Privacy Policy
Introduction
Tasran Digital Solutions ("Company," "we," "our," or "us") is committed to protecting the privacy and personal data of our website visitors, clients, customers, and users of our mobile applications and software services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you interact with our company, website, applications, and digital services.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services. By accessing or using Tasran Digital Solutions' services, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.
1. Information We Collect
We may collect personal information in various ways depending on how you interact with our services:
1.1 Information You Provide Directly
- Contact Information: When you contact us via email, contact forms, or inquiries, we collect your name, email address, phone number, company name, and message content.
- Service Request Information: When you request quotes, consultations, or custom software development services, we collect project specifications, requirements, and business information.
- Account Information: If you create an account on our platforms, we collect login credentials, profile information, and account preferences.
- Payment Information: When you make purchases or subscribe to services, we collect billing address and payment method information (through secure third-party payment gateways).
- Communication Records: We retain emails, chat messages, and communications you send us regarding services, inquiries, or support.
1.2 Information Collected Automatically
- Website Usage Data: We collect information about how you interact with our website, including pages visited, time spent, links clicked, and referral sources.
- Device Information: We automatically receive information about the device you use to access our services, including device type, operating system, browser type, and IP address.
- Cookies & Tracking: We use cookies, web beacons, and similar tracking technologies to enhance user experience and analyze website performance.
- Analytics Data: We use analytics services to understand user behavior, traffic patterns, and service performance.
1.3 Third-Party Information
We may receive information about you from third-party sources, including business partners, payment processors, analytics providers, and publicly available sources to verify information and enhance our services.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, deliver, and maintain our software development services, mobile applications, and digital solutions.
- Communication: To respond to your inquiries, provide customer support, send service updates, and communicate about projects and deliverables.
- Payment Processing: To process payments, manage billing, generate invoices, and handle financial transactions securely.
- Business Operations: To manage client relationships, track project progress, schedule meetings, and maintain service records.
- Compliance & Legal: To comply with legal obligations, verify client identity, prevent fraud, and protect our legal rights.
- Marketing & Promotions: To send newsletters, promotional materials, and service updates (with your consent).
- Website Improvement: To analyze website usage, improve user experience, optimize features, and conduct research.
- Security & Safety: To protect against unauthorized access, malicious activity, and ensure system security.
3. Payment Information & Security
Tasran Digital Solutions processes payments through secure, PCI-DSS compliant third-party payment gateways, including PayHere and other authorized processors.
3.1 Payment Processing
- Payment transactions are processed through encrypted, PCI-compliant payment gateways.
- We collect billing address and payment method information only as necessary for transaction processing.
- Payment details are never stored in plaintext on our systems.
- We maintain tokenization systems for recurring payment authorization when applicable.
3.2 Billing & Invoice Information
We retain billing records, invoices, and transaction history for accounting, regulatory compliance, and dispute resolution purposes. These records are stored securely and accessed only by authorized personnel.
4. Data Security & Protection
We implement comprehensive technical, administrative, and organizational security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction:
- Encryption: We use industry-standard SSL/TLS encryption for data transmission over the internet.
- Access Controls: Access to personal data is restricted to authorized employees and contractors who need it for business purposes.
- Secure Servers: We maintain secure, regularly updated servers with firewalls and intrusion detection systems.
- Regular Audits: We conduct regular security audits and vulnerability assessments.
- Employee Training: Our staff undergoes regular data protection and security training.
- Data Minimization: We only collect and retain personal data that is necessary for stated purposes.
Note: While we implement robust security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your information.
5. Data Sharing & Third Parties
5.1 When We Share Information
We do NOT sell, trade, or lease your personal information to third parties for marketing purposes. However, we may share information in the following circumstances:
- Service Providers: We share information with third-party service providers who assist us in delivering services (hosting providers, payment processors, email services, analytics providers).
- Legal Requirements: We may disclose information when required by law, court order, or government request to comply with legal obligations.
- Business Transfers: If our company is acquired, merged, or sold, your information may be transferred as part of the business transaction.
- Fraud Prevention: We may share information with law enforcement or fraud prevention agencies when necessary to prevent illegal activity.
- Your Consent: We may share information with third parties when you explicitly consent.
5.2 Data Processing Agreements
Our third-party service providers are bound by Data Processing Agreements (DPAs) requiring them to maintain strict confidentiality and implement adequate security measures. We carefully select service providers based on their security practices and compliance with data protection regulations.
5.3 International Data Transfers
If your information is transferred internationally, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) and other legal mechanisms to ensure adequate protection.
6. Your Privacy Rights & Choices
6.1 Access & Portability
You have the right to request access to the personal data we hold about you and to receive a copy in a portable format.
6.2 Correction & Updates
You may request that we correct inaccurate or incomplete personal data. You can update account information directly or contact us for assistance.
6.3 Deletion & Erasure
You have the right to request deletion of your personal data, subject to certain legal and business exceptions. We will comply with erasure requests unless we have legitimate reasons to retain the information.
6.4 Marketing Communications
You may opt out of receiving promotional emails and marketing communications by clicking the unsubscribe link in our emails or contacting us directly. Please note that we may still send transactional emails related to your services.
6.5 Cookie Preferences
You can control cookie settings through your browser preferences. Most browsers allow you to refuse cookies or alert you when cookies are being sent.
6.6 Do Not Track
Some browsers include a "Do Not Track" feature. Our website currently does not respond to Do Not Track signals, but you can control tracking through browser settings.
7. Data Retention
We retain personal data for as long as necessary to provide services and fulfill the purposes outlined in this policy:
- Client & Project Data: Retained during the service period and for 7 years after project completion for legal, tax, and audit purposes.
- Contact & Inquiry Data: Retained for 2 years or until you request deletion.
- Website Analytics: Retained for 26 months by default; you can configure retention periods.
- Payment Records: Retained for 7 years for tax and compliance purposes.
- Marketing Lists: Retained until you unsubscribe or request removal.
We securely delete or anonymize information that is no longer necessary for stated purposes.
8. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a minor, we will take immediate steps to delete such information. Parents or guardians who believe their child has provided information to us should contact us immediately at tasran.digi@gmail.com.
9. Policy Changes & Updates
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last Updated" date at the top of this policy. Your continued use of our services following changes constitutes your acceptance of the revised Privacy Policy.
We encourage you to review this Privacy Policy regularly to stay informed about how we protect your information.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us:
Email: tasran.digi@gmail.com
Business Hours: Monday – Friday, 9:00 AM – 6:00 PM (GMT +5:30)
We will respond to your inquiries within 14 business days.
10.1 Data Protection Requests
To exercise your privacy rights (access, correction, deletion, portability), please submit a formal request to tasran.digi@gmail.com with sufficient identification information. We will verify your identity and respond according to applicable privacy laws.
11. Jurisdiction & Compliance
This Privacy Policy is governed by the laws of applicable jurisdictions where Tasran Digital Solutions operates. We comply with internationally recognized privacy standards and regulations, including:
- General Data Protection Regulation (GDPR) for EU residents
- California Consumer Privacy Act (CCPA) for California residents
- Sri Lanka Personal Data Protection Act and relevant local regulations
- Payment Card Industry Data Security Standard (PCI-DSS) for payment processing
12. Acknowledgment & Agreement
By accessing or using Tasran Digital Solutions' services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. You consent to our collection, use, and disclosure of your personal data as described herein. If you do not agree with any aspect of this policy, please discontinue using our services.