Privacy notice

[vc_row][vc_column][vc_column_text]1. OVERVIEW
________________________________________
Your privacy is very important to Serendib Airways , a member of Serendib Ortus Holding, and we understand how important it is to you. We want you to feel safe when visiting our websites or using our services and are committed to maintaining your privacy when you do. We require our employees, suppliers and partners to maintain confidentiality in accordance with applicable data protection laws.

This privacy notice (together with our Terms of Service, our Cookie Policy and any other documents referred to herein) sets out the basis on which any personal data we collect from you, or that you provide to us (“Privacy Notice”). Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

This Privacy Notice can be changed over time to comply with law or to meet our changing business requirements. The most up-to-date Privacy Notice can be found on our website.

________________________________________
2. DEFINITIONS
By “Personal Data” we mean any information relating to an identified or identifiable natural person.
________________________________________
3. WHEN DOES THIS PRIVACY NOTICE APPLY?
This Privacy Notice applies to the processing by Serendib Airways of all Personal Data we gather or use in connection with your relationship with us as a customer or potential customer of our airline when you use our website, www.serendib.aero (from now on referred to as our “Website”), services provided by us or others acting on our behalf (including when you travel with us) and when you interact with us. We will only use your Personal Data in accordance with this Privacy Notice.
4. WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA?
4.1 Serendib Airways is responsible for the collection and use of all Personal Data described in this Privacy Notice. Serendib Airways is the Controller, as defined in the GDPR. In this Privacy Notice we explain what Personal Data we collect and use and for what purposes, and to which persons or entities the Personal Data will be provided.
4.2 Please be aware however that our Website may contain links to enable you to visit third-party websites, for your convenience and information. Please note that we do not have any control over these third-party websites and are not responsible for the protection and privacy of any information that you provide whilst visiting those sites. Third-party websites, are governed by their own privacy policies and not this Privacy Notice. Please refer to the privacy and cookie policies of the relevant third party websites/social media for information on the processing of Personal Data by those websites/social media and their use of cookies.
________________________________________
5. HOW WE COLLECT AND RECEIVE PERSONAL DATA
1. 5.1 We may collect and receive Personal Data directly from you, or from your authorized representative(s) (i.e., person(s) whom you have authorized, person(s) who has/have been validly identified as being you or your authorized representative(s) pursuant to our then-current security procedures), from third parties (e.g., your travel agent or our service providers). We may also collect the Personal Data of your relatives or principal where you disclose same on their behalf, including when you:

o (a) use any of our services, including when you travel with us or use airports where we operate or any facilities within those airports that we operate, such as our lounge facilities;
o (b) use or access our Website, particularly when completing the “passenger details” section during the course of a booking, even if you do not complete the booking;
o (c) communicate with us such as by email, telephone, in writing or through our customer services pages or social media platforms; or
o (d) Register, create or modify an online or in-app account with us.
2. 5.2 We may also collect your Personal Data from publicly available sources through our Website or Mobile Apps and other channels including our ticketing counters and airport operations and third party providers where you have consented to providing your Personal Data to them.
3. 5.3 Where you disclose Personal Data on behalf of another person, you undertake and will ensure that the individual whose Personal Data is supplied to Serendib Airways has authorized the disclosure, is informed of and consents to the terms and conditions of this Privacy Notice. Where the disclosure is in respect of a minor’s Personal Data, you may only do so as the parent or legal guardian of that child.
6. WHY DO WE USE YOUR PERSONAL DATA?
1. 6.1 When you interact with Serendib Airways (online or offline)
For answering your questions or responding to your complaints or requests
o (a) What does this mean?
If you get in touch with us in person, through our reservations, by email, by telephone, in writing or through our customer service page, through social media, or by your authorized representative for the purposes of the relevant correspondence, we will use your Personal Data in order to reply to you (e.g., to assist you in processing a transaction, to provide technical assistance).
o (b) What are our legal grounds for doing this?
We will process your Personal Data based on the performance of our passenger transport contract with you or in our legitimate business interests in providing customer care to you based on your request depending on the specific case.
o (c) What Personal Data do we use for this purpose?
For this purpose, we use your name, contact details, email address, country of residence, flight number, date of travel, origin, destination, your correspondence with Serendib Airways about your correspondence and all other Personal Data necessary to respond to you. We may monitor or record our phone conversations for training and customer service purposes.
o (d) How long do we keep your Personal Data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
2. 6.2 To allow you to connect with us via social media
o (a) What does this mean?
Serendib Airways is active on social media platforms like Facebook, Twitter, LinkedIn, YouTube, and Instagram. When you contact us via social media, we will use your Personal Data in order to answer your questions and to respond to your messages.

