(a) This Appendix identifies key third-party dependencies used in connection with BlockchainCert and the responsibility boundaries between the Service Provider, the Subscriber, and relevant providers.
(b) This Appendix applies together with Clause 15, including the provisions relating to SLA exclusions, service availability, responsibility boundaries, and Excluded Events.
(c) This Appendix clarifies operational responsibility and does not relieve the Service Provider of configuration, integration, monitoring, security-setting, vendor-coordination, escalation, mitigation, and diligence obligations within its reasonable control.
For the purposes of this Appendix, the following control levels apply:-
(a) Direct Control
“Direct Control” means a component directly operated and controlled by the Service Provider as part of BlockchainCert. A failure remains within the Service Provider’s responsibility unless caused by an Excluded Event.
(b) Shared Control
“Shared Control” means a component where the Service Provider manages configuration, integration, orchestration, access controls, monitoring, vendor coordination, and response, while underlying infrastructure or a network is operated by another provider. The Service Provider remains responsible for matters within its reasonable control.
(c) Third-Party Control
“Third-Party Control” means a component operated by an independent provider whose underlying availability, performance, network, or service operation is not directly controlled by the Service Provider. The Service Provider remains responsible for its integration, vendor coordination, monitoring, escalation, and reasonable mitigation.
| Dependency | Control Level | Service Provider Responsibility | Third-Party Responsibility | SLA Treatment |
|---|---|---|---|---|
| Cloud Hosting | Shared Control | Configuration, deployment, monitoring, security settings, backups, access controls, and reasonable resilience design | Physical infrastructure, cloud platform availability, and provider-operated services | Excluded only to the extent caused by provider-side infrastructure failure outside the Service Provider’s reasonable control |
| Email Delivery | Third-Party Control | Provider integration, configuration, retry logic, monitoring, escalation, and error handling | Mail-provider systems, recipient mail servers, anti-spam controls, recipient settings, and internet delivery | Excluded only to the extent caused by delivery infrastructure or recipient-side systems outside the Service Provider’s reasonable control |
| MasChain Network | Shared Control | Blockchain integration, managed-wallet and transaction orchestration, monitoring, confirmation handling, reconciliation, and escalation | Underlying blockchain network, consensus, validator, finality, and network infrastructure outside direct control | Excluded only to the portion caused by an external MasChain Network event outside the Service Provider’s reasonable control |
| eGHL or Approved Payment Gateway | Third-Party Control | Gateway integration, payment-request handling, configuration, reconciliation support, monitoring, and escalation | Authorisation, settlement, banking rails, fraud screening, and gateway availability | Excluded only to the extent caused by the payment gateway, bank, card network, or payment network |
| Document and PDF Generation | Shared Control | Template processing, generation workflow, configuration, monitoring, retry, and error handling | Underlying rendering libraries or provider-operated document services, where used | Included unless the failure is attributable to an external rendering dependency outside reasonable control |
| Managed Credential and File Storage | Shared Control | Storage configuration, permissions, lifecycle rules, encryption settings, monitoring, and retrieval integration | Underlying storage platform availability and provider-operated infrastructure | Excluded only to the extent caused by provider-side storage failure outside reasonable control |
| DNS Providers | Shared Control | DNS records, routing configuration, domain administration, monitoring, escalation, and reasonable redundancy | DNS platform availability, registry-level issues, and global DNS propagation infrastructure | Excluded only to the extent caused by DNS, registry, or propagation failure outside the Service Provider’s reasonable control |
| CDN Providers | Shared Control | CDN configuration, cache rules, origin settings, certificates, routing, monitoring, and escalation | CDN edge network availability and provider-operated content delivery infrastructure | Excluded only to the extent caused by provider-side CDN failure outside reasonable control |
| Subscriber Systems, Devices, and Connectivity | Third-Party Control | Reasonable compatibility information, support triage, and diagnosis at the BlockchainCert service boundary | Subscriber systems, browsers, devices, networks, email access, firewalls, configurations, and internet providers | Excluded to the extent caused or prolonged by the Subscriber environment or a Subscriber-controlled provider |
A failure involving a Shared Control or Third-Party Control dependency is an Excluded Event only to the extent the Service Provider can reasonably demonstrate that:-
(a) the root cause originated outside the Service Provider’s directly controlled systems;
(b) the incident was not caused by the Service Provider’s misconfiguration, inadequate integration, security settings, access controls, monitoring, selection, or operational processes;
(c) the incident was not materially contributed to or prolonged by the Service Provider’s acts or omissions; and
(d) The Service Provider used reasonable diligence and efforts to monitor, escalate, mitigate, and coordinate with the provider.
A third party’s involvement alone does not classify an incident as an Excluded Event.
