Last Updated: October 2026
- Privacy Policy – Overview
Hayleys Leisure PLC is committed to protecting the personal information of all guests, website visitors, and partners. This Privacy Policy outlines how we collect, use, store, share, and protect your personal data across all interactions — whether through our website, in person at our resorts, via phone or email communication, or through third-party channels.
Guided by the corporate values and code of conduct of our parent company, Hayleys PLC (the Hayleys Way), we are committed to protecting your privacy and handling your information responsibly.
We recognize the importance of maintaining your privacy and upholding the trust you place in us when you choose our hospitality services. In accordance with global best practices and local laws (including Sri Lanka’s Personal Data Protection Act No. 9 of 2022), this Policy is designed to ensure transparency, accountability, and compliance in all our data handling practices.
We also align our practices with relevant international standards, such as the European Union’s General Data Protection Regulation (GDPR), ensuring accountability across all our guest touchpoints.
This Privacy Policy applies to all properties and brands under the Hayleys Leisure PLC. It covers information collected both online and offline, including through our websites, reservations, marketing activities, guest services, and partner platforms.
This includes The Kingsbury Colombo, Amaya Resorts & Spas, The Fortress Resort & Spa, Amuna Ayurveda & Wellness Retreat, and Boutique Collection by Amaya. When we say “Hayleys Leisure”, “we”, “us” or “our”, we refer to Hayleys Leisure PLC and the property or brand you are interacting with.
For the purposes of this Policy, “Personal Data”, “Data Controller” and “Data Processor” shall have the meanings assigned to them under the Personal Data Protection Act No. 9 of 2022 (“PDPA”).
Who Collects Your Personal Data
Depending on the context, Hayleys Leisure PLC acts as the Data Controller and may appoint third-party service providers as Data Processors, who act only on our written instructions. Depending on the service you use, the relevant Hayleys Leisure property or Hayleys Group company you engage with may act as the Data Controller responsible for your information.
- Data Covered by This Policy
This Privacy Policy covers all personal data that Hayleys Leisure PLC collects and processes about its guests, customers, website users, partners, vendors, and other stakeholders. This includes:
- Personal identifiers: Name, address, email, phone number, nationality, passport number, and other contact details
- Reservation and transaction data: Booking details, room preferences, travel dates, special requests, payment methods, billing history
- Demographic information: Age and date of birth, where necessary for booking, identification, legal, or service-related purposes.
- Guest stay data: Amenities used, services requested, feedback given, itemized bills, incident reports, and preferences
- Digital activity: IP address, device identifiers, location data, browser type, time spent on site, cookies, interaction logs
- Communications: Emails, messages, feedback forms, surveys, and any correspondence
- Loyalty or membership data (if applicable): Program details, redemption history, and status
- Recruitment data: CVs, qualifications and other information you provide when applying for a position with us
We limit data collection to the information necessary for specific business operations, and ensure that all personal data collected is relevant, limited and used only for its intended purpose.
Special Categories of Personal Data
We only collect personal data that falls under the special categories defined in the PDPA where it is essential — for example, health information required to deliver Ayurveda, spa and wellness treatments, to manage dietary or medical requirements, or to support employment and safety. Such data may include health, biometric, genetic, criminal offence-related and other categories set out in the PDPA, and is processed with your explicit consent, except where the PDPA permits otherwise (such as protecting your vital interests in a medical emergency).
- How and Where We Collect Your Data
We collect personal data in a number of ways depending on how you interact with us. These include:
1. Directly from You
- When you make a booking through our website, phone, or email
- When you check in or check out at a property
- When you fill out feedback forms, surveys, or participate in promotions
- When you subscribe to newsletters or engage with us via social media
- When you apply for a job with us or contact us with an enquiry
2. Automatically
- Through cookies and web tracking technologies when visiting our websites
- Through Wi-Fi usage at our properties (where applicable)
- Via call recordings for customer service quality assurance
3. From Third Parties
- Booking platforms (e.g., Agoda, Booking.com)
- Travel agents and tour operators
- Corporate clients for group bookings or events
- Payment gateways or financial institutions
- Marketing service providers and analytics vendors
- Public sources, including social media platforms where you interact with us
- Legal Basis for Processing Your Data
We only process your personal data when we have a lawful basis to do so under applicable data protection regulations. The legal bases may include:
- Consent – where you have agreed to receive marketing communications or to other specific processing activities. You may withdraw your consent at any time.
- Contractual Necessity – to fulfill a reservation or provide requested services
- Legal Obligations – for record-keeping, financial compliance, tax reporting, or responding to lawful requests from authorities
- Legitimate Interests – to improve services, enhance guest experience, prevent fraud, or analyze operations
- Vital Interests – in emergencies or medical incidents requiring your data to be used to protect life or health
Purposes of Processing
We use your personal data for the following primary purposes:
- Service Delivery – processing reservations and payments, and delivering the accommodation, dining, spa and wellness services you request
- Communication – responding to enquiries, sending booking updates and, where you have agreed, marketing and recruitment updates
- Improvement – enhancing our websites and guest experience through analytics and feedback
- Compliance and Safety – preventing fraud, maintaining security, and meeting legal or regulatory obligations
- Protection of Life, Health and Safety – responding to emergencies affecting guests, employees or visitors
- With Whom We Share Your Data
We do not sell or rent your personal data. We only share it where necessary for the purposes outlined in this Policy, such as fulfilling a contract with you or meeting legal or legitimate requirements.
