SERAPH
ServicesLeadership
Contact
01Home02Services03Leadership04Contact
Vetted talent. Compliant operations. One system.
Legal

Privacy & Data Protection Notice

Effective 18 August 2026 · Seraph Security Agency (Pvt) Ltd

Discretion is the service we sell, so it would be incoherent to treat your data casually. This notice sets out plainly what this website collects, what it deliberately does not, and what you can require of us.

1. Who is responsible for your data

Seraph Security Agency (Pvt) Ltd (“Seraph”, “we”) is the controller of personal data described in this notice. We are a private company incorporated in Sri Lanka, registration number PV 00338336, with its registered office at 96/5 Rosemead Place, Colombo 07, Sri Lanka.

Data protection enquiries: info@ssaone.com, or +94 70 396 6499.

2. What this notice covers

This notice covers this website and enquiries made through it. It does not cover the personal data we process in the course of delivering protective services under a signed engagement. That is governed by the data protection terms of the engagement itself, which are provided separately and are considerably more detailed, because that processing is considerably more sensitive.

It also does not cover applications to join our agent network. That processing is far more extensive, and is governed by the Recruitment Privacy Notice presented on the application form itself, which must be read before an application can be submitted. Storage used by that form is listed in our Cookie Policy.

3. The law we apply

We are incorporated in Sri Lanka, so the Personal Data Protection Act, No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, applies to our processing under section 2(1)(b)(ii) of that Act. References to “the Authority” below mean the Data Protection Authority of Sri Lanka, established under Part V.

Where we process the personal data of individuals in the United Arab Emirates, we also observe the applicable UAE data protection law. If the law of another country applies to you and gives you stronger rights than those set out here, we will honour those rights rather than rely on this notice to deny them.

4. What the website collects

Very little, and none of it silently. In ordinary browsing, this site collects no personal data from you at all.

  • Enquiries you send us. The contact links open your own email client. If you write to us, we receive whatever you choose to put in that message: typically your name, your email address, and the context of your enquiry. You decide what to disclose; nothing is required.
  • Server logs. Our hosting provider records standard technical request data, including IP address, timestamp, requested page and browser user agent. This is generated automatically by the act of serving a web page and is used for security and diagnosing faults. An IP address can constitute personal data, which is why it is disclosed here rather than passed over.

5. What this website does not do

This section exists because most privacy notices are written to excuse tracking. Ours has nothing to excuse, and the claims below are verifiable. Open your browser’s developer tools and check.

  • No cookie is set without your consent. Strictly necessary storage keeps the site working and remembers what you chose. Everything else stays off until you switch it on, and can be withdrawn at any time from the footer. Our Cookie Policy lists every key by name.
  • No analytics today. No Google Analytics, no page-view counter, no heatmaps, no session recording. We intend to introduce aggregate analytics, which is why you are offered a choice before anything loads rather than after.
  • No advertising or tracking pixels, and no social media trackers.
  • No third-party requests. Fonts and every other asset are served from our own domain. Loading this page does not tell any other company that you visited it.
  • No profiling and no automated decision-making.
  • We do not sell, rent or trade personal data. Not to anyone, under any circumstances.

6. Why we process it, and on what basis

Each purpose below is matched to its lawful ground in Schedule I of the Personal Data Protection Act.

  • To respond to your enquiry. Schedule I(b): processing necessary to take steps at your request before entering into a contract.
  • To keep the site available and secure. Schedule I(f): our legitimate interests. Schedule I(h)(iv) expressly recognises processing strictly necessary and proportionate for network and information security.
  • To meet legal obligations. Schedule I(c): processing necessary to comply with an obligation imposed on us by written law.

We do not rely on consent for any of the above, which is why you are not asked for it. Where we ever do, you will be told, and you may withdraw it.

7. Who else sees it

Access inside Seraph is limited to the people who need it to answer you. Outside Seraph, personal data reaches only:

  • Our hosting provider, which serves this site and generates the logs described above.
  • Our email provider, which carries correspondence between us.
  • Professional advisers, regulators or law enforcement, where we are legally required to disclose. We will not volunteer client information absent that obligation.

These providers act on our instructions and may not use your data for their own purposes.

8. Transfers outside Sri Lanka

Under the Act, a “third country” means any territory other than Sri Lanka , so this covers the United Arab Emirates as much as anywhere else. We are based in Sri Lanka and operate in the UAE and the wider Gulf, and our hosting and email providers operate internationally, so personal data may be processed outside Sri Lanka.

Section 26 of the Act, as replaced by the 2025 amendment, permits such transfers where we continue to meet our obligations under Parts I and II and sections 20 to 25, and adopt instruments giving binding, enforceable commitments from the recipient. It also permits a transfer that is necessary to perform a contract with you, or to take pre-contractual steps at your request, which is the basis on which correspondence about an enquiry may cross a border.

9. How long we keep it

Enquiry correspondence is retained only while it is useful: to answer you, and to keep a record of what was discussed if it leads to an engagement. Where an enquiry does not proceed, we delete it once it no longer serves a purpose. Server logs are retained on a short rolling basis by our hosting provider. We do not keep personal data indefinitely on the theory that it might one day be useful.

10. How we protect it

We apply access control, encryption in transit, and the same confidentiality discipline we apply to client work, as section 10 of the Act requires. No system is perfectly secure and we do not claim otherwise. In the event of a personal data breach we will notify the Authority in the form and within the time required by section 23, and will tell you directly where the breach is likely to affect your rights.

11. Your rights

Part II of the Personal Data Protection Act gives you the following rights. They are exercised by written request to us.

  • Access (section 13). Confirmation of whether we process your personal data, a copy of it, and the further information listed in Schedule V.
  • Withdraw consent (section 14). Applies where processing rests on consent. As noted above, ours does not.
  • Rectification or completion (section 15). Correction of data that is inaccurate or incomplete.
  • Erasure (section 16). Deletion in the circumstances the section sets out.
  • Review of automated decisions (section 18). We make none, so this should never arise.

How quickly we must answer

Section 17, as amended in 2025, requires us to tell you in writing within one month whether your request is granted or refused, with reasons for any refusal. If we need longer we may extend by a further two months, three months in total at the very most, and we must tell you about the extension before the first month is up. Complying with your request is free of charge.

If we refuse

You have a right of appeal to the Data Protection Authority of Sri Lanka under section 19, and we are obliged to tell you so at the point of refusal. You may also complain to the Authority, or to the data protection regulator where you live.

Write to info@ssaone.com. We may need to verify your identity first. For obvious reasons, we will not release information about a person to someone who has merely claimed to be them.

12. Children

This website is intended for adults engaging our services in a professional capacity. We do not knowingly collect personal data from children through it.

13. Changes

If this notice changes materially, we will update the effective date at the top and, where the change affects how we handle data already held, take reasonable steps to tell you.

14. Contact

Seraph Security Agency (Pvt) Ltd
96/5 Rosemead Place, Colombo 07, Sri Lanka
info@ssaone.com · +94 70 396 6499

Privacy & Data ProtectionTerms of UseCookie PolicyReturn to site
© 2026 Seraph Security Agency (Pvt) Ltd
96/5 Rosemead Place, Colombo 07, Sri Lanka
Confidential · For authorised recipients