Service Level Agreement

14. Subscriber Responsibilities

14.1 General Responsibility

The Subscriber is responsible for using BlockchainCert in a properly configured, lawful, and authorised manner consistent with the Service Documentation.

14.2 Integration and Technical Implementation

(a) Where API access is included, the Subscriber is responsible for implementing and maintaining its integration, including proper configuration, authentication, request formatting, and secure credential handling.

(b) The Subscriber shall submit valid requests and implement appropriate error handling, retry, backoff, timeout, and reconciliation controls for its integrations.

(c) The Subscriber shall maintain compatibility of its systems with supported interfaces, browsers, file formats, and protocols.

(d) The Service Provider is not responsible for issues caused by incorrect implementation, malformed requests, unsupported environments, or improper use by the Subscriber.

14.3 Systems, Connectivity and Infrastructure

The Subscriber is responsible for its systems, networks, devices, browsers, email access, and internet connectivity required to use BlockchainCert.

14.4 Security and Access Management

(a) The Subscriber shall secure its administrator accounts, passwords, API keys, credentials, and access tokens; apply appropriate internal access controls; promptly revoke unnecessary access; and promptly notify the Service Provider of suspected compromise.

(b) An action performed using the Subscriber’s credentials is deemed authorised by the Subscriber unless caused by the Service Provider’s fraud, wilful misconduct, or breach of the Agreement.

14.5 Data Accuracy, Retention and Usage

(a) The Subscriber is responsible for the accuracy, completeness, legality, authority, and non-infringement of Credential content, Recipient data, templates, brand assets, and other data submitted to BlockchainCert, and for validating outputs before publication.

(b) The Subscriber acknowledges that a cryptographic hash, transaction reference, NFT record, or minimised verification metadata may be permanently recorded on the MasChain Network and, once confirmed, may not be altered or deleted due to blockchain immutability.

(c) The Service Provider may retain off-chain data and records for operation, security, audit, legal compliance, billing, support, backup, and disaster-recovery purposes, including the following indicative categories:-

Data CategoryRetention Basis
Access, authentication, and security logsFor the operational, security, and legally required period stated in applicable policies or the Subscription Agreement
Notification, webhook, and delivery recordsFor the period reasonably required for delivery, support, reconciliation, and incident investigation
Credential processing and publication recordsFor the subscription term and any lawful or agreed post-termination retention period
Billing, invoice, audit, and compliance recordsFor the applicable statutory or contractual retention period
Temporary processing files, retry queues, and backupsAccording to the Service Provider’s documented operational and backup lifecycle, subject to applicable law

Retention under this Clause 14.5(c) is in each case subject to applicable law.

(d) Historical records may be archived. Retrieval may require additional processing time and may be subject to reasonable fees if outside the standard Covered Services.

(e) The Subscriber remains responsible for its own retention obligations and independent backups and shall not submit unlawful or unnecessarily sensitive data, particularly where later deletion may be required.

(f) The Service Provider does not guarantee deletion of on-chain records. It is not responsible for errors or claims caused by inaccurate, incomplete, unlawful, or unauthorised data supplied or approved by the Subscriber.

14.6 Compliance and Regulatory Obligations

The Subscriber is responsible for regulatory, accreditation, employment, admission, licensing, privacy, consumer-protection, and internal-governance requirements applicable to its Credentials. Use of BlockchainCert does not transfer those obligations to the Service Provider.

14.7 Acceptable Use and Conduct

(a) The Subscriber shall not issue fraudulent, misleading, unlawful, defamatory, infringing, or unauthorised Credentials; misuse, overload, scrape, or interfere with BlockchainCert; bypass security or access controls; or use the Covered Services for unlawful or harmful activity.

(b) The Service Provider may suspend or restrict access where such activity is detected, subject to reasonable notice where practicable and safe.

14.8 API Rate Limiting and Traffic Management

(a) To preserve stability, security, fair use, and service availability, the Service Provider may apply documented API request limits, concurrency controls, throttling, traffic shaping, and abuse-prevention safeguards.

(b) Controls may apply per Subscriber, API key, IP address, endpoint, Covered Service, Subscription Package, or platform-wide. Where applicable, BlockchainCert may return a standard rate-limit response such as HTTP 429.

(c) The Subscriber shall implement appropriate retry logic, exponential backoff, request pacing, timeout handling, idempotency where relevant, and resilient integration practices.

(d) Repeated threshold violations, abusive traffic, credential misuse, or sustained disruption may result in temporary restriction or suspension. Impact caused by such Subscriber behaviour is an Excluded Event under Clause 15.

Operational limits and integration parameters are stated in the Service Documentation and may vary by Subscription Package. They are not separate service-level guarantees unless expressly stated in the Subscription Agreement.

Operational ControlSLA Treatment
API rate limitsDocumented limits, concurrency controls, payload sizes, and timeouts apply. A valid request rejected because BlockchainCert is below its documented limit may be considered in the applicable Covered Service’s Availability; traffic above the limit is excluded.
Callbacks and webhooksRetry timing and exhaustion rules are operational parameters in the Service Documentation. Third-party endpoint or Subscriber-system failure is excluded to the extent attributable to that dependency.
Bulk Credential publicationSupported batches of up to five hundred (500) Credentials remain subject to data validation, available allocations, file-format requirements, and reasonable processing queues.
MasChain Network confirmationBlockchain confirmation and finality times vary with network conditions. Availability is measured at the BlockchainCert service boundary and excludes external network delay under Clause 15 and Appendix A.

14.9 Cooperation and Incident Support

During an incident or investigation, the Subscriber shall provide reasonable cooperation, including timely clarification, logs, screenshots, sample Credentials, affected Recipient details, or other diagnostic information reasonably required. Failure to cooperate may affect response, resolution, and SLA Credit eligibility to the extent it causes or prolongs the issue.

14.10 Effect on SLA

A failure by the Subscriber to meet Clause 14 responsibilities may affect performance or availability. Resulting impact is an Excluded Event only to the extent the Subscriber’s act or omission caused or prolonged it.