Service Level Agreement

1. Preamble

1.1 This Service Level Agreement (“SLA”) forms part of and is incorporated into the BlockchainCert subscription agreement or other principal written agreement, together with each schedule other than this SLA, order form, subscription package and statement of work forming part of it, entered into between MASVERSE EDUTECH SDN BHD (Registration No. 202301015731 (1509653-K)) (“Service Provider”) and the subscriber identified therein (“Subscriber”), under which the Subscriber is granted access to the BlockchainCert platform and related services (collectively, the “Subscription Agreement”). The version of this SLA applicable to a Subscriber is the version identified in that Subscriber’s Subscription Agreement.

1.2 This SLA sets out the service availability commitments, incident response targets, SLA Credit mechanism, support obligations, exclusions, limitations, and responsibility boundaries applicable to the production BlockchainCert Covered Services.

1.3 In the event of any inconsistency or conflict between this SLA and the Subscription Agreement in relation to service availability, service levels, support obligations, incident response, disaster recovery, business continuity, SLA Credits, or other operational service commitments of a similar nature, this SLA shall prevail to the extent of such inconsistency, unless the Subscription Agreement expressly states otherwise.

1.4 For the avoidance of doubt, this SLA does not relieve the Subscriber of any regulatory, statutory, supervisory, institutional, or compliance obligation applicable to the Subscriber, its Credential content, or its recipients. The Service Provider shall only be responsible for the obligations assumed by it under this SLA and the Subscription Agreement.

1.5 This SLA applies only to a Subscriber that has entered into a Subscription Agreement with the Service Provider, and only to the Covered Services enabled for that Subscriber. It confers no right on any other person and no right in respect of any sandbox, test, beta, preview, trial, proof-of-concept or free service.

2. Definitions and Interpretation

2.1 In this SLA, unless the context otherwise requires, the following terms have the meanings set out below. Capitalised terms used but not defined in this SLA have the meanings given to them in the Subscription Agreement.

Defined TermMeaning
Authorised Contactmeans an individual designated by the Subscriber in writing or through the BlockchainCert Portal as authorised to report incidents, submit support requests, and receive communications under this SLA.
Business Daymeans any day other than a Saturday, Sunday, or Malaysian federal public holiday.
Business Hourshas the meaning given in Clause 8.7.
Critical (P1)”, “High (P2)”, “Medium (P3)”, and “Low (P4)have the meanings given in Clause 7.
Subscriberhas the meaning given in the Preamble. References to the Subscriber include each Authorised Contact acting on its behalf.
Subscriber Confidential Informationhas the meaning given in Clause 12.1 (also referred to in this SLA as “Subscriber Information”).
Subscriber Personal Datameans personal data, as defined under the PDPA, relating to the Subscriber’s Credential recipients, personnel, users, or other natural persons, processed by the Service Provider in connection with the Covered Services.
Unavailable Minutemeans an Eligible Minute during which the applicable Covered Service is not Available.
Availabilitymeans the percentage of Eligible Minutes in a Measurement Period during which the applicable Covered Service is Available, calculated in accordance with Clause 5.2.
Emergency Maintenancehas the meaning given in Clause 6.2.
BlockchainCert Portalmeans the production organisation, administration, credential-management, recipient, public-verification, support, or monitoring interface made available by the Service Provider, as applicable to the relevant user.
Excluded Eventhas the meaning given in Clause 15.4.
Maintenance Windowmeans a scheduled period notified by the Service Provider in accordance with Clause 6.1 during which Scheduled Maintenance may be performed.
BlockchainCertmeans the digital credential issuance, management, recipient-access, and public-verification platform operated by MASVERSE EDUTECH SDN BHD.
Subscription Agreementhas the meaning given in the Preamble.
Eligible Minutesmeans all minutes in a Measurement Period for the applicable Covered Service, excluding minutes affected by an Excluded Event or Scheduled Maintenance notified in accordance with Clause 6.1.
Monthly Equivalent Feehas the meaning given in Clause 9.2.
MasChain Networkmeans the underlying MasChain blockchain network on which a cryptographic hash, transaction reference, NFT record, or other minimised verification metadata may be anchored for a Credential.
PDPAmeans the Personal Data Protection Act 2010 of Malaysia.
Recipientmeans the individual or entity to whom a Credential is issued or who is authorised to access or claim it.
Resolutionshall be construed in accordance with Clauses 8.2 and 8.4.
Responsehas the meaning given in Clause 8.3.
Scheduled Maintenancemeans scheduled maintenance carried out by the Service Provider in accordance with Clause 6.1.
SLA Creditsmeans the credits calculated and applied in accordance with Clause 9.
Service Documentationmeans the functional specifications, API documentation, implementation guides, operational requirements, usage procedures, limitations, and other documentation made available or notified by the Service Provider to the Subscriber from time to time in respect of BlockchainCert.
Subscription Packagemeans the BlockchainCert subscription package or plan selected by the Subscriber under the Subscription Agreement.
Services“ or “Covered Servicesmeans the production BlockchainCert services described in Clauses 3.2 and 4 that are enabled for the Subscriber, and any other service expressly stated in the Subscription Agreement or Service Documentation as being covered by this SLA.
SLAmeans this Service Level Agreement.
Service Tiermeans the Standard availability and support tier described in Clause 5.1 and the applicable Subscription Agreement.
Sub-Processormeans any third party engaged by the Service Provider to process Subscriber Personal Data on behalf of the Subscriber in connection with the Covered Services, as contemplated in Clause 11.3.
Credentialmeans a digital certificate, academic or professional credential, badge, record, or similar verification document issued, managed, or verified through BlockchainCert.
Availablemeans materially accessible and capable of performing the material production function for the applicable Covered Service and its intended users.
Measurement Periodmeans each calendar month during the term of the Subscription Agreement for which Availability and any Credits are calculated.
Subscriber Datameans Subscriber Personal Data, Credential content, files, templates, brand assets, records, and other data submitted to or generated through BlockchainCert for the Subscriber, excluding public on-chain verification records and Service Provider system data that does not identify the Subscriber or a Recipient.

2.2 Headings are inserted for convenience only and shall not affect the interpretation of this SLA. Unless otherwise stated, references to a “Clause” or “Schedule” are references to a Clause or schedule of this SLA. References to any statute, regulation, guideline, directive, notice, or other applicable law shall include any subsidiary legislation made under it, and any amendment, modification, replacement, or re-enactment of it from time to time. Words importing the singular shall include the plural and vice versa.

3. Purpose and Scope

3.1 This SLA defines the minimum operational standards for the production BlockchainCert platform, including credential issuance, credential management, recipient access, public verification, subscription and credit administration, notifications, reporting, and optional API or white-label functions expressly included in the Subscription Agreement.

3.2 This SLA applies only to the following production Covered Services to the extent they are enabled for the Subscriber and directly operated, managed, or controlled by the Service Provider:-

(a) organisation onboarding, profile administration, know-your-business (KYB) workflow, departments, staff roles, and access management;

(b) Credential template creation, design, preview, branding, and management;

(c) individual and bulk Credential creation, validation, PDF generation, publication, and delivery;

(d) blockchain anchoring of Credential verification records on the MasChain Network, including managed wallet and transaction handling performed by BlockchainCert;

(e) the organisation Credential management dashboard and lifecycle-status functions;

(f) the Recipient portal, including access, sharing, download, claim, and supported ownership-transfer workflows;

(g) the public verification portal, QR-code, reference-number, file-fingerprint, public-search, and microsite functions;

(h) subscription package, allocation, credit, top-up, invoice, and billing-administration functions;

(i) email notification and supported payment-gateway integration functions;

(j) API keys, documented API endpoints, callbacks, and webhooks, where included in the Subscription Package;

(k) platform reports, audit logs, localisation, and multilingual interface functions; and

(l) optional white-label, cloud, or on-premises deployment services only where expressly included in an Order Form or Statement of Work.

