SYS Nature Life Resort respects the privacy of its Guests, visitors, customers and website users and is committed to handling personal information responsibly, securely and transparently.
This Privacy Policy explains how SYS Nature Life Resort, operated by SYS Investments (Pvt) Ltd, Business Registration No. PV 00275365, of 193/D, Gangabada Road, Kindelpitiya, Welmilla Junction, Bandaragama, Sri Lanka (“SYS Nature Life Resort”, “Resort”, “we”, “us” or “our”), collects, uses, stores, shares and otherwise processes personal data.
This Policy applies to personal data processed in connection with:
- our website;
- accommodation reservations;
- multi-room reservations;
- accommodation Packages;
- meal and Board Plans;
- Day-Out Packages;
- activities and Add-ons;
- weddings and private Events;
- meeting rooms and corporate Events;
- enquiries;
- payments;
- Guest registration;
- customer support;
- promotional communications;
- Resort security and CCTV; and
- other Resort services.
This Policy should be read together with our Terms and Conditions, Booking & Cancellation Policy and any booking-specific or Event-specific terms.
1. Who Is Responsible for Your Personal Data? #
For the purposes of applicable data-protection law, the entity responsible for determining why and how your personal data is processed is:
SYS Investments (Pvt) Ltd
Trading as: SYS Nature Life Resort
Business Registration No.: PV 00275365
Registered Address: 193/D, Gangabada Road, Kindelpitiya, Welmilla Junction, Bandaragama, Sri Lanka
Resort Address: Rajasanthaka Estate, Pothupitiya, Thalwita, Porapola, Wellawa, Kurunegala, Sri Lanka
Email: [email protected]
Telephone: 077-7766551
Privacy Contact: 077-4248663
Where applicable under Sri Lankan data-protection law, this entity may act as the Controller of personal data processed in connection with Resort operations.
2. What Is Personal Data? #
“Personal data” generally means information relating to an identified or identifiable individual.
This may include information that identifies a person directly or indirectly, such as:
- name;
- identification number;
- contact information;
- financial information;
- online identifiers;
- booking information; or
- other information capable of being linked to an individual.
3. Personal Data We May Collect #
Depending on how you interact with the Resort, we may collect the following categories of information.
3.1 Identification Information #
This may include:
- full name;
- title;
- date of birth or age where required;
- gender where relevant and lawfully collected;
- nationality;
- National Identity Card details;
- passport details;
- passport number;
- identification document information; and
- signature.
We will collect identification information only where reasonably required for Guest registration, security, legal compliance, booking administration or other legitimate Resort purposes.
3.2 Contact Information #
This may include:
- residential or postal address;
- email address;
- telephone number;
- mobile number;
- WhatsApp number; and
- emergency contact information where appropriate.
3.3 Booking Information #
We may collect details relating to your reservation, including:
- Booking Reference Number;
- arrival date;
- departure date;
- number of nights;
- room type;
- allocated room;
- number of rooms;
- number of adults;
- number of children;
- ages of children where relevant;
- selected Board Plan;
- accommodation Package;
- activities;
- Add-ons;
- special requests;
- rates;
- discounts;
- promotional offers;
- booking channel;
- booking history; and
- cancellation or amendment information.
4. Multi-Room Booking Information #
Where one person makes a reservation for multiple rooms, we may process information relating to other Guests included in the Booking.
The Lead Guest should only provide information about another person where they are authorised or otherwise entitled to provide that information.
The Lead Guest should make other members of the booking party aware of this Privacy Policy where appropriate.
We may request additional Guest information at check-in where necessary.
5. Accommodation Package Information #
Where a Guest purchases a Package, we may process information relating to:
- room allocation;
- Package preferences;
- meal choices;
- activity selections;
- romantic or honeymoon arrangements;
- decorations;
- celebrations;
- special occasions; and
- optional Package Add-ons.
We will use this information to arrange and deliver the services requested by the Guest.
6. Food and Dietary Information #
Where Guests inform us about:
- food allergies;
- food intolerances;
- medical dietary requirements;
- religious or cultural dietary requirements; or
- other dietary preferences,
we may process that information in order to provide appropriate food and beverage services and protect Guest safety.
Certain dietary or allergy information may reveal information of a sensitive nature.
Such information will be collected and used only where reasonably necessary and in accordance with applicable law.
7. Health, Accessibility and Safety Information #
Where necessary, a Guest may voluntarily provide information concerning:
- mobility requirements;
- accessibility needs;
- allergies;
- medical conditions relevant to participation in an Activity;
- emergency assistance requirements; or
- other safety-related matters.
