{"_id":"69045844594952f94e4720b3","type":"privacy-policy","content":"     <div\n            className=\"container mt-5 pt-5\"\n\n        >\n\n            <h2\n                className=\"fw-semibold mb-4\"\n                style={{\n                    fontSize: \"1.8rem\",\n                    fontWeight: \"700\",\n                    marginBottom: \"1.5rem\",\n                }}\n            >\n                Privacy Policy — Shilpa Advisors\n            </h2>\n\n\n            <section style={{ marginBottom: \"2rem\" }}>\n                <h5 style={{ fontWeight: \"600\", fontSize: \"1.1rem\", marginBottom: \"0.8rem\" }}>\n                    1) Who we are & how to reach us\n                </h5>\n                <p>\n                    <strong>Controller (website/marketing/consulting/training/security):</strong> Shilpa Advisors<br />\n                    <strong>Processor (HRMS/SaaS):</strong> Shilpa Advisors acting under your instructions<br />\n                    <strong>Address:</strong> 215 – J5, Park Road, Colombo 00500, Sri Lanka<br />\n                    <strong>Contact:</strong> privacy@shilpaadvisors.com · +94 77 764 0985\n                </p>\n            </section>\n\n\n            <section style={{ marginBottom: \"2rem\" }}>\n                <h5 style={{ fontWeight: \"600\", fontSize: \"1.1rem\", marginBottom: \"0.8rem\" }}>\n                    2) Scope\n                </h5>\n                <p>This notice explains how we collect, use, disclose, retain, secure, and transfer personal data across:</p>\n                <ul style={{ paddingLeft: \"1.2rem\", marginTop: \"0.5rem\" }}>\n                    <li><strong>Website & marketing</strong> (inquiries, downloads, newsletters)</li>\n                    <li><strong>HRMS (SaaS)</strong> (attendance, leave, payroll, payslips, bank files)</li>\n                    <li><strong>International Standards/ISO Consulting</strong></li>\n                    <li><strong>Employee Training & OBT (Kitulgala)</strong></li>\n                    <li>Private Security Industry Support</li>\n                </ul>\n            </section>\n\n\n            <section style={{ marginBottom: \"2rem\" }}>\n                <h5 style={{ fontWeight: \"600\", fontSize: \"1.1rem\", marginBottom: \"0.8rem\" }}>\n                    3) PDPA alignment\n                </h5>\n                <p>\n                    We align with Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 (PDPA)\n                    principles and will meet enforceable obligations and DPA rules/directives as\n                    they come into force. We maintain governance for transparency, purpose\n                    limitation, data minimisation, security, retention, and rights handling.\n                </p>\n            </section>\n\n\n            <section style={{ marginBottom: \"2rem\" }}>\n                <h5 style={{ fontWeight: \"600\", fontSize: \"1.1rem\", marginBottom: \"0.8rem\" }}>\n                    4) Data we collect \n                </h5>\n\n                <p><strong>4.1 Website/marketing:</strong> Name, company, role, email, phone/WhatsApp, preferences, IP, device, pages viewed, referrers, cookies/analytics, downloads, event sign-ups, messages.</p>\n\n                <p><strong>4.2 HRMS (SaaS):</strong> Employee master data (IDs, name, designation, department), attendance logs (biometric/web/CSV), leave balances/requests, payroll elements (earnings/deductions), statutory details (EPF/ETF/APIT), payslip and bank-file outputs, audit logs. Biometric templates are stored only on devices you control unless explicitly integrated by agreement.</p>\n\n                <p><strong>4.3 International Standards/ISO:</strong> Contact details of project owners/participants, training records, audit notes, CAPA logs, SOP approvals, evidence samples (document codes, not business secrets where avoidable).</p>\n\n                <p><strong>4.4 Training & OBT:</strong> Participant lists, role/department, attendance, feedback; limited health/dietary notes only if voluntarily provided for safety/logistics; emergency contact.</p>\n\n                <p><strong>4.5 Private Security Support:</strong> Point-of-contact details, guard roster names/IDs (where needed), drill registers, incident logs/metadata (we avoid sensitive content unless you instruct).</p>\n            </section>\n\n\n            <section style={{ marginBottom: \"2rem\" }}>\n                <h5 style={{ fontWeight: \"600\", fontSize: \"1.1rem\", marginBottom: \"0.8rem\" }}>\n                    5) Sources of data\n                </h5>\n                <p>\n                    Directly from you; from your employer (controller) for HRMS/consulting; from\n                    devices/automation; automatic cookies/analytics; from training/OBT partners or\n                    venues (logistics only).\n                </p>\n            </section>\n\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>6) Why we process data </h5>\n            <ul style={{ marginTop: \"10px\", paddingLeft: \"20px\" }}>\n                <li><strong>Provide and improve services</strong> across all lines.</li>\n                <li><strong>Operate HRMS:</strong> authentication, configuration, calculations, outputs, audit trails.</li>\n                <li><strong>Client support & account management,</strong> billing, collections.</li>\n                <li><strong>Compliance:</strong> statutory, audit, safety/incident records where applicable.</li>\n                <li><strong>Security & fraud prevention.</strong></li>\n                <li><strong>Marketing with choice:</strong> newsletters, updates, invitations (opt-out anytime).