Emergency support: +94 713 838 638 · Support Center

Privacy Policy

Company: MERNcrest Solutions (Pvt) Ltd

Website: merncrest.lk

Effective Date: June 20, 2025

Last Updated: June 20, 2025

Contact: merncrestsolution@gmail.com

1. Introduction and Legal Framework

MERNcrest Solutions (Pvt) Ltd (hereinafter referred to as "MERNcrest," "we," "us," or "our") is a private limited company incorporated and registered under the Companies Act No. 07 of 2007 of the Democratic Socialist Republic of Sri Lanka. We are committed to protecting the privacy and personal data of all individuals who interact with our website, products, and services.

This Privacy Policy is drafted in compliance with the following legal frameworks:

Sri Lankan Law:

  • Personal Data Protection Act No. 09 of 2022 (PDPA) — Sri Lanka's primary data protection legislation
  • Computer Crimes Act No. 24 of 2007 — governs unauthorized access and cybercrime
  • Electronic Transactions Act No. 19 of 2006 — governs electronic records and communications
  • Consumer Affairs Authority Act No. 09 of 2003 — consumer protection obligations
  • Telecommunications Act No. 25 of 1991 (as amended) — communications data regulations

International Standards and Frameworks:

  • General Data Protection Regulation (GDPR) — European Union Regulation 2016/679 (applicable to EU residents)
  • California Consumer Privacy Act (CCPA) — applicable to California residents
  • ISO/IEC 27001:2022 — international standard for information security management
  • OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data
  • UN Guidelines for the Regulation of Computerized Personal Data Files (1990)

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Section 2 of the Personal Data Protection Act No. 09 of 2022 of Sri Lanka and Article 4(1) of the EU GDPR.
  • "Processing" means any operation performed on personal data, including collection, recording, storage, alteration, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
  • "Data Controller" means MERNcrest Solutions (Pvt) Ltd, which determines the purposes and means of processing personal data.
  • "Data Subject" means the natural person whose personal data is being processed.
  • "Consent" means freely given, specific, informed, and unambiguous indication of the data subject's agreement to the processing of their personal data.
  • "Third Party" means any natural or legal person other than the data subject, the data controller, or persons authorized to process data under the direct authority of the controller.

3. Personal Data We Collect

3.1 Information You Provide Directly

  • Full name and contact details (email address, telephone number, postal address)
  • Company name, job title, and business information
  • Project requirements, technical specifications, and business objectives shared during consultations
  • Payment information (processed securely through third-party payment processors; we do not store card data)
  • Login credentials for client portals and administrative systems (passwords are encrypted using industry-standard hashing algorithms)
  • Communications, feedback, support requests, and correspondence
  • Curriculum vitae, cover letters, and employment application materials

3.2 Information Collected Automatically

  • IP address and approximate geographic location
  • Browser type, version, and device information
  • Operating system and screen resolution
  • Pages visited, time spent on pages, and navigation patterns
  • Referring website or search engine
  • Cookie identifiers and session tokens
  • Error logs and technical diagnostic information

3.3 Information From Third Parties

  • Publicly available business information from LinkedIn and professional directories
  • Information from referral partners with your consent
  • Analytics data from Google Analytics and similar services

4. Legal Basis for Processing (PDPA & GDPR)

Under Section 5 of the Sri Lanka Personal Data Protection Act No. 09 of 2022 and Article 6 of the EU GDPR, we process your personal data on the following legal bases:

  • Contractual Necessity: Processing required to fulfill our service agreements and contracts with clients.
  • Legitimate Interests: Processing necessary for our legitimate business interests, including improving our services, preventing fraud, and maintaining business security, where these interests are not overridden by your rights.
  • Legal Obligation: Processing required to comply with applicable Sri Lankan laws and regulations, including tax laws, accounting requirements, and court orders.
  • Consent: Where you have provided explicit consent for specific processing activities, such as marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Vital Interests: Processing necessary to protect the vital interests of the data subject or another person in emergency situations.

5. How We Use Your Personal Data

5.1 Service Delivery

  • Providing, maintaining, and improving our software development, cloud, cybersecurity, and digital services
  • Processing project requirements and communicating project status
  • Managing client accounts, billing, and contractual obligations
  • Providing technical support and customer service

5.2 Business Operations

  • Conducting due diligence and client verification as required by Sri Lankan law
  • Maintaining business records as required under the Companies Act No. 07 of 2007
  • Processing financial transactions and maintaining accounting records under the Inland Revenue Act No. 24 of 2017
  • Managing employment records and payroll in compliance with the Shop and Office Employees Act and the Employees' Provident Fund Act

5.3 Marketing and Communications (With Consent)

  • Sending newsletters, technical updates, and promotional content (only with opt-in consent)
  • Conducting surveys and collecting feedback to improve services
  • Retargeting campaigns through digital advertising platforms

5.4 Security and Compliance

  • Monitoring for security threats, fraud, and unauthorized access
  • Complying with legal obligations, court orders, and regulatory requirements
  • Maintaining audit logs as required for cybersecurity compliance