In addition, when you visit a “Connect with Us” screen on our Websites you can contact us through a variety of communication channels. We provide you with our email address for you to send us your feedback and suggested improvements, as well as our Website, Twitter, Facebook, and YouTube contact details. When you click one of the corresponding icons, you will be referred to the website or app of the applicable third party, whether this is your email provider or a social media platform of which you are a member or subscriber and your access and use of any social media platforms is governed by their own terms of use and privacy and cookie policies.
o (b) What are our legal grounds for doing this?
We understand that you require a convenient method of communicating with us being a subscriber to those social media platforms.
o (c) What Personal Data do we use for this purpose?
For this, we use the communication channel you have chosen to use to connect with us and any Personal Data you supply to Serendib Airways . This may include your (user) name, home address, email address, gender and other Personal Data you have included in your message. In addition, when you click one of the buttons displayed for example “Like” or “Share” or retweet on our Website to indicate your interest and communicate with your network via the third party social media platform of which you are subscriber or have elected to become a subscriber, the relevant social media platform might place cookies on your device. To read more about cookies, please read our Cookie Policy.
3.
o Any information which you choose to voluntarily post to our interactive forum is by nature made publicly available to other users who have access to that portion of our Website. We encourage you not to share your Personal Data and we are not responsible for any information you choose to provide or communicate in such forums. Any disclosures you make are at your own risk.
o (d) How long do we keep your Personal Data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
4. 6.3 For the development and improvement of our products and/or services
o (a) What does this mean?
It is important for us to continue to provide you with our excellence services and uphold the Serendib Airways brand. In order to achieve this, we use your Personal Data so that we can assess, analyse and improve our services to you as an airline and enhance our products and services on-board or make changes to our newsletters or our Website.

This means that we keep track of how often you read our newsletters, how often you visit our Website and, which pages you click on and what services you purchase through our Website. We may also collect your Personal Data from publicly available sources, such as information on third party websites or from our business partners, in order to support and optimize our service offerings to you.

We may use non-personally identifiable data (aggregated data) to analyse our customers’ behaviour, perform research into market trends through statistical analysis to evaluate and adapt our products and marketing to new developments and to make our promotions and offers relevant to you. Our research results are only reported within our organisation on an aggregated basis. We may purchase supplementary data from public sources to complement our database for the above purposes.

We also regularly use surveys to find out whether you are satisfied with our service. These surveys are conducted through our Website. We use your responses to surveys for quality assessments and to improve your customer experience, for instance concerns with a flight transfer or misplaced baggage.
o (b) What are our legal grounds for doing this?
We will process your Personal Data based on the performance of our passenger transport contract with you or in our legitimate business interests in enhancing our services to you. To ensure the security of your Personal Data, our research and analytics are aggregated and anonymized and we require our employees, suppliers and partners to maintain confidentiality in accordance with applicable data protection laws.
o (c) What Personal Data do we use for this purpose?
For this purpose, we use your contact details such as your home address and email address, personal details such as your name and date of birth, payment and credit information, and correspondence with us. In addition, we use the Personal Data you entered into the Website and or that were generated by the functionalities you used in the Website and the technical data from your device such as its IP-address, the pages you visited on our Websites, your click-through and surf behaviour and the length of your session.

If you choose to participate in our surveys, we can ask you to provide us with Personal Data, such as age group, gender, and your preferences in terms of choice of destination. We can also use the Personal Data that you have provided in the survey for this purpose.
o (d) How long do we keep your Personal Data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
o
6.4 When you travel with us or use our ancillary services
For the assessment and acceptance of a customer
• (a) What does this mean?
When you contact Serendib Airways , your Personal Data will be processed for assessment and acceptance purposes. This includes, confirming and verifying your identity or that of your authorised representative(s), verifying your identity at the security checkpoint, and confirming your Personal Data at the check-in (i.e., at our counters or at self-check-in kiosks), and during boarding or disembarkation, (i.e., security screening, baggage screening, and flight transfers).

Serendib Airways will also process your Personal Data for other administrative and regulatory purposes such as due diligence and transportation security screening against publicly available government and/or law enforcement agency sanctions lists.

Serendib Airways may also use and disclose your Personal Data to persons who have been validly identified as being you or your authorised representative(s) pursuant to our then-current security procedures for the purpose of the relevant transaction or enquiry.
• (b) What are our legal grounds for doing this?
We will process your Personal Data based on your request to enter into a passenger transport contract with us and applicable legal obligations and regulatory requirements. For example, you will not be allowed to enter the security checkpoint if your identity cannot be confirmed, you chose to not provide proper identification or you decline to cooperate with the identity verification process.
• (c) What Personal Data do we use for this purpose?
For this purpose, we process your contact details such as your postal address and email address, visas for your transit and final destinations, personal details such as your name and date of birth, payment and credit information and details of your correspondence with us. We will also process the Personal Data of those passengers travelling on the same flight with you in a similar manner.
• (d) Automated decision-making?
We use automated fraud detection algorithms to screen your online purchases in order to prevent fraudulent credit card transactions.