3.3 This SLA does not apply to any unavailability, degradation, delay, failure, loss, or interruption arising from or relating to:-

(a) Subscriber systems, applications, databases, networks, devices, browsers, access credentials, API integrations, or internal infrastructure;

(b) third-party email, telecommunications, internet, hosting, payment, identity, storage, DNS, CDN, or external API services not directly controlled by the Service Provider, subject to Appendix A;

(c) the MasChain Network or other distributed-ledger components outside the Service Provider’s direct operational control, subject to the responsibility and evidence standards in Appendix A;

(d) Subscriber-side configuration errors, inaccurate Credential content, misuse, unauthorised access, failure to follow Service Documentation, or failure to implement required updates or security measures;

(e) Scheduled Maintenance notified in accordance with Clause 6.1, Emergency Maintenance, or other exclusions expressly stated in this SLA;

(f) force majeure events, extraordinary cyberattacks, denial-of-service attacks, malware, regulatory intervention, or other events beyond the Service Provider’s reasonable control; or

(g) legal, regulatory, accreditation, employment, admission, licensing, commercial, financial, or other business outcomes arising from the Subscriber’s issuance or use of Credentials.

3.4 The Service Provider is responsible for the availability and performance of the Covered Services within its operational control. The Subscriber remains responsible for its Credential content, issuing authority, recipient notices and consents, users, access controls, compliance obligations, internal approvals, systems, integrations, and use of outputs generated through BlockchainCert.

4. Services

4.1 Subject to the Subscription Agreement, Service Documentation, and any other written agreement between the parties, this SLA applies to the Covered Services described in this Clause 4.

4.2 The Service Provider may update, enhance, modify, suspend, replace, or retire a Covered Service or related feature, interface, API, dependency, or Service Documentation in accordance with the Subscription Agreement, provided that it shall not materially reduce the core functionality or service commitments expressly agreed with the Subscriber during the active subscription term without reasonable prior notice or an alternative path where practicable.

4.3 The Covered Services are set out below. Availability is measured only for the material production functions of each Covered Service and not for each individual capability listed in the final column:-

No.ServiceService DescriptionCovered Capabilities
1. Organisation Onboarding and Administration

Enables subscribing organisations to register, complete applicable KYB steps, maintain their BlockchainCert profile, structure departments, and administer authorised users.

(a) Organisation Registration and Approval: Self-registration, email verification, administrator review, approval, rejection, suspension, and reactivation workflows.

(b) Organisation Profile: Maintenance of legal, contact, branding, and organisation information displayed or used by BlockchainCert.

(c) KYB Workflow: Submission and review of organisation verification information where required for the relevant package or use case.

(d) Department Management: Creation and administration of departments or business units for delegated Credential operations.

(e) Staff and Role Management: Administrator, sub-administrator, department, and other role-based permissions supported by the platform.

(f) Access Controls: Account authentication, invitation, activation, deactivation, permission assignment, and password-management functions.

(g) Organisation Directory and Taxonomy: Platform-supported categories and organisation classifications.

(h) Administrative Auditability: Relevant activity records and reports available to authorised administrators.

(i) Localisation: Interface support for English, Chinese, and Malay where implemented in the subscribed release.

2. Credential Template and Design

Enables authorised users to create, configure, preview, brand, and manage reusable templates for Credentials issued through BlockchainCert.

(a) Template Library: Creation, copying, updating, activation, deactivation, search, and organisation of reusable templates.

(b) Template Designer: Browser-based layout and design tools for supported Credential formats.

(c) Data Fields: Configuration of recipient, Credential, issuing-organisation, date, reference, and custom fields supported by the selected template.

(d) Brand Assets: Upload and placement of supported logos, backgrounds, signatures, seals, images, and other design assets.

(e) Verification Elements: Placement of QR codes, reference identifiers, verification links, and other supported authenticity indicators.

(f) Preview and Validation: Preview of representative content and validation of required fields before publication.

(g) Template Permissions: Role-based access to create, edit, approve, and use templates.

(h) Template Governance: Status, ownership, and change controls supported by the platform.

3. Credential Issuance and Blockchain Publishing

Enables authorised organisations to create, validate, publish, and deliver Credentials, with a tamper-evident verification record anchored on the MasChain Network.

(a) Individual Issuance: Creation and publication of a Credential for a single Recipient through the production workflow.

(b) Bulk Issuance: CSV or supported-file import, validation, preview, and publication of up to five hundred (500) Credentials per supported batch, subject to package allocations and platform limits.

(c) Issuance Validation: Required-field, duplicate, format, allocation, and workflow checks before publication.

(d) Managed Blockchain Processing: Platform-managed wallet, NFT, smart-contract, and transaction functions required to anchor the verification record.

(e) Data Minimisation: BlockchainCert is designed to anchor a cryptographic hash, transaction reference, or minimised verification metadata rather than direct personal data, unless expressly agreed and lawful.

(f) Credential Rendering: Generation of the supported Credential document or image with QR code, reference number, and verification link.

(g) Publication Status: Queued, processing, published, failed, revoked, expired, or other lifecycle statuses supported by the platform.

(h) Delivery Workflow: Supported email delivery and status notifications, subject to third-party delivery dependencies.

(i) Transaction Confirmation: Processing and display of the relevant blockchain transaction reference and confirmation status.

(j) Retry and Exception Handling: Supported reprocessing, error reporting, and operational handling for failed publication attempts.

4. Credential Management and Public Verification

Provides the organisation dashboard and public-facing mechanisms for managing, locating, and verifying Credentials issued through BlockchainCert.

(a) Credential Dashboard: Search, filter, view, download, tag, categorise, revoke, expire, and otherwise manage issued Credentials according to supported permissions.

(b) Verification Methods: Verification by QR code, reference number, supported file upload or fingerprint, verification link, or public Credential search.

(c) Public Results and Microsites: Display of authenticity, issuer, status, and other permitted Credential information through the verification portal or configured organisation microsite.

5. Recipient Portal and Credential Lifecycle

Enables Recipients to access and manage Credentials made available to them, subject to the issuing organisation’s configuration and the selected Subscription Package.

(a) Recipient Authentication: Email one-time password or other supported authentication for Recipient access.

(b) Credential Access: View, share, and download supported Credentials and verification links.

(c) Status Visibility: Display of published, revoked, expired, pending, claimed, or other supported lifecycle status.

(d) Ownership Claim: Supported claim workflow for an eligible Credential, subject to issuer rules and verification.

(e) Ownership Transfer: Supported transfer workflow using confirmation controls such as one-time passwords, where enabled.

(f) Recipient Payment: Payment-enabled access or transfer functions only where expressly enabled and subject to the payment-gateway boundary in Appendix A.

(g) Support Requests: Recipient or user support-ticket submission where enabled.

(h) Recipient Communications: Supported access, claim, transfer, payment, and status notifications.

(i) Privacy Controls: Display and processing limited by the issuing organisation’s configuration, lawful instructions, and applicable privacy requirements.

(j) Lifecycle Integrity: A status change does not erase the underlying blockchain record and must be reflected through the supported verification status.

(k) Activity History: Supported records of relevant Recipient and Credential lifecycle events.

6. Subscription, Credits, and Billing

Provides the Subscriber with package-selection, Credential-allocation, credit, top-up, renewal, invoice, and billing-administration functions supported by BlockchainCert.

