×

Protecting your privacy

This Privacy Policy (“Privacy Policy”) explains how MAS Holdings (Private) Limited and our Affiliates ("we," "us," "our," “MAS” collect, use, share, and protect information in connection with MAS services that refer or link to this Privacy Policy ("our Services"). The Affiliates (defined below) to whom this Privacy Policy applies includes without limitation, all MAS Group companies. This Privacy Policy applies regardless of the type of device you use to access our Services.

For purposes of this Privacy Policy, Affiliates shall mean any one or more business entities which, directly or indirectly, are controlling, controlled by, or under common control of MAS. Control shall mean the ownership of 33% or more of the share capital of a company or having management control of a company.

MAS reserves the right to change this Privacy Policy at any time by posting the updated policy here along with the date on which the Privacy Policy was changed. If we make material changes to this Privacy Policy that affect the way we collect, use and/or share your personal information, if you have signed-up with us or subscribed to our newsletters (if applicable) we will notify you by including a "NEWLY UPDATED" label with the "PRIVACY POLICY" link on our Services for 30 days after material changes are made. Else, upon such material revisions are made, this Privacy Policy will for a period of 30 days indicate that it is “NEWLY UPDATED”.

Information we collect and how we collect it

We collect and maintain personal information about you from many sources to understand and meet your needs, facilitate your request and provide our Services, manage our business, and for other purposes disclosed to you. For example, we collect personal information about you from: You, when you voluntarily provide us with such personal information. Your transactions with MAS and our Affiliates Recruitment agencies when looking for potential employees.

If the information is to be collected directly from you, you may in some cases have the option to decline providing that information. However, your choice to not provide information may impact your use of certain features or Services.

The personal information/personal data we collect about you through these various sources may include, but is not limited to:

- Name, addresses and telephone numbers

- Email addresses

- Bank account number and associated billing address

- Information required to facilitate travel or other services such as passport number for your visit to MAS premises.

- Corporate-contract, employer and/or other corporate affiliation (e.g., employer name, title, work address and contact information).

- Personal details (contact, birthdates, gender etc.), education and work experience (for potential employment candidates).

To the extent that the personal information we collect constitutes sensitive personal information under applicable law, MAS will collect and process this sensitive personal information within the limits provided by applicable law, and only after establishing reasonable security safeguards for such sensitive personal information. Where required by law, MAS will seek your consent before processing sensitive personal information.

Minors

Our website is not designed or directed at children. We will not intentionally collect, maintain, or distribute information about anyone under the age of 13. If you are a parent or guardian of a child who has provided personal information without your knowledge and consent, you may request us to remove the minor’s information by emailing us at PrivacyOffice@www.masholdings.com.

Automatically collected information (including cookies and geolocation)

When you use our Services, we may receive technical information such as your browser type, the type of operating system you use, your geolocation, the name of your internet service provider, mobile advertising identifiers, and pages visited on our Services. MAS gets this information by using technologies, including cookies, web beacons, and mobile device geolocation to provide and improve our Services, including across browsers and devices). We also use this information to verify that visitors meet the criteria required to process their requests and for reporting activity on our Services.

Cookies on our services

When you use our Services, you may receive cookies from us and the third parties that collect information on our Services. We use cookies to determine that we give you a high-quality experience on our Services. If you continue to browse our website without changing your web browser's or device's settings that control cookies, you agree to receive cookies when you use our Services. However, if you prefer, you can change your cookie settings. Some browsers have options that allow the visitor to control whether the browser will accept cookies, reject cookies, or notify the visitor each time a cookie is sent. You may elect to reject cookies by adjusting your settings, but doing so will limit the range of features available to you on our Services and other major websites that use cookies. Find out more about our cookie policy https://www.masholdings.com/cookie-policy/

Information collected by third parties on our Services

Some of our Services include social network or other third-party plug-ins (such as link to our Facebook page), the providers of these plug-ins may be able to collect information about you even if you do not click on or otherwise interact with the plug-in or widget and regardless of whether you have an account or other relationship with these social networks and third parties. If you use social network tools or visit social networking sites, you should read their privacy disclosures to learn what information they collect, use, and share.

How your information will be used

Our Services

We use personal information to provide you on our products and Services. For example, we require you to provide personal information when making an inquiry to us via the Contact Us form. MAS may use your personal information for several purposes including, without limitation: - Business purposes and communication: To provide Services or information you requested, to communicate with you for business or customer service reasons, or for other such reasons such as changes to our policies or in response to your inquiry. - Financial transaction management: To facilitate payment for services or provide refunds - Legal and Regulatory Obligations: To comply with legal, regulatory, or fiscal obligations, or in connection with litigation or an internal investigation or audit. - Analytics: To perform data analyses and other processing to improve our website. - Site maintenance: To improve content, functionality, and usability of our sites - Security management: To secure MAS premises, assets, and information - Third party requests: To respond to and comply with outside requests initiated by you, as well as in response to legal requests. - Audit and controls: To evaluate internal controls and audits for compliance (including those conducted by MAS internal and external audit service providers) There are Closed Circuit Television (CCTV) cameras in operation within and around our stations and other premises, which are used for the following purposes: - to prevent and detect crime; - to protect the health and safety of MAS visitors and employees; - to manage and protect MAS property and the property of MAS guests and other visitors; and - for quality assurance purposes.

