appropriate internal access controls; promptly revoke unnecessary access; and promptly notify the Service Provider of suspected compromise.
(b) An action performed using the Subscriber’s credentials is deemed authorised by the Subscriber unless caused by the Service Provider’s fraud, wilful misconduct, or breach of the Agreement.
(a) The Subscriber is responsible for the accuracy, completeness, legality, authority, and non-infringement of Credential content, Recipient data, templates, brand assets, and other data submitted to BlockchainCert, and for validating outputs before publication.
(b) The Subscriber acknowledges that a cryptographic hash, transaction reference, NFT record, or minimised verification metadata may be permanently recorded on the MasChain Network and, once confirmed, may not be altered or deleted due to blockchain immutability.
(c) The Service Provider may retain off-chain data and records for operation, security, audit, legal compliance, billing, support, backup, and disaster-recovery purposes, including the following indicative categories:-
| Data Category | Retention Basis |
|---|---|
| Access, authentication, and security logs | For the operational, security, and legally required period stated in applicable policies or the Subscription Agreement |
| Notification, webhook, and delivery records | For the period reasonably required for delivery, support, reconciliation, and incident investigation |
| Credential processing and publication records | For the subscription term and any lawful or agreed post-termination retention period |
| Billing, invoice, audit, and compliance records | For the applicable statutory or contractual retention period |
| Temporary processing files, retry queues, and backups | According to the Service Provider’s documented operational and backup lifecycle, subject to applicable law |
Retention under this Clause 14.5(c) is in each case subject to applicable law.
(d) Historical records may be archived. Retrieval may require additional processing time and may be subject to reasonable fees if outside the standard Covered Services.
(e) The Subscriber remains responsible for its own retention obligations and independent backups and shall not submit unlawful or unnecessarily sensitive data, particularly where later deletion may be required.
(f) The Service Provider does not guarantee deletion of on-chain records. It is not responsible for errors or claims caused by inaccurate, incomplete, unlawful, or unauthorised data supplied or approved by the Subscriber.
The Subscriber is responsible for regulatory, accreditation, employment, admission, licensing, privacy, consumer-protection, and internal-governance requirements applicable to its Credentials. Use of BlockchainCert does not transfer those obligations to the Service Provider.
(a) The Subscriber shall not issue fraudulent, misleading, unlawful, defamatory, infringing, or unauthorised Credentials; misuse, overload, scrape, or interfere with BlockchainCert; bypass security or access controls; or use the Covered Services for unlawful or harmful activity.
(b) The Service Provider may suspend or restrict access where such activity is detected, subject to reasonable notice where practicable and safe.
(a) To preserve stability, security, fair use, and service availability, the Service Provider may apply documented API request limits, concurrency controls, throttling, traffic shaping, and abuse-prevention safeguards.
(b) Controls may apply per Subscriber, API key, IP address, endpoint, Covered Service, Subscription Package, or platform-wide. Where applicable, BlockchainCert may return a standard rate-limit response such as HTTP 429.
(c) The Subscriber shall implement appropriate retry logic, exponential backoff, request pacing, timeout handling, idempotency where relevant, and resilient integration practices.
(d) Repeated threshold violations, abusive traffic, credential misuse, or sustained disruption may result in temporary restriction or suspension. Impact caused by such Subscriber behaviour is an Excluded Event under Clause 15.
Operational limits and integration parameters are stated in the Service Documentation and may vary by Subscription Package. They are not separate service-level guarantees unless expressly stated in the Subscription Agreement.
| Operational Control | SLA Treatment |
|---|---|
| API rate limits | Documented limits, concurrency controls, payload sizes, and timeouts apply. A valid request rejected because BlockchainCert is below its documented limit may be considered in the applicable Covered Service’s Availability; traffic above the limit is excluded. |
| Callbacks and webhooks | Retry timing and exhaustion rules are operational parameters in the Service Documentation. Third-party endpoint or Subscriber-system failure is excluded to the extent attributable to that dependency. |
| Bulk Credential publication | Supported batches of up to five hundred (500) Credentials remain subject to data validation, available allocations, file-format requirements, and reasonable processing queues. |
| MasChain Network confirmation | Blockchain confirmation and finality times vary with network conditions. Availability is measured at the BlockchainCert service boundary and excludes external network delay under Clause 15 and Appendix A. |
During an incident or investigation, the Subscriber shall provide reasonable cooperation, including timely clarification, logs, screenshots, sample Credentials, affected Recipient details, or other diagnostic information reasonably required. Failure to cooperate may affect response, resolution, and SLA Credit eligibility to the extent it causes or prolongs the issue.
A failure by the Subscriber to meet Clause 14 responsibilities may affect performance or availability. Resulting impact is an Excluded Event only to the extent the Subscriber’s act or omission caused or prolonged it.