Legal

Privacy Policy

How Daan Holdings (Private) Limited collects, uses, stores, and protects your data on the Sync Enterprise platform.

Daan Holdings (Private) Limited Governed by the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka Last updated: 2026

This Privacy Policy is between Daan Holdings (Private) Limited (the "Service Provider") and the User, governing the use of the Sync Enterprise platform and services. This Policy constitutes a legal agreement between you, as a user, and the company, as the provider. You must be a natural person who is at least 18 years of age.

1Introduction and applicability

  • The Service Provider is committed to protecting and respecting the User's privacy and ensuring compliance with the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka.
  • This Policy defines the framework for collection, use, storage, disclosure, and protection of personal and/or sensitive data collected through our platform and ensures that all processing is conducted lawfully, fairly, and transparently.

2Lawful basis for processing

The Service Provider processes personal data only where one or more of the following lawful grounds apply:

  • Consent: the User has given explicit consent for one or more specific purposes.
  • Contractual necessity: processing is required for the performance of a contract with the User.
  • Legal obligation: processing is necessary to comply with applicable law.
  • Vital interest: processing is necessary to protect life, health, or safety.
  • Public interest: processing is required for functions carried out in the public interest.
  • Legitimate interest: processing is necessary for the legitimate interests of the Service Provider or a third party, provided these do not override the rights of the User.

4Categories of information collected

The Service Provider may collect the following categories of data:

  • Personal data: name, contact details, email, age, gender, and information about related persons (e.g., emergency contacts).
  • Technical data: IP address, device ID, browser type, operating system, cookies, and usage statistics.
  • Location data: GPS and similar locational data.
  • Non-personal / anonymized data: aggregated or statistical information that cannot identify an individual.

5Purpose of collection and use

Data is collected and processed to:

  • Provide and maintain services.
  • Improve user experience and functionality.
  • Respond to user queries and complaints.
  • Conduct analytics, research, and quality assurance.
  • Prevent fraud, ensure security, and comply with legal obligations.
  • Send communications or updates (only where users have opted in).

Processing for purposes other than those initially collected will occur only with consent or where permitted by law.

5AOperational data collected through the platform

In addition to the above, the Service Provider collects data necessary for the functioning of the operations management system, including but not limited to:

  • Staff & team management: names, contact details, roles, departments, shift schedules, and attendance records of staff and team members.
  • Notice & communication logs: records of notices, broadcasts, and internal communications sent through the Platform, including sender, recipients, timestamps, and content.
  • Task & work order management: task descriptions, assignees, completion statuses, timestamps, and related operational notes.
  • Visitor management: visitor name, contact number, identification details (if provided), and time of entry or exit.
  • Complaint management: nature of complaint, time of submission, status updates, and resolution time.
  • Facility & space management: space type, usage schedules, booking records, and related usage details.

These data points are collected solely for operational functionality. The Service Provider does not use any of the above data for targeted advertising, behavioural profiling, or marketing purposes, nor are they shared with third parties for unrelated commercial use.

Upon request, Users may request correction or deletion of any such information, subject to applicable legal or operational retention requirements. All requests will be processed within timelines prescribed by the PDPA.

5BArtificial Intelligence (AI) services

The Platform may provide access to AI-powered assistant features to help Users with operational queries, task management, reporting, support requests, and other Platform functions.

When a User interacts with AI-assisted features, the Service Provider may process:

  • Messages, prompts, questions, and instructions entered by the User.
  • Operational, task, staff, facility, or complaint-related information relevant to the User's request.
  • User account information necessary to authenticate or fulfil a request.
  • Technical and session information required to provide AI-assisted services.

To generate AI-powered responses, information submitted through these features may be securely transmitted to and processed by authorised third-party AI service providers engaged by the Service Provider.

  • The Service Provider does not sell information submitted through AI features to third parties and does not permit such information to be used for advertising or marketing purposes.
  • Users should avoid submitting sensitive personal information, financial information, passwords, government-issued identification numbers, or other confidential information through AI features unless specifically required for the requested service.
  • Use of AI features is optional. Users who choose not to use AI functionality may continue to access and use other features of the Platform.

