Service Level Agreement

Appendix A — Third Party Dependencies and Responsibility Boundaries

1. Purpose and Scope

(a) This Appendix identifies key third-party dependencies used in connection with BlockchainCert and the responsibility boundaries between the Service Provider, the Subscriber, and relevant providers.

(b) This Appendix applies together with Clause 15, including the provisions relating to SLA exclusions, service availability, responsibility boundaries, and Excluded Events.

(c) This Appendix clarifies operational responsibility and does not relieve the Service Provider of configuration, integration, monitoring, security-setting, vendor-coordination, escalation, mitigation, and diligence obligations within its reasonable control.

2. Control Levels

For the purposes of this Appendix, the following control levels apply:-

(a) Direct Control

Direct Control” means a component directly operated and controlled by the Service Provider as part of BlockchainCert. A failure remains within the Service Provider’s responsibility unless caused by an Excluded Event.

(b) Shared Control

Shared Control” means a component where the Service Provider manages configuration, integration, orchestration, access controls, monitoring, vendor coordination, and response, while underlying infrastructure or a network is operated by another provider. The Service Provider remains responsible for matters within its reasonable control.

(c) Third-Party Control

Third-Party Control” means a component operated by an independent provider whose underlying availability, performance, network, or service operation is not directly controlled by the Service Provider. The Service Provider remains responsible for its integration, vendor coordination, monitoring, escalation, and reasonable mitigation.

3. Dependency Matrix

DependencyControl LevelService Provider ResponsibilityThird-Party ResponsibilitySLA Treatment
Cloud HostingShared ControlConfiguration, deployment, monitoring, security settings, backups, access controls, and reasonable resilience designPhysical infrastructure, cloud platform availability, and provider-operated servicesExcluded only to the extent caused by provider-side infrastructure failure outside the Service Provider’s reasonable control
Email DeliveryThird-Party ControlProvider integration, configuration, retry logic, monitoring, escalation, and error handlingMail-provider systems, recipient mail servers, anti-spam controls, recipient settings, and internet deliveryExcluded only to the extent caused by delivery infrastructure or recipient-side systems outside the Service Provider’s reasonable control
MasChain NetworkShared ControlBlockchain integration, managed-wallet and transaction orchestration, monitoring, confirmation handling, reconciliation, and escalationUnderlying blockchain network, consensus, validator, finality, and network infrastructure outside direct controlExcluded only to the portion caused by an external MasChain Network event outside the Service Provider’s reasonable control
eGHL or Approved Payment GatewayThird-Party ControlGateway integration, payment-request handling, configuration, reconciliation support, monitoring, and escalationAuthorisation, settlement, banking rails, fraud screening, and gateway availabilityExcluded only to the extent caused by the payment gateway, bank, card network, or payment network
Document and PDF GenerationShared ControlTemplate processing, generation workflow, configuration, monitoring, retry, and error handlingUnderlying rendering libraries or provider-operated document services, where usedIncluded unless the failure is attributable to an external rendering dependency outside reasonable control
Managed Credential and File StorageShared ControlStorage configuration, permissions, lifecycle rules, encryption settings, monitoring, and retrieval integrationUnderlying storage platform availability and provider-operated infrastructureExcluded only to the extent caused by provider-side storage failure outside reasonable control
DNS ProvidersShared ControlDNS records, routing configuration, domain administration, monitoring, escalation, and reasonable redundancyDNS platform availability, registry-level issues, and global DNS propagation infrastructureExcluded only to the extent caused by DNS, registry, or propagation failure outside the Service Provider’s reasonable control
CDN ProvidersShared ControlCDN configuration, cache rules, origin settings, certificates, routing, monitoring, and escalationCDN edge network availability and provider-operated content delivery infrastructureExcluded only to the extent caused by provider-side CDN failure outside reasonable control
Subscriber Systems, Devices, and ConnectivityThird-Party ControlReasonable compatibility information, support triage, and diagnosis at the BlockchainCert service boundarySubscriber systems, browsers, devices, networks, email access, firewalls, configurations, and internet providersExcluded to the extent caused or prolonged by the Subscriber environment or a Subscriber-controlled provider

4. SLA Exclusion Standard

A failure involving a Shared Control or Third-Party Control dependency is an Excluded Event only to the extent the Service Provider can reasonably demonstrate that:-

(a) the root cause originated outside the Service Provider’s directly controlled systems;

(b) the incident was not caused by the Service Provider’s misconfiguration, inadequate integration, security settings, access controls, monitoring, selection, or operational processes;

(c) the incident was not materially contributed to or prolonged by the Service Provider’s acts or omissions; and

(d) The Service Provider used reasonable diligence and efforts to monitor, escalate, mitigate, and coordinate with the provider.

A third party’s involvement alone does not classify an incident as an Excluded Event.

