Information We Collect
We may collect personal data to deliver our services and fulfil our obligations as a destination management company.
Personal data we may collect includes name, company name, and designation; email address and phone or WhatsApp number; travel details, preferences, and passport-related data where required; and billing and transaction information.
We also collect non-personal data such as browser type, device, and usage data for analytical and performance purposes.
How We Use Information
We use personal data strictly for the purposes for which it was provided.
This includes processing enquiries, bookings, and itineraries; delivering travel services and ground handling; communicating with partners, clients, and suppliers; improving our services and operational performance; and marketing, only where explicit consent has been provided.
B2B Partner Data
As a B2B DMC, we process data received from travel agents, tour operators, and partners with the utmost discretion.
Data shared by partners is processed strictly for service fulfilment, operational coordination, and guest experience delivery.
Partners confirm they have obtained proper consent from their clients before sharing any personal data with us.
Data Security
We implement appropriate technical and organisational measures to protect personal data.
These measures are designed to safeguard data against unauthorised access, loss, or misuse, in line with applicable industry standards and legal requirements.
Data Retention
Personal data is retained only for as long as necessary.
Retention periods are determined by operational, legal, and accounting requirements, in line with established industry practice and applicable data protection law.
Your Rights
You hold rights over your personal data and may exercise them at any time.
You may request access to, correction of, or deletion of your data; restriction of or objection to processing; and withdrawal of consent at any time.
Where applicable, you may also lodge a complaint with the relevant regulatory authority in your jurisdiction.
Legal Framework
We align with the Personal Data Protection Act No. 9 of 2022 (Sri Lanka) and applicable international data protection standards.
Where our services involve partners or clients in jurisdictions with their own data protection frameworks — including the EU's GDPR — we apply relevant standards accordingly.
Policy Updates
This policy may be updated periodically to reflect changes in our operations or applicable law.
Continued use of our services following any revision constitutes acceptance of the updated policy. We encourage periodic review of this page.
Contact
For any data protection enquiries, requests, or concerns, please contact us directly.


