PRIVACY POLICY

Last Updated : 15 September 2026

1. Introduction

Colombo Lotus Tower Management Company (Pvt) Ltd (“CLT”, “we”, “us” or “our”) operates the official Colombo Lotus Tower online ticketing platform.

This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you use our ticketing website, purchase tickets, communicate with us or use a ticket to visit Colombo Lotus Tower.

We process personal information in accordance with applicable Sri Lankan law and will update our practices as applicable data-protection requirements come into operation.

2. Information We May Collect

Depending on how you use our services, we may collect:

Identity and contact information, including your name, email address, telephone number, country, nationality or other information required for a particular ticket category.

Booking information, including booking reference, visit date, admission time, ticket category, quantity, selected experiences, ticket status and QR or admission credential information.

Eligibility information, where necessary to determine entitlement to a ticket category, age category, local visitor category, foreign visitor category, concession or other eligibility requirement.

Payment and transaction information, including amount, currency, transaction reference, payment status and limited information received from the applicable payment processor.

Payment-card information may be processed directly by an authorised bank or payment service provider. CLT does not require customers to provide full payment-card details to CLT through ordinary customer-support communications.

Technical information, including IP address, device information, browser information, operating system, timestamps, security logs and website interaction information.

Communications, including emails, telephone enquiries, support requests, complaints and correspondence relating to a booking.

Fraud and security information, including information reasonably necessary to prevent unauthorised transactions, ticket fraud, misuse of the platform or security incidents.

Where identification documents are inspected at the premises to verify eligibility, CLT will only collect or retain information from those documents where reasonably necessary and permitted by law.

3. How We Collect Information

We may collect information:

  • directly from you when you make a booking or contact us;
  • automatically when you use the Site;
  • from our payment processor when a payment is authorised or declined;
  • from security and fraud-prevention systems;
  • from a person booking a ticket on your behalf; and
  • where lawfully permitted, from service providers or authorities.

Where a purchaser provides information relating to another visitor, the purchaser should ensure that they are authorised to provide that information where required.

4. Why We Use Personal Information

We may use personal information to:

  • create and manage bookings;
  • issue tickets and QR codes;
  • process and reconcile payments;
  • verify ticket eligibility;
  • validate tickets at entry;
  • provide customer support;
  • communicate booking confirmations and operational changes;
  • prevent fraud and ticket misuse;
  • secure our website and systems;
  • maintain accounting, audit and transaction records;
  • respond to disputes, chargebacks and legal claims;
  • comply with applicable laws and lawful requests;
  • analyse and improve the operation of the ticketing service;
  • investigate security incidents; and
  • protect visitors, CLT personnel, property and systems.

Where marketing communications are offered, marketing will be handled separately from communications necessary to perform a ticket booking.

5. Basis for Processing

Depending on the circumstances and applicable law, CLT may process information because processing is:

  • necessary to enter into or perform the ticketing contract;
  • necessary to comply with a legal obligation;
  • necessary for legitimate organisational, security, fraud-prevention or operational purposes;
  • necessary for another lawful purpose recognised by applicable law; or
  • based on consent where consent is the appropriate basis.

Where processing depends on consent, withdrawal of consent will apply prospectively and will not invalidate lawful processing already performed.

Withdrawal of optional consent does not necessarily prevent CLT from processing information that must still be processed for another lawful reason, such as completing a ticket contract, maintaining legally required records or addressing fraud.

6. Information Required to Complete a Booking

Certain information is necessary to complete and administer a ticket purchase.

If you do not provide information reasonably required for payment, ticket issuance, visitor eligibility, security or booking administration, CLT may be unable to complete or honour the booking.

7. Payment Processing

Online payments may be processed by an authorised bank, payment gateway, card network or payment service provider.

Those providers may process payment information according to their own legal obligations and privacy practices.

CLT may receive transaction references, authorisation status, masked payment information and other data necessary to confirm and reconcile a transaction.

Customers should never send full card numbers, card security codes, passwords or online-banking credentials to CLT through ordinary email or customer-support channels.

8. Sharing Personal Information

CLT does not sell personal information.