6Disclosure and sharing

The Service Provider may share data in the following circumstances:

  • With third-party service providers (e.g., hosting, analytics, payments) under confidentiality obligations.
  • To comply with legal or regulatory obligations or law enforcement requests.
  • During mergers, acquisitions, or business restructuring, with prior notice to users.
  • Internally, on a strict need-to-know basis.

No personal data will be rented, sold, or disclosed to any third parties. All sharing arrangements ensure binding and enforceable commitments to safeguard data as per the PDPA.

6.4 AI service providers

Where AI-assisted services are used, the Service Provider may share relevant information with authorised AI service providers solely for the purpose of generating responses and delivering AI-powered functionality within the Platform.

  • Such service providers are required to implement appropriate technical and organisational safeguards to protect information processed on behalf of the Service Provider.
  • They may process such information only in accordance with applicable laws, contractual obligations, and the Service Provider's instructions.
  • The Service Provider remains responsible for ensuring that any such processing is conducted in accordance with applicable privacy and data protection requirements.

7Cross-border data transfers

Where data is transferred outside Sri Lanka, such transfer will occur only:

  • To countries approved under a PDPA adequacy decision; or
  • With appropriate safeguards ensuring equivalent protection (e.g., contractual clauses); or
  • With the User's explicit consent after informing them of potential risks.

8Data retention

Personal data will be retained only as long as necessary for the purposes for which it was collected or as required by law. Data will be securely deleted or anonymized thereafter.

9User rights under the PDPA

Users have the following rights under applicable law:

  • Access: obtain confirmation and a copy of their personal data.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of personal data in specified circumstances.
  • Objection: object to processing, including automated decisions.
  • Withdrawal of consent: stop processing based on consent.
  • Data portability: receive data in a structured, commonly used format.

Requests will be addressed within 21 working days. Users dissatisfied with the response may appeal to the Data Protection Authority of Sri Lanka.

10Data Protection Officer (DPO)

In accordance with the PDPA, the Service Provider has appointed a Data Protection Officer to oversee compliance and handle data-related queries.

DPO — Daan Holdings (Private) Limited dpo@sync-enterprise.com

11Data security and breach notification

  • The Service Provider applies technical and organizational measures (encryption, access control, secure servers) to ensure confidentiality and integrity of data.
  • In case of a personal data breach, the Service Provider will notify the Data Protection Authority and affected Users without undue delay, describing the breach and remedial measures taken.

12Marketing and communication

Marketing messages ("solicited messages") will be sent only to Users who have explicitly opted in. Every message will contain an opt-out link. The Service Provider will identify itself clearly in all communications, as required under the PDPA.

13Cookies and tracking technologies

Cookies are used to analyze traffic, improve functionality, and enhance User experience. Users can modify browser settings to manage or block cookies. Cookie usage complies with PDPA transparency standards.

13AContact access

The Platform may request access to a User's device contacts where such access is required to facilitate team communications, staff notifications, or similar functionality initiated by the User.

  • Access to contacts is requested only after obtaining the User's permission through the operating system's consent mechanism.
  • Contact information accessed through this feature is used solely for the purpose requested by the User and is not used for advertising, profiling, or unrelated marketing activities.

14Children's privacy

The Service Provider does not knowingly collect data from individuals under 16 years without verified parental consent. Any such data discovered will be deleted promptly.

15Accountability and governance

The Service Provider maintains a Data Protection Management Programme integrating risk assessments, employee training, and complaint-handling procedures, as required by the PDPA.

16Updates to this Policy

This Policy may be reviewed and updated periodically. Updates will be posted on the Platform with the revision date. Continued use of services after any update signifies acceptance.

17Contact and complaints

For privacy concerns, access requests, or complaints, please contact:

If unresolved, Users may escalate complaints to the Data Protection Authority of Sri Lanka.

18Acceptance

By using or visiting the Platform, the User signifies agreement with this Privacy Policy. If the User does not agree, they should discontinue use of the Platform and Services.