Privacy Policy Central Finance Company PLC
01 Scope of This Privacy Policy
This Privacy Policy applies to all personal data collected through:
- CENTRAL Finance’s official website (https://cf.lk)
- Online platforms ( https://careka.lk, https://careka.lk/tukeka)
- Mobile applications, including the CF Click App , Centrix Payment App
- Online services (advertising, telephone)
- Offline services (in-branch, paper applications, etc.)
- Third-party sources, such as public databases or social media, as permitted by law
It also applies to any personal information obtained through the recruitment process, customer complaints, or feedback systems.
02 Data Protection Principles
We adhere to the following principles to ensure the safety and integrity of your personal data:
Information We Collect
We collect personal data necessary for business operations and regulatory compliance, including but not limited to:
How We Collect Personal Data
We collect personal data through various methods, including:
- Directly from you when you apply for services, fill out forms (electronically or physically), use our website, or communicate with us
- Automatically when you interact with our website or mobile apps (via cookies, usage data, etc.)
- From third parties, such as public databases, credit reference agencies, and social media (in compliance with legal regulations)
Cookies and Tracking Technologies:
We use cookies to enhance user experience, analyze website traffic, and ensure the website’s functionality. You can manage your cookie preferences through your browser settings. For more details, refer to our Cookie Policy.
03 Purposes of Data Collection
We process your personal data for the following purposes:
04 Legal Basis for Processing Personal Data
We rely on the following legal bases for processing personal data:
Where we obtain your explicit consent, particularly for marketing purposes.
Where data processing is required to fulfill contractual obligations (e.g., account management, service provision).
To comply with statutory and regulatory requirements (e.g., reporting to government authorities).
For purposes such as fraud detection, system security, and customer service improvement.
05 Data Subject Rights
Under the PDPA Sri Lanka, you have the following rights concerning your personal data:
Request access to your personal data held by us.
Request corrections to inaccurate or incomplete data.
Request deletion of your data where it is no longer necessary for the intended purposes.
Restrict the processing of your data in certain situations.
Receive your personal data in a machine-readable format for transfer to another data controller.
Object to the processing of your personal data for certain purposes, such as direct marketing.
You may withdraw your consent for processing personal data at any time, without affecting the lawfulness of processing carried out before withdrawal.
You have the right to lodge a complaint with the Data Protection Authority of Sri Lanka if you believe your rights under the PDPA have been violated.
You have the right to be informed about the collection, use, storage, disclosure, and retention of your personal data, at the time of collection and whenever processing purposes change.
If automated decision-making, including profiling, significantly affects you, you have the right to request human intervention and to contest such decisions.
06 Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or to comply with statutory retention periods (e.g., tax, financial regulations). Once personal data is no longer needed, we securely destroy or anonymize it.
07 Disclosure of Personal Data
We may disclose your personal data to the following categories of recipients, strictly in accordance with applicable laws and for legitimate business purposes:
Third-Party Service Providers and Group Companies :
We may engage trusted third party service providers to support various functions necessary for our operations and service delivery. These may include, but are not limited to:
All such third parties are contractually obligated to maintain the confidentiality, integrity, and security of personal data and to process such data only in accordance with our instructions and applicable data protection laws.
Governmental, Regulatory, and Law-Enforcement Authorities :
We may disclose personal data when required by law, regulation, or legal process to government, regulatory, or law enforcement bodies. These may include, but are not limited to:
are legally mandated to request such informations.
Business Transfers :
In the event of mergers, acquisitions, or restructuring, personal data may be transferred subject to confidentiality safeguards.
We will not disclose your personal data to external parties without your consent unless required by law or permitted under applicable regulations
08 Cross-Border Data Transfers
When personal data is transferred outside of Sri Lanka, we ensure that the destination country has adequate data protection measures in place, or we implement appropriate contractual safeguards, in compliance with applicable data protection laws and relevant regulatory frameworks
09 Data Security
We implement technical and organizational measures to ensure the security of personal data in compliance with applicable regulatory frameworks. These measures include
10 Data Breach Notification
In the event of a data breach, we will notify affected individuals and the Data Protection Authority of Sri Lanka within the required timeframe if the breach poses a risk to your rights and freedoms, as stipulated by the PDPA.
11 Credit Information and Service Eligibility
As part of our service eligibility assessment, we may obtain credit information from the Credit Information Bureau of Sri Lanka (CRIB) in accordance with applicable laws and regulations.
13 CCTV Surveillance
We operate CCTV systems within our premises to enhance safety, security, and asset protection. Surveillance is conducted based on our legitimate interest under the PDPA Sri Lanka.
Footage may capture identifiable individuals and is processed solely for security-related purposes. Recordings are retained for a limited period and automatically overwritten unless required for investigations. Data subjects may request access or object to processing, subject to legal and technical limitations.
14 Updates to This Privacy Policy
We may update this policy periodically to reflect changes in legal, regulatory, or operational requirements. We will notify you of any significant changes by posting the updated policy on our website. Please review this policy regularly.
15 Contact Us
If you have any questions or concerns about this privacy policy, or if you wish to exercise your data protection rights, please contact us
Data Protection Officer (DPO)