The Resort does not ordinarily seek detailed medical records.
Where health-related information is required to safely provide a service or Activity, we will seek to limit collection to information reasonably necessary for that purpose.
Additional consent or acknowledgement may be requested where required.
8. Activities and Add-Ons #
Where you participate in Resort activities, we may process information concerning:
- selected Activity;
- Participant name;
- age;
- booking date and time;
- equipment requirements;
- safety information;
- parental or guardian consent;
- participation acknowledgement;
- incident information where necessary; and
- payments.
Activities may include swimming, cycling, fishing, cricket, nature experiences, farm activities, air-rifle shooting and other Resort experiences.
For certain controlled or higher-risk activities, additional information or acknowledgement may be required for safety purposes.
9. Day-Out Package Information #
For Day-Out Packages, we may collect information including:
- organiser name;
- organisation or group name;
- contact information;
- expected Guest numbers;
- number of adults and children;
- meal selections;
- activity selections;
- arrival and departure times;
- payment details;
- special requirements; and
- other information required to organise the Day-Out experience.
10. Weddings and Private Events #
Where you enquire about or book a Wedding or private Event, we may process information including:
- names of the organisers;
- names of the couple where relevant;
- contact information;
- Event date;
- venue;
- estimated and final Guest count;
- menu selections;
- seating or venue arrangements;
- accommodation requirements;
- decoration requirements;
- suppliers;
- photographers and videographers;
- entertainment providers;
- special requests;
- payment information;
- Event correspondence; and
- contractual information.
Information concerning third-party suppliers may also be collected where reasonably required to manage the Event.
11. Meetings and Corporate Events #
Where a company, organisation or individual books a meeting room or corporate Event, we may collect:
- organiser name;
- company or organisation name;
- job title where relevant;
- telephone number;
- email address;
- attendee information where required;
- meeting date and time;
- catering requirements;
- equipment requirements;
- billing information;
- purchase order or invoice information; and
- Event correspondence.
12. Payment Information #
When a Guest makes a payment, we may process information including:
- payment amount;
- payment date;
- transaction reference;
- payment status;
- billing name;
- billing address;
- payment method;
- partial card information where provided by an authorised payment processor; and
- information necessary to reconcile payments and issue refunds.
Where payments are processed using a third-party bank or payment gateway, payment-card information may be submitted directly to that provider.
Where this arrangement applies, the Resort should avoid storing full payment-card numbers, card security codes, online banking passwords or PIN numbers unless expressly permitted, necessary and appropriately secured.
Guests should never send payment-card PIN numbers, online banking passwords or similar authentication credentials to the Resort.
13. Information from Third-Party Booking Channels #
We may receive personal information when a reservation is made through:
- online travel agencies;
- travel agents;
- tour operators;
- corporate booking partners;
- Event organisers; or
- other authorised booking intermediaries.
This information may include:
- name;
- contact information;
- booking dates;
- Guest numbers;
- selected room;
- Package;
- booking reference;
- payment status; and
- special requests.
The relevant third party may also process your information under its own privacy policy.
14. Information Collected Through Enquiries #
When you contact us through:
- website forms;
- telephone;
- email;
- WhatsApp;
- social media;
- direct messaging; or
- other communication channels,
we may retain the information contained within that communication where reasonably required to respond to your enquiry or maintain appropriate business records.
15. Website and Device Information #
When you visit our website, certain technical information may be collected automatically.
This may include:
- IP address;
- browser type;
- operating system;
- device type;
- language settings;
- date and time of access;
- pages viewed;
- referring website;
- session information;
- website errors; and
- other technical diagnostic information.
We may use this information for:
- website operation;
- cybersecurity;
- fraud prevention;
- troubleshooting;
- performance monitoring;
- statistical analysis; and
- improvement of our digital services.
16. Cookies and Similar Technologies #
Our website uses cookies and similar technologies.
Cookies may include:
Essential Cookies
Necessary for functions such as:
- website navigation;
- booking sessions;
- security;
- authentication;
- shopping or booking selections; and
- payment processes.
Functional Cookies
Used to remember Guest preferences such as:
- language;
- currency;
- booking selections; or
- other website preferences.
Analytics Cookies
Analytics technologies help us understand:
- website traffic;
- popular pages;
- visitor interactions;
- technical performance; and
- website effectiveness.