We take care to only share your personal data when it is necessary, and always under secure, legally binding conditions. We may share your information with:
- Third-party service providers – for booking engines, payment gateways, customer surveys, marketing automation, or loyalty programs
- Law enforcement or government authorities – if required to comply with a legal obligation or court order
- Affiliates and subsidiaries – within the Hayleys Leisure PLC for centralized operations, reporting, or guest service continuity, and within the wider Hayleys Group to provide seamless service and unified support
- Business partners – such as travel agents or event organizers when a shared service is offered to you
- Auditors, lawyers, or consultants – to fulfill our regulatory or contractual obligations
All third parties are required to handle your data in accordance with applicable privacy laws and confidentiality agreements.
All our service providers process personal data only on our written instructions and are contractually required to maintain confidentiality, implement appropriate security measures, and delete or return personal data on completion of their services.
- How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention periods may vary depending on:
- Legal requirements for tax, accounting, and auditing purposes
- Duration of your relationship with Hayleys Leisure PLC (e.g., loyalty membership, frequent guest)
- Whether you have opted into or out of receiving marketing communications
- Our legitimate interest in keeping historical records for guest service improvements or legal defense
- Contractual obligations, regulatory standards, and operational necessity
After the applicable retention period expires, we securely delete, anonymize, or destroy the data.
A detailed retention schedule is maintained internally to ensure we do not keep your personal data for longer than is required for its intended purpose.
- Cookies and Marketing Technologies
Our websites use cookies and similar tracking technologies to enhance your browsing experience, enable core functionality, and improve our marketing efforts. These technologies may:
- Remember your preferences and previous interactions
- Measure and analyze website performance and usage
- Deliver targeted advertisements or retarget content based on your interests
You can manage your cookie preferences through your browser settings. However, disabling some cookies may affect the website’s functionality. For more information, refer to our Cookie Policy.
- Your Privacy Rights & Choices
Under the PDPA, you have the following rights:
- Access – to know what personal data we hold about you
- Rectification – to correct inaccurate or incomplete data
- Erasure – to request deletion of your data (“right to be forgotten”)
- Restriction – to limit how we process your data
- Objection – to object to specific processing (e.g., direct marketing)
- Portability – to obtain a copy of your data in a machine-readable format
- Withdraw Consent – where you previously gave us permission (e.g., newsletters)
- Review of Automated Decisions – to request meaningful information about the logic involved in, and a human review of, any automated decision that affects you
You may exercise these rights by contacting our Data Protection Officer. We will respond to your request within 21 working days.
These rights may also be exercised by authorised representatives, or by heirs within ten years of an individual’s passing, in accordance with the PDPA.
To exercise your rights, email our Data Protection Officer at [DPO email address]. We will respond within a maximum of 21 working days. If we are unable to grant your request for legal or security reasons, we will provide a written explanation of our decision.
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka.
- Children’s Privacy
We do not knowingly collect personal information from children under the age of 16 without verified parental consent. If we discover that such data has been collected unintentionally, we will promptly delete it unless required for legal or safety reasons.
Parents or guardians who believe that their child may have submitted personal information can contact us to review or delete such data.
- Security of Your Data
We implement technical and organizational safeguards to protect your data from unauthorized access, loss, misuse, or alteration. These include:
- Encryption of sensitive data during transmission and storage
- Access controls and authentication procedures, ensuring personal data is accessible only to personnel with a verified business requirement
- Physical security measures at data centers
- Regular security assessments and staff training
- Firewalls and network security controls
- Privacy risk assessments to identify and mitigate potential risks to your personal data
While no system can be guaranteed 100% secure, we follow industry best practices to minimize risk and respond swiftly in the event of a suspected breach.
We maintain incident response procedures to identify, investigate and respond to personal data breaches in accordance with applicable legal requirements.
Data Protection Management Programme
In line with the Hayleys Group, we maintain a Data Protection Management Programme to ensure ongoing compliance with applicable data protection laws, including governance oversight, risk assessments, breach management and continuous improvement.
- International Data Transfers
We may transfer your personal data to countries outside your residence for operational reasons. These transfers will only occur:
- To countries deemed to have adequate data protection laws
- Under appropriate safeguards such as Standard Contractual Clauses (SCCs)
- With your explicit consent where required
All international transfers are made in accordance with data protection legislation to ensure your data remains protected.
Binding contractual safeguards are applied to maintain a level of protection consistent with Sri Lankan law and international requirements.
- Policy Updates & Revisions
We may update this Privacy Policy periodically to reflect legal changes, service updates, or privacy best practices. The revised policy will be posted on our website with a new effective date.
In the event of material changes, we will notify you through prominent notices or by email, where appropriate. The revised policy will take effect from the date stated in the updated notice.
This Policy is subject to periodic review to ensure ongoing alignment with regulatory changes and the Hayleys Group’s operational standards. The latest version is always available on our website.
- Contact Us
For privacy-related queries, data access requests, or to exercise your rights, please contact:
Data Protection Officer
Hayleys Leisure PLC
Corporate Head Office, Level 27
East Tower, World Trade Center
Colombo 01, Sri Lanka
Email: [email protected].
- Additional Provisions
This Privacy Policy is governed by the laws of Sri Lanka. In case of conflict between translated versions, the English version shall prevail.
Third-party websites accessed via our services operate under their own policies. We encourage you to review them before submitting data.
By using our services, you agree to the terms outlined in this Privacy Policy.
Your trust matters deeply to us. This commitment to privacy reflects our identity as part of a responsible corporate citizen that values people and integrity in everything we do.
Amaya Resorts à Privacy Policy