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

6.1 Service Providers and Sub-Processors

  • Amazon Web Services (AWS) — cloud hosting and infrastructure (US servers; covered by AWS Data Processing Agreement and Standard Contractual Clauses for GDPR)
  • Cloudinary — media storage and delivery
  • Brevo (formerly Sendinblue) — email communication services (EU-based, GDPR compliant)
  • Google Analytics — website analytics (data anonymized; EU-US Data Privacy Framework applies)
  • Stripe / PayHere — payment processing (PCI DSS Level 1 certified processors)

6.2 Legal and Regulatory Disclosure

  • Sri Lanka Police and law enforcement authorities pursuant to the Code of Criminal Procedure Act No. 15 of 1979
  • Sri Lanka Telecommunications Regulatory Commission under lawful orders
  • Department of Inland Revenue under the Inland Revenue Act
  • Any court of competent jurisdiction within Sri Lanka or internationally
  • The Information and Communication Technology Agency (ICTA) of Sri Lanka under applicable ICT regulations

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity, subject to the same privacy protections described in this Policy. You will be notified of any such transfer.

7. International Data Transfers

Some of our service providers are located outside Sri Lanka. When we transfer personal data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to and from EU/EEA
  • Adequacy decisions where applicable
  • Binding Corporate Rules where appropriate
  • Your explicit consent for specific transfers, where required under Section 28 of the Personal Data Protection Act No. 09 of 2022

All international transfers comply with Chapter V of the EU GDPR and the international transfer provisions of the Sri Lanka PDPA.

8. Your Rights as a Data Subject

Under the Personal Data Protection Act No. 09 of 2022 of Sri Lanka and the EU GDPR (for EU residents), you have the following rights:

  • Right to Access (Section 18, PDPA): You may request a copy of the personal data we hold about you.
  • Right to Rectification (Section 19, PDPA / Article 16, GDPR): You may request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Section 20, PDPA / Article 17, GDPR): You may request deletion of your personal data, subject to legal retention requirements.
  • Right to Restriction of Processing (Article 18, GDPR): You may request that we restrict processing of your data under certain circumstances.
  • Right to Data Portability (Article 20, GDPR): You may receive your data in a structured, machine-readable format.
  • Right to Object (Section 21, PDPA / Article 21, GDPR): You may object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
  • Right Not to be Subject to Automated Decision-Making (Article 22, GDPR): You may request human review of automated decisions that significantly affect you.

To exercise any of these rights, submit a written request to: merncrestsolution@gmail.com

We will respond within 30 days as required by the PDPA and within the 30-day period under the GDPR. If we require additional time (up to 60 additional days under GDPR), we will notify you with reasons.

⚠ Note: Sri Lankan residents may also lodge complaints with the Data Protection Authority of Sri Lanka established under the Personal Data Protection Act No. 09 of 2022. EU residents may lodge complaints with their local Data Protection Authority.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies. Under the EU ePrivacy Directive (Directive 2002/58/EC) and GDPR, we obtain your consent before placing non-essential cookies.

Cookie Categories:

  • Strictly Necessary Cookies: Required for the website to function. No consent required. Includes session tokens and security cookies.
  • Performance / Analytics Cookies: Google Analytics cookies to measure website usage. Requires opt-in consent. Data is anonymized where possible.
  • Functional Cookies: Remember your preferences such as language selection (EN/TA/SI) and theme settings. Requires consent.
  • Marketing / Targeting Cookies: Used for retargeting campaigns. Requires explicit opt-in consent. You may withdraw consent at any time.

You may manage cookie preferences through our cookie consent banner or your browser settings. Note that disabling certain cookies may affect website functionality.

10. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law:

  • Client project data: 7 years from project completion (required under Sri Lanka's Inland Revenue Act for tax records)
  • Employment and HR records: 5 years from end of employment (Shop and Office Employees Act requirements)
  • Marketing contact data: Until consent is withdrawn or 2 years from last interaction
  • Website analytics data: 26 months (Google Analytics default)
  • Security logs and audit trails: 1 year from creation
  • Financial transaction records: 7 years (statutory requirement under Sri Lanka accounting standards)

11. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage, in accordance with Section 30 of the Personal Data Protection Act No. 09 of 2022 and Article 32 of the EU GDPR, including:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Role-based access controls (RBAC) limiting data access to authorized personnel only
  • Multi-factor authentication for all administrative systems
  • Regular security audits and penetration testing
  • Automated vulnerability scanning and patch management
  • Secure development practices compliant with OWASP Top 10 standards
  • Employee data protection training and confidentiality agreements
  • Incident response procedures with a maximum 72-hour breach notification timeline (as required by GDPR Article 33)

12. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a child under 18, we will delete such data immediately. Parents or guardians who believe their child has provided us with personal information should contact us at merncrestsolution@gmail.com.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will notify you by:

  • Posting the updated Policy on our website with a revised "Last Updated" date
  • Sending an email notification to registered users (where we hold your email address)
  • Displaying a prominent notice on our website for 30 days following material changes

Continued use of our website or services after the effective date of changes constitutes acceptance of the updated Policy.

14. Contact Information and Data Protection Officer

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

MERNcrest Solutions (Pvt) Ltd

Attn: Data Protection Officer

Email: merncrestsolution@gmail.com

Website: merncrest.lk

Country: Sri Lanka