PRIVACY POLICY
Effective Date: 2026 / 02 / 13
Last Updated: 2026 / 02 / 13
1. Legal Notice and Scope
This Privacy Policy governs the manner in which Nuwara Osu (Private) Limited (“Nuwara Osu”, “Company”, “we”, “our”, or “us”) collects, processes, stores, discloses, and protects personal data obtained from customers, website users, distributors, suppliers, and other stakeholders. This Policy applies to all interactions with Nuwara Osu, including but not limited to:
-> Visits to our official website
-> Online and offline product purchases
-> Wholesale and distribution arrangements
-> Marketing communications
-> Participation in promotional campaigns
-> Any digital or physical engagement with the Company
By accessing or using our website or services, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy
______________________________________________________________________________________________________________________
2. Compliance With Applicable Laws
Nuwara Osu is committed to processing personal data in accordance with applicable data protection and privacy laws, including but not limited to:
-> The Personal Data Protection Act, No. 9 of 2022 (Sri Lanka), where applicable
-> Electronic Transactions Act of Sri Lanka
-> Any other relevant local or international data protection regulations governing our operations
Where international customers are involved, we endeavor to align our practices with globally recognized data protection principles.
______________________________________________________________________________________________________________________
3. Categories of Personal Data Collected
We may collect and process the following categories of data:
3.1 Personal Identification Information
-> Full name
-> National Identity Card (NIC) number or passport details (where legally required)
-> Contact number
-> Email address
-> Residential and delivery address
3.2 Transactional Information
-> Purchase history
-> Billing details
-> Payment confirmations
-> Refund and return records
Note: Full debit/credit card details are not stored by Nuwara Osu and are processed exclusively via secure third-party payment gateways.
3.3 Business and Corporate Data (Wholesale / Distributors)
-> Business registration certificates
-> Tax Identification Numbers (TIN/VAT)
-> Authorized representative details
-> Banking information for approved commercial transactions
3.4 Technical and Usage Data
-> IP address
-> Browser type and version
-> Device identifiers
-> Website usage statistics
-> Cookies and analytics data
______________________________________________________________________________________________________________________
4. Lawful Basis for Processing
We process personal data only when there is a lawful basis to do so, including:
-> Performance of a contract (order fulfillment, distribution agreements)
-> Compliance with legal or regulatory obligations
-> Legitimate business interests (service improvement, fraud prevention, operational efficiency)
-> Explicit consent (marketing communications and promotional activities)
______________________________________________________________________________________________________________________
5. Purpose of Data Processing
Personal data is collected and processed strictly for legitimate business purposes, including:
-> Order processing and product delivery
-> Customer relationship management
-> Managing distributor and wholesale networks
-> Regulatory compliance and reporting
-> Quality assurance and product traceability
-> Fraud prevention and risk management
-> Internal auditing and financial recordkeeping
-> Marketing communications (subject to consent)
We do not sell, trade, lease, or commercially exploit personal data belonging to our customers or partners.
______________________________________________________________________________________________________________________
6. Data Sharing and Disclosure
Personal data may be disclosed under the following strictly controlled circumstances:
-> To authorized courier and logistics providers for delivery purposes
-> To certified payment gateway providers for secure transaction processing
-> To regulatory authorities, courts, or law enforcement agencies when legally required
-> To professional advisors (legal, auditors, compliance officers) under confidentiality obligations
-> To technology service providers operating under binding data protection agreements
All third-party processors are contractually obligated to implement adequate data protection and confidentiality safeguards.
______________________________________________________________________________________________________________________
7. International Data Transfers
Where data is transferred outside Sri Lanka (for example, cloud hosting or payment processing), we ensure that appropriate safeguards are in place to maintain compliance with applicable data protection standards.
______________________________________________________________________________________________________________________
8. Data Retention Policy
Nuwara Osu retains personal data only for as long as necessary to:
-> Fulfill contractual obligations
-> Comply with statutory, tax, and accounting requirements
-> Resolve disputes
-> Enforce agreements
Upon expiration of the applicable retention period, data is securely deleted, anonymized, or archived in accordance with legal requirements
______________________________________________________________________________________________________________________
9. Data Security Measures
We implement reasonable administrative, technical, and physical safeguards designed to:
• Prevent unauthorized access
• Protect against data loss
• Mitigate misuse or alteration
• Ensure confidentiality and integrity
Security measures include encrypted communications (where applicable), restricted access controls, secure server environments, and internal compliance protocols.
However, no data transmission over the internet can be guaranteed to be completely secure. Users acknowledge this inherent risk.
______________________________________________________________________________________________________________________
10. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to:
-> Improve website functionality
-> Analyze traffic and usage patterns
-> Enhance user experience
Users may manage cookie preferences through browser settings. Disabling cookies may affect website performance
______________________________________________________________________________________________________________________
11. Rights of Data Subjects
Subject to applicable law, individuals may have the right to:
• Request access to their personal data
• Request rectification of inaccurate information
• Request erasure (where legally permissible)
• Restrict or object to certain processing activities
• Withdraw consent for marketing communications
Requests must be submitted in writing to the contact details provided below
______________________________________________________________________________________________________________________
12. Children's Data
Our services and products are not directed toward individuals under 18 years of age without parental or legal guardian involvement. We do not knowingly collect personal data from minors.
______________________________________________________________________________________________________________________
13. Third-Party Websites
Our website may contain links to external websites. Nuwara Osu is not responsible for the privacy practices, security standards, or content of third-party websites.
______________________________________________________________________________________________________________________
14. Policy Amendments
Nuwara Osu reserves the right to amend, modify, or update this Privacy Policy at its sole discretion. Anychanges shall become effective upon publication on the official website.
Continued use of our website or services constitutes acceptance of the revised Privacy Policy.
______________________________________________________________________________________________________________________
15. Contact Information
For privacy-related inquiries, data access requests, or compliance matters, please contact: The kandy ayurvedic pharmacy LTD kandy Sri Lanka
Phone : +94 81 222 0696
Email : nuwaraosu@sltnet.lk
Website : nuwaraosu.com
