Privacy Policy
UltiViz Labs (Pvt) Ltd · RemKliQ Platform · app.remkliq.com · remkliq.com
1. Introduction
UltiViz Labs (Pvt) Ltd (the Company, we, us, or our) owns and operates the RemKliQ platform, accessible at app.remkliq.com. We are committed to protecting the personal data of our Clients, Users, Staff Users, and their Customers in compliance with the Personal Data Protection Act No. 9 of 2022 as amended by the Personal Data Protection (Amendment) Act No. 22 of 2025 (collectively, the PDPA), the Electronic Transactions Act No. 19 of 2006, the Computer Crimes Act No. 24 of 2007, and all other applicable laws of Sri Lanka.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, who we share it with, and what rights you have as a data subject. By registering for or using the RemKliQ platform, you confirm that you have read and understood this Policy.
This Policy uses the same defined terms as the Terms and Conditions published on the platform. In this Policy, Client refers to businesses that subscribe to the RemKliQ platform. Customer refers to third parties whose contact details are entered by Clients into the platform for the purpose of receiving automated reminders.
The provisions of Section 17 governing cookies and analytics technologies apply to all visitors of the website at remkliq.com, including persons who have not registered for or used the platform.
2. Document Information and Version Control
The version of this Privacy Policy accepted by a Client at the time of account creation or password activation is recorded in the Company's system. This version supersedes all prior versions of this Privacy Policy.
3. Who We Are as Data Controller and Data Processor
Under the PDPA, UltiViz Labs (Pvt) Ltd is the Data Controller for personal data belonging to our Clients, Users, and Staff Users. We determine the purposes and means of processing that data and are responsible for its protection.
For Customer Data entered into the platform by Clients, the Client is the Data Controller and the Company acts solely as a Data Processor. In this capacity, the Company processes Customer Data only on the instructions of the Client and for the purposes described in these documents.
If you are a Customer of one of our Clients and wish to understand how your personal data is used, you should contact the business that entered your details into the platform. That business is the Data Controller responsible for your data.
4. Data We Collect
4.1 Data Collected from Clients and Users at Registration
When a Client registers for RemKliQ through the website or is registered by a Company administrator, we collect the following:
- Business name and city
- Contact person's full name, email address, and phone number
- Login credentials, comprising email address and an encrypted password set by the User
- Subscription and payment records processed through our payment gateway or by bank transfer
- Platform activity data including login timestamps, session activity, actions performed, and system logs
4.2 Acceptance Audit Trail Data
When a Client accepts the Terms and Conditions, Privacy Policy, and Refund Policy, the following data is recorded:
- Full name of the accepting individual
- Company name, email address, phone number, and city
- Date and time of acceptance
- Version number of each document accepted
- User identifier
- Method of acceptance: self registration via the website or admin initiated onboarding
This record is retained as a legally valid electronic acceptance record under the Electronic Transactions Act No. 19 of 2006.
4.3 Staff User Data
When a Client creates a Staff User account, we collect the following information in relation to that Staff User:
- Full name (as provided by the Client)
- Phone number (used as the Staff User's login username)
- Login activity and session data
Staff User personal data is provided and managed by the Client. The Client is responsible for ensuring that Staff Users are made aware of this Privacy Policy.
4.4 Customer Data Entered by Clients
When Clients use the platform to manage quotations and invoices, they may enter the following personal data about their own Customers:
- Customer name and business name
- Customer email address and phone number
- Quotation and invoice details including amounts, dates, and payment types
This data is entered solely by the Client. The Company processes it as a Data Processor on the Client's behalf. The Company does not independently collect, verify, or use this data for any purpose other than delivering the platform's services to the Client.
4.5 Automated System Log Data
The platform automatically generates and retains system logs recording automated reminder messages delivered to Customers on behalf of Clients. These logs record the fact of delivery, timing, and associated account identifiers. They are retained for legal and compliance purposes and are not used for marketing or commercial profiling.