Where you have requested medical clearance to assess your fitness to travel prior to your flight, you will be required to consent to and authorize the attending doctor to disclose the necessary my medical information at any time to Serendib Airways and its commissioned medical advisors solely for the purpose of determining your fitness to fly on your booked flights and release the attending doctor from his or her obligation to maintain your medical information confidential strictly with respect to the disclosure to Serendib Airways .
• (e) How long do we keep your personal data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
6.5 For the conclusion and execution of agreements
• (a) What does this mean?
When you travel with us, we process your Personal Data for administrative purposes such as facilitating your bookings and travel arrangements or when you use airports. We process your Personal Data for administrative purposes such as to conduct security transportation identification and screening requirements required by those airports and imposed upon airlines.

Please note that by using our services, our Website and by providing any Personal Data to us, you agree to your Personal Data being sent to and processed in countries outside of your country of residence, and for individuals resident in the European Economic Area (“EEA”), this includes transfers outside of the EEA. Some of these countries may not have data protection laws that provide an equivalent level of data protection as the laws in your country of residence. Please refer to Clause 8 of this Privacy Notice for more details.
• (b) What are our legal grounds for doing this?
We will process your Personal Data based on the performance of our passenger transport contract with you. If you provide Personal Data on behalf of someone else (e.g., making a booking on behalf of an adult or a child of whom you are the parent or legal guardian), you enter into a passenger transport contract on behalf of that child or person.
• (c) Which personal data do we use for this purpose?
For this purpose, we process the passenger’s contact details such as home address and email address, Personal Data such as name and date of birth, payment and credit information, order history and other data stored in our customer, supplier and business partner database in relation to that passenger transport contract with you and any other contracts for ancillary or other services that you have contracted for with the Serendib Airways Group.
• (d) How long do we keep your Personal Data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
6.6 For organisational analysis and development, internal management, organisation reporting, and acquisition and divestitures
• (a) What does this mean?
We process your Personal Data to benefit the performance and organisation of our business and our management reporting and analysis. This includes general management, order management and management of Serendib Airways assets. Serendib Airways also processes your Personal Data for its internal management. We provide central processing facilities in order to work more efficiently. We conduct audits and investigations, implement business controls, and manage and use customer, supplier and business partner directories. Also, we process your Personal Data for finance and accounting, archiving and insurance purposes, legal and business consulting and in the context of dispute resolution.

We may use Personal Data to create management reports and to analyse Serendib Airways ’s business. We conduct customer, supplier and business partner surveys to learn more about your views and opinions in preparation of our management reporting.
• (b) What are our legal grounds for doing this?
We will process your Personal Data based on the performance of our passenger transport contract with you or in our legitimate business interests in maintaining the expected service levels to you. To ensure the security of your Personal Data, our analysis, reporting may be aggregated and anonymized and we require our employees, suppliers and partners to maintain confidentiality in accordance with applicable data protection laws.
• (c) Which Personal Data do we use for this purpose?
For this purpose, we process your contact details such as your home address and email address, personal details such as your name and date of birth, payment and credit information, payment and order history, correspondence with Serendib Airways , data generated during the performance of the agreement between you and Serendib Airways , correspondence with Serendib Airways and the information you provide when responding to our surveys.
• (d) How long do we keep your personal data for this purpose?
For this purpose, your Personal Data will be retained for as long as is legally required or for other business reasons in connection with the purposes described in this Privacy Notice and in line with our data retention policies.
• 6.7 For compliance with law and to monitor and investigate compliance READ MORE
o (a) What does this mean?
Serendib Airways is required to comply with certain legal obligations (e.g. responding to government information requests or complying with rules on Advanced Passenger Information as defined in sub-clause 8.2(e)) and monitors its Website, Mobile Apps and IT systems to check compliance with Serendib Airways ’s internal policies and regulations. During monitoring activities, your Personal Data can be accessed and viewed.
o (b) What are our legal grounds for doing this?
We will process your Personal Data based on:

 i. our legitimate business interests in maintaining adherence to our company policies and the standards which we uphold for our employees, suppliers and partners;
 ii. legal obligation to comply with laws and regulations which are applicable to the airline industry or to specific geographic locations.

o (c) What Personal Data do we use for this purpose?
For this purpose, any Personal Data that is stored on Serendib Airways IT systems can be accessed and viewed for compliance purposes. The Personal Data that is accessed and viewed will not be stored for compliance purposes, unless we need them to further investigate potential non-compliant behaviour or in the course of legal proceedings.
o (d) How long do we keep your Personal Data for this purpose?
We do not retain your Personal Data for this purpose, unless they are linked to non-compliant behaviour. We will then keep the relevant Personal Data until the investigation or proceedings have been concluded.
________________________________________
7. COOKIES
We also collect information through the use of cookies. Cookies are small files of information which save and retrieve information about your visit to our Website, for example, how you entered our site, how you navigated through the site, and what information was of interest to you.

