Privacy policy
Effective Date: September 16, 2025
Introduction
Welcome to Affinity Consulting (Pvt) Ltd (“we”, “us”, or “our”). We respect your privacy and are committed to protecting the personal information you provide. This Privacy Policy explains how we collect, use, and secure your data; specifically for internal marketing and sales purposes. We do not share your data with third parties, unless required by law or with your explicit consent.
By using our website or services, you agree to the practices described in the policy below.
This Privacy Policy applies to information collected via our website, forms, email communications, mobile or other digital services, promotional events, and physical submissions. We may also collect data when you provide contact info to request quotes, support, or otherwise send messages through our website.
Information We Collect
We do not collect personally identifiable information unless you voluntarily provide it through our website. You can browse our site without sharing any personal details. However, if you choose to contact us or request more information, we will collect the information you submit. The purpose of collecting your information will be clearly stated at the point of collection.
We may collect the following categories of personal information:
- Name
- Email address
- Phone number
- Company name (if applicable)
- Any other information you voluntarily provide through forms, surveys, or communications
- Technical Data – such as your IP address, browser type, time zone, and operating system
- Profile Data – such as your preferences, feedback, and interests
- Usage Data – including how you interact with our website and services
- Marketing & Communications Data – such as your preferences in receiving communications
- Aggregated Data – statistical or analytical data that does not reveal your identity
- Identity Verification Data – such as national identity card numbers, passport numbers, or driver’s license numbers, where applicable
- Location Data – when relevant to services that require geographic-based personalization or analytics
How We Collect Your Information
We collect personal information through:
- Forms you submit on our website
- Subscriptions to our emails or newsletters
- Feedback or surveys you voluntarily complete
- Automated technologies such as cookies or analytics tools
- Publicly available sources or third-party platforms where applicable
- When you interact with our mobile applications or digital products
- When you participate in promotional events or campaigns, whether online or in-person
- From third-party service providers or partners, including financial institutions, insurers, or marketing affiliates (where permissible)
- When you contact us via email or submit questions/requests via website, we collect the contact information you provide to respond to your request.
How We Use Your Information
Your personal data is used solely for internal purposes, including:
- Responding to your inquiries and providing customer support
- Personalizing and improving your experience on our website
- Sending marketing communications, promotions, and updates related to our services — by providing your information, you give implied consent to receive such communications. You may withdraw this consent at any time by contacting us or using the unsubscribe option
- Sending newsletters, quotes, sales follow-ups, help desk responses, or other communications based on contact information you provided
- Conducting analytics to understand user behavior and improve services
- Generating Aggregated Data for internal insight (non-identifiable information)
- Verifying your identity to facilitate secure access to services or accounts
- Processing payments and transactions if applicable
- Providing location-based services and real-time notifications (e.g., for service updates or facilities near you)
- Sharing insights with trusted affiliates solely for operational, support, or improvement purposes under strict confidentiality protocols
We only use your data for the purposes for which it was collected, or for compatible purposes. If we need to use your data for an unrelated purpose, we will seek your consent, via your preferred mode of communication being either telephone, email or text message to use it for that new purpose.
Please note that we may process your personal data without your knowledge or consent, where this is required or permitted by law.
Legal Basis for Processing
We rely on implied consent for sending you marketing communications.
For service-related communications, we rely on legitimate interests or contractual necessity, depending on the context.
Where legally required, we may rely on your explicit consent.
We also process data as required to comply with applicable financial, regulatory, and operational laws in Sri Lanka, including electronic payment regulations, data protection standards, and service-level agreements.
Data Retention
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy, or to comply with legal, regulatory, or operational requirements. After this period, data is securely deleted or anonymized.
In some instances (e.g., regulatory audits, ongoing disputes, or prevention of fraud), certain types of personal or transactional data may be retained for longer periods as permitted by law.
Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain the proper functioning of our website
- Analyze how users interact with our site
- Improve user experience and site performance
You may disable cookies through your browser settings, although doing so may affect site functionality.
We may also allow third parties (such as analytics providers or ad platforms) to use cookies or similar tools to collect anonymized data on usage and engagement patterns.
We use cookies and log information to collect technical details (like IP, browser, arrival site, date/time) for diagnostics, usage measurement, and internal site monitoring.
Sharing and Disclosure of Information
Unless otherwise stated below, we will not disclose or otherwise make your personal information available, or sell your information to third parties.
We may share your information:
- When legally required (e.g., in response to subpoenas or legal processes)
- With trusted service providers who process data on our behalf, under strict confidentiality agreements
- Within our internal teams or affiliated entities, where necessary for business purposes
- Only with your explicit consent, for any purpose not already outlined
- With identity verification services, payment processors, cloud storage providers, or marketing platforms as required to provide our services
- With consultants, legal advisors, and technical support vendors under confidentiality obligations
- With public or regulatory authorities in compliance with applicable laws and legal processes
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of any inaccurate or incomplete data
- Request deletion of your personal data, where appropriate
- Object to or restrict how we use your data, particularly for direct marketing
- Withdraw consent for marketing communications at any time
- Lodge a complaint with a data protection authority, if you believe your rights have been violated
To exercise these rights, please contact us using the information below.
If you wish to delete your account or subscription, please submit a formal request to us in writing or via email. We may retain some data even after deletion due to legal obligations.
Personal Data Protection Act No 9 of 2022
In compliance with the Personal Data Protection Act, No. 9 of 2022:
- You may exercise any of your data protection rights as stipulated in the Privacy Policy:
- If you are above 18 years of age;
- Where you are a minor, by a parent or a person who has parental authority over you or has been appointed as your legal guardian;
- Where you are physically or mentally unfit, by a personal who has been appointed as your guardian or administrator by a court of law;
- Except in items b) and c) above, by a person duly authorized in writing by you to make a request; or
- By your legal heir within a period of 10 years from your demise.
What we may need from you:
- We may request a valid form of identification (e.g., NIC or passport) to verify your identity when you exercise your rights
- We aim to respond to all data requests within 30 days. If additional time is needed, you will be notified
- We may have the right to charge fees which are directly related to and necessary for the processing of any Personal Data Request. Where a fee is charged, we shall inform you of the details of such fees and the reasons for imposing the same.
- We reserve the right to charge a reasonable fee for repeat, excessive, or unfounded requests
- You may appeal our decision or lodge a complaint with the Data Protection Authority of Sri Lanka
Changes to This Policy
We reserve the right at any time to add to, change, update or modify this Privacy Policy from time to time. The revised version will be posted on this page with a new Effective Date.
Where material changes are made, we may notify you via email or a notice on our website.
We encourage you to review our Privacy Policy regularly to stay informed of any updates that may affect your rights.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
Affinity Consulting (Pvt) LTD
affinitywebcontact@gmail.com
+94 773449819 | +971 56 962 7819
29/3, Alfred Place, Colombo 3