4.6 Messaging Centre Data
Communications between a Client and the Company through the platform's Messaging Centre are recorded and retained for the purpose of support delivery, quality assurance, and compliance monitoring.
4.7 Website and Platform Analytics Data
Through cookies and third party analytics technologies, the platform collects analytics data relating to visitors of the website at remkliq.com and to Clients and Staff Users of the platform at app.remkliq.com. This data comprises website browsing activity and platform usage information, including the sections accessed and the time spent within them. This data is collected and processed on an aggregate basis for the purpose of platform stability, error monitoring, and the improvement of the website, the platform, and the user experience. It is not used to construct individual profiles of Clients, Staff Users, or Customers for marketing purposes. Further provisions are set out in Section 17.
5. How We Use Personal Data
We use the personal data we collect for the following purposes:
- To operate the RemKliQ platform and deliver the services described in the Terms and Conditions
- To manage Client accounts, including registration, email verification, password creation, and subscription management
- To send automated quotation and invoice reminder messages to Customers on behalf of Clients, as directed by the Client through the platform
- To verify subscription payments and activate platform features upon confirmed payment
- To communicate with Clients and Users about their accounts, subscription status, platform updates, and support matters
- To monitor the platform for security, fraud, and misuse
- For internal analytics and business intelligence to improve the quality and performance of the platform
- To comply with legal obligations under Sri Lankan law
- To retain acceptance records as legally required under the Electronic Transactions Act No. 19 of 2006
- To send re-engagement communications where a Client account has entered Unpaid Status and no confirmed cancellation has been received, as described in Section 10 of this Policy
We do not use Customer Data entered by Clients for any marketing, commercial profiling, or any purpose other than delivering the platform's automated reminder service on the Client's behalf.
6. Legal Basis for Processing
We process personal data on the following lawful bases under the PDPA:
Contract Performance: Processing is necessary to fulfil our obligations to Clients under the subscription agreement.
Legitimate Interests: Processing is necessary for the legitimate operation, security, improvement, and commercial continuity of the platform, including re-engagement communications to Clients in Unpaid Status.
Legal Obligation: Processing is required to meet legal and regulatory requirements under the laws of Sri Lanka, including financial record keeping and data protection compliance.
Consent: Where personal data is used for direct marketing communications, we rely on consent, which may be withdrawn at any time by contacting us at connect@remkliq.com.
7. Data Sharing and Third Party Sub-processors
We do not sell, trade, or rent personal data to any third party. We may share data in the following limited and controlled circumstances:
- With our cloud infrastructure, database hosting, SMS delivery, email delivery, and other technical service providers. These sub-processors process data solely on our instructions and under strict confidentiality and security obligations.
- With our payment gateway provider, being an authorised Internet Payment Gateway provider operating under the regulatory framework of the Central Bank of Sri Lanka, for the purpose of processing subscription payments.
- With our website analytics provider, for the purpose of measuring visitor activity on the website and improving its performance. Such providers process data under their own privacy terms.
- With our platform diagnostics and analytics provider, for the purpose of error monitoring, platform stability, and the measurement of general platform usage. Such providers process data under their own privacy terms.
- With regulatory authorities, law enforcement, or courts in Sri Lanka where legally required.
- In the event of a business acquisition, merger, or restructure, with the acquiring or successor entity, subject to equivalent data protection obligations.
We do not transfer personal data outside Sri Lanka unless the receiving party provides an adequate level of protection consistent with the PDPA and its associated guidelines issued by the Data Protection Authority of Sri Lanka. Where international transfers are necessary for platform operations, we ensure appropriate safeguards are in place.
8. Data Retention Schedule
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. The following retention periods apply:
Active Accounts
Client, User, and Staff User account data is retained for the full duration of the active subscription. Data remains accessible to the Client within the platform throughout this period.