Where consent is legally required for a particular category of cookie or similar technology, such technology should only be activated after the required consent has been obtained.
17. Analytics and Third-Party Services #
The Resort uses the following third-party services, which may process personal data or online identifiers:
- Cloudflare Web Analytics (website analytics);
- Google reCAPTCHA (spam and abuse prevention on forms and sign-in);
- Google Sign-In (optional sign-in with a Google account);
- Facebook Login (optional sign-in with a Facebook account); and
- PayHere (payment gateway).
18. Why We Process Personal Data #
We may process personal data for purposes including:
- creating and managing reservations;
- allocating rooms;
- administering multi-room Bookings;
- providing accommodation;
- providing meals;
- administering Packages;
- arranging Day-Out Packages;
- arranging activities and Add-ons;
- organising Weddings and Events;
- organising meetings;
- processing payments;
- processing refunds;
- issuing invoices and receipts;
- confirming reservations;
- communicating changes;
- responding to enquiries;
- providing customer support;
- handling complaints;
- maintaining Guest records;
- maintaining Resort security;
- preventing fraud;
- investigating incidents;
- managing lost property;
- complying with legal and regulatory requirements;
- maintaining financial records;
- improving Resort services;
- maintaining and protecting our website and IT systems; and
- conducting permitted marketing activities.
19. Grounds for Processing #
We will process personal data only where there is an appropriate basis or ground permitted under applicable law.
Depending on the circumstances, processing may be necessary:
- to take steps requested by a Guest before entering into a Booking;
- to perform a Booking or other agreement;
- to comply with legal or regulatory obligations;
- to protect the safety or vital interests of persons where applicable;
- for security, fraud prevention or legitimate operational requirements where permitted;
- for other grounds permitted by applicable law; or
- on the basis of consent where consent is required.
Where processing depends on consent, the Guest may be able to withdraw that consent in accordance with applicable law.
Withdrawal of consent does not necessarily affect processing lawfully carried out before the withdrawal.
20. Marketing Communications #
Where permitted by applicable law, we may use Guest contact information to communicate information concerning:
- Resort offers;
- accommodation Packages;
- seasonal promotions;
- Day-Out Packages;
- Weddings;
- Events;
- dining;
- activities; and
- other Resort services.
Where consent is required, marketing communications will only be sent after the appropriate consent has been obtained.
Guests may request to stop receiving promotional communications at any time through:
- the unsubscribe function provided;
- email;
- telephone; or
- another communication method provided by the Resort.
Stopping marketing communications will not prevent necessary communications concerning an existing Booking or transaction.
21. Transactional Communications #
We may contact Guests about an existing Booking without treating the communication as marketing where the communication is reasonably necessary to administer the reservation.
Examples include:
- booking confirmations;
- payment confirmations;
- payment reminders;
- check-in information;
- changes to reservations;
- Event coordination;
- safety notices;
- cancellation information; and
- refund updates.
22. CCTV #
Closed-circuit television (“CCTV”) may be used in selected Resort locations for purposes such as:
- Guest safety;
- employee safety;
- property security;
- crime prevention;
- incident investigation; and
- protection of Resort assets.
CCTV may operate in areas such as:
- entrances;
- reception areas;
- public corridors;
- parking areas;
- selected outdoor areas; and
- other security-sensitive public areas.
CCTV will not be intentionally installed in locations where Guests reasonably expect complete privacy, including:
- inside Guest bedrooms;
- bathrooms;
- changing rooms; or
- similar private locations.
23. CCTV Retention #
CCTV recordings should be retained only for a period reasonably necessary for their intended purpose unless:
- an incident has occurred;
- footage is required for an investigation;
- footage is required for legal proceedings;
- law enforcement has lawfully requested preservation; or
- a longer period is required by law.
Standard CCTV retention period: for a limited period appropriate to its purpose.
Access to CCTV recordings should be restricted to authorised persons.
24. Photography and Video at the Resort #
Guests may appear incidentally in general photographs or video where photography occurs within public Event environments.
However, acceptance of this Privacy Policy or the Resort's general Terms and Conditions alone will not be treated as blanket consent for the Resort to use an identifiable Guest as the subject of commercial advertising where separate consent is required.
Where the Resort intends to intentionally photograph or film identifiable Guests for marketing, advertising or promotional purposes, appropriate consent should be obtained.
Separate parental or guardian consent should be considered before intentionally using identifiable images of children for promotional purposes.
