Cookie Policy
This policy explains what this site stores on your device, what it does not, and what you can decide. It sits alongside our Privacy & Data Protection Notice, which governs personal data more broadly.
1. The current position, stated plainly
At the date above this site sets no analytics cookies and no advertising cookies. It loads no tracking script, no page-view counter, no heatmap and no session recording. The only storage in use is strictly necessary, described in section 3.
We publish a consent banner because we intend to introduce aggregate analytics, and because consent must be gathered before anything in a non-necessary category runs rather than after. Until you allow analytics, nothing in that category is loaded and no identifier is created for you. Declining leaves the site fully functional.
2. What a cookie is here
We use “cookie” in the broad sense both regulators intend: a cookie proper, and any equivalent technology that stores or reads data on your device, including localStorage, session storage and similar. Where this policy says cookie, it covers all of them, because the legal treatment follows what the storage does rather than what it is called.
3. Strictly necessary storage
This category cannot be switched off, because without it the site or a service you have asked for does not work. It is not used to profile you, and none of it is shared.
- Your cookie choice. Key
ssa_cookie_consent, held inlocalStorageon your device. Records what you decided and when, so you are not asked repeatedly. Kept until you withdraw it or clear your browser storage. - Security agent application drafts. On the application form only, keys
ssa_draft_id,ssa_draft_stateandssa_intro_locale. These save a part-finished application and your language choice so you can return to it. This is storage strictly necessary to deliver a service you requested. See the Recruitment Privacy Notice shown on that form. - Hosting and security. Our hosting provider may set short-lived storage necessary to serve pages and to protect the site from abuse. It is not used for advertising or analytics.
4. Analytics, once enabled
If you allow analytics, we will use it only to understand in aggregate which pages are read and how the site performs. We will not use it to build a profile of you, to make an automated decision about you, or for advertising. When a provider is selected, this section will name it, name the country its processing occurs in, and state the retention period, before that provider is loaded for anyone.
We do not sell, rent or trade personal data, in any category, under any circumstances.
5. Your choices and how to change them
The banner offers accept all, reject all, or a per-category choice, and each is equally available. Rejecting is a single click, exactly like accepting.
You can change or withdraw consent at any time using the Cookie choices control in the site footer, which returns the banner. Withdrawal is as easy as granting, and takes effect immediately. You may also block or delete storage in your browser settings; the site will continue to work, though a part-finished application will not survive.
6. Sri Lanka
Seraph Security Agency (Pvt) Ltd is incorporated in Sri Lanka, so the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, applies to our processing under section 2(1)(b)(ii). Where a cookie processes personal data, we rely on your consent under Schedule I(a) for non-necessary categories, and on our legitimate interests under Schedule I(f), read with Schedule I(h)(iv) on network and information security, for strictly necessary storage.
Consent under the Act must be freely given, specific and informed, and it may be withdrawn under section 14. That is what the footer control is for. References to the Authority mean the Data Protection Authority of Sri Lanka, established under Part V, to whom you may complain.
7. United Arab Emirates
Where we process the personal data of individuals in the UAE, Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing decisions apply. Consent under that law must be specific, clear, unambiguous and freely given, must be capable of being proven, and may be withdrawn at any time. Non-necessary cookies are therefore off until you switch them on, and the record of what you chose is kept so the choice is demonstrable.
If you deal with us through the Dubai International Financial Centre or Abu Dhabi Global Market, the DIFC Data Protection Law No. 5 of 2020 or the ADGM Data Protection Regulations 2021 may apply instead of, or in addition to, the federal law. Where they give you stronger rights, we will honour those rights rather than rely on this policy to deny them. The same applies to any other jurisdiction whose law reaches you.
8. Transfers outside your country
Under the Sri Lankan Act a third country means any territory other than Sri Lanka, which includes the UAE. Our hosting operates internationally, so data described here may be processed outside Sri Lanka. Section 26 of the Act, as replaced by the 2025 amendment, permits such transfers where we continue to meet our obligations and adopt instruments giving binding, enforceable commitments from the recipient. If an analytics provider is introduced, its transfer position will be stated in section 4 before it is enabled.
9. Changes
If the categories change, or a processor is added, we will update the effective date above and ask you to choose again. Consent gathered against an older description is not consent for a new one, so a material change resets it rather than carrying it forward.
10. Contact
Seraph Security Agency (Pvt) Ltd
96/5 Rosemead Place, Colombo 07, Sri Lanka
info@ssaone.com · +94 70 396 6499