Privacy Policy
- Effective date
- 1 September 2026
- Last updated
- 30 August 2026
- Version
- 2.1
This policy explains what personal data Zelenso Travel collects, why we need it, who we share it with, how long we keep it and what rights you have. Arranging travel means sending your details to hotels, drivers and guides in Sri Lanka, so we set out plainly what leaves our hands and why.
1. Who is responsible for your data
The controller of your personal data is ZELENSO (PVT) LTD, trading as Zelenso Travel, of 4/1, Wewagedara, Kurunegala 60000, North Western Province, Sri Lanka, Sri Lanka.
- Privacy contact: contact@zelenso.com
- Postal address for privacy requests: 4/1, Wewagedara, Kurunegala 60000, North Western Province, Sri Lanka
We have not appointed a Data Protection Officer. Privacy questions, requests and complaints go to the address above and are handled by our management team.
2. What we collect
Information you give us
- Identity and contact details: name, email address, telephone number, postal address, nationality and country of residence.
- Travel party details: names, ages of children where relevant and the relationship between travellers.
- Booking details: dates, itinerary, accommodation and room preferences, activities and special occasions.
- Passport information where a supplier, airline or the authorities require it, which for most bookings means passport number, full name, date of birth, nationality and expiry date.
- Requirements you tell us about: dietary requirements, allergies, accessibility and mobility needs, and any health information you choose to share so that we can arrange your trip safely.
- Payment and billing information.
- Correspondence with us by email, contact form, telephone, WhatsApp or social media.
- Reviews, photographs and feedback you choose to share with us.
Information collected automatically
- IP address, approximate location derived from it, device type, operating system and browser.
- Pages visited, referring page and time spent, where analytics cookies are used.
- Cookie identifiers, as described in our Cookie Policy.
Health information, and information about religious or dietary practice that reveals belief, is treated as sensitive under several data protection laws. We ask for it only where it is genuinely needed to arrange your trip safely, we limit who can see it, and we do not use it for marketing. If you would rather give a requirement directly to the hotel or activity operator, tell us and we will arrange that instead.
3. Why we use your data and our legal basis
Where the EU or UK General Data Protection Regulation applies to our processing, we rely on the following legal bases.
- What we do
- Prepare a quotation and answer an enquiry
- Why
- To respond to you and design a trip
- Legal basis
- Steps at your request before entering a contract
- What we do
- Confirm and deliver your booking
- Why
- To perform the contract
- Legal basis
- Performance of a contract
- What we do
- Send your details to hotels, drivers, guides and activity operators
- Why
- So the services can be delivered
- Legal basis
- Performance of a contract
- What we do
- Arrange requirements arising from health, disability or diet
- Why
- To keep you safe and meet your needs
- Legal basis
- Your explicit consent, given when you tell us
- What we do
- Take payment and prevent payment fraud
- Why
- To be paid and to protect both of us
- Legal basis
- Performance of a contract, and our legitimate interest in preventing fraud
- What we do
- Keep accounting and tax records
- Why
- To meet our obligations in Sri Lanka
- Legal basis
- Legal obligation
- What we do
- Handle complaints, insurance and legal claims
- Why
- To resolve issues and defend claims
- Legal basis
- Our legitimate interest in managing our business
- What we do
- Improve the website using analytics
- Why
- To understand what is useful
- Legal basis
- Your consent, given through the cookie banner
- What we do
- Send marketing emails and newsletters
- Why
- To tell you about trips and offers
- Legal basis
- Your consent, which you can withdraw at any time
- What we do
- Respond in a medical or safety emergency
- Why
- To protect life
- Legal basis
- Vital interests of you or another person
| What we do | Why | Legal basis |
|---|---|---|
| Prepare a quotation and answer an enquiry | To respond to you and design a trip | Steps at your request before entering a contract |
| Confirm and deliver your booking | To perform the contract | Performance of a contract |
| Send your details to hotels, drivers, guides and activity operators | So the services can be delivered | Performance of a contract |
| Arrange requirements arising from health, disability or diet | To keep you safe and meet your needs | Your explicit consent, given when you tell us |
| Take payment and prevent payment fraud | To be paid and to protect both of us | Performance of a contract, and our legitimate interest in preventing fraud |
| Keep accounting and tax records | To meet our obligations in Sri Lanka | Legal obligation |
| Handle complaints, insurance and legal claims | To resolve issues and defend claims | Our legitimate interest in managing our business |
| Improve the website using analytics | To understand what is useful | Your consent, given through the cookie banner |
| Send marketing emails and newsletters | To tell you about trips and offers | Your consent, which you can withdraw at any time |
| Respond in a medical or safety emergency | To protect life | Vital interests of you or another person |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling of that kind.
