4.1 Subject to the Subscription Agreement, Service Documentation, and any other written agreement between the parties, this SLA applies to the Covered Services described in this Clause 4.
4.2 The Service Provider may update, enhance, modify, suspend, replace, or retire a Covered Service or related feature, interface, API, dependency, or Service Documentation in accordance with the Subscription Agreement, provided that it shall not materially reduce the core functionality or service commitments expressly agreed with the Subscriber during the active subscription term without reasonable prior notice or an alternative path where practicable.
4.3 The Covered Services are set out below. Availability is measured only for the material production functions of each Covered Service and not for each individual capability listed in the final column:-
| No. | Service | Service Description | Covered Capabilities |
|---|---|---|---|
| 1. | Organisation Onboarding and Administration | Enables subscribing organisations to register, complete applicable KYB steps, maintain their BlockchainCert profile, structure departments, and administer authorised users. |
(a) Organisation Registration and Approval: Self-registration, email verification, administrator review, approval, rejection, suspension, and reactivation workflows. (b) Organisation Profile: Maintenance of legal, contact, branding, and organisation information displayed or used by BlockchainCert. (c) KYB Workflow: Submission and review of organisation verification information where required for the relevant package or use case. (d) Department Management: Creation and administration of departments or business units for delegated Credential operations. (e) Staff and Role Management: Administrator, sub-administrator, department, and other role-based permissions supported by the platform. (f) Access Controls: Account authentication, invitation, activation, deactivation, permission assignment, and password-management functions. (g) Organisation Directory and Taxonomy: Platform-supported categories and organisation classifications. (h) Administrative Auditability: Relevant activity records and reports available to authorised administrators. (i) Localisation: Interface support for English, Chinese, and Malay where implemented in the subscribed release. |
| 2. | Credential Template and Design | Enables authorised users to create, configure, preview, brand, and manage reusable templates for Credentials issued through BlockchainCert. |
(a) Template Library: Creation, copying, updating, activation, deactivation, search, and organisation of reusable templates. (b) Template Designer: Browser-based layout and design tools for supported Credential formats. (c) Data Fields: Configuration of recipient, Credential, issuing-organisation, date, reference, and custom fields supported by the selected template. (d) Brand Assets: Upload and placement of supported logos, backgrounds, signatures, seals, images, and other design assets. (e) Verification Elements: Placement of QR codes, reference identifiers, verification links, and other supported authenticity indicators. (f) Preview and Validation: Preview of representative content and validation of required fields before publication. (g) Template Permissions: Role-based access to create, edit, approve, and use templates. (h) Template Governance: Status, ownership, and change controls supported by the platform. |
| 3. | Credential Issuance and Blockchain Publishing | Enables authorised organisations to create, validate, publish, and deliver Credentials, with a tamper-evident verification record anchored on the MasChain Network. |
(a) Individual Issuance: Creation and publication of a Credential for a single Recipient through the production workflow. (b) Bulk Issuance: CSV or supported-file import, validation, preview, and publication of up to five hundred (500) Credentials per supported batch, subject to package allocations and platform limits. (c) Issuance Validation: Required-field, duplicate, format, allocation, and workflow checks before publication. (d) Managed Blockchain Processing: Platform-managed wallet, NFT, smart-contract, and transaction functions required to anchor the verification record. (e) Data Minimisation: BlockchainCert is designed to anchor a cryptographic hash, transaction reference, or minimised verification metadata rather than direct personal data, unless expressly agreed and lawful. (f) Credential Rendering: Generation of the supported Credential document or image with QR code, reference number, and verification link. (g) Publication Status: Queued, processing, published, failed, revoked, expired, or other lifecycle statuses supported by the platform. (h) Delivery Workflow: Supported email delivery and status notifications, subject to third-party delivery dependencies. (i) Transaction Confirmation: Processing and display of the relevant blockchain transaction reference and confirmation status. (j) Retry and Exception Handling: Supported reprocessing, error reporting, and operational handling for failed publication attempts. |
| 4. | Credential Management and Public Verification | Provides the organisation dashboard and public-facing mechanisms for managing, locating, and verifying Credentials issued through BlockchainCert. |