Accounts in Unpaid Status
Where a Client account enters Unpaid Status (no active subscription), the following operational data is retained for a period of six continuous months, after which it is permanently and irreversibly deleted. All Staff User accounts created under the Client account will also be permanently closed and deleted at the same time:
- Quotation records, invoice records, and scheduled reminders
- Customer records entered by the Client
- Messaging Centre message history
- All other operational records associated with the account
Warning notification emails will be sent to the Client's registered email address at the ninety day and one hundred and fifty day marks following the account entering Unpaid Status. Failure to receive or read these notifications, for any reason, does not prevent the Company from proceeding with the scheduled deletion.
Retained Data Following Deletion
The following data is retained beyond the six month deletion period:
- Client full name, company name, city, phone number, and email address: retained indefinitely for legitimate business and compliance purposes
- Payment and financial transaction records: retained for a minimum of seven years from the date of the transaction, in compliance with Sri Lanka's financial record keeping requirements
- System logs of automated reminders delivered: retained for legal and compliance purposes
- Acceptance audit trail records: retained for a minimum of seven years from the date of acceptance
- Compliance records as required by applicable law
Customer Data
Customer Data entered by Clients is retained for the duration of the Client's active subscription and for a period of up to six months following the account entering Unpaid Status, after which it is permanently deleted as described above.
Payment Records
Payment and transaction records are retained for a minimum of seven years in compliance with Sri Lanka's financial and accounting record keeping requirements.
9. Inactivity Notifications and Deletion Process
Where a Client account enters Unpaid Status, the Company will send notification emails to the Client's registered email address as follows:
- At ninety days of Unpaid Status: a first notification informing the Client that their account data is at risk of deletion.
- At one hundred and fifty days of Unpaid Status: a final notification informing the Client that their account data is scheduled for deletion in thirty days.
- At one hundred and eighty days of Unpaid Status: permanent deletion of all operational records commences.
These notifications are automated and logged by the Company's system. The Company's obligation to notify is fulfilled upon the successful dispatch of the notification email to the Client's registered email address. Delivery failure, spam filtering, inbox issues, an abandoned or inaccessible email address, or the Client's failure to monitor their registered email address shall not prevent the Company from proceeding with the scheduled deletion or give rise to any claim against the Company.
10. Re-engagement Communications
Where a Client account enters Unpaid Status without a confirmed cancellation request, the Company may contact the Client through available communication channels, including phone calls, email, SMS, or in person meetings, to assist with account renewal or to understand the Client's situation. This outreach is conducted as a legitimate business interest activity.
Such communications will cease upon the Client's confirmed decision not to continue with the platform. Following confirmed termination or cancellation, no further promotional or commercial communications will be sent to the Client, beyond those required for legal, compliance, or account administration purposes.
11. Reactivation
A Client who reactivates their account within six months of entering Unpaid Status will have full access to their existing operational records upon subscribing to a valid plan.
A Client who returns after the six month deletion period will retain their existing account credentials and reference profile. All previously deleted operational records are permanently removed and cannot be recovered under any circumstances. The reactivated account will operate as a fresh environment with no prior records.
12. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure, and destruction. Our security measures include:
- Encrypted storage of passwords and sensitive credentials
- Access controls ensuring only the Company's directors and authorised service providers can access personal data
- Secure cloud infrastructure hosted with reputable third party providers
- Activity logging within the platform for security monitoring and audit purposes
- Restriction of access to Client and Customer data to the Company's directors and authorised third-party service providers who require it to deliver the platform's services
No system can be guaranteed to be completely immune to risk. In the event of a personal data breach, the Company will act promptly as described in Section 13 of this Policy.