Security

MAS uses reasonable technical, administrative, and physical measures to protect your personal information. When your personal information is shared, MAS will take a reasonable approach to prevent the unauthorized use of personal information. Please note, however, that while MAS attempts to safeguard your personal information, no method of transmitting or storing electronic information is ever completely secure, and thus we make no warranty, express, implied, or otherwise, that your information will never be accessed, used or released in a manner that is inconsistent with this Privacy Policy. In no event shall we be liable for any damages (whether consequential, direct, incidental, indirect, punitive, special or otherwise) arising out of, or in any way connected with, a third party's unauthorized access to your information, regardless of whether such damages are based on contract, strict liability, tort or other theories of liability, and also regardless of whether we are given actual or constructive notice that damages were possible, except as provided under applicable laws.

Storage and retention

We may keep information and content in our systems, backup files and archives. Your personal data will be retained as long as necessary to provide you with the Services requested. When we no longer need to use your personal data to comply with business requirements, contractual or statutory obligations, we will remove it from our systems and records and/or take steps to properly anonymize it so that you can no longer be identified from it, unless we need to keep your personal data, including if we need to keep your personal data to comply with legal or regulatory obligations to which we are subject, e.g. statutory retention periods and usually contain retention periods, or if we need it to preserve evidence within the statutes of limitation.

With whom your information will be shared

General

MAS does not share personal information with third parties except as stated in this Privacy Policy. We may disclose information to companies affiliated with MAS and/or unaffiliated third parties (i) to provide the products and Services you have requested; and (ii) for administrative, analytical, and logistical purposes. For example, we may provide information we collect about you to third parties to distribute products. In addition, we may share information with MAS and its subsidiaries for the purposes such as vendor and customer registrations, visitor management, developing and designing products, manufacturing and shipping of products to customers. We also share information with certain third-party companies with which we have a business relationship such as logistic partners, system developers, auditors, business consultants, travel and hotel agents (only upon visitors’ request), legal and regulatory institutes. In the event we undergo a business transition involving another company, such as a merger, corporate reorganization, acquisition, the lease or sale of all or a portion of our assets, or in the event of bankruptcy, information that we have collected from or about you or your devices may be disclosed to such other entity as part of the due diligence or business integration process and will be transferred to such entity as one of the transferred assets.

Legal requirements

Please note that the laws and regulations of several countries, including without limitation, the requirements imposed under the applicable regulation, require us to provide foreign and domestic government agencies with access to the personal information you disclose to us and data that we have about you and transaction history. MAS does not have control or knowledge of the storage and use of that data after it has been delivered to the respective government entity. Further, to the extent required by law, we may disclose personal information to government authorities, or to third parties pursuant to a subpoena or other legal process, and we may also use or disclose your information as permitted by law to protect the rights or property of MAS, our customers, our services, or its users.

Your rights

If you have declared your consent for any personal data processing activities, you can withdraw this consent at any time with future effect. Such withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal.

Pursuant to applicable data protection law you may have the right to: request access to your personal data, request rectification of your personal data; request erasure of your personal data, request restriction of processing of your personal data; request data portability, and object to the processing of your personal data. Please note that these rights might be limited under the applicable national data protection law. For further information on these rights, please refer to Section “Your rights in detail”.

You also have the right to lodge a complaint with a data protection supervisory authority. To exercise your rights please contact us as stated in Section “Contact us”.

Your rights in detail

Right of access You may have the right to obtain from us confirmation as to whether personal data concerning you is processed, and, where that is the case, to request access to the personal data. The access information includes – inter alia – the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed. However, this is not an absolute right and the interests of other individuals may restrict your right of access. You may have the right to obtain a copy of the personal data undergoing processing. For further copies requested by you, we may charge a reasonable fee based on administrative costs. Right to be informed You may have the right to know the purposes for processing your personal data, our retention periods for that personal data, and with whom it will be shared. This Privacy Policy provides you with this information. You may reach out to us to obtain any further information needed to enable to exercise your rights. Right to rectification You may have the right to obtain from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you may have the right to have incomplete personal data completed, including by means of providing a supplementary statement. Right to erasure (“right to be forgotten”) Under certain circumstances, you may have the right to obtain from us the erasure of personal data concerning you and we may be obliged to erase such personal data. Right to restriction of processing Under certain circumstances, you may have the right to obtain from us restriction of processing your personal data. In this case, the respective data will be marked and may only be processed by us for certain purposes. Right to data portability Under certain circumstances, you may have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you may have the right to transmit those data to another entity without hindrance from us. Right to object If the processing of your personal data is based on legitimate interests, you may have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us and we can be required to no longer process your personal data. Moreover, if your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. In this case, your personal data will no longer be processed for such purposes by us.