(a) Subscription Packages: Selection and administration of available plans, features, limits, and renewal settings.

(b) Allocations and Credits: Tracking of Credential allocations or credits, consumption, expiry, and eligible top-ups (being Credential issuance allocations under the Subscription Agreement, and not SLA Credits) in accordance with the Subscription Agreement.

(c) Plan Changes: Supported upgrade, downgrade, renewal, cancellation, and package-change workflows, subject to the applicable commercial terms.

(d) Payment and Invoices: Integration with eGHL or another approved gateway for supported payments, together with invoice or receipt records made available by the platform.

7. APIs, Integrations, Notifications, and Reporting

Provides optional technical interfaces and operational information for integrating BlockchainCert with Subscriber systems and for administering the subscribed service.

(a) API Credential Management: Creation, activation, rotation, restriction, and revocation of API keys or credentials where API access is included.

(b) Documented Endpoints: Supported organisation, template, Credential, verification, Recipient, subscription, report, or other endpoints identified in the Service Documentation.

(c) Callbacks and Webhooks: Configurable event notifications, delivery status, retry handling, and callback records for supported events.

(d) Email Notifications: Platform-triggered delivery and operational messages, subject to third-party mail systems and recipient settings.

(e) Reports and Audit Logs: Supported usage, issuance, verification, credit, billing, operational, and administrative reports.

(f) Blockchain Explorer Linkage: Display of relevant MasChain Network transaction references where supported.

(g) Localisation: Supported language and date, time, currency, or regional display settings.

(h) Optional White-Label Deployment: Dedicated cloud or on-premises deployment, branding, integration, testing, UAT, handover, training, and ongoing support only where expressly scoped in a Statement of Work.

4.4 The technical specifications, APIs, endpoints, supported functions, operational requirements, limitations, dependencies, usage procedures, and implementation requirements for each Covered Service shall be set out in the applicable Service Documentation, which may be updated in accordance with the Subscription Agreement.

4.5 The Subscriber shall comply with the applicable Service Documentation, including authentication, configuration, data-formatting, operational, integration, privacy, and security requirements.

4.6 Unless expressly stated otherwise in the Subscription Agreement or Service Documentation, this SLA applies only to the Covered Services and capabilities enabled for the Subscriber, and not to any feature, module, API, white-label deployment, endpoint, or functionality outside the applicable commercial arrangement.

5. Service Availability Commitment

5.1 The Service Provider shall use commercially reasonable efforts to make each applicable production Covered Service available in accordance with the following Monthly Availability Commitment:-

Service TierMonthly Availability CommitmentEligibility
Standard99.5%Applicable to the Subscriber

The Monthly Availability Commitment applies separately to each production Covered Service that is:-

(a) expressly included in the Subscriber’s Subscription Package;

(b) directly operated, managed, or controlled by the Service Provider; and

(c) made available for production use under the Subscription Agreement.

For the avoidance of doubt, the Monthly Availability Commitment does not apply to sandbox, test, beta, proof-of-concept, free-trial, preview, custom-development, implementation, training, or professional-services environments unless expressly agreed in writing.

5.2 Measurement of Availability

(a) Availability for each Covered Service and Measurement Period shall be calculated as follows:-

Availability = (Eligible Minutes − Unavailable Minutes) ÷ Eligible Minutes × 100

The calculation shall be made separately for each Covered Service.

(b) A minute is an Unavailable Minute only where a material production function of the applicable Covered Service is unavailable to a material proportion of its intended users, as confirmed by the Service Provider’s monitoring and incident records.

(c) The Service Provider’s monitoring systems shall be the primary reference source. Where the Subscriber reasonably demonstrates a material discrepancy using its own evidence, the parties shall in good faith reconcile the records and adjust the calculation where appropriate.

(d) Unavailable Minutes shall exclude Excluded Events, Emergency Maintenance meeting Clause 6.2, and Scheduled Maintenance notified in accordance with Clause 6.1.

(e) Where a Covered Service is provided for part only of a Measurement Period, Availability is calculated by reference to that part. Where there are no Eligible Minutes in a Measurement Period, the applicable Monthly Availability Commitment is deemed to have been met and no SLA Credit is payable for that Measurement Period.

(f) Covered Service Measurement Boundaries

Availability is measured separately for each Covered Service against its material production function as set out below:-

Covered ServiceMaterial Production Function
Credential IssuanceCreation, validation, publication, and delivery processing for a Credential through the production issuance workflow.
Credential Management DashboardAuthenticated access to locate, view, and perform supported lifecycle management of issued Credentials.
Public Verification PortalVerification of an issued Credential by a supported QR code, reference, link, file fingerprint, upload, or public search method.
Recipient PortalRecipient authentication and access to view, share, or download an eligible Credential, where included in the Subscription Package.
Subscribed API EndpointsAcceptance and processing of valid authenticated requests at the BlockchainCert service boundary, where API access is expressly included.
Other Platform FunctionsOrganisation administration, billing, notifications, and other functions are not separately measured unless expressly identified as a Covered Service; their impact counts where it makes a listed Covered Service unavailable.

A failure of one capability does not make another Covered Service unavailable unless that other Covered Service is also unable to perform its material production function.

Availability does not measure the legal validity, recipient acceptance, accreditation, payment outcome, email delivery, or blockchain finality of a Credential.

6. Maintenance

6.1 Scheduled Maintenance

(a) The Service Provider may perform Scheduled Maintenance to maintain the reliability, security, compliance, performance, or proper operation of the Covered Services.

(b) Where Scheduled Maintenance is expected to cause a material service interruption, the Service Provider shall, where practicable, provide at least five (5) Business Days’ prior notice.

(c) Where Scheduled Maintenance is not expected to cause a material service interruption, the Service Provider shall use commercially reasonable efforts to provide reasonable prior notice.

(d) Scheduled Maintenance shall, where reasonably practicable, be performed during the notified Maintenance Window.

6.2 Emergency Maintenance

(a) The Service Provider may perform Emergency Maintenance where reasonably necessary to address a security vulnerability, active threat, material defect, platform instability, data-integrity risk, legal requirement, or other urgent operational issue.

(b) Where Emergency Maintenance is required and service interruption is expected, the Service Provider shall use commercially reasonable efforts to notify the Subscriber in advance where practicable.

(c) Where prior notice is not practicable, the Service Provider shall notify the Subscriber as soon as reasonably possible after commencement.

(d) Emergency Maintenance shall be excluded from Availability only to the extent reasonably necessary and meeting the requirements of this Clause 6.2.

6.3 Disaster Recovery and Business Continuity

(a) The Service Provider shall maintain commercially reasonable disaster-recovery and business-continuity procedures designed to support the continuity, restoration, and resilience of the Covered Services within its operational control.

(b) Those procedures may include backup, restoration, incident escalation, infrastructure recovery, and periodic internal review or testing appropriate to BlockchainCert.

(c) Unless expressly agreed in the Subscription Agreement, any recovery time objective, recovery point objective, test frequency, or similar recovery commitment is an operational target and not a guaranteed service commitment.

(d) This Clause 6.3 does not apply to Subscriber-managed systems, Subscriber integrations, third-party infrastructure outside the Service Provider’s control, MasChain Network confirmation delays or consensus events, or permanent on-chain records already confirmed.

(e) The Subscriber acknowledges that verification records confirmed on the MasChain Network are designed to be immutable and permanently retained as part of the applicable blockchain architecture.