</li>\n            </ul>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>7) Legal bases </h5>\n            <p style={{ marginTop: \"10px\" }}>\n                Depending on context, we rely on <strong>contract necessity, legal obligation, consent</strong> (e.g., marketing, OBT health notes),\n                <strong> public interest</strong>/emergency (safety), and <strong>legitimate interests</strong> (service improvement, network security,\n                quality assurance) balanced with your rights.\n            </p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>8) Cookies & analytics</h5>\n            <p style={{ marginTop: \"10px\" }}>\n                We use essential cookies (security, session) and analytics (aggregate usage). You can disable non-essential cookies in your browser;\n                some features may not work without them.\n            </p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>9) Sharing your data </h5>\n            <p>We share personal data only as needed to deliver services or comply with law:</p>\n            <ul style={{ paddingLeft: \"20px\" }}>\n                <li><strong>Processors/vendors:</strong> cloud hosting, email, analytics, ticketing, SMS/WhatsApp, training venues, OBT partners, device/biometric integrators (where agreed), bank/ERP file interfaces.</li>\n                <li><strong>ISO/Certification Bodies & auditors:</strong> only when you instruct us in consulting engagements.</li>\n                <li><strong>Legal/regulatory:</strong> upon lawful request or to protect rights, safety, or security.</li>\n            </ul>\n            <p>All processors are bound by confidentiality and data protection terms.</p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>10) International transfers</h5>\n            <p>\n                Where data is stored/processed outside Sri Lanka (e.g., reputable cloud providers), we apply\n                <strong> reasonable safeguards</strong> aligned with PDPA and any DPA rules/directives for cross-border transfers.\n                We assess vendor security and limit data to the minimum necessary.\n            </p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>11) Security measures</h5>\n            <p>\n                Role-based access, least-privilege, strong authentication options, encryption in transit/at rest (where applicable),\n                logging/audit trails, backups with retention, secure development practices, and incident response procedures.\n                Where a personal data breach is suspected, we assess and notify you/authorities as required by law.\n            </p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>12) Retention </h5>\n            <ul style={{ paddingLeft: \"20px\" }}>\n                <li><strong>Website/marketing leads:</strong> while active + 24 months of inactivity, then delete or anonymise.</li>\n                <li><strong>HRMS:</strong> you control retention; we provide export and deletion tooling. Backups follow rolling retention schedules.</li>\n                <li><strong>Consulting/ISO/Training/Security:</strong> records kept for contract duration + 24 months unless legal duties require longer or deletion requested.</li>\n                <li><strong>Financial records:</strong> per Sri Lankan law and accounting standards.</li>\n            </ul>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>13) Your rights </h5>\n            <p>\n                When enforceable, you may request <strong>access, rectification/completion, erasure, objection,</strong> and\n                <strong> restriction</strong> (subject to legal limits).\n                Exercise rights via{\" \"}\n                <a href=\"mailto:shilpa.advisors@sltnet.lk\" style={{ color: \"#000\", textDecoration: \"none\", fontWeight: \"600\" }}>\n                    shilpa.advisors@sltnet.lk                </a>.\n                For HRMS, requests should go to your employer as the <strong>Controller</strong>; we support them as <strong>Processor</strong>.\n            </p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>14) Children</h5>\n            <p>We serve organisations, not children. For OBT involving minors (e.g., educational clients), the organiser must secure appropriate consent.</p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>15) Marketing choices</h5>\n            <p>Unsubscribe anytime via email footer or by contacting us. For WhatsApp/SMS, reply <strong>STOP.</strong></p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>16) Training/OBT photos & testimonials</h5>\n            <p>We may request permission to capture photos/testimonials for internal or marketing use. We never publish identifiable content without explicit consent (withdrawable anytime).</p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>17) Links & third-party sites</h5>\n            <p>Our site may link to others. Their privacy practices are their own; please review their notices.</p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>18) Changes to this notice</h5>\n            <p>We may update this notice for legal or operational reasons. We will update the “Last updated” date and notify account holders where appropriate.</p>\n\n            <h5 style={{ fontWeight: \"600\", marginTop: \"25px\" }}>19) Contact & complaints</h5>\n            <p>\n                Questions/requests:{\" \"}\n                <a href=\"mailto:privacy@shilpaadvisors.com\" style={{ color: \"#000\", textDecoration: \"none\", fontWeight: \"600\" }}>\n                    privacy@shilpaadvisors.com\n                </a>\n            </p>\n            <p>\n                If unresolved, you may contact the <strong>Data Protection Authority of Sri Lanka</strong> once its enforcement operations and procedures are in effect.\n            </p>\n        </div>","createdAt":"2025-10-31T00:00:00.000Z","updatedAt":"2025-10-31T00:00:00.000Z"}