Privacy Policy for California residents

Your California Privacy Rights

In addition to the privacy policy displayed for customers from all geographies, if you are a California resident you have certain rights that is detailed in this policy. If you have any concerns about how we process your data or would like to exercise any of your California privacy rights, including those described below, you can make a request by writing to PrivacyOffice@masholdings.com MAS Holdings (Private) Limited -c/o – Data Protection Officer Privacy Office No.199, Kaduwela Road, Battaramulla Sri Lanka. Please identify yourself as a California resident and provide sufficient information such as your name, email address or any additional information required, so we can take appropriate action.

"Shine the Light" Law

California residents may request certain information regarding our disclosure (if any) of personal information to third parties for their direct marketing purposes (where applicable), pursuant to California Civil Code Section 1798.83 (the California “Shine the Light” law). To make such a request, please contact us, identify yourself as a California resident and provide sufficient information, such as your name, email address or any additional information required so we can take appropriate action.

California Consumer Privacy Act (CCPA)

California Civil Code Section 1798.100

We may collect and maintain personal information about you to understand and meet your needs, facilitate your request, provide our services, manage our business, and for other purposes disclosed to you. If the information is to be collected directly from you, you may in some cases have the option to decline providing that information. However, your choice to not provide information may impact your use of certain features or services. The personal information/personal data we collect about you through these various sources may include, but is not limited to: 1. Name, addresses and telephone numbers 2. Email addresses 3. Bank account number and associated billing address 4. Information required to facilitate travel or other services such as passport number for your visit to MAS premises. 5. Corporate-contract, employer and/or other corporate affiliation (e.g., employer name, title, work address and contact information). 6. Personal details (contact, birthdates, gender etc.), education and work experience (for potential employment candidates). To the extent that the personal information we collect constitutes sensitive personal information under applicable law, MAS will collect and process such sensitive personal information within the limits provided by applicable law, after establishing reasonable security safeguards for such sensitive personal information. Where required by law, MAS will seek your consent before processing sensitive personal information. This means that, in addition to other exceptions under the CCPA that may apply (including for employees, contractors and business contacts), our processing of data as a service provider may not involve a sale of personal information of a consumer.

Minors

Our website is not designed or directed at children. We will not intentionally collect, maintain, or distribute information about anyone under the age of 16. If you are a parent or guardian of a child who has provided personal information without your knowledge and consent, you may request us to remove the minor’s information by emailing us at PrivacyOffice@masholdings.com

Your Rights

Right To Access

Certain California consumers may have the right to disclosure of information about our collection, sale or disclosure for a business purpose of their personal information, including, to the extent applicable, the following: 1. The categories of personal information we have collected about such consumer. 2. The categories of sources from which such personal information has been collected. 3. The categories of third parties with whom we have shared such personal information. 4. The business or commercial purpose for collecting or selling such personal information. 5. The categories of such consumer’s personal information we have sold or disclosed for a business purpose, by category for each category of third parties to whom the personal information was sold or disclosed, or we will state that we have not sold or disclosed for a business purpose such consumer’s personal information. 6. The specific pieces of personal information we have collected about such consumer. However, this is not an absolute right and the interests of other individuals may restrict your right of access. We will provide appropriate disclosures upon receipt of a verifiable request, to the extent required by law (or in our discretion if not required by law) and as permitted by our contracts, confidentiality obligations and applicable laws and regulations.

Right To Object

If processing your personal data is based on legitimate interests, you may have the right to object on grounds relating to your particular situation, and we can be required to no longer process your personal data. Moreover, if your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. In this case, your personal data will no longer be processed for such purposes by us. If you do not wish for your personal information to not be sold for marketing or other purposes, you can opt out by writing to PrivacyOffice@masholdings.com

Right to Deletion (CCPA)

Certain California consumers have the right to request deletion of their personal information by contacting us and providing the required verification information and other details we need in order to handle the request appropriately.

Non-Discrimination (CCPA)

California consumers have the right not to receive discriminatory treatment for exercising any of the privacy rights conferred by the CCPA, except as permitted under the CCPA. If you believe you have received discriminatory treatment for exercising your CCPA privacy rights, please contact us.

Do-Not Track

If you wish to opt-out of any cookies, you may do so by clicking on the relevant option on the Cookie consent banner that will be presented to you the first time you visit our website. You may change your preferences for websites by changing your browser settings - for details, see aboutcookies.org . If you reject the use of cookies, you will still be able to visit our website but some of the functions may not work correctly.

Contact us

If you have other questions, comments or concerns about our privacy practices, or if you wish to issue a request to exercise your rights where applicable by law, please contact our Privacy Office at PrivacyOffice@www.masholdings.com Please provide your name and contact information along with the request. Alternatively, inquiries may be mailed to the following address:

Mailing address: PrivacyOffice@masholdings.com

MAS Holdings (Private) Limited

-c/o – Data Protection Officer

Privacy Office

No.199, Kaduwela Road,

Battaramulla

Sri Lanka

Effective date - Policy was last updated and effective on MARCH 15, 2021.