7. Incident Severity Classification

7.1 Incidents shall be classified according to the severity levels set out in the table below:-

SeverityDescription
Critical (“P1”)A material production outage of Credential issuance, the Credential management dashboard, or the public verification portal affecting all or substantially all intended users; or a confirmed security incident materially affecting Subscriber Personal Data, with no reasonable workaround.
High (“P2”)Significant degradation or partial outage of a core BlockchainCert function affecting a material subset of users, where the function is impaired but remains partially available or a limited workaround exists.
Medium (“P3”)A non-critical defect, limited degradation, or feature failure with a reasonable workaround and limited operational impact.
Low (“P4”)A cosmetic issue, documentation error, configuration question, how-to request, or general enquiry with no material functional impact.

8. Incident Response and Resolution Targets

8.1 The Service Provider shall provide Standard Support during Business Hours. Restoration efforts and incident updates under this Clause 8 are provided during Business Hours, unless otherwise agreed in writing. A reference in this Clause 8 to continuous efforts means continuous during Business Hours. Any activity carried out by the Service Provider outside Business Hours is at its discretion and does not extend its obligations under this Clause.

8.2 The applicable target response times and target resolution times are set out below:-

SeverityTarget Response TimeTarget Resolution Time
P1Standard: within two (2) Business Hours.Continuous commercially reasonable efforts to restore the affected Covered Service as soon as reasonably practicable.
P2Standard: within four (4) Business Hours.Commercially reasonable efforts, with priority based on impact, complexity, and available mitigation.
P3Within one (1) Business Day.Commercially reasonable efforts or inclusion in an appropriate scheduled release.
P4Within two (2) Business Days.As reasonably prioritised based on impact, roadmap, and operational considerations.

8.3 For this SLA, “Response” means acknowledgement, logging, initial triage, and an initial indication of severity or support category.

8.4 Response targets are operational service targets. Resolution targets are commercially reasonable objectives and not fixed guarantees. A qualifying missed P1 or P2 response target may give rise only to the response SLA Credits in Clause 9.

8.5 For P1 incidents, the Service Provider shall provide reasonable status updates at least every four (4) hours during active incident management, where practicable, and may provide a workaround or interim mitigation. Upon written request, a material P1 incident summary shall be provided within ten (10) Business Days after closure.

8.6 Incidents must be reported through a support channel designated by the Service Provider and include the affected Covered Service, time and impact, users or Recipients affected, error messages or screenshots where available, and reasonable diagnostic information.

8.7 For the purposes of this SLA, “Business Hours” means 9:00 a.m. to 5:00 p.m. Malaysia Time, Monday to Friday, excluding Malaysian federal public holidays. A period expressed in Business Hours is counted only during Business Hours, running from receipt of a conforming incident report under Clause 8.6, and time falling outside Business Hours does not count.

9. SLA Credits

9.1 SLA Credit Eligibility

(a) If Availability falls below the applicable Monthly Availability Commitment for an affected Covered Service, the Subscriber may be eligible for SLA Credits calculated against the Monthly Equivalent Fee under this Clause 9.

(b) The applicable Availability SLA Credits are as follows:-

Monthly Availability for the affected Covered ServiceSLA Credit
Below the applicable commitment and equal to or greater than 99.0%5% of the Monthly Equivalent Fee
Less than 99.0% and equal to or greater than 97.0%15% of the Monthly Equivalent Fee
Less than 97.0% and equal to or greater than 95.0%25% of the Monthly Equivalent Fee
Less than 95.0%50% of the Monthly Equivalent Fee

(c) The aggregate of Availability and response SLA Credits for a calendar month shall not exceed fifty per cent (50%) of the Monthly Equivalent Fee for the affected Covered Service.

9.2 Monthly Equivalent Fee

For this SLA, “Monthly Equivalent Fee” means the recurring subscription fee allocated to the affected Covered Service for the relevant month. An annual prepaid fee is divided by twelve (12). If the Subscription Agreement does not allocate a fee by Covered Service, the Service Provider shall make a reasonable pro-rata allocation.

The Monthly Equivalent Fee excludes taxes, one-time and professional-services fees, implementation and integration fees, top-ups, variable usage charges, third-party pass-through charges, and fees for unaffected services.

9.3 SLA Credit Mechanics

(a) SLA Credits shall be calculated monthly for the affected Covered Service.

(b) Approved SLA Credits may be applied against future subscription fees, renewal fees, eligible top-ups, or add-ons and remain valid for twelve (12) months from approval.

(c) SLA Credits have no cash value, are non-transferable, and are not refundable, except for the termination and refund rights expressly provided in Clause 9.5.

(d) SLA Credits do not apply automatically. The Subscriber must submit a valid claim under Clause 9.6.

9.4 Sole Remedy

Subject to Clause 13.3 and the termination and refund rights set out in Clause 9.5, SLA Credits are the Subscriber’s sole financial remedy for a failure to meet an Availability or support-response target under this SLA, but only to the extent SLA Credits are available to the Subscriber in respect of that failure. This Clause does not limit the Subscriber’s rights under Clause 9.5 or under the Subscription Agreement, and does not exclude any remedy where no SLA Credit is available in respect of that failure.

9.5 Support Response Credits and Repeated Service Availability Failure

(a) For a calendar month, two (2) to three (3) qualifying missed P1 or P2 initial response targets entitle the Subscriber to a five per cent (5%) response SLA Credit, and four (4) or more qualifying misses entitle the Subscriber to a ten per cent (10%) response SLA Credit, each calculated against the Monthly Equivalent Fee and subject to the aggregate cap in Clause 9.1.

(b) A missed response target is a qualifying miss only where it:-

(i) relates to a single valid incident reported in accordance with Clause 8.6 at the applicable severity; and

(ii) was not caused by, or attributable to, an Excluded Event.

Multiple reports of the same underlying incident count as one incident.

(c) A repeated service availability failure shall be deemed to occur for the same affected Covered Service where, excluding Excluded Events:-

(i) Availability is below 99.0% in two (2) consecutive months;

(ii) the applicable commitment is missed in three (3) months within a rolling six (6)-month period; or

(iii) three (3) P1 incidents occur within a rolling three (3)-month period and each causes more than four (4) hours of Unavailable Minutes.

(d) Where a repeated service availability failure occurs, the Subscriber may, by written notice given within thirty (30) calendar days after the earlier of (i) the Service Provider’s written confirmation that the relevant event has occurred and (ii) the end of the calendar month in which the last failure constituting that event occurred, terminate the affected Subscription Package and receive a prorated refund of any unused prepaid fees attributable to the affected Subscription Package, less any SLA Credits already granted for the same period.

9.6 SLA Credit Claims

(a) To be eligible for SLA Credits, the Subscriber must submit a written claim within thirty (30) calendar days after the end of the affected month and provide reasonable details of the affected times, Covered Service, user impact, relevant support tickets, and available evidence.

(b) The Service Provider shall determine eligibility using monitoring, incident, and support records, acting reasonably and in good faith.

(c) Where the Subscriber reasonably challenges the calculation using its own evidence, the parties shall review and reconcile the records in good faith.

(d) An approved SLA Credit shall be applied in accordance with Clauses 9.3 (b) and 9.3 (c).

10. Information Security

10.1 Security Programme

(a) The Service Provider shall maintain a commercially reasonable information-security programme designed to protect the confidentiality, integrity, and availability of BlockchainCert and Subscriber Data processed by the Service Provider.

(b) The programme shall include administrative, technical, and organisational safeguards appropriate to the nature of the Covered Services, the data processed, and the associated risks.

(c) Upon the Subscriber’s written request and subject to confidentiality obligations, the Service Provider may make available reasonable security documentation or summaries of its security practices, where available and appropriate.