4. Who we share it with
Arranging travel necessarily means sharing your details with the businesses that deliver it.
- Accommodation providers: hotels, villas, resorts and lodges, which receive names, dates, room requirements and any relevant requirements you have disclosed.
- Transport providers and drivers: names, pickup details and contact number.
- Guides, safari operators and activity operators: names, party details and, where safety requires it, relevant health or fitness information.
- Rail, air and seaplane operators, where a ticket must be issued in your name.
- National park and permit authorities, where a permit requires passenger details.
- Our bank, for receiving payments. We do not take card payments through this website and this website has no payment page.
- Where a booking is paid through a payment provider rather than by bank transfer, that provider is named in your quotation before you pay.
- Website hosting: Vercel, which serves this website. Vercel processes technical request data such as IP addresses in order to deliver the site and protect it from abuse.
- Business email and file storage, used to hold your booking correspondence and itinerary documents.
- We do not use website analytics, advertising platforms or customer tracking tools. See our Cookie Policy.
- Professional advisers: accountants, auditors, insurers and lawyers, where needed.
- Government authorities and regulators, where the law requires disclosure.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
5. International transfers
We are established in Sri Lanka. If you live in the United Kingdom, the European Union or the European Economic Area, arranging your trip necessarily involves transferring your data outside your own country.
- Your data is transferred to Sri Lanka, where we operate and where our suppliers are located.
- Sri Lanka has not been the subject of an adequacy decision by the European Commission or the United Kingdom, so an appropriate safeguard or a derogation is needed for transfers from the EU or the UK.
- Where the EU or UK GDPR applies, the transfer of your booking data to us in Sri Lanka is necessary for the performance of the contract between you and us, and for the pre-contractual steps you asked us to take. We rely on that basis, in Article 49(1)(b) of the GDPR and the equivalent UK provision, because your trip cannot be arranged or delivered without it.
- The same applies to the onward transfer of your details to the Sri Lankan hotels, drivers, guides and activity operators who deliver your trip, which is necessary for the performance of your contract with us.
- Where we use a processor rather than a travel supplier, we put appropriate contractual protections in place, including standard contractual clauses where they are required.
- Our website host operates a global network and may process technical request data in a region close to the visitor. Our business email and file storage may hold data outside Sri Lanka. Ask us and we will tell you the current arrangements for a specific service.
We do not claim to be "GDPR compliant" as a slogan. We describe what we actually do. If you need details of the safeguards for a particular transfer, ask us and we will provide them.