25. Who We May Share Personal Data with #
Where reasonably necessary, personal data may be shared with authorised third parties including:
- payment processors;
- banks;
- booking-system providers;
- website hosting providers;
- IT service providers;
- email or communication providers;
- online travel agencies;
- travel agents;
- Event suppliers;
- approved activity providers;
- transport providers;
- auditors;
- accountants;
- insurers;
- professional advisers;
- lawyers;
- security providers;
- regulatory authorities;
- law-enforcement authorities; and
- government authorities.
Personal information should only be disclosed where there is an appropriate operational, contractual, legal, safety or other lawful basis.
26. Service Providers and Processors #
Some third-party service providers may process personal data on behalf of the Resort.
Where applicable, the Resort should take reasonable steps to ensure such providers:
- process information only for agreed purposes;
- maintain appropriate confidentiality;
- maintain reasonable security measures;
- comply with applicable data-protection obligations; and
- return, delete or otherwise appropriately handle data after the service relationship ends.
27. International or Cross-Border Processing #
Some technology, booking, cloud, payment, communication or other service providers may process information outside Sri Lanka.
Where personal data is processed outside Sri Lanka, the Resort will seek to ensure that the processing complies with applicable Sri Lankan legal requirements concerning international or cross-border processing.
28. Legal and Regulatory Disclosures #
We may disclose personal information where reasonably necessary to:
- comply with applicable law;
- comply with a court order;
- respond to a lawful request from an authorised public authority;
- comply with tourism or Guest-registration requirements;
- cooperate with law-enforcement authorities;
- establish or defend legal claims;
- investigate suspected fraud;
- protect life or safety; or
- protect the lawful rights and property of the Resort.
Only information reasonably necessary for the relevant purpose should be disclosed.
29. Children's Personal Data #
Because families may stay at the Resort, we may process limited information relating to children.
This may include:
- name;
- age;
- date of birth where required;
- room allocation;
- meal requirements;
- Activity participation;
- safety information; and
- parental or guardian information.
The Resort should limit collection of children's information to information reasonably necessary for:
- booking;
- occupancy;
- pricing;
- safety;
- food service;
- activities; or
- legal requirements.
Where consent is required in relation to a child, appropriate consent from a parent or legal guardian should be obtained in accordance with applicable law.
30. Data Accuracy #
We take reasonable steps to maintain accurate and up-to-date personal information.
Guests are encouraged to inform us if information associated with their Booking is inaccurate or changes.
Guests may request correction of inaccurate or incomplete information in accordance with applicable law and Resort procedures.
31. How Long We Keep Personal Data #
We will not intentionally retain personal information for longer than reasonably necessary for the purpose for which it was collected, subject to legal, regulatory, accounting, taxation, insurance, security and dispute-resolution requirements.
Different categories of information may require different retention periods.
32. Data Deletion and Anonymisation #
When personal data is no longer required, the Resort may securely:
- delete it;
- destroy physical copies;
- anonymise it; or
- otherwise make it no longer identifiable,
subject to legal or legitimate record-retention requirements.
Backup systems may retain information for limited additional periods until the relevant backup is securely overwritten or deleted.
33. Information Security #
The Resort will seek to maintain appropriate technical and organisational measures designed to protect personal information against:
- unauthorised access;
- unauthorised disclosure;
- loss;
- alteration;
- destruction;
- accidental disclosure;
- malware;
- fraud; and
- other inappropriate processing.
Measures may include, where appropriate:
- access controls;
- passwords and authentication controls;
- encryption;
- restricted administrative access;
- staff confidentiality obligations;
- backups;
- network security;
- software updates;
- security monitoring;
- payment-provider controls;
- physical security; and
- employee awareness and training.
No electronic system can be guaranteed to be completely secure, and the Resort will continually assess reasonable safeguards appropriate to the risks involved.
34. Staff Access #
Employees and authorised contractors should only access personal information where required for legitimate work purposes.
Access should be limited according to job responsibilities where reasonably practicable.
Employees handling personal information should be subject to appropriate confidentiality and data-protection requirements.
35. Data Breaches and Security Incidents #
If the Resort becomes aware of a personal-data security incident, it will assess the incident and take reasonable steps to:
- contain the incident;
- investigate what occurred;
- reduce potential harm;
- restore security;
- preserve relevant records;
- notify appropriate persons where required; and
- notify the relevant authority where required by applicable law.
36. Your Privacy Requests #
Subject to applicable Sri Lankan law and any conditions, limitations or exemptions contained in that law, an individual may be entitled to make requests concerning personal data relating to them.