10.2 Security Controls

The Service Provider shall implement and maintain commercially reasonable security controls, which may include the following:-

Security ControlRequirement
Encryption in transitThe Service Provider shall use commercially reasonable encryption protocols for external interfaces, where applicable.
Encryption at restThe Service Provider shall apply encryption or other appropriate safeguards for sensitive Subscriber Data stored in Service Provider-controlled systems, where applicable.
Access controlThe Service Provider shall maintain access controls designed to restrict access to Subscriber Data and production systems to authorised personnel only.
Identity and access managementThe Service Provider shall apply role-based access control and the principle of least privilege for access to production systems, where reasonably practicable.
Vulnerability managementThe Service Provider shall maintain reasonable vulnerability management and patching processes based on severity, risk, and operational impact.
Application securityThe Service Provider shall apply reasonable secure development practices in the design, development, testing, and deployment of the Services.
Security testingThe Service Provider may conduct security testing, vulnerability assessments, or penetration testing from time to time as the Service Provider considers appropriate.

10.3 Personnel Security

The Service Provider’s personnel with access to Subscriber Data shall be subject to appropriate confidentiality obligations and internal security requirements. The Service Provider may provide security-awareness or data-protection training to relevant personnel under its policies and procedures.

10.4 Security Incident Notification

(a) The Service Provider shall notify the Subscriber without undue delay after becoming aware of a security incident that materially affects Subscriber Personal Data or Subscriber Confidential Information and, where applicable, in sufficient time to support the Subscriber’s statutory notification deadlines.

(b) The Service Provider shall provide information reasonably available regarding:-

(i) the nature, date, and likely consequences of the security incident;

(ii) the affected Covered Services, data categories, and approximate data-subject scope, to the extent known;

(iii) the containment, mitigation, remediation, and investigation measures taken or proposed; and

(iv) a contact point and information reasonably required for the Subscriber’s legally required notifications.

(c) The Service Provider shall provide reasonable updates, preserve appropriate incident records, and reasonably assist the Subscriber with its response obligations.

(d) Any notification or cooperation under this Clause 10.4 shall not be construed as an admission of fault or liability by the Service Provider.

11. Data Protection and Privacy

11.1 Compliance with Data Protection Laws

(a) Each party shall comply with the Personal Data Protection Act 2010 of Malaysia, as amended, and other data-protection laws applicable to that party in connection with BlockchainCert.

(b) To the extent the Subscriber determines the purposes and means of processing Subscriber Personal Data, the Subscriber acts as data controller and the Service Provider acts as data processor.

(c) The Subscriber is responsible for appropriate privacy notices, consents or other lawful bases, data accuracy, and instructions for collecting, issuing, publishing, verifying, retaining, transferring, and otherwise processing Subscriber Personal Data and Credential content.

(d) The Service Provider acts as an independent data controller for personal data processed for its own lawful purposes, including account administration, KYB, billing, security, fraud prevention and legal compliance.

11.2 Data Hosting, Residency and Cross-Border Transfers

(a) Subscriber Personal Data may be hosted or processed in the locations used by the Service Provider and its approved providers, subject to the Subscription Agreement and applicable cross-border transfer requirements.

(b) The Service Provider shall effect cross-border transfers in accordance with applicable law and shall provide reasonable information needed for the Subscriber to assess those transfers.

(c) Any specific data-residency or localisation requirement must be expressly agreed in the Subscription Agreement or an applicable Statement of Work.

11.3 Sub-Processors

(a) The Service Provider may use Sub-Processors to host, secure, maintain, support, or deliver BlockchainCert. The Service Provider shall provide reasonable information about material Sub-Processors and reasonable notice of a material change where required by the Subscription Agreement or applicable law.

(b) The Service Provider shall impose confidentiality, data-protection, and security obligations on each material Sub-Processor that are appropriate to the processing performed and shall remain responsible for its obligations under this SLA.

(c) Upon written request, the Service Provider shall provide reasonable information regarding material Sub-Processors, subject to confidentiality and security limitations.

11.4 Data Subject Rights

Taking into account the nature of processing and information available, the Service Provider shall reasonably assist the Subscriber with data-subject requests, data-protection impact assessments, regulatory enquiries, and security-incident obligations. The Subscriber remains primarily responsible for responding as controller.

11.5 Data Return and Deletion

(a) Upon expiry or termination, the Service Provider shall, on the Subscriber’s written request, return or delete Subscriber Personal Data held in Service Provider-controlled off-chain systems within a reasonable period, unless retention is required or permitted by law, the Subscription Agreement, security requirements, or ordinary backup cycles.

(b) The Service Provider is not required to delete a record that is immutably recorded on the MasChain Network or that it is legally required or permitted to retain.

(c) The Subscriber shall not knowingly submit direct personal data for on-chain recording unless expressly agreed, lawful, and technically supported. BlockchainCert is intended to anchor a cryptographic hash, reference, or minimised metadata; the Subscriber must review Credential content and metadata before issuance.

12. Subscriber Confidential Information

12.1 Confidentiality

This Clause 12 is subject to, and does not expand, Clause 9 of the Subscription Agreement. The Service Provider shall treat Subscriber Confidential Information (“Subscriber Information”) as confidential and shall not access, use, disclose or process such information except:-

(a) as necessary to provide, maintain, support, secure or improve the Services, and in the case of improvement of the Services using aggregated or de-identified information where reasonably practicable;

(b) in accordance with the Subscriber’s written instructions;

(c) as permitted under this SLA, the Subscription Agreement or applicable Service Documentation;

(d) to approved personnel, affiliates, contractors, service providers or sub-processors who require access for the purpose of providing the Services and who are subject to appropriate confidentiality obligations; or

(e) where required by applicable law, court order, regulator direction, governmental authority or legal process.

12.2 Protection of Subscriber Confidential Information

The Service Provider shall implement reasonable administrative, technical and organisational measures designed to protect Subscriber Confidential Information against unauthorised access, disclosure, alteration, loss or destruction.

12.3 Exclusions

Subscriber Confidential Information shall not include information that:-

(a) is or becomes publicly available other than through a breach of this SLA by the Service Provider;

(b) was lawfully known to the Service Provider before receiving it from the Subscriber;

(c) is lawfully received by the Service Provider from a third party without breach of confidentiality obligations; or

(d) is independently developed by the Service Provider without use of or reference to the Subscriber Confidential Information.

12.4 Survival

The obligations in this Clause 12 survive expiry or termination for the same period as applies under Clause 9.5 of the Subscription Agreement.

13. Liability Boundary

13.1 Limitation of Liability

Subject to Clause 13.3 and the Subscription Agreement, the Service Provider’s aggregate financial liability under this SLA for failure to meet an Availability or response target is limited to the SLA Credits and the termination and refund rights expressly provided under Clause 9, provided that this Clause does not operate to exclude every remedy for that failure where no SLA Credit and no right under Clause 9 is available to the Subscriber in respect of it.

13.2 Exclusion of Damages

Subject to Clause 13.3 and the Subscription Agreement, the Service Provider shall not be liable under this SLA for indirect, incidental, consequential, punitive, exemplary, or special damages, including loss of profit, revenue, opportunity, goodwill, reputation, business, use, or data.

13.3 Carve-Outs

Nothing in this SLA shall exclude or limit liability to the extent such liability cannot be excluded or limited under applicable law. Any additional exclusions from limitation of liability, liability caps, indemnities, or special liability arrangements shall be governed by the Subscription Agreement.

13.4 Interaction with Subscription Agreement

(a) This Clause 13 shall be read together with the corresponding limitation and indemnity provisions of the Subscription Agreement.

(b) If this Clause 13 conflicts with an express liability provision in the Subscription Agreement, the Subscription Agreement shall prevail to the extent of the conflict.