The Service Provider remains responsible for all matters within its reasonable control, including:-
(a) configuration of third-party integrations;
(b) secure management of credentials, keys, certificates, secrets, and access controls;
(c) monitoring of material dependencies;
(d) reasonable incident detection and escalation;
(e) implementation of retry logic, fallback handling, or graceful degradation where commercially reasonable;
(f) vendor coordination during incidents;
(g) maintaining reasonable records of incidents affecting the Services;
(h) applying available fixes, patches, configuration updates, or provider recommendations where applicable and commercially reasonable;
(i) avoiding foreseeable single points of failure where reasonable for the relevant Service; and
(j) communicating material service impacts to the Subscriber in accordance with this Appendix.
A third-party dependency shall not be treated as an Excluded Event to the extent the relevant failure, delay, degradation, or disruption was caused or materially worsened by the Service Provider’s failure to perform the responsibilities set out above.
Any SLA exclusion arising from a third-party dependency shall apply only:-
(a) to the affected Service component;
(b) for the period during which the third-party dependency directly caused the relevant failure, delay, degradation, or disruption; and
(c) to the extent the impact could not reasonably have been prevented, mitigated, or reduced by the Service Provider.
Unaffected Service components shall remain subject to the applicable SLA.
Where an incident has multiple causes, only the Unavailable Minutes or degradation reasonably attributable to the external provider or dependency are excluded from SLA calculations.
Where a confirmed third-party incident materially affects a Covered Service, the Service Provider shall use reasonable efforts to post a notice through the BlockchainCert Portal or another designated channel within two (2) hours after confirming the third-party root cause, counted during Business Hours only. The notice should include, where reasonably available:-
(a) the affected Service component or functionality;
(b) the known or estimated impact on the Subscriber;
(c) the suspected or confirmed third-party dependency involved;
(d) mitigation steps being taken by the Service Provider;
(e) any workaround available to the Subscriber;
(f) any indicative resolution timeline made available by the third-party provider; and
(g) the time of the next expected update, where practicable.
The Service Provider shall issue a follow-up notice upon restoration or when the material impact ends.
Where the Service Provider relies on a third-party dependency to exclude Unavailable Minutes, degradation, or failure from SLA calculations or SLA Credit eligibility, it shall maintain reasonable supporting records, which may include:-
(a) provider status notices;
(b) provider incident reports or service advisories;
(c) monitoring data;
(d) incident tickets;
(e) internal incident timelines;
(f) logs showing the affected component or integration;
(g) escalation records; and
(h) mitigation steps taken by the Service Provider.
On written request, the Service Provider shall provide a reasonable summary of evidence supporting a claimed exclusion, subject to confidentiality, security, legal, and third-party contractual restrictions.
(a) The Service Provider remains responsible for selecting, replacing, integrating, and managing providers used to support BlockchainCert.
(b) The Service Provider shall use commercially reasonable diligence when engaging material providers, having regard to the operational, security, availability, privacy, and regulatory risks of the dependency.
(c) Where relevant and commercially reasonable, the Service Provider may consider recognised assurance reports or certifications such as ISO 27001, SOC 2 Type II, or equivalent standards.
(d) The Service Provider may change providers in the ordinary course, provided that the change does not materially reduce the overall functionality, security, availability, data-protection standard, or regulatory-compliance posture of BlockchainCert.
(e) The Service Provider shall give advance notice where reasonably practicable of a planned material provider change affecting the Subscriber’s use, data-processing arrangements, security posture, or availability.
The Service Provider is not responsible for a failure caused by systems, networks, configurations, credentials, devices, applications, providers, or integrations controlled by the Subscriber or its users. Subscriber-side issues may include:-
(a) Subscriber network or internet connectivity failures;
(b) Subscriber firewall, proxy, VPN, browser, endpoint, or device issues;
(c) Subscriber misconfiguration of APIs, webhooks, credentials, permissions, or access controls;
(d) Subscriber failure to maintain required integrations or software environments;
(e) Subscriber-provided third-party systems or data sources;
(f) unauthorised changes made by the Subscriber or its users; and
(g) failure by the Subscriber to follow reasonable technical requirements or implementation guidance provided by the Service Provider.
Such Subscriber-caused issues shall be excluded from SLA calculations and SLA Credit eligibility to the extent they caused or contributed to the relevant failure, delay, degradation, or disruption.
The listed dependencies are illustrative and non-exhaustive. An additional dependency is assessed under the same control, responsibility, evidence, and exclusion standards. Listing a dependency does not automatically exclude every incident involving it.
If this Appendix conflicts with the main body of the SLA, the main body prevails unless expressly stated otherwise. Nothing here limits liability that cannot lawfully be limited or excluded.