The short version
- Your customers' data belongs to you. We only use it to provide the services you've asked for.
- You decide how it's used, and you're responsible for having the right to collect it.
- We keep it secure and confidential, and only use trusted providers for things like backups and email.
- If there's a data breach, we tell you without delay, aiming for within 48 hours.
- When our services end, we return your data if you ask, then delete it.
This summary helps you read the page. The full text below is what applies.
When this applies
This agreement applies whenever we store or handle personal data on your behalf, for example contact form messages, bookings, orders, customer accounts or staff logins in a website or system we build, host or look after for you.
For that data, you are the controller: you decide why and how it's used. We are the processor: we handle it only to provide our services to you. These are the roles described in Sri Lanka's Personal Data Protection Act, No. 9 of 2022.
It forms part of our Terms & conditions. If it conflicts with them on how personal data is handled, this agreement wins.
The data we handle
- Whose data: your customers, website visitors, staff and anyone else whose information is in your website or system.
- What data: usually names, contact details, messages, bookings or orders, account details, and basic technical information. Your proposal may list more.
- Why: to build, host, back up, secure, fix and improve your website or system, as agreed with you.
- How long: for as long as we provide services to you, plus the time needed to return and delete it afterwards.
Please don't ask us to store especially sensitive data, such as health, financial account, religious or biometric information, unless we've agreed it in writing first.
Your responsibilities
As the controller, you are responsible for:
- having a lawful reason to collect and use the data;
- telling people how their data is used, including through a privacy policy on your website;
- only collecting the data you actually need;
- making sure the instructions you give us are lawful; and
- responding to requests from your customers about their data, and to the authorities.
Our responsibilities
As the processor, we will:
- only use the data to provide our services, following your documented instructions (our agreement with you, plus written instructions you give us), unless the law requires otherwise;
- tell you if we believe an instruction breaks the law;
- make sure everyone who can access the data is bound to keep it confidential; and
- never sell the data or use it for our own purposes.
Security
We use reasonable security measures suitable for the kind of data involved, including:
- encrypted connections for the websites and systems we look after;
- giving access only to people who need it for the work;
- strong passwords, and two-step sign-in where the service supports it;
- applying security updates; and
- regular backups.
Security also depends on you, for example keeping your own logins safe and removing access for staff who leave.
Other companies we use
To provide our services we use other companies, such as backup, monitoring, email and payment providers. Your hosting provider is chosen and paid for by you, so it works for you directly. These are sub-processors. By accepting our terms, you allow us to use them.
- We choose established providers that protect personal data properly.
- We bind them to data protection obligations suitable for the data.
- We'll give you a list of the sub-processors we use for you on request.
- We'll tell you at least 14 days before adding or replacing one. If you have a reasonable data protection concern, tell us within that time and we'll try to find a solution. If we can't, you may end the affected service by giving notice.
Data outside Sri Lanka
Some of our providers store or handle data outside Sri Lanka. You agree that this may happen. We'll take the steps the law requires to keep the data protected when it's transferred.
Helping with requests
If one of your customers asks to see, correct or delete their data, we'll help you respond, for example by finding or deleting records in your system. If a request comes to us directly, we'll pass it to you rather than answer it ourselves.
Small requests are included in your monthly plan. Larger work, such as exports or searches across a lot of data, or helping with an investigation by the authorities, is priced with you first.
If something goes wrong
If we become aware of a breach affecting your data, we'll tell you without undue delay, aiming for within 48 hours. We'll share what we know, what we're doing about it, and keep you updated.
That gives you time to meet your own duty to notify the authorities, which can be as short as 72 hours. As the controller, you decide whether to notify the authorities and the people affected, and we'll give you reasonable help to do so.
Checks and audits
We'll give you the information you reasonably need to show that we're meeting this agreement.
If you need an audit beyond that, you may carry out one per year, with at least 30 days' written notice, during our support hours, at your cost, and under a confidentiality agreement. An audit can't give access to other customers' data or put our security at risk.
When our services end
If you ask within 30 days of our services ending, and everything owed has been paid, we'll return your data to you in a common format.
We then delete it within 60 days of the services ending. Copies in backups are deleted as those backups expire. We only keep data where the law requires us to.
Responsibility and limits
Each of us is responsible for meeting our own duties under data protection law. The limits on our responsibility in our Terms & conditions also apply to this agreement, as far as the law allows.
Questions about this agreement? Email hello@coredile.com.
Who "we" are
"Coredile", "we", "us" and "our" mean the company below. "You" means the person or business using our website or our services.
- Trading name
- Coredile
- Registered name
- Coredile (Pvt) Ltd
- Registered address
- Kelaniya, Sri Lanka
- hello@coredile.com