14. Subscriber Responsibilities

14.1 General Responsibility

The Subscriber is responsible for using BlockchainCert in a properly configured, lawful, and authorised manner consistent with the Service Documentation.

14.2 Integration and Technical Implementation

(a) Where API access is included, the Subscriber is responsible for implementing and maintaining its integration, including proper configuration, authentication, request formatting, and secure credential handling.

(b) The Subscriber shall submit valid requests and implement appropriate error handling, retry, backoff, timeout, and reconciliation controls for its integrations.

(c) The Subscriber shall maintain compatibility of its systems with supported interfaces, browsers, file formats, and protocols.

(d) The Service Provider is not responsible for issues caused by incorrect implementation, malformed requests, unsupported environments, or improper use by the Subscriber.

14.3 Systems, Connectivity and Infrastructure

The Subscriber is responsible for its systems, networks, devices, browsers, email access, and internet connectivity required to use BlockchainCert.

14.4 Security and Access Management

(a) The Subscriber shall secure its administrator accounts, passwords, API keys, credentials, and access tokens; apply appropriate internal access controls; promptly revoke unnecessary access; and promptly notify the Service Provider of suspected compromise.

(b) An action performed using the Subscriber’s credentials is deemed authorised by the Subscriber unless caused by the Service Provider’s fraud, wilful misconduct, or breach of the Agreement.

14.5 Data Accuracy, Retention and Usage

(a) The Subscriber is responsible for the accuracy, completeness, legality, authority, and non-infringement of Credential content, Recipient data, templates, brand assets, and other data submitted to BlockchainCert, and for validating outputs before publication.

(b) The Subscriber acknowledges that a cryptographic hash, transaction reference, NFT record, or minimised verification metadata may be permanently recorded on the MasChain Network and, once confirmed, may not be altered or deleted due to blockchain immutability.

(c) The Service Provider may retain off-chain data and records for operation, security, audit, legal compliance, billing, support, backup, and disaster-recovery purposes, including the following indicative categories:-

Data CategoryRetention Basis
Access, authentication, and security logsFor the operational, security, and legally required period stated in applicable policies or the Subscription Agreement
Notification, webhook, and delivery recordsFor the period reasonably required for delivery, support, reconciliation, and incident investigation
Credential processing and publication recordsFor the subscription term and any lawful or agreed post-termination retention period
Billing, invoice, audit, and compliance recordsFor the applicable statutory or contractual retention period
Temporary processing files, retry queues, and backupsAccording to the Service Provider’s documented operational and backup lifecycle, subject to applicable law

Retention under this Clause 14.5(c) is in each case subject to applicable law.

(d) Historical records may be archived. Retrieval may require additional processing time and may be subject to reasonable fees if outside the standard Covered Services.

(e) The Subscriber remains responsible for its own retention obligations and independent backups and shall not submit unlawful or unnecessarily sensitive data, particularly where later deletion may be required.

(f) The Service Provider does not guarantee deletion of on-chain records. It is not responsible for errors or claims caused by inaccurate, incomplete, unlawful, or unauthorised data supplied or approved by the Subscriber.

14.6 Compliance and Regulatory Obligations

The Subscriber is responsible for regulatory, accreditation, employment, admission, licensing, privacy, consumer-protection, and internal-governance requirements applicable to its Credentials. Use of BlockchainCert does not transfer those obligations to the Service Provider.

14.7 Acceptable Use and Conduct

(a) The Subscriber shall not issue fraudulent, misleading, unlawful, defamatory, infringing, or unauthorised Credentials; misuse, overload, scrape, or interfere with BlockchainCert; bypass security or access controls; or use the Covered Services for unlawful or harmful activity.

(b) The Service Provider may suspend or restrict access where such activity is detected, subject to reasonable notice where practicable and safe.

14.8 API Rate Limiting and Traffic Management

(a) To preserve stability, security, fair use, and service availability, the Service Provider may apply documented API request limits, concurrency controls, throttling, traffic shaping, and abuse-prevention safeguards.

(b) Controls may apply per Subscriber, API key, IP address, endpoint, Covered Service, Subscription Package, or platform-wide. Where applicable, BlockchainCert may return a standard rate-limit response such as HTTP 429.

(c) The Subscriber shall implement appropriate retry logic, exponential backoff, request pacing, timeout handling, idempotency where relevant, and resilient integration practices.

(d) Repeated threshold violations, abusive traffic, credential misuse, or sustained disruption may result in temporary restriction or suspension. Impact caused by such Subscriber behaviour is an Excluded Event under Clause 15.

Operational limits and integration parameters are stated in the Service Documentation and may vary by Subscription Package. They are not separate service-level guarantees unless expressly stated in the Subscription Agreement.

Operational ControlSLA Treatment
API rate limitsDocumented limits, concurrency controls, payload sizes, and timeouts apply. A valid request rejected because BlockchainCert is below its documented limit may be considered in the applicable Covered Service’s Availability; traffic above the limit is excluded.
Callbacks and webhooksRetry timing and exhaustion rules are operational parameters in the Service Documentation. Third-party endpoint or Subscriber-system failure is excluded to the extent attributable to that dependency.
Bulk Credential publicationSupported batches of up to five hundred (500) Credentials remain subject to data validation, available allocations, file-format requirements, and reasonable processing queues.
MasChain Network confirmationBlockchain confirmation and finality times vary with network conditions. Availability is measured at the BlockchainCert service boundary and excludes external network delay under Clause 15 and Appendix A.

14.9 Cooperation and Incident Support

During an incident or investigation, the Subscriber shall provide reasonable cooperation, including timely clarification, logs, screenshots, sample Credentials, affected Recipient details, or other diagnostic information reasonably required. Failure to cooperate may affect response, resolution, and SLA Credit eligibility to the extent it causes or prolongs the issue.

14.10 Effect on SLA

A failure by the Subscriber to meet Clause 14 responsibilities may affect performance or availability. Resulting impact is an Excluded Event only to the extent the Subscriber’s act or omission caused or prolonged it.

15. Regulatory and Security Overrides

15.1 General Principle of Responsibility

(a) The Service Provider is responsible for the operation, availability, and performance of BlockchainCert under normal operating conditions, including application components and integrations within its direct control. The MasChain Network and third-party dependencies are subject to Appendix A.

(b) The Service Provider shall operate the Covered Services in accordance with applicable law and commercially reasonable, industry-aligned security practices, having regard to relevant OWASP guidance where applicable. Such reference does not represent certification or full adoption unless expressly stated.

15.2 Scope of Responsibility

The Service Provider’s responsibility includes:-

(a) operation of the BlockchainCert application, administration interfaces, Recipient portal, public verification portal, and Service Provider-controlled APIs;

(b) submission, processing, and handling of valid Credential, verification, portal, and API requests; and

(c) commercially reasonable security and resilience measures for the Covered Services within its control.

15.3 Regulatory and Security Overrides

Notwithstanding any other provision, and notwithstanding Clause 12.1 of the Subscription Agreement, the Service Provider may proportionately suspend, restrict, modify, throttle, delay, or isolate access where it reasonably determines that action is necessary for legal, regulatory, security, fraud-prevention, Credential-integrity, operational-integrity, payment-risk, or platform-stability reasons, including:-

(a) compliance with applicable laws, regulations, regulatory directions, enforcement requests, sanctions, court orders or governmental requirements;

(b) the prevention, investigation or mitigation of suspected unlawful, fraudulent, abusive, unauthorised or non-compliant activity;

(c) preservation of the integrity, security, or stability of BlockchainCert, the MasChain Network integration, or related infrastructure;

(d) temporary suspension of transaction processing, throttling, rate limiting, isolation of affected components or emergency operational measures to prevent systemic risk, cascading failures or material service disruption;

(e) security incidents, malicious attacks, distributed denial-of-service attacks, coordinated attacks, zero-day exploits, or other vulnerabilities that exceed reasonable mitigation capacity despite appropriate security practices; and

(f) any Subscriber breach, fraudulent or unauthorised Credential activity, misuse, or abuse of the Covered Services.