13. Data Breach Notification
The Company has established internal procedures for identifying, assessing, containing, and responding to personal data breaches. In the event of a data breach that is likely to result in a risk to the rights or interests of affected individuals, the Company will:
- Investigate and contain the breach as promptly as practicable
- Assess the nature, scope, and likely impact of the breach
- Take all reasonable corrective and remedial action
- Notify the Data Protection Authority of Sri Lanka within seventy two hours of becoming aware of the breach, in accordance with the notification requirements of the PDPA and the rules issued thereunder
- Notify affected Clients within the timeframes prescribed by the PDPA and the Data Protection Authority
Where a breach affects Customer Data processed on the Client's behalf, the Company will notify the relevant Client promptly so that the Client, as Data Controller of that data, can fulfil their own legal obligations.
The Company will maintain a record of all data breaches, including those not required to be reported to the Data Protection Authority, consistent with its obligations as a Data Processor.
14. Your Rights as a Data Subject
Under the PDPA, you have the following rights in relation to your personal data. These rights apply in accordance with the provisions and phased implementation timelines of the PDPA and its amendments:
Right to Access: Request a copy of the personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where processing is unlawful.
Right to Object: Object to the processing of your personal data, including for direct marketing purposes.
Right to Restrict Processing: Request restriction of processing in certain circumstances.
Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
Right to Complain: Lodge a complaint with the Data Protection Authority of Sri Lanka.
To exercise any of these rights, contact us at connect@remkliq.com. We will respond within the timeframe required by the PDPA and any applicable regulations issued by the Data Protection Authority.
If you are a Customer of one of our Clients, please contact the relevant Client directly to exercise your data rights, as they are the Data Controller of your personal data.
15. International Data Transfers
The Company uses third party service providers for certain technical functions, including cloud infrastructure and database hosting, which may involve the storage or processing of personal data on servers located outside Sri Lanka. Where such transfers occur, we ensure that the receiving party provides an adequate level of data protection consistent with the standards required by the PDPA and the Data Protection Authority of Sri Lanka.
We will update this section as the Data Protection Authority issues further guidance on cross-border transfer requirements and adequacy determinations.
16. Data Protection Responsibility
Data protection responsibilities are managed collectively by the Company's directors, who are responsible for ensuring compliance with the Personal Data Protection Act No. 9 of 2022 and its amendments. The Company will review this position and appoint a Data Protection Officer if and when required to do so by applicable law or regulation. If you have any data protection queries, concerns, or requests, please contact us using the details provided in Section 19 of this Policy.
17. Cookies and Tracking
The platform at app.remkliq.com uses session cookies for the purpose of maintaining login state and basic security.
The website at remkliq.com uses cookies and third party analytics technologies for the purpose of measuring visitor activity and improving the website. A cookie consent notice is presented to visitors upon their first access to the website. Non essential cookies, including analytics cookies, are set only upon the visitor providing consent through that notice.
The platform at app.remkliq.com uses third party analytics and diagnostic technologies for the purpose of error monitoring, platform stability, and the measurement of general platform usage, including the sections accessed and the time spent within them. Such measurement is conducted on an aggregate basis and is not used to construct individual profiles of Clients, Staff Users, or Customers for marketing purposes.
The third party providers of these technologies process data under their own privacy terms. The Company is not responsible for the data handling, security, or privacy practices of such providers.
You may configure your browser to reject cookies, though this may affect certain platform and website functions.
18. Changes to This Policy
We may update this Privacy Policy at any time. When this Policy is amended, the updated version will be published on the platform and at remkliq.com with an updated version number and effective date. Clients will be required to actively confirm their acceptance of the updated Policy through the in-platform consent mechanism described in the Terms and Conditions. Access to the platform will remain restricted until the Client confirms acceptance. The date, version, and method of acceptance will be recorded in the Company's system. For significant changes to how we process personal data, we will endeavour to notify Clients through their registered email address prior to the changes taking effect.
19. Contact Us
Company: UltiViz Labs (Pvt) Ltd
Registration Number: PV00362722
Brand: RemKliQ
Platform: app.remkliq.com
Website: remkliq.com
Email: connect@remkliq.com
Phone: +94 71 880 8666
Address: No. 46/5A, Asiri Mawatha, Kalubowila, Dehiwala 10350, Sri Lanka