legal
Privacy Policy
augmara.com · Last updated: July 2026
1. Introduction & Data Controller
This Privacy Policy explains how Augmara (Private) Limited (“Augmara”, “we”, “us”, “our”), a company incorporated under the laws of Sri Lanka, collects, uses, stores, and protects your personal data when you visit our website at augmara.com (the “Website”).
Augmara is the data controller responsible for your personal data within the meaning of the Personal Data Protection Act No. 9 of 2022 (Sri Lanka) (“PDPA”). We are committed to processing your personal data in accordance with the PDPA and applicable data protection laws.
Registered Office: BA3, Aspire Residencies by Odeliya, Bakmeegaha Road, Athurugiriya, Kaduwela
Contact: info@augmara.com
2. Information We Collect
2.1 Information You Provide Directly
When you use our contact form, request a consultation, or subscribe to our newsletter, we collect the information you voluntarily provide, including:
- Your name
- Email address
- Company name
- Project details or inquiry description
- Any other information you choose to include in your message
2.2 Information Collected Automatically
When you visit the Website, we automatically collect certain technical data, including:
- IP address (anonymised where possible)
- Browser type and version
- Device type and operating system
- Pages visited, time spent, and navigation patterns
- Referring URL (the page that directed you to our Website)
- Date and time of access
This data is collected primarily through cookies and analytics tools and may be anonymised or aggregated so that it does not identify you personally.
3. Lawful Basis for Processing
Under Section 5 of the PDPA, we process your personal data on the following lawful bases:
- Consent - When you submit a contact form, subscribe to our newsletter, or accept cookies, you provide affirmative consent for us to process your data for the stated purpose.
- Legitimate Interest - We process anonymous analytics data and implement security measures based on our legitimate interest in maintaining and improving the Website, provided this does not override your fundamental rights.
- Contractual Necessity - Where you make an inquiry about our services, processing your contact details is necessary to respond to your request and, where applicable, to take steps prior to entering a service agreement.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal (see Section 10 below).
4. How We Use Your Information
We use your personal data for the following specific purposes:
- To respond to your inquiries and provide information about our services
- To deliver newsletters you have subscribed to
- To improve the Website’s functionality, content, and user experience
- To monitor and ensure the security of the Website
- To comply with legal obligations
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
5. Cookies & Tracking Technologies
5.1 Types of Cookies
- Essential Cookies - Required for basic Website functionality (e.g. session management). These do not require consent.
- Analytics Cookies - Used to understand visitor behaviour and improve the Website. We use Google Analytics, which collects anonymised usage data. These are set only after you provide consent via our cookie banner.
5.2 Managing Cookies
When you first visit the Website, a cookie consent banner will allow you to accept or reject non-essential cookies. You may also manage cookie preferences through your browser settings at any time. Disabling analytics cookies will not affect your ability to use the Website.
6. Data Sharing & Third-Party Services
6.1 Service Providers
We engage the following categories of third-party service providers who may process your data on our behalf:
- Cloud hosting providers (for Website infrastructure)
- Email delivery services (for newsletter distribution and inquiry responses)
- Analytics providers (Google Analytics, anonymised data only)
These processors are contractually bound to process your data only for the purposes we specify and to implement appropriate security measures.
6.2 Legal Obligations
We may disclose your personal data where required by law, regulation, legal process, or enforceable governmental request, or to protect our rights, property, or safety.
7. Cross-Border Data Transfers
Your personal data may be transferred to and processed in countries outside Sri Lanka, including where our cloud hosting and analytics providers operate (e.g. the United States, European Union). These countries may have data protection laws that differ from Sri Lankan law.
In accordance with Part III of the PDPA, where we transfer personal data outside Sri Lanka, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses with our service providers
- Verification that the recipient country provides an adequate level of data protection, or
- Your explicit consent to the transfer where required
By using the Website, you acknowledge that your data may be processed internationally subject to these safeguards.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our specific retention periods are:
| Data Type | Retention Period |
|---|---|
| Contact form submissions | 2 years from date of submission |
| Newsletter subscribers | Until unsubscribe + 30 days for processing |
| Analytics data (Google Analytics) | 26 months (Google Analytics default) |
| Website server logs | 12 months |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data in transit
- Access controls limiting data access to authorised personnel only
- Regular security reviews of our infrastructure and processes
While we strive to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but commit to notifying affected individuals and the relevant authority without undue delay in the event of a personal data breach, as required under the PDPA.
10. Your Rights Under the PDPA
Under the Personal Data Protection Act No. 9 of 2022, you have the following rights in relation to your personal data:
- Right of Access - Request confirmation of whether we process your data and obtain a copy
- Right to Rectification - Request correction of inaccurate or incomplete data
- Right to Erasure - Request deletion of your personal data where it is no longer necessary for the purpose collected
- Right to Restriction - Request that we limit processing in certain circumstances
- Right to Data Portability - Receive your data in a structured, commonly used format
- Right to Object - Object to processing based on legitimate interest
- Right to Withdraw Consent - Withdraw consent at any time without affecting prior lawful processing
To exercise any of these rights, please contact us at info@augmara.com with the subject line “Data Subject Request”. We will respond within thirty (30) days of receiving your verified request. We may request identity verification before processing your request.
11. Children’s Data
The Website is not directed at persons under eighteen (18) years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a person under 18, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us at info@augmara.com.
12. International Users (GDPR)
If you are located in the European Union or European Economic Area, you may have additional rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”), including the right to lodge a complaint with your local supervisory authority.
Where the GDPR applies to our processing of your data, we rely on the lawful bases described in Section 3 above (consent, legitimate interest, contractual necessity), which align with Article 6(1) of the GDPR. For cross-border transfers to countries without an EU adequacy decision, we rely on Standard Contractual Clauses.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. For material changes, we will provide at least fourteen (14) days’ prior notice by posting the revised policy on this page with an updated “Last updated” date.
Your continued use of the Website after the effective date of any modification constitutes your acceptance of the revised policy. If you do not agree, please discontinue use of the Website.
14. Contact & Data Protection Queries
For any questions about this Privacy Policy, to exercise your data protection rights, or to raise a concern about how we handle your personal data, please contact us:
Augmara (Private) Limited
Email: info@augmara.com
Subject line for data requests: “Data Subject Request”
Registered Office: BA3, Aspire Residencies by Odeliya, Bakmeegaha Road, Athurugiriya, Kaduwela
We aim to resolve all queries within thirty (30) days. If you are not satisfied with our response, you may have the right to lodge a complaint with the Data Protection Authority of Sri Lanka once established under the PDPA.