Depending on the applicable legal framework, requests may concern matters such as:
- access to personal data;
- correction or completion of inaccurate or incomplete data;
- withdrawal of consent where processing depends on consent;
- requests concerning further processing;
- erasure where legally applicable;
- review of certain automated decisions where applicable; or
- other rights provided by applicable law.
37. How to Make a Privacy Request #
Privacy-related requests may be submitted to:
Privacy Contact / Data Protection Contact
SYS Nature Life Resort
Email: [email protected]
Telephone: 077-7766551
Postal Address: Rajasanthaka Estate, Pothupitiya, Thalwita, Porapola, Wellawa, Kurunegala, Sri Lanka
Please include sufficient information for us to identify:
- you;
- the relevant Booking or interaction where applicable; and
- the nature of your request.
We may request reasonable proof of identity before disclosing, correcting or deleting personal data in order to protect Guest information from unauthorised access.
38. Requests Made on Behalf of Another Person #
Where a person makes a privacy request on behalf of another individual, the Resort may require evidence that the requester is legally authorised to act for that individual.
This may include:
- written authority;
- parental or guardian authority;
- power of attorney; or
- other appropriate evidence.
39. Automated Decision-Making #
The Resort does not intend to make decisions producing significant effects on Guests solely through automated processing unless such processing is appropriately disclosed and permitted by applicable law.
Automated systems may nevertheless be used for operational functions such as:
- availability calculations;
- room pricing;
- capacity validation;
- booking totals;
- availability of Packages; and
- transaction screening.
These routine automated functions do not necessarily constitute automated decision-making for legal purposes.
40. External Websites and Services #
Our website may contain links to third-party websites or services.
These may include:
- social media platforms;
- online maps;
- payment gateways;
- booking platforms;
- tourism websites; or
- partner services.
The Resort does not control the privacy practices of independent third-party websites.
Guests should review the privacy policies of those third parties before providing personal information.
41. Social Media #
Where you communicate with the Resort through social media, both the Resort and the relevant social-media provider may process information.
The provider's own terms and privacy policy will apply independently to its processing.
Information publicly posted on social media may be visible to other users.
Guests should avoid posting sensitive Booking or payment information publicly.
42. WhatsApp and Messaging Services #
Where Guests communicate with the Resort through WhatsApp or another messaging platform, the relevant platform provider may process information according to its own terms and privacy practices.
Guests should avoid sending:
- payment-card PINs;
- passwords;
- unnecessary identification documents;
- highly sensitive medical records; or
- other information that is not required for the relevant request
through general messaging services.
43. Email Communication #
Email communications may contain Booking or personal information.
Guests should take reasonable care when forwarding Resort emails or sharing Booking confirmations with others.
The Resort will take reasonable precautions when sending sensitive information electronically.
44. Changes to This Privacy Policy #
We may update this Privacy Policy from time to time because of:
- changes to law;
- regulatory requirements;
- changes to Resort operations;
- new website features;
- new booking services;
- new technology;
- new payment systems; or
- changes to how personal data is processed.
The current version will display the date on which it was last updated.
Where a material change requires additional notice or consent, the Resort will take appropriate steps as required by applicable law.
45. Contact Us #
Questions, concerns or requests concerning this Privacy Policy may be directed to:
SYS Nature Life Resort
Operated by: SYS Investments (Pvt) Ltd
Business Registration No.: PV 00275365
Registered Address: 193/D, Gangabada Road, Kindelpitiya, Welmilla Junction, Bandaragama, Sri Lanka
Resort Address: Rajasanthaka Estate, Pothupitiya, Thalwita, Porapola, Wellawa, Kurunegala, Sri Lanka
Telephone: 077-7766551
WhatsApp: 077-7766551
Email: [email protected]
Privacy Email: [email protected]
Website: https://www.sysnaturelife.com
46. Data Protection Authority #
Where applicable under Sri Lankan law, an individual may have the right to contact or appeal to the Data Protection Authority of Sri Lanka concerning the processing of personal data.
Data Protection Authority of Sri Lanka
First Floor, Block 5
Bandaranaike Memorial International Conference Hall (BMICH)
Bauddhaloka Mawatha
Colombo 7
Sri Lanka
The Resort recommends that Guests first contact the Resort's Privacy Contact where appropriate so that the matter can be reviewed and, where possible, resolved promptly.
Nothing in this provision limits any right to approach a competent authority directly where provided by law.