Data Privacy Policy

 

Privacy Policy

Effective Date: 1st April 2022

Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your personal information in accordance with the Sri Lankan Personal Data Protection Act, No. 9 of 2022 (PDPA).

1. Information We Collect

When you register and place orders on our online store, we collect the following personal data:

  • Full name
  • Email address
  • Phone number
  • Delivery address
  • Order and transaction history

2. Why We Collect Your Data

We use your personal information to:

  • Create and manage your customer account
  • Process and deliver your orders
  • Communicate with you about your orders or customer support requests
  • Comply with legal and regulatory requirements (e.g., tax reporting to the IRD)
  • Send you marketing emails (only if you give your consent)

3. How We Store Your Data

Your personal data is stored securely in two ways:

  • As part of your customer profile, which can be updated or deleted upon your request
  • As part of your order history and transaction records, which we are required to retain for tax and audit purposes under applicable law

We implement technical and organizational safeguards to protect your information from unauthorized access or disclosure.

4. Data Retention

  • Your customer account data will be retained as long as your account is active.
  • If you request deletion of your account, we will remove your profile and associated personal data.
  • However, we will retain order and transaction records (including personal information) as required for legal compliance with IRD regulations and other applicable laws.

5. Your Rights

Under the PDPA, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your customer profile (excluding records required by law)
  • Withdraw consent for marketing communications at any time

To exercise your rights, please contact us at: info@o2.lk

6. Sharing Your Data

We only share your personal data with:

  • Delivery and logistics providers to fulfill your orders
  • Government agencies, when required by law

We do not sell or rent your personal data to third parties.

7. Cross-Border Transfers

If we store or process data using services located outside Sri Lanka, we ensure that appropriate data protection safeguards are in place in accordance with the PDPA.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website with the updated effective date.

If you have any questions about this Privacy Policy or how we handle your data, feel free to reach out at info@o2.lk.