Effective Date: 01 June 2026
This Privacy Policy explains how Pro CODE collects, uses, stores, protects, shares, retains, and manages customer information in connection with its website, accounts, orders, quotations, invoices, subscriptions, payment verification, dashboard features, installation support, warranty support, and related services.
Document Structure
- 1. Preliminary Provisions, Scope and Application
- 2. Definitions and Interpretation
- 3. Categories of Personal Information Collected
- 4. Sources from Which Information May Be Obtained
- 5. Purposes for Which Information Is Processed
- 6. Lawful Basis, Consent and Customer Authority
- 7. Account Creation, Email Verification and Identity Confirmation
- 8. Payment, Invoice, Quotation and Transaction Records
- 9. Customer Dashboard, Profile Details and Subscription Records
- 10. Communications Through Email, WhatsApp and Other Channels
- 11. Cookies, Website Logs and Similar Technologies
- 12. Technical Support, Remote Assistance and Installation Help
- 13. Disclosure of Information to Third Parties
- 14. International Transfers and External Platforms
- 15. Data Retention and Deletion
- 16. Security and Confidentiality Measures
- 17. Customer Rights, Access Requests and Corrections
- 18. Marketing Communications and Promotional Messages
- 19. Minors and Use by Students
- 20. Automated Processing and Fraud Prevention
- 21. Data Breach Handling and Notifications
- 22. Changes to This Privacy Policy
- 23. Contact, Complaints and Privacy Requests
- 24. Miscellaneous Privacy Provisions
Opening Statement
This document is written in a deliberately formal and comprehensive commercial style so that the policies of Pro CODE may be presented in a manner consistent with a traditional legal document; nevertheless, the provisions are intended to be used transparently, published clearly on the Website, and reviewed by customers as part of the ordinary process of purchasing digital Products and Services from the Company.
1. PRELIMINARY PROVISIONS, SCOPE AND APPLICATION
1.1 Purpose and policy objective. This Privacy Policy sets out, in a formal and comprehensive manner, the basis upon which Pro CODE, being a business engaged in the online supply of software subscriptions, digital product access, activation assistance, customer support, quotation issuance, invoice generation, dashboard-based subscription management and related services, may collect, receive, record, organize, store, consult, use, disclose, transmit, retain, restrict, erase or otherwise process personal information relating to customers, prospective customers, website visitors, account holders, support requesters and any other persons who interact with the Website or the Company through electronic, written, verbal or other means of communication.
1.2 Application to all customer interactions. This Privacy Policy shall apply to all interactions between the Company and the Customer, whether such interaction occurs through the Website, by means of an online order form, through a customer dashboard, by email, by WhatsApp, through a payment slip submission, through a support request, through social media communication, through telephone communication, through remote assistance, or by any other medium which the Company may from time to time make available for the purpose of providing Products, Services, customer care, order processing, account administration or post-sale support.
1.3 Relationship with other documents. This Privacy Policy shall be read together with the Terms and Conditions, Refund Policy, Warranty Policy, Delivery Policy, Support Policy, Cookie Policy, account registration requirements, order confirmation notices, invoices, quotations, product pages and any additional written notices made available by the Company, and where any specific notice provides more detailed information concerning a particular processing activity, such specific notice shall supplement, and shall not be deemed to replace, the provisions contained herein unless expressly stated otherwise.
1.4 General privacy commitment. The Company recognizes that customer information is commercially and personally important, and accordingly intends, subject to the practical requirements of operating an online digital products business, to process personal information in a manner that is reasonably secure, proportionate, purpose-related, transparent and consistent with the legitimate expectations arising from the relationship between the Company and the Customer.
2. DEFINITIONS AND INTERPRETATION
2.1 Company and related expressions. For the purposes of this Privacy Policy, the expressions “Company”, “we”, “us”, “our” and similar grammatical variations shall mean and refer to Pro CODE, together with its owners, administrators, employees, contractors, support personnel, authorized representatives and operational service providers, but only to the extent that such persons are acting for or on behalf of the Company in connection with the Website, Products or Services.
2.2 Customer and user expressions. The expressions “Customer”, “User”, “you”, “your”, “Purchaser”, “Account Holder” and similar grammatical variations shall mean and include any individual, organization, institution, representative, employee, student, parent, guardian, business customer or other person who accesses the Website, creates an account, submits an order, requests a quotation, purchases a subscription, downloads an invoice, uploads a payment slip, requests installation assistance, contacts support, or otherwise provides information to the Company.
2.3 Personal information. The expression “Personal Information” shall mean any information which identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to a particular natural person, including, without limitation, name, email address, WhatsApp number, telephone number, billing information, payment confirmation information, order history, subscription records, support communications, account credentials, device information, internet protocol information and any other information that may be capable of identifying or contacting the relevant person.
2.4 Processing. The expression “Processing” shall include any operation or set of operations performed upon Personal Information, whether or not by automated means, including collection, recording, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, erasure, destruction, backup, archival or any other handling of such information in the course of the Company carrying out its business activities.
2.5 Interpretation. Words importing the singular shall include the plural and vice versa, references to a gender shall include every gender, references to electronic communication shall include any digital or electronically stored communication, and headings are inserted for convenience of reference only and shall not affect the construction or interpretation of this Privacy Policy.
3. CATEGORIES OF PERSONAL INFORMATION COLLECTED
3.1 Identity and contact information. The Company may collect identity and contact information including the Customer name, business or institution name, email address, WhatsApp number, mobile number, country, general location, billing name, account username and any other contact details reasonably required for the purpose of communicating with the Customer, verifying an account, processing an order, generating an invoice, providing subscription access or responding to a support request.
