Privacy Policy
How RENTITEM.LK (PVT) LTD collects, uses, retains and protects your personal data, aligned with Sri Lanka's Personal Data Protection Act No. 9 of 2022.
Version and effective date
Version 3.0
26 July 2026
Data controller
RENTITEM.LK (PVT) LTD
Company No. PV 00307947
No. 113/28, Dr. NM Perera Mawatha, Colombo 08, 00800, Sri Lanka
Introduction
- This Privacy Policy explains how RENTITEM.LK (PVT) LTD ("Rentitem.lk", "the Company", "we", "us") collects, uses, stores, shares, and protects your personal data, and the rights you have over that data. It is written to comply with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka (the "PDPA").
- It applies to our website, WhatsApp and phone channels, our stores and delivery operations, and every rental or service you take from us. Where the law requires your consent for a specific purpose, we ask for it separately and you may withdraw it at any time.
1. Who is responsible for your data
- The data controller is RENTITEM.LK (PVT) LTD (Company No. PV 00307947), of No. 113/28, Dr. NM Perera Mawatha, Colombo 08, 00800, Sri Lanka.
- Data Protection Officer (DPO): You can reach our DPO for any privacy question, request, or complaint at legal@rentitem.lk, or by post to "The DPO" at our registered office.
2. What personal data we collect
We collect only what a stated purpose needs (data minimisation). Depending on how you interact with us, this may include:
- Identity and contact data: Full name, date of birth (only where age or eligibility must be confirmed), NIC / passport / driving licence details and a copy, phone and WhatsApp numbers, email, postal and delivery addresses, and address location pins.
- Verification and account data: Your verification tier and completed verification items, profile photo and (for higher tiers) additional customer photos you upload, and for business/corporate accounts your business registration, authorised contacts, and purchase-order references.
- Transaction and rental data: Items rented, dates, prices, deposits, invoices, and payment records (we record that a payment was made and its reference; we do not store full card numbers or CVV), plus delivery, condition-check, and return records.
- Communications: Messages you send us on WhatsApp, email, or website chat, and our replies, and recordings of calls to and from our official numbers where recording applies (you are notified).
- Technical and usage data: IP address, device and browser information, and cookies/analytics on our website.
- Security data: CCTV footage at our premises, and photos taken at handover and return to record equipment condition.
- Event media: For videography, photography, and operator services only, photos and video captured during a service we provide to you.
- We do not knowingly collect data from anyone under 18, and we do not collect biometric data (fingerprints, face-geometry, or voiceprints).
3. Why we use your data, and our lawful basis
Under the PDPA we must have a lawful basis for each purpose:
- Fulfil your booking; deliver, set up, and collect equipment: Performance of our contract with you.
- Verify identity and eligibility; set the security deposit: Performance of contract and our legitimate interest in preventing fraud and loss.
- Take and refund deposits, invoice you, and recover money owed: Performance of contract and legal obligation (tax/accounting).
- Prevent, detect, and investigate fraud, theft, and misuse: Our legitimate interest in protecting our property and other customers, balanced against your rights.
- Respond to your messages and provide support: Performance of contract or your request.
- Keep accounting and tax records: Legal obligation.
- Send you marketing about our products: Only with your separate opt-in consent.
- Use event media for our portfolio/marketing: Legitimate interest, and only if you have not opted out in writing before the event.
- Website analytics and cookies: Your consent, via the cookie banner.
- Verification documents are never used for marketing, ever.
4. How we use AI and automation
- We use software automation and AI tools to help with booking accuracy, identity checks, fraud detection, communication logs, and equipment diagnostics. AI assists our staff; it does not make final eligibility or blacklist decisions on its own.
- If any decision that significantly affects you were ever made by automated means alone, you have the right to ask for human review (see section 7). Identity-document image analysis runs on our own local systems and the document does not leave our controlled environment.
6. Evidence in fraud, theft, or non-return cases
- If equipment is not returned, or in cases of fraud, theft, threats, or unpaid amounts, we may compile relevant records (identity copies, communications, photos, invoices, payment records, CCTV) and share them with the police, the courts, your bank or payment provider, and our lawyers, strictly to recover our property or money and to support lawful proceedings.
- We do not publish your identity documents, photographs, or private messages on our website or social media. Recovery is handled through lawful channels, not public exposure.
7. How long we keep your data
We keep data only as long as the purpose and the law require:
- Transaction, invoice, and accounting records: 7 years after the transaction (tax/accounting law).
- Verification documents (NIC/passport/DL copies): 3 years for individuals, 7 years for corporate accounts, then securely destroyed; sooner on a valid erasure request unless we must keep them for a legal claim.
- Communication logs (WhatsApp/email/chat): Up to 3 years from last contact, then summary-only.
- Call recordings: Up to 12 months, unless needed for a specific dispute.
- CCTV footage: Typically 30 to 90 days, unless flagged for an incident.
- Marketing consent and preferences: Until you withdraw consent.
- When retention ends, data is securely deleted or anonymised.
8. Your rights under the PDPA
You have the right to:
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase your data (right to be forgotten), where no legal reason to keep it applies
- Withdraw consent at any time for anything based on consent (for example, marketing)
- Object to processing based on legitimate interests, and to solely-automated decisions, and ask for human review
- Restrict processing while a dispute about your data is resolved
- Complain to us and, if unresolved, to the Data Protection Authority of Sri Lanka
- How to exercise a right: Email legal@rentitem.lk or write to our DPO. We will verify your identity to protect your data and respond within 21 business days, telling you whether we can grant the request and why. There is normally no charge.
9. Data we never store
- To protect you, we do not store full payment-card numbers or CVV codes (handled by the payment provider), your plaintext passwords (we store only a secure hash), or biometric data. Please do not send us card numbers or passwords over chat or email.
10. How we protect your data
- Access is restricted to staff who need it, and sensitive verification documents are held in an encrypted archive with access logged.
- Data is encrypted in transit and, for sensitive categories, at rest.
- We do not load third-party tracking scripts on pages where you upload identity documents, and we keep no real customer data in test systems.
11. Data breach
- If a personal-data breach occurs that is likely to affect you, we will notify the Data Protection Authority within 72 hours of becoming aware of it, and notify you without undue delay where the law requires, along with the steps we are taking.
13. Cross-border transfers
- We store and process data primarily in Sri Lanka. If any service provider processes data outside Sri Lanka, we ensure appropriate safeguards consistent with the PDPA before doing so.
14. Children
- Our services are for adults (18+). We do not knowingly collect the data of children. If you believe a child's data has reached us, contact legal@rentitem.lk and we will delete it.
15. Changes to this Policy
- We may update this Policy. We will post the new version with a new effective date and keep a dated change log. Material changes are announced; we do not change the basis on which we already processed your data retroactively. The version in force when you gave data or made a booking is the version that governed it.
© 2026 RENTITEM.LK (PVT) LTD. See also our Terms & Conditions, Refund & Cancellation Policy, Damage & Deposit Policy and Trademark Notice.