This Privacy Notice outlines the commitment of Hayleys PLC to the secure and transparent management of personal data. We operate in accordance with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka (“PDPA”) and relevant international standards such as the European Union’s General Data Protection Regulation (GDPR), ensuring accountability across all our global touchpoints.
This notice applies to Hayleys PLC and all our subsidiaries. When we say “Hayleys,” “we,” or “us,” we refer to the Hayleys Group company you are interacting with.
For the purposes of this notice, “Personal Data”, “Data Controller”, “Data Processor”, shall have the meanings assigned to them under the PDPA.
Who collects your Personal Data
We are a globally present, diversified conglomerate with operations in over 20 countries. We comply with the PDPA and uphold equivalent international standards for data protection.
What Personal Data we collect
- Information you give us: Examples include your name, date of birth, ID or passport number, email, phone number and financial details for transactions.
- Information collected automatically: Examples include IP address, browser type, device identifiers and website usage data (such as pages visited and time spent).
We ensure that all Personal Data collected is relevant, limited and used only for its intended purpose.
How we collect it
- Directly when you fill out a form, apply for a job, or contact us.
- Automatically through cookies and tracking tools that remember your preferences.
- From others, occasionally from trusted partners or public sources (for example, if you interact with us through social media).
Why we use your Personal Data
Primary purposes include:
- Service Delivery: Creating accounts, processing payments and delivering products.
- Communication: Sending updates, responding to inquiries, or recruitment updates.
- Improvement: Enhancing our websites and customer experiences through analytics.
- Compliance and Safety: Preventing fraud, ensuring security or meeting legal or regulatory obligations.
- Legal obligation or Legitimate Interests: Processing may also occur where we are obligated under law or in the interests of subjects such as responding to emergencies affecting life, health, or safety.
Special Categories of Personal Data and Children
Our websites and services are not intended for children under 16. If we become aware that we have collected such data without parental consent, we will delete it immediately. Parents or guardians can contact our Data Protection Officer to request its deletion.
Sharing your Personal Data
- Within the Hayleys Group to provide seamless service and unified support.
- With trusted third-party service providers and partners (such as cloud or payment providers) under written agreements that enforce strict confidentiality and security obligations.
- For legal or legitimate reasons – if required by law, court order, or regulatory authorities or to protect interests.
All our service providers process Personal Data only on our written instructions and are contractually required to maintain confidentiality, implement security measures, and delete or return of Personal Data after completion of services.
Your rights
| Your Right | What It Means |
|---|---|
| Access & Correction | Ask for a copy of your data or correct any inaccuracies. |
| Erasure (“Be Forgotten”) | Request deletion of your data when it is no longer needed. |
| Restrict or Object | Limit how we use your data or object to certain processing. |
| Data Portability | Request your data in a format you can transfer elsewhere. |
| Withdraw Consent | Withdraw your consent for specific uses at any time. |
| Review of Automated Decisions | The right to request meaningful information about the logic involved and to ask for a human review of any automated decision that affects you. |
These rights may also be exercised by authorised representatives, or by heirs within ten years of an individual’s passing, in accordance with the Act.
To exercise your rights, email us at DPO@hayleys.com. We will respond to you within a maximum of 21 working days. If we are unable to grant your request due to legal or security reasons, we will provide you with a written explanation for our decision.
If you are not satisfied with our response, you have the right to raise a complaint with the Data Protection Authority of Sri Lanka.
How we keep your Personal Data safe
We also maintain incident response procedures to identify, investigate, and respond to Personal Data breaches in accordance with applicable legal requirements.
We also conduct assessments to identify and mitigate potential risks to your privacy.
All third-party service providers process Personal Data under written agreements with appropriate confidentiality and security obligations.
Data Protection Management Programme
How long we keep your Personal Data
How we protect cross-border transfers of Personal Data
Cookies and tracking
Updates to this notice
Contact our Data Protection Officer
Data Protection Officer
Last Updated: February 2026
