Privacy Policy
Your privacy and data protection are fundamental to our business operations in Sri Lanka.
Introduction
QCETL (“we,” “our,” or “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or engage with our enterprise solutions in Sri Lanka.
This policy complies with the Data Protection Act No. 9 of 2022 of Sri Lanka.
Information We Collect
Personal Information
- Name, email address, phone number, and business contact details
- Company information and job title
- Billing and payment information for our services
- Technical support communications and service requests
Technical Information
- IP addresses, browser type, and operating system
- Website usage patterns and navigation data
- Cookies and similar tracking technologies
- Network infrastructure data for our automation services
Business Information
- Information about your IT infrastructure and requirements
- POS system transaction data (when using our QC POS solutions)
- Network performance and security analytics
- Support tickets and service interaction logs
Mobile App Data
- Location Data: Precise or approximate geographic location when you use the app, collected for sales team tracking, field staff movement monitoring, and shop/outlet registration services
- Camera Data: Camera access is used exclusively for QR code scanning during payment transactions; no images or video are stored
- Voice / Audio Data: Microphone access is used exclusively for in-app SIP/intercom calling features; calls are not recorded or stored
- Payment Instrument References: Local encrypted references to payment cards stored on your device only (see Payment Card Security section below)
How We Use Your Information
Service Delivery
- Provide network automation services
- Deliver POS system solutions
- Offer technical support and maintenance
- Process payments and billing
Business Operations
- Communicate about services and updates
- Improve our products and services
- Comply with legal obligations
- Prevent fraud and ensure security
Mobile App Permissions
Our mobile application (available on iOS and Android) requests certain device permissions to deliver specific features. Below is a full disclosure of every permission requested, why it is needed, and what we do — and do not do — with the data.
Location Access
Why we need it: The app collects device location to support the following business functions for our enterprise clients:
- Real-time tracking of sales representatives and field staff to help businesses manage their mobile workforce
- Monitoring staff movement and attendance for operational reporting
- Auto-filling geographic information during shop, outlet, or client registration to reduce manual data entry errors
What we do with it: Location data is transmitted securely to the client business account (your employer or the business whose system you are using). It is used solely for that client's operational purposes.
What we do NOT do: We do not sell, share, or transfer your location data to any third party. We do not use location data for advertising or analytics beyond the direct operational purposes stated above.
Camera Access
Why we need it: Camera access is required exclusively for scanning QR codes during business payment transactions (e.g., QR-based payments at point-of-sale).
What we do with it: The camera viewfinder is used in real time to decode QR codes. No images, photographs, or video frames are captured, stored, or transmitted by our systems.
What we do NOT do: We do not record video, take photographs, access the camera in the background, or share any camera-derived data with third parties.
Microphone & Speaker Access
Why we need it: Our app includes an internal SIP (Session Initiation Protocol) calling feature that enables intercom-style voice communication between extension users within the same client business network.
What we do with it: Microphone access is used only while an active call is in progress through the intercom/extension calling service. Audio is transmitted peer-to-peer over the SIP protocol within the client's own communication system.
What we do NOT do: We do not record, store, or transmit calls to QCETL servers. We do not access the microphone outside of an active call session, and we do not share voice data with any third party.
Important Note on Client Data: All data collected through these permissions (location, QR scan events, call activity) is processed exclusively for the respective client business that has deployed our system. QCETL does not use this data for any purpose beyond delivering the contracted service, and we do not sell, trade, or share it with any third party for commercial, advertising, or analytical purposes.
Payment Card Security
If you add payment card details within the QCETL mobile app, please be aware of the following:
- Device-only storage: Card details are stored exclusively on your mobile device in an encrypted format. They are never transmitted to or stored on QCETL servers.
- AES-256 encryption: All card data stored on the device is protected using AES-256 encryption keys that are generated and held locally on your device. Not even QCETL staff can read your card details.
- No cross-device sync: Because card data is not held on our servers, it cannot be restored if you switch to a new device. You will need to re-enter your card details on any new or replacement device.
- No third-party sharing: Card information is never shared with, sold to, or accessible by any third party. It is used only for payment processing within the app session.
Data Sharing and Disclosure
We do not sell your data — ever.
QCETL does not sell, rent, trade, or otherwise transfer any personal information, location data, payment data, camera data, or audio data to any third party for commercial, advertising, or marketing purposes. All data collected through our mobile app and services is used exclusively to deliver the contracted service to the respective client business.
We may disclose information only in the following limited circumstances:
- Client Business Access: Data collected on behalf of a client business (e.g., employee location, sales activity) is accessible only to that specific client through their authorized account
- Service Providers: Trusted technical partners who assist solely in delivering our contracted services, under strict confidentiality agreements
- Legal Requirements: When required by law or court order, or to protect the rights and safety of individuals
- Business Transfers: In connection with mergers, acquisitions, or asset sales, with prior notice to affected parties
- Explicit Consent: Only when you have given explicit, informed consent for a specific sharing purpose
Data Security
We implement appropriate technical and organizational security measures to protect your personal data:
- SSL/TLS encryption for all data in transit between the app and our servers
- AES-256 encryption for payment card data stored locally on your device
- Regular security audits and vulnerability assessments
- Strict access controls — even QCETL staff cannot read device-stored card details
- Employee security training and data handling procedures
- Secure data centers with 24/7 monitoring
- Regular data backups and disaster recovery plans
Your Rights
Under Sri Lanka Data Protection Act
- Right to be informed about data processing
- Right to access and rectify personal data
- Right to erasure in certain circumstances
- Right to withdraw consent
Data Protection
We ensure appropriate safeguards are in place for data protection, including:
- Adequacy decisions by relevant authorities
- Standard contractual clauses
- Binding corporate rules
- Explicit consent where required
Cookies and Tracking
We use cookies and similar technologies to enhance your experience on our website. You can control cookie preferences through your browser settings.
Note: Disabling certain cookies may affect the functionality of our services.
User Data Deletion
Automatic Data Deletion (30-Day Inactivity)
If you do not use your QCETL account for 30 consecutive days, all personal data associated with your account will be automatically and permanently deleted from our systems.
This includes profile information, login credentials, preferences, usage logs, and any third-party app connections (including WhatsApp integrations).
Request Immediate Deletion
To request immediate deletion of your personal data, please contact us at:
For full details, please visit our User Data Deletion page.
Third-Party App Integrations
Our services may integrate with third-party platforms including WhatsApp, Meta, and other messaging services. When you use these integrations:
- Data shared through integrations is subject to both our privacy policy and the third party's privacy policy
- You can revoke third-party access at any time through your account settings
- Deleting your QCETL account will automatically revoke all third-party connections
- For data held directly by third parties (e.g., Meta/WhatsApp), please refer to their respective privacy policies
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
General Privacy Inquiries
Email: [email protected]
Data Deletion Requests
Email: [email protected]
Address
QCETL (Private) Limited, No 43, Walukarama Road, Colombo 03, Sri Lanka
Policy Updates
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.