ACTSSL Privacy Policy
1. About ACTSSL
The Association of Cardiothoracic & Thoracic Surgeons of Sri Lanka (ACTSSL) ("ACTSSL", "we", "us", "our") operates the ACTSSL Membership Management and Event Registration Platform ("Platform") to administer memberships, renewals, communications, and event registrations.
- Organization: ACTSSL
- Address: National Hospital Sri Lanka, Colombo
- Email: secretariat@actssl.lk
- Phone: +94 77 209 4676
2. Scope
This Privacy Policy applies when you:
- Apply for, renew, or manage ACTSSL membership
- Register for ACTSSL events (conferences, workshops, webinars, etc.)
- Make payments via our Platform
- Contact ACTSSL through the Platform, email, or official communication channels
3. Personal Data We Collect
We may collect:
A) Identity & Contact Data
- Full name, title, email, phone number, postal address
- NIC/passport number only if required for verification or event access control
B) Professional Data (Membership)
- Institution/hospital/organization, designation, specialties, qualifications
- Professional registration details (if applicable)
- Membership category, membership number, membership status and history
C) Platform & Account Data
- Username, encrypted password, login activity, system logs
- IP address, device/browser details (for security and audit)
D) Event Data
- Event registrations, attendance, certificates records (if applicable)
- Dietary/accessibility requirements only if you choose to provide them (may be sensitive)
E) Payment Data
- Payment confirmations, transaction reference IDs, amount, date/time, invoice/receipt details
Note: We do not store full card details. Payments are processed by third-party payment gateways/banks.
F) Photos / Recordings (Events)
- Photos/videos taken at ACTSSL events for documentation and association communications.
4. How We Use Your Data
We use personal data to:
- Create/manage member accounts and membership records
- Review membership applications and administer approvals
- Process renewals and generate receipts
- Register you for events and manage attendee lists
- Send confirmations, reminders, and important notices (email/SMS/WhatsApp if enabled)
- Provide certificates/attendance confirmation where applicable
- Maintain platform security, prevent misuse/fraud, and perform audits
- Produce internal reports and analytics (preferably in aggregated form)
5. Lawful Basis & PDPA Alignment
We process personal data based on:
- Consent (e.g., optional marketing communications, optional profile visibility)
- Service necessity (membership administration, event registration)
- Legal obligations (financial recordkeeping where applicable)
- Legitimate interests (platform security, preventing fraud)
ACTSSL aims to comply with Sri Lanka's Personal Data Protection Act, No. 9 of 2022, as amended, including applicable rights and controller/processor responsibilities.
6. Sharing of Personal Data
We may share data only when necessary with:
- Hosting/infrastructure providers (servers, backups)
- Email/SMS service providers (OTPs, alerts, confirmations)
- Payment gateway/banks (payment processing and verification)
- Event service partners (venue access control, badge printing)
- Auditors/legal advisors where required
- Authorities where required by law
We do not sell personal data.
7. International / Cross-Border Processing
If any third-party providers process data outside Sri Lanka (e.g., cloud hosting or email delivery), we take reasonable steps to ensure safeguards consistent with PDPA expectations.
8. Data Retention
We retain data only as necessary:
- Membership records: during active membership and up to 5 years after expiry/termination for administrative/audit purposes
- Event records: up to 5 years for verification/certificates
- Financial records: for the period required by applicable laws and audits
After that, data is securely deleted or anonymized.
9. Security
We use reasonable safeguards such as:
- Role-based access controls
- Secure authentication and encrypted credential storage
- HTTPS encryption in transit
- Backups and monitoring
10. Your Rights & Requests
You may request access, correction, deletion/restriction (where applicable), or withdraw consent (where processing is based on consent) by contacting:
PDPA-related rights are subject to lawful limitations.
11. Cookies (If Applicable)
We may use cookies for login sessions and security. You can control cookies via browser settings.
12. Updates
We may update this policy from time to time. The latest version will be published with the updated date.