8. WHO HAS ACCESS TO YOUR PERSONAL DATA?
1. 8.1 Access to your Personal Data within Serendib Ortus Holding.
2. 8.2 Access to your Personal Data by third parties
When you make a travel booking or other purchase via our Website, we utilise support and other functions which may require the transfer of your Personal Data to and from countries outside of your country of residence from time to time that may be processed and stored by relevant third parties, such as ground handling agents, to provide you with the arrangements you require.

In order for you to travel overseas, we may be required to disclose certain of your Personal Data in the following cases:

o (a) to you or those acting on your behalf. Where local regulations require, we may obtain your consent in writing for the purpose of allowing anyone else to act on your behalf;
o (b) to third parties including service providers to provide a service to, or perform a function for, us or who are otherwise appointed by us in connection with the services we offer you including those who are acting as our agent or sub-contractor, including, without limitation, Ground handling service providers, medical assistance providers, authorities in case of declaration of firearms, catering in case of special meals, credit card and credit reference agencies, data processing service providers and our legal and other professional advisors;
o (c) to third parties in connection with a proposed or actual financing, securitization, insuring, merger, restructure, sale, acquisition, assignment or other disposal of all or part of our business or assets or the assets of any Affiliate or to anyone whom we may transfer our rights and/or obligations for the purposes of evaluating and performing the proposed transaction;
o (d) to third parties, including law enforcement officials, law courts and government and regulatory authorities: (a) if we believe disclosure is required by any applicable law, regulation or legal process (such as to respond to subpoenas or judicial orders); or (b) to protect and defend our rights, or the rights or safety of third parties, including to defend against legal claims. Even if it is not mandatory for us to provide information to such authorities, we may exercise our discretion to assist them where appropriate;
o (e) to customs, border control, security, anti-terrorism and immigrations authorities in Serendib Airways , the EEA and in other countries, which require by law access to booking and travel itinerary information including “Advanced Passenger Information” (passport and associated Personal Data) for all passengers prior to your travel and upon their request in accordance with the law;
o (f) Where you have made a travel booking, to passengers travelling under the same booking as you.
1. In other cases, your Personal Data will not be supplied to third parties, except where required by law.
________________________________________
9. HOW DO WE KEEP YOUR DATA SAFE?
(a) Safeguards
Serendib Airways has taken adequate safeguards to ensure the confidentiality and security of your Personal Data. We are committed to ensuring that your Personal Data is secure. In an effort to prevent unauthorised access to, or disclosure of, your Personal Data, we have put in place physical, technical, and administrative safeguards to protect your Personal Data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorised disclosure or access, as well as all other forms of unlawful processing (including, but not limited to, unnecessary collection) or further processing. In order to protect the security of your information, we use encryption technology when collecting or transferring sensitive Personal Data.
1. (b) Minors
Outside of required passenger details, we do not intentionally gather Personal Data about minors. We are not able to identify the age of persons who access and use our Website. If you believe we have inadvertently collected Personal Data about your child, please contact us, and we will attempt to remove this information. If a minor (according to applicable laws) has provided us with Personal Data without parental or guardian consent, the parent or guardian should contact us to remove the relevant Personal Data.
2. (c) Retention
We will retain Personal Data for as long as it is necessary to fulfill the purpose for which it was collected, the legal or business purposes of Serendib Airways , or as required by relevant laws.

When destroying Personal Data, we will take commercially reasonable and technically possible measures to make the personal information irrecoverable or irreproducible in accordance with the applicable laws.

10. CONTACT US
You can request access, correction, restriction, or removal of the data that Serendib Airways processes about you at any time by sending a request to Contact Us page of our Website. You will also, under certain circumstances, have the right to data portability, meaning that you have the right to receive your personal data in a structured, commonly used and machine-readable format to transmit those data to another controller. We may charge you a small, reasonable administration fee to respond to your request. Any request must include the following information: your name and address and any other information which may identify you.

Should you have any questions about the processing of your Personal Data or this Privacy Notice, please contact:

Serendib Airways,
10th Floor, East Tower, World Trade Center, Colombo 01. SriLanka.
Attention: Data Protection Officer

We will make reasonable efforts to revise any information that is incorrect, or update or change your information or preferences, as permitted by law. It may take several weeks to implement the changes. If you feel that we do not comply with applicable privacy rules, you have the right to lodge a complaint with a competent data protection authority.

Our Website may, from time to time, contain links to and from the websites of our partner networks and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any Personal Data to these websites.[/vc_column_text][/vc_column][/vc_row][vc_row][vc_column][/vc_column][/vc_row]