Asian Island respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard personal information when you visit our website, submit enquiries, request quotations, book travel services, or interact with our advertising campaigns.

Where applicable, this Policy is intended to comply with the General Data Protection Regulation (GDPR) and other relevant data protection laws.

Data Controller

Asian Island is the Data Controller for the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR), where it applies. This means we determine the purposes and means of processing personal data collected through our website, advertising campaigns, booking processes, and related communications.

If you have any questions regarding this Privacy Policy or the way we process personal data, you may contact us using the details provided above.

Scope of This Policy

We respect your privacy and are committed to protecting personal information shared with us. This Privacy Policy explains how we collect, use, disclose, transfer, retain, and safeguard personal data when you:

  • Visit our website,
  • Submit an enquiry or request a quotation,
  • Book or participate in a tour,
  • Interact with our advertising campaigns, including Meta (Facebook and Instagram) Lead Ads,
  • Communicate with us by email, telephone, WhatsApp, or similar platforms.

This Policy is intended to comply with Articles 13 and 14 of the GDPR where applicable.

Personal Information We Collect

A. Information You Provide Directly

We may collect personal data that you provide voluntarily, including:

  • Identity and contact details such as your name, email address, telephone number, and country of residence or nationality.
  • Travel enquiry details, including preferred travel dates, destinations, group size, budget range, accommodation preferences, interests, and special requests.
  • Booking and service information, including itinerary selections, confirmations, travel documentation necessary for service delivery, and communications with us.
  • Payment-related information such as billing details, transaction references, and payment confirmations. We generally do not request full card details via email or messaging platforms.
  • Communications you send to us through contact forms, email, WhatsApp, or other channels.

B. Information Collected Automatically

When you use our website, we may collect certain technical and usage information automatically, including:

  • Your IP address,
  • Device type,
  • Browser type,
  • Approximate geographic location,
  • Pages visited,
  • Referral source,
  • Timestamps,
  • Cookie identifiers.

Where consent is required, we also collect analytics and advertising-related data to measure performance and improve marketing effectiveness.

C. Information Collected from Third Parties (Article 14 Disclosure)

In some circumstances, we may obtain personal data about you from third parties rather than directly from you. These sources may include:

  • Meta Platforms Ireland Ltd., when you submit a Facebook or Instagram lead form connected to our advertising campaigns.
  • Travel or referral partners who pass on enquiry information with your knowledge.
  • Service providers involved in booking fulfilment.
  • Publicly available sources, such as publicly listed business contact details.

The categories of data obtained in this manner may include:

  • Your name,
  • Email address,
  • Telephone number,
  • Travel preferences,
  • Advertising interaction data,
  • Any publicly available contact details.

We do not intentionally collect special categories of personal data through these channels.

Where we receive personal data indirectly, we will provide this Privacy Policy within one month of obtaining the data, at the time of first communication with you, or before disclosing the data to another recipient, whichever occurs first.

How We Use Your Information and Legal Basis for Processing

We process personal data only where we have a lawful basis to do so. Some of the ways in which we may use your personal data when necessary include:

  • To respond to enquiries and provide quotations, we rely on the performance of a contract or pre-contractual steps at your request.
  • To arrange and deliver tours, transfers, guides, accommodation, and related travel services, we process personal data for the performance of a contract and, where required, to comply with legal obligations.
  • To communicate booking confirmations, schedule changes, and essential travel notices, we rely on contractual necessity and legitimate interests.
  • To process payments and prevent fraud, we rely on contractual necessity and legal obligations.
  • To improve our website, services, and customer experience, including analytics and quality control, we rely on legitimate interests, provided those interests are not overridden by your rights.
  • For marketing communications and advertising activities, including Meta Lead Ads and Meta Pixel where implemented, we rely on consent where required by law and, where appropriate, legitimate interests.
  • To comply with legal, accounting, or regulatory requirements, we rely on legal obligations.

Where processing is based on consent, you may withdraw consent at any time.

Automated Decision-Making and Profiling (Article 22)

We do not make decisions based solely on automated processing that produces legal or similarly significant effects concerning individuals.

However, our advertising partners and we may use automated tools, including Meta Pixel, to analyse interactions with our website and create audience segments for advertising optimisation. This may constitute profiling for marketing purposes. Such processing is used for aggregated reporting and campaign improvement and does not result in legally binding decisions.