(a) Credential Dashboard: Search, filter, view, download, tag, categorise, revoke, expire, and otherwise manage issued Credentials according to supported permissions. (b) Verification Methods: Verification by QR code, reference number, supported file upload or fingerprint, verification link, or public Credential search. (c) Public Results and Microsites: Display of authenticity, issuer, status, and other permitted Credential information through the verification portal or configured organisation microsite. |
| 5. | Recipient Portal and Credential Lifecycle | Enables Recipients to access and manage Credentials made available to them, subject to the issuing organisation’s configuration and the selected Subscription Package. |
(a) Recipient Authentication: Email one-time password or other supported authentication for Recipient access. (b) Credential Access: View, share, and download supported Credentials and verification links. (c) Status Visibility: Display of published, revoked, expired, pending, claimed, or other supported lifecycle status. (d) Ownership Claim: Supported claim workflow for an eligible Credential, subject to issuer rules and verification. (e) Ownership Transfer: Supported transfer workflow using confirmation controls such as one-time passwords, where enabled. (f) Recipient Payment: Payment-enabled access or transfer functions only where expressly enabled and subject to the payment-gateway boundary in Appendix A. (g) Support Requests: Recipient or user support-ticket submission where enabled. (h) Recipient Communications: Supported access, claim, transfer, payment, and status notifications. (i) Privacy Controls: Display and processing limited by the issuing organisation’s configuration, lawful instructions, and applicable privacy requirements. (j) Lifecycle Integrity: A status change does not erase the underlying blockchain record and must be reflected through the supported verification status. (k) Activity History: Supported records of relevant Recipient and Credential lifecycle events. |
| 6. | Subscription, Credits, and Billing | Provides the Subscriber with package-selection, Credential-allocation, credit, top-up, renewal, invoice, and billing-administration functions supported by BlockchainCert. |
(a) Subscription Packages: Selection and administration of available plans, features, limits, and renewal settings. (b) Allocations and Credits: Tracking of Credential allocations or credits, consumption, expiry, and eligible top-ups (being Credential issuance allocations under the Subscription Agreement, and not SLA Credits) in accordance with the Subscription Agreement. (c) Plan Changes: Supported upgrade, downgrade, renewal, cancellation, and package-change workflows, subject to the applicable commercial terms. (d) Payment and Invoices: Integration with eGHL or another approved gateway for supported payments, together with invoice or receipt records made available by the platform. |
| 7. | APIs, Integrations, Notifications, and Reporting | Provides optional technical interfaces and operational information for integrating BlockchainCert with Subscriber systems and for administering the subscribed service. |
(a) API Credential Management: Creation, activation, rotation, restriction, and revocation of API keys or credentials where API access is included. (b) Documented Endpoints: Supported organisation, template, Credential, verification, Recipient, subscription, report, or other endpoints identified in the Service Documentation. (c) Callbacks and Webhooks: Configurable event notifications, delivery status, retry handling, and callback records for supported events. (d) Email Notifications: Platform-triggered delivery and operational messages, subject to third-party mail systems and recipient settings. (e) Reports and Audit Logs: Supported usage, issuance, verification, credit, billing, operational, and administrative reports. (f) Blockchain Explorer Linkage: Display of relevant MasChain Network transaction references where supported. (g) Localisation: Supported language and date, time, currency, or regional display settings. (h) Optional White-Label Deployment: Dedicated cloud or on-premises deployment, branding, integration, testing, UAT, handover, training, and ongoing support only where expressly scoped in a Statement of Work. |
4.4 The technical specifications, APIs, endpoints, supported functions, operational requirements, limitations, dependencies, usage procedures, and implementation requirements for each Covered Service shall be set out in the applicable Service Documentation, which may be updated in accordance with the Subscription Agreement.
4.5 The Subscriber shall comply with the applicable Service Documentation, including authentication, configuration, data-formatting, operational, integration, privacy, and security requirements.
4.6 Unless expressly stated otherwise in the Subscription Agreement or Service Documentation, this SLA applies only to the Covered Services and capabilities enabled for the Subscriber, and not to any feature, module, API, white-label deployment, endpoint, or functionality outside the applicable commercial arrangement.