Suspension for overdue payment remains governed by Clause 5.4 of the Subscription Agreement.

15.4 Excluded Events

SLA commitments shall not apply to Unavailable Minutes, degradation, suspension, restriction, modification, throttling, delay, isolation, or another impact arising from any of the following events, circumstances, or actions, each an “Excluded Event”:-

(a) Subscriber Systems and Integration Issues: failures caused by Subscriber systems, browsers, devices, email access, networks, applications, data, credentials, configuration, or integrations;

(b) Third-Party Dependencies: failures of providers or services not under the Service Provider’s direct control, including email delivery, eGHL or another payment gateway, cloud, DNS, CDN, storage, the MasChain Network, or Subscriber-selected integrations, subject to Appendix A;

(c) Infrastructure and Hosting Limitation: failures of underlying cloud, hosting, data-centre, storage, or network infrastructure outside the Service Provider’s direct administrative control despite reasonable safeguards;

(d) Network Integrity and Stability Measures: actions taken by the Service Provider to preserve the integrity, security or stability of the platform, including temporary suspension of transaction processing, throttling, rate limiting, isolation of affected components and emergency operational measures to prevent systemic risk or cascading failures;

(e) Security Incidents and Malicious Attacks: Unavailable Minutes resulting from security incidents within reasonable and expected mitigation capabilities remain the Service Provider’s responsibility. SLA commitments do not apply to the portion caused by an incident that: (i) exceeds reasonable and proportionate mitigation capacity based on prevailing industry standards; (ii) involves a large-scale, coordinated, or state-level attack; or (iii) exploits a previously unknown vulnerability, including a zero-day exploit, where the Service Provider otherwise maintained appropriate security practices;

(f) Regulatory and Legal Compliance Actions: actions taken by the Service Provider in good faith where necessary to maintain compliance with applicable laws, regulations, regulatory directions, enforcement requests, sanctions, court orders or governmental requirements, including suspension, restriction or modification of the Services;

(g) Force Majeure: events beyond the Service Provider’s reasonable control, including natural disasters, acts of God, acts of war, terrorism, civil unrest, national emergencies, widespread power failures and large-scale telecommunications or internet outages;

(h) Subscriber Misuse or Breach: suspension or restriction resulting from breach of the Subscription Agreement, misuse or abuse of the Services, or unlawful, restricted or non-compliant activities by the Subscriber; and

(i) Blockchain Finality and Irreversibility: a verification record confirmed on the MasChain Network may be permanent and irreversible. The Service Provider does not guarantee reversal, amendment, recovery, or deletion of an on-chain hash, reference, NFT record, or transaction. A broadcast, callback, receipt, or confirmation is not a guarantee of legal validity, accreditation, employment, payment, or other business outcome. The Subscriber must validate Credential content, recipient details, permissions, and approvals before publication.

15.5 Effect of Regulatory and Security Overrides

An impact arising from a valid Regulatory and Security Override or Excluded Event is excluded only to the extent reasonably attributable to that event and does not give rise to SLA Credits. The Service Provider shall use reasonable efforts to minimise the scope and duration, communicate material impact, restore normal service, and provide information reasonably required for the Subscriber’s lawful notifications where permitted.

16. Reporting and Governance

16.1 Continuous Improvement

For Enterprise, Custom, or other eligible Subscription Packages, the parties may agree service reviews, reports, escalation contacts, enhanced support, or additional governance arrangements in the Subscription Agreement.

17. Exit Assistance and Transition

17.1 Exit Assistance

Upon expiry or termination of the Subscription Agreement, the Service Provider shall provide reasonable transition assistance requested within thirty (30) calendar days after the effective date, or another period agreed in writing.

Transition assistance may include:-

(a) continued access to a Covered Service after the effective termination date only where expressly agreed and all applicable fees are paid;

(b) export of Subscriber Data held in Service Provider-controlled off-chain systems in a supported, structured, commonly used format;

(c) reasonable knowledge transfer and relevant Service Documentation for an agreed migration;

(d) reasonable cooperation with the Subscriber or an authorised successor, subject to confidentiality, security, and third-party restrictions; and

(e) reasonable explanation of Credential status and on-chain verification-record treatment following termination.

Transition assistance may be subject to reasonable fees and does not require disclosure of source code, security-sensitive information, the Service Provider’s confidential information, or another subscriber’s information.

18. Governing Law

18.1 Governing Law

This SLA shall be governed by, and construed in accordance with, the laws of Malaysia.

18.2 Jurisdiction

Subject to Clause 18.3 and the dispute-resolution provisions of the Subscription Agreement, the courts of Malaysia shall have exclusive jurisdiction over disputes arising from this SLA. Where the Subscription Agreement provides for arbitration or another mechanism, that provision prevails to the extent of inconsistency.

18.3 Dispute Resolution

The parties shall first seek to resolve a dispute in good faith through their senior representatives and any agreed governance process. If unresolved within thirty (30) calendar days after written notice, or where urgent relief is required or a mandatory limitation period or statutory process applies, either party may use the forum stated in the Subscription Agreement or, if none is stated, the courts of Malaysia.

Appendix A — Third Party Dependencies and Responsibility Boundaries

1. Purpose and Scope

(a) This Appendix identifies key third-party dependencies used in connection with BlockchainCert and the responsibility boundaries between the Service Provider, the Subscriber, and relevant providers.

(b) This Appendix applies together with Clause 15, including the provisions relating to SLA exclusions, service availability, responsibility boundaries, and Excluded Events.

(c) This Appendix clarifies operational responsibility and does not relieve the Service Provider of configuration, integration, monitoring, security-setting, vendor-coordination, escalation, mitigation, and diligence obligations within its reasonable control.

2. Control Levels

For the purposes of this Appendix, the following control levels apply:-

(a) Direct Control

Direct Control” means a component directly operated and controlled by the Service Provider as part of BlockchainCert. A failure remains within the Service Provider’s responsibility unless caused by an Excluded Event.

(b) Shared Control

Shared Control” means a component where the Service Provider manages configuration, integration, orchestration, access controls, monitoring, vendor coordination, and response, while underlying infrastructure or a network is operated by another provider. The Service Provider remains responsible for matters within its reasonable control.

(c) Third-Party Control

Third-Party Control” means a component operated by an independent provider whose underlying availability, performance, network, or service operation is not directly controlled by the Service Provider. The Service Provider remains responsible for its integration, vendor coordination, monitoring, escalation, and reasonable mitigation.