Where required, this processing is based on consent. You may object to profiling or withdraw consent at any time.

Cookies, Meta Pixel, and Consent Governance

We use cookies and similar technologies to enable core website functions, measure website performance, and support advertising optimisation.

We categorise cookies as strictly necessary, preferences, analytics, and marketing. Non-essential cookies, including analytics and marketing cookies, are deployed only after you provide consent where required by applicable law.

You may manage or withdraw consent at any time through our cookie settings panel available on the website. You may also adjust your browser settings to refuse cookies. Withdrawing consent does not affect prior lawful processing.

If Meta Pixel is enabled, it is implemented in a manner consistent with applicable data protection requirements. We do not intentionally transmit sensitive personal data through Pixel. Pixel data is primarily used for aggregated analytics and campaign measurement.

Monitoring and Recording of Communications

To maintain service quality, resolve disputes, and train staff, we may monitor or record communications, including telephone calls and online conversations, where permitted by law. Such processing is based on legitimate interests and, where required, legal obligations.

When We Share Information

We disclose personal data only where necessary. This may include sharing information with:

  • Hotels,
  • Transport providers,
  • Guides,
  • Activity operators,
  • Security,
  • Customs,
  • Immigration,
  • Legal compliance,
  • Other lawful purposes and service providers necessary to fulfil your travel arrangements.

We may share data with vendors supporting our operations, including:

  • Hosting providers,
  • CRM systems,
  • Analytics services,
  • Advertising platforms,
  • Payment processors.

We do not sell personal data.

Processor Safeguards and Data Processing Agreements

We engage service providers who process personal data on our behalf. We implement written Data Processing Agreements with such processors, requiring them to:

  • Apply appropriate technical and organisational safeguards,
  • Maintain confidentiality,
  • Notify us of data breaches,
  • Process data only in accordance with our documented instructions.

Where platforms such as Meta act as independent or joint controllers, we rely on their published contractual terms and applicable data transfer safeguards.

International Data Transfers (Chapter V)

As we are based in Sri Lanka, personal data may be transferred outside the EU/EEA.

Where GDPR applies, we implement appropriate safeguards for cross-border transfers. These may include:

  • Reliance on Standard Contractual Clauses approved by the European Commission,
  • Adequacy decisions where applicable,
  • Supplementary technical and organisational measures,
  • Data Processing Agreements with processors.

You may request additional information about transfer safeguards by contacting us.

Data Retention

We retain personal data only for as long as necessary.

  • Enquiry records are generally retained for up to 24 months from the last contact.
  • Booking and accounting records are retained for approximately 7 years to comply with legal and tax obligations.
  • Marketing consent records are retained until consent is withdrawn and for a limited administrative period thereafter.
  • Analytics data is retained for up to 24 months unless aggregated earlier.

Retention periods may be extended where required by law or for dispute resolution.

Children’s Privacy

Our services are not directed to children under 16. We do not knowingly collect personal data from children under this age. If we become aware that such data has been collected, we will take appropriate steps to delete it.

Your Rights

Subject to applicable law, you may have the right to:

  • Request access to your personal data.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Request restriction of processing.
  • Object to processing based on legitimate interests, including direct marketing and profiling.
  • Request data portability where processing is based on contract or consent.
  • Withdraw consent at any time.

You also have the right to lodge a complaint with a competent Supervisory Authority in the EU/EEA Member State where you reside, work, or where an alleged infringement occurred.

To exercise your rights, please email contact@asianisland.lk. We will respond within one month unless an extension is legally permitted.

EU Representative (Article 27 Assessment)

If our activities require the appointment of an EU Representative under Article 27 of the GDPR, we will designate such a representative and make their contact details available. If you are located in the EU/EEA and require representative details, please contact us.

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in legal requirements, technology, or business practices. Updates will be posted on this page with a revised effective date.

Contact

Asian Island

29/1, 02, Kolonnawa Road, Colombo, 11100, Sri Lanka

contact@asianisland.lk

+94 777 485 582

Discover the
Genius of Geoffrey Bawa

Join our exclusive one-day architectural tour and experience the visionary works of Sri Lanka's most famous architect.