5. Service Provider Responsibilities Despite Third Party Dependencies

The Service Provider remains responsible for all matters within its reasonable control, including:-

(a) configuration of third-party integrations;

(b) secure management of credentials, keys, certificates, secrets, and access controls;

(c) monitoring of material dependencies;

(d) reasonable incident detection and escalation;

(e) implementation of retry logic, fallback handling, or graceful degradation where commercially reasonable;

(f) vendor coordination during incidents;

(g) maintaining reasonable records of incidents affecting the Services;

(h) applying available fixes, patches, configuration updates, or provider recommendations where applicable and commercially reasonable;

(i) avoiding foreseeable single points of failure where reasonable for the relevant Service; and

(j) communicating material service impacts to the Subscriber in accordance with this Appendix.

A third-party dependency shall not be treated as an Excluded Event to the extent the relevant failure, delay, degradation, or disruption was caused or materially worsened by the Service Provider’s failure to perform the responsibilities set out above.

6. Scope and Duration of SLA Exclusion

Any SLA exclusion arising from a third-party dependency shall apply only:-

(a) to the affected Service component;

(b) for the period during which the third-party dependency directly caused the relevant failure, delay, degradation, or disruption; and

(c) to the extent the impact could not reasonably have been prevented, mitigated, or reduced by the Service Provider.

Unaffected Service components shall remain subject to the applicable SLA.

Where an incident has multiple causes, only the Unavailable Minutes or degradation reasonably attributable to the external provider or dependency are excluded from SLA calculations.

7. Third-Party Incident Notification

Where a confirmed third-party incident materially affects a Covered Service, the Service Provider shall use reasonable efforts to post a notice through the BlockchainCert Portal or another designated channel within two (2) hours after confirming the third-party root cause, counted during Business Hours only. The notice should include, where reasonably available:-

(a) the affected Service component or functionality;

(b) the known or estimated impact on the Subscriber;

(c) the suspected or confirmed third-party dependency involved;

(d) mitigation steps being taken by the Service Provider;

(e) any workaround available to the Subscriber;

(f) any indicative resolution timeline made available by the third-party provider; and

(g) the time of the next expected update, where practicable.

The Service Provider shall issue a follow-up notice upon restoration or when the material impact ends.

8. Evidence of Third-Party Cause

Where the Service Provider relies on a third-party dependency to exclude Unavailable Minutes, degradation, or failure from SLA calculations or SLA Credit eligibility, it shall maintain reasonable supporting records, which may include:-

(a) provider status notices;

(b) provider incident reports or service advisories;

(c) monitoring data;

(d) incident tickets;

(e) internal incident timelines;

(f) logs showing the affected component or integration;

(g) escalation records; and

(h) mitigation steps taken by the Service Provider.

On written request, the Service Provider shall provide a reasonable summary of evidence supporting a claimed exclusion, subject to confidentiality, security, legal, and third-party contractual restrictions.

9. Provider Selection, Management and Changes

(a) The Service Provider remains responsible for selecting, replacing, integrating, and managing providers used to support BlockchainCert.

(b) The Service Provider shall use commercially reasonable diligence when engaging material providers, having regard to the operational, security, availability, privacy, and regulatory risks of the dependency.

(c) Where relevant and commercially reasonable, the Service Provider may consider recognised assurance reports or certifications such as ISO 27001, SOC 2 Type II, or equivalent standards.

(d) The Service Provider may change providers in the ordinary course, provided that the change does not materially reduce the overall functionality, security, availability, data-protection standard, or regulatory-compliance posture of BlockchainCert.

(e) The Service Provider shall give advance notice where reasonably practicable of a planned material provider change affecting the Subscriber’s use, data-processing arrangements, security posture, or availability.

10. Subscriber Dependencies and Subscriber-Caused Issues

The Service Provider is not responsible for a failure caused by systems, networks, configurations, credentials, devices, applications, providers, or integrations controlled by the Subscriber or its users. Subscriber-side issues may include:-

(a) Subscriber network or internet connectivity failures;

(b) Subscriber firewall, proxy, VPN, browser, endpoint, or device issues;

(c) Subscriber misconfiguration of APIs, webhooks, credentials, permissions, or access controls;

(d) Subscriber failure to maintain required integrations or software environments;

(e) Subscriber-provided third-party systems or data sources;

(f) unauthorised changes made by the Subscriber or its users; and

(g) failure by the Subscriber to follow reasonable technical requirements or implementation guidance provided by the Service Provider.

Such Subscriber-caused issues shall be excluded from SLA calculations and SLA Credit eligibility to the extent they caused or contributed to the relevant failure, delay, degradation, or disruption.

11. Non-Exhaustive Dependencies

The listed dependencies are illustrative and non-exhaustive. An additional dependency is assessed under the same control, responsibility, evidence, and exclusion standards. Listing a dependency does not automatically exclude every incident involving it.

12. Order of Precedence

If this Appendix conflicts with the main body of the SLA, the main body prevails unless expressly stated otherwise. Nothing here limits liability that cannot lawfully be limited or excluded.