3. Dependency Matrix

DependencyControl LevelService Provider ResponsibilityThird-Party ResponsibilitySLA Treatment
Cloud HostingShared ControlConfiguration, deployment, monitoring, security settings, backups, access controls, and reasonable resilience designPhysical infrastructure, cloud platform availability, and provider-operated servicesExcluded only to the extent caused by provider-side infrastructure failure outside the Service Provider’s reasonable control
Email DeliveryThird-Party ControlProvider integration, configuration, retry logic, monitoring, escalation, and error handlingMail-provider systems, recipient mail servers, anti-spam controls, recipient settings, and internet deliveryExcluded only to the extent caused by delivery infrastructure or recipient-side systems outside the Service Provider’s reasonable control
MasChain NetworkShared ControlBlockchain integration, managed-wallet and transaction orchestration, monitoring, confirmation handling, reconciliation, and escalationUnderlying blockchain network, consensus, validator, finality, and network infrastructure outside direct controlExcluded only to the portion caused by an external MasChain Network event outside the Service Provider’s reasonable control
eGHL or Approved Payment GatewayThird-Party ControlGateway integration, payment-request handling, configuration, reconciliation support, monitoring, and escalationAuthorisation, settlement, banking rails, fraud screening, and gateway availabilityExcluded only to the extent caused by the payment gateway, bank, card network, or payment network
Document and PDF GenerationShared ControlTemplate processing, generation workflow, configuration, monitoring, retry, and error handlingUnderlying rendering libraries or provider-operated document services, where usedIncluded unless the failure is attributable to an external rendering dependency outside reasonable control
Managed Credential and File StorageShared ControlStorage configuration, permissions, lifecycle rules, encryption settings, monitoring, and retrieval integrationUnderlying storage platform availability and provider-operated infrastructureExcluded only to the extent caused by provider-side storage failure outside reasonable control
DNS ProvidersShared ControlDNS records, routing configuration, domain administration, monitoring, escalation, and reasonable redundancyDNS platform availability, registry-level issues, and global DNS propagation infrastructureExcluded only to the extent caused by DNS, registry, or propagation failure outside the Service Provider’s reasonable control
CDN ProvidersShared ControlCDN configuration, cache rules, origin settings, certificates, routing, monitoring, and escalationCDN edge network availability and provider-operated content delivery infrastructureExcluded only to the extent caused by provider-side CDN failure outside reasonable control
Subscriber Systems, Devices, and ConnectivityThird-Party ControlReasonable compatibility information, support triage, and diagnosis at the BlockchainCert service boundarySubscriber systems, browsers, devices, networks, email access, firewalls, configurations, and internet providersExcluded to the extent caused or prolonged by the Subscriber environment or a Subscriber-controlled provider

4. SLA Exclusion Standard

A failure involving a Shared Control or Third-Party Control dependency is an Excluded Event only to the extent the Service Provider can reasonably demonstrate that:-

(a) the root cause originated outside the Service Provider’s directly controlled systems;

(b) the incident was not caused by the Service Provider’s misconfiguration, inadequate integration, security settings, access controls, monitoring, selection, or operational processes;

(c) the incident was not materially contributed to or prolonged by the Service Provider’s acts or omissions; and

(d) The Service Provider used reasonable diligence and efforts to monitor, escalate, mitigate, and coordinate with the provider.

A third party’s involvement alone does not classify an incident as an Excluded Event.

5. Service Provider Responsibilities Despite Third Party Dependencies

The Service Provider remains responsible for all matters within its reasonable control, including:-

(a) configuration of third-party integrations;

(b) secure management of credentials, keys, certificates, secrets, and access controls;

(c) monitoring of material dependencies;

(d) reasonable incident detection and escalation;

(e) implementation of retry logic, fallback handling, or graceful degradation where commercially reasonable;

(f) vendor coordination during incidents;

(g) maintaining reasonable records of incidents affecting the Services;

(h) applying available fixes, patches, configuration updates, or provider recommendations where applicable and commercially reasonable;

(i) avoiding foreseeable single points of failure where reasonable for the relevant Service; and

(j) communicating material service impacts to the Subscriber in accordance with this Appendix.

A third-party dependency shall not be treated as an Excluded Event to the extent the relevant failure, delay, degradation, or disruption was caused or materially worsened by the Service Provider’s failure to perform the responsibilities set out above.

6. Scope and Duration of SLA Exclusion

Any SLA exclusion arising from a third-party dependency shall apply only:-

(a) to the affected Service component;

(b) for the period during which the third-party dependency directly caused the relevant failure, delay, degradation, or disruption; and

(c) to the extent the impact could not reasonably have been prevented, mitigated, or reduced by the Service Provider.

Unaffected Service components shall remain subject to the applicable SLA.

Where an incident has multiple causes, only the Unavailable Minutes or degradation reasonably attributable to the external provider or dependency are excluded from SLA calculations.

7. Third-Party Incident Notification

Where a confirmed third-party incident materially affects a Covered Service, the Service Provider shall use reasonable efforts to post a notice through the BlockchainCert Portal or another designated channel within two (2) hours after confirming the third-party root cause, counted during Business Hours only. The notice should include, where reasonably available:-

(a) the affected Service component or functionality;

(b) the known or estimated impact on the Subscriber;

(c) the suspected or confirmed third-party dependency involved;

(d) mitigation steps being taken by the Service Provider;

(e) any workaround available to the Subscriber;

(f) any indicative resolution timeline made available by the third-party provider; and

(g) the time of the next expected update, where practicable.

The Service Provider shall issue a follow-up notice upon restoration or when the material impact ends.

8. Evidence of Third-Party Cause

Where the Service Provider relies on a third-party dependency to exclude Unavailable Minutes, degradation, or failure from SLA calculations or SLA Credit eligibility, it shall maintain reasonable supporting records, which may include:-

(a) provider status notices;

(b) provider incident reports or service advisories;

(c) monitoring data;

(d) incident tickets;

(e) internal incident timelines;

(f) logs showing the affected component or integration;

(g) escalation records; and

(h) mitigation steps taken by the Service Provider.

On written request, the Service Provider shall provide a reasonable summary of evidence supporting a claimed exclusion, subject to confidentiality, security, legal, and third-party contractual restrictions.

9. Provider Selection, Management and Changes

(a) The Service Provider remains responsible for selecting, replacing, integrating, and managing providers used to support BlockchainCert.

(b) The Service Provider shall use commercially reasonable diligence when engaging material providers, having regard to the operational, security, availability, privacy, and regulatory risks of the dependency.

(c) Where relevant and commercially reasonable, the Service Provider may consider recognised assurance reports or certifications such as ISO 27001, SOC 2 Type II, or equivalent standards.

(d) The Service Provider may change providers in the ordinary course, provided that the change does not materially reduce the overall functionality, security, availability, data-protection standard, or regulatory-compliance posture of BlockchainCert.

(e) The Service Provider shall give advance notice where reasonably practicable of a planned material provider change affecting the Subscriber’s use, data-processing arrangements, security posture, or availability.

10. Subscriber Dependencies and Subscriber-Caused Issues

The Service Provider is not responsible for a failure caused by systems, networks, configurations, credentials, devices, applications, providers, or integrations controlled by the Subscriber or its users. Subscriber-side issues may include:-

(a) Subscriber network or internet connectivity failures;

(b) Subscriber firewall, proxy, VPN, browser, endpoint, or device issues;

(c) Subscriber misconfiguration of APIs, webhooks, credentials, permissions, or access controls;

(d) Subscriber failure to maintain required integrations or software environments;

(e) Subscriber-provided third-party systems or data sources;

(f) unauthorised changes made by the Subscriber or its users; and

(g) failure by the Subscriber to follow reasonable technical requirements or implementation guidance provided by the Service Provider.

Such Subscriber-caused issues shall be excluded from SLA calculations and SLA Credit eligibility to the extent they caused or contributed to the relevant failure, delay, degradation, or disruption.

11. Non-Exhaustive Dependencies

The listed dependencies are illustrative and non-exhaustive. An additional dependency is assessed under the same control, responsibility, evidence, and exclusion standards. Listing a dependency does not automatically exclude every incident involving it.

12. Order of Precedence

If this Appendix conflicts with the main body of the SLA, the main body prevails unless expressly stated otherwise. Nothing here limits liability that cannot lawfully be limited or excluded.