We may disclose information where reasonably necessary to:

  • banks, payment gateways and payment processors;
  • providers hosting, operating, maintaining or securing the ticketing platform;
  • email, messaging or notification providers used to deliver booking communications;
  • analytics and technology providers where used;
  • fraud-prevention or cybersecurity providers;
  • professional advisers, auditors and insurers;
  • government, regulatory, law-enforcement or judicial authorities where required or lawfully requested; and
  • other service providers that process information on CLT’s behalf for a legitimate operational purpose.

Providers acting on CLT’s behalf are expected to process information only for authorised purposes and subject to applicable confidentiality, security and data-protection requirements.

9. Cross-Border Processing

Some technology or service providers may operate infrastructure outside Sri Lanka.

Where personal information is transferred or processed outside Sri Lanka, CLT will take measures required by applicable law in relation to those transfers.

Information concerning relevant cross-border processing will be provided where required.

10. Data Retention

CLT will retain identifiable personal information only for as long as reasonably necessary for the purpose for which it was collected or for a period required by applicable law.

Retention periods may differ depending on the type of information.

For example:

  • ticket and transaction records may be retained for accounting, audit, tax, fraud-prevention and legal purposes;
  • customer-support correspondence may be retained while reasonably necessary to resolve enquiries or disputes;
  • security records may be retained for a period appropriate to the security purpose; and
  • cookie and analytics information will be retained according to the relevant technology and applicable settings.

Where an exact retention period cannot reasonably be stated in advance, CLT will determine retention by reference to the purpose, legal requirements, risk, dispute periods and operational necessity.

Sri Lanka’s PDPA framework expressly adopts a storage-limitation principle and requires appropriate technical and organisational protections for personal information.

11. Data Security

CLT uses reasonable technical and organisational measures designed to protect personal information against unauthorised access, unlawful processing, accidental loss, disclosure, alteration or destruction.

Measures may include access restrictions, authentication controls, system monitoring, logging, encryption where appropriate, backups, security review and controls imposed on relevant service providers.

No internet transmission or electronic storage system can be guaranteed to be completely secure. Accordingly, CLT cannot guarantee absolute security, but will take measures appropriate to the nature and risk of the processing.

12. Your Privacy Choices and Rights

Subject to applicable law and the commencement of relevant statutory provisions, individuals may have rights relating to their personal information, including rights concerning access, correction, completion, withdrawal of consent, objection or restriction of certain processing, erasure in qualifying circumstances, and review of certain automated decisions.

Even where a particular statutory right has not yet become operative, CLT may consider reasonable privacy requests in accordance with its policies and applicable law.

CLT may need to verify the identity of the person making a request.

Certain information may need to be retained notwithstanding a deletion request where retention is required for legal, accounting, evidentiary, fraud-prevention, dispute-resolution or other lawful purposes.

13. Marketing Communications

Transactional communications necessary for a ticket booking are not marketing communications.

Where CLT sends optional marketing communications, recipients will be provided with the ability to unsubscribe or otherwise manage marketing preferences where applicable.

Opting out of marketing will not stop booking confirmations, ticket delivery, security messages or important operational communications relating to a purchase.

14. Cookies and Similar Technologies

The ticketing Site may use cookies and similar technologies for security, session management, language or preference storage, ticket-cart functionality, analytics and other legitimate website functions.

Further information is provided in our Cookies Policy.

15. CCTV and Premises Security

CCTV or other security systems may operate at Colombo Lotus Tower for visitor safety, security, incident investigation and protection of persons and property.

Where applicable, additional notices displayed at the premises may provide further information about such processing.

16. Children's Information

Ticket bookings for children should be completed by or under the authority of an appropriate adult where required.

CLT does not intentionally request unnecessary personal information from children through the ticketing platform.

Information relating to children will be processed only to the extent reasonably necessary for booking, admission, safety or applicable legal requirements.

17. Third-Party Websites and Services

The Site may contain links to services operated independently by third parties.

CLT is not responsible for the privacy practices of independent third-party websites. Customers should review the relevant provider’s privacy information where appropriate.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, service providers or our processing activities.

The latest version will be published on the Site together with an updated revision date.

19. Contact Us