6. How long we keep it
- Type of record
- Enquiries that do not become bookings
- Retention period
- 24 months from your last contact with us
- Type of record
- Booking and itinerary records
- Retention period
- 6 years from the end of your trip, which covers the period in which a claim could be brought
- Type of record
- Accounting and tax records
- Retention period
- The period required by Sri Lankan companies and tax legislation, which we apply as 6 years from the end of the financial year concerned
- Type of record
- Passport details
- Retention period
- Deleted once your trip is complete and no permit, ticket or claim still requires them, and in any event within 6 months
- Type of record
- Health, dietary and accessibility information
- Retention period
- Deleted within 3 months of the end of your trip, unless a claim or complaint is open
- Type of record
- Complaints and claims files
- Retention period
- 6 years from resolution
- Type of record
- Marketing consents and opt-outs
- Retention period
- Until you withdraw consent, and a record of the withdrawal afterwards
- Type of record
- Website analytics
- Retention period
- As set out in our Cookie Policy
| Type of record | Retention period |
|---|---|
| Enquiries that do not become bookings | 24 months from your last contact with us |
| Booking and itinerary records | 6 years from the end of your trip, which covers the period in which a claim could be brought |
| Accounting and tax records | The period required by Sri Lankan companies and tax legislation, which we apply as 6 years from the end of the financial year concerned |
| Passport details | Deleted once your trip is complete and no permit, ticket or claim still requires them, and in any event within 6 months |
| Health, dietary and accessibility information | Deleted within 3 months of the end of your trip, unless a claim or complaint is open |
| Complaints and claims files | 6 years from resolution |
| Marketing consents and opt-outs | Until you withdraw consent, and a record of the withdrawal afterwards |
| Website analytics | As set out in our Cookie Policy |
Where a complaint, claim, insurance matter or investigation is open, we keep the records that relate to it until it is closed and the period for challenging the outcome has passed. We review what we hold and delete or anonymise records that are no longer needed.
7. Your rights
Depending on where you live and which law applies, you may have the right to:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- ask us to delete data we no longer need;
- ask us to restrict how we use your data while a question is resolved;
- object to processing we carry out on the basis of legitimate interests;
- receive certain data in a portable format, or ask us to transmit it to another controller;
- withdraw consent at any time, without affecting processing already carried out; and
- complain to a data protection authority.
To exercise any of these, write to contact@zelenso.com. We will respond within one month, and we will tell you if we need longer because a request is complex. We may ask you to confirm your identity before we release data.
If you live in the European Union or the United Kingdom you may complain to your national supervisory authority. If your data is processed in Sri Lanka you may also contact the Data Protection Authority of Sri Lanka.
8. Marketing
- We send marketing only where you have asked to receive it, or where the law otherwise permits it.
- Every marketing email carries an unsubscribe link that works.
- If we contact you by WhatsApp or messaging apps, it is to service a booking or an enquiry you started, unless you have separately agreed to marketing that way.
- You can opt out at any time by using the unsubscribe link or writing to contact@zelenso.com.
- Advertising and remarketing cookies are only set with your consent. See our Cookie Policy.
9. Security
We take reasonable technical and organisational measures to protect your data, including access controls, encrypted connections to this website, restricting who can see sensitive information and using reputable service providers.
No system is completely secure, and we do not claim otherwise. Please do not send passport scans or payment card details to us by ordinary email or messaging app. Ask us for a secure method.
10. Data breaches
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the time the applicable law requires, and we will tell you directly where the law requires it or where telling you would help you protect yourself.
11. Children
Our services are sold to adults. We collect data about children only as part of a family booking, from the adult making the booking, and we use it only to arrange the trip. We do not knowingly market to children.
12. Cookies
Cookies and similar technologies are covered in our Cookie Policy.
13. Which data protection law applies
- We are established in Sri Lanka and are subject to the Personal Data Protection Act No. 9 of 2022, whose principal obligations came into operation on 18 March 2025.
- Because we offer services to travellers in the European Union and the United Kingdom, the EU GDPR and UK GDPR may also apply to processing connected with those offers.
- [LAWYER REVIEW REQUIRED: confirmation of the extent to which the EU GDPR and UK GDPR apply to Zelenso's processing, and whether an Article 27 representative in the EU or UK must be appointed.]
14. Changes to this policy
We will update this policy when our practices change. The version and date at the top show when it was last revised. Where a change is significant, we will tell affected travellers directly.
Discover your next Sri Lanka adventure
From ancient sacred temples and misty tea highlands to serene golden sunsets, let our experts curate your perfect private island journey.

