Hayleys Leisure PLC is committed to protecting the personal information of all guests, website visitors, and partners. This Privacy Policy outlines how we collect, use, store, share, and protect your personal data across all interactions — whether through our website, in person at our resorts, via phone or email communication, or through third-party channels.
We recognize the importance of maintaining your privacy and upholding the trust you place in us when you choose our hospitality services. In accordance with global best practices and local laws (including Sri Lanka’s Personal Data Protection Act No. 9 of 2022), this Policy is designed to ensure transparency, accountability, and compliance in all our data handling practices.
This Privacy Policy applies to all properties and brands under the Hayleys Leisure PLC. It covers information collected both online and offline, including through our websites, reservations, marketing activities, guest services, and partner platforms.
This Privacy Policy covers all personal data that Hayleys Leisure PLC collects and processes about its guests, customers, website users, partners, vendors, and other stakeholders. This includes:
We collect personal data in a number of ways depending on how you interact with us. These include:
A. Directly from You
B. Automatically
C. From Third Parties
We only process your personal data when we have a lawful basis to do so under applicable data protection regulations. The legal bases may include:
We take care to only share your personal data when it is necessary, and always under secure, legally binding conditions. We may share your information with:
All third parties are required to handle your data in accordance with applicable privacy laws and confidentiality agreements.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention periods may vary depending on:
After the applicable retention period expires, we securely delete, anonymize, or destroy the data.
Our websites use cookies and similar tracking technologies to enhance your browsing experience, enable core functionality, and improve our marketing efforts. These technologies may:
You can manage your cookie preferences through your browser settings. However, disabling some cookies may affect the website’s functionality. For more information, refer to our Cookie Policy (if published separately).
Depending on your jurisdiction, you may have the following rights:
You may exercise these rights by contacting our Data Protection Officer. We will respond within the timeframes required by applicable law.
We do not knowingly collect personal information from children under the age of 16 without verified parental consent. If we discover that such data has been collected unintentionally, we will promptly delete it unless required for legal or safety reasons.
Parents or guardians who believe that their child may have submitted personal information can contact us to review or delete such data.
We implement technical and organizational safeguards to protect your data from unauthorized access, loss, misuse, or alteration. These include:
While no system can be guaranteed 100% secure, we follow industry best practices to minimize risk and respond swiftly in the event of a suspected breach.
We may transfer your personal data to countries outside your residence for operational reasons. These transfers will only occur:
All international transfers are made in accordance with data protection legislation to ensure your data remains protected.
We may update this Privacy Policy periodically to reflect legal changes, service updates, or privacy best practices. The revised policy will be posted on our website with a new effective date.
In the event of material changes, we will notify you via prominent notices or email (where appropriate). Your continued use of our services after an update indicates your acceptance of the revised policy.
For privacy-related queries, data access requests, or to exercise your rights, please contact:
Hayleys Leisure PLC
Corporate Head Office, Level 27
East Tower, World Trade Center
Colombo 01, Sri Lanka
This Privacy Policy is governed by the laws of Sri Lanka. In case of conflict between translated versions, the English version shall prevail.
Third-party websites accessed via our services operate under their own policies. We encourage you to review them before submitting data.
By using our services, you agree to the terms outlined in this Privacy Policy.