3.2 Account and authentication information. The Company may collect account-related information including login details, email verification status, password-related technical records, account creation date, account activity records, dashboard preferences, saved profile details and any other information submitted or generated in connection with the Customer creating, maintaining, changing, authenticating, accessing or recovering a user account.
3.3 Order and subscription information. The Company may collect order information including selected Product, package or subscription period, order number, invoice number, quotation reference, warranty period, subscription start date, subscription expiry date, product delivery status, payment status, dashboard purchase history, renewal reminders and communications made in relation to any Product or Service purchased or requested by the Customer.
3.4 Payment and billing information. The Company may collect billing and payment-related information including payment method, payment date, bank transfer confirmation details, payment slip images or files, transaction references, invoice details, quotation details, refund records, chargeback communications and any other information necessary to verify whether an order has been validly paid and whether an invoice or refund record should be issued.
3.5 Technical and device information. When the Customer uses the Website or requests technical support, the Company may collect technical information such as internet protocol address, browser type, device type, operating system, approximate access time, pages visited, error records, installation issue descriptions, screenshots voluntarily shared by the Customer and other technical diagnostics that are reasonably relevant to the provision, security, troubleshooting, improvement or protection of the Website and Services.
3.6 Support and communication information. The Company may collect and store communications including emails, WhatsApp messages, website form submissions, support tickets, installation requests, warranty requests, refund requests, complaint records, audio or written notes prepared by support personnel and any documents, images, screenshots or files voluntarily provided by the Customer during such communications.
3.7 Optional information. Where the Website or support process permits the Customer to provide optional information, including business field, intended software use, preferred version, student or professional category, additional billing instructions or any other non-mandatory details, such information shall be processed on the basis that the Customer voluntarily submitted it for the purpose of obtaining a more accurate service, quotation, recommendation or support response.
4. SOURCES FROM WHICH INFORMATION MAY BE OBTAINED
4.1 Direct collection from the Customer. Most Personal Information processed by the Company is collected directly from the Customer when the Customer accesses the Website, completes an order form, creates an account, verifies an email address, enters profile information, selects a subscription, requests a quotation, uploads a payment slip, downloads an invoice, submits a support request, contacts the Company through WhatsApp or otherwise voluntarily provides information in connection with a Product or Service.
4.2 Information generated by the Website. Certain information may be generated automatically when the Customer uses the Website, including log records, session data, cookie identifiers, device details, dashboard activity, page access records, system error information and other technical information which assists the Company in maintaining the security, functionality, performance and usability of the Website.
4.3 Information from service providers. The Company may receive limited information from payment processors, banks, hosting providers, email delivery providers, analytics providers, communication tools, software vendors or other operational service providers, but only to the extent that such information is relevant to confirming payment, delivering a Product, maintaining customer accounts, preventing fraud, responding to support requests, protecting business systems or fulfilling legal or administrative obligations.
4.4 Information from authorized representatives. Where a Customer acts through an employee, parent, guardian, purchasing officer, institution, company representative or any other person purporting to act with authority, the Company may collect and process information submitted by such representative and may reasonably rely upon the accuracy and authority of that representative unless the Company is clearly notified otherwise in writing.
5. PURPOSES FOR WHICH INFORMATION IS PROCESSED
5.1 Account administration. The Company may process Personal Information for the purpose of creating, verifying, maintaining, securing, updating, suspending, restoring or closing user accounts, including confirming that the email address and WhatsApp number provided by the Customer are valid and suitable for receiving order-related and subscription-related communications.
5.2 Order processing and delivery. The Company may process Personal Information for the purpose of receiving orders, verifying payment, confirming subscription selections, issuing order confirmations, arranging digital delivery, enabling activation, communicating access instructions, maintaining delivery records and providing evidence of the services supplied to the Customer.
5.3 Invoice and quotation administration. The Company may process Personal Information for the purpose of generating, storing, making available for download, reissuing or correcting invoices, quotations, receipts, payment acknowledgments and other transaction documents, including documents which contain customer name, billing information, selected Product, subscription period, price, date, invoice number and related references.
5.4 Support and warranty services. The Company may process Personal Information for the purpose of providing technical assistance, installation support, warranty support, update guidance, troubleshooting, customer communication, dispute handling and after-sales service throughout the relevant subscription or warranty period.
5.5 Website operation and improvement. The Company may process Personal Information and technical information for the purpose of operating, maintaining, testing, improving, securing and optimizing the Website, dashboard, order forms, invoice download features, customer profile features and other online systems used by the Customer.
5.6 Fraud prevention and business protection. The Company may process Personal Information to verify payment slips, detect duplicate payments, identify suspicious orders, prevent unauthorized account access, investigate refund abuse, handle chargebacks, protect intellectual property, enforce the Terms and Conditions and preserve the lawful business interests of the Company.
5.7 Legal and regulatory purposes. The Company may process Personal Information where reasonably necessary to comply with applicable laws, tax or accounting obligations, lawful requests, court orders, dispute resolution procedures, consumer inquiries, regulatory requirements or any other legal or administrative obligation to which the Company may be subject.
6. LAWFUL BASIS, CONSENT AND CUSTOMER AUTHORITY
6.1 Customer consent and instruction. By creating an account, submitting an order, providing Personal Information, uploading a payment slip, requesting support, downloading an invoice or otherwise interacting with the Company, the Customer acknowledges that the Company may process such Personal Information for the purposes described in this Privacy Policy and for any additional purpose that is reasonably necessary to perform the requested transaction or service.
6.2 Contractual necessity. Where the Customer purchases or attempts to purchase a Product or Service, the Company may process Personal Information to the extent reasonably necessary for taking steps at the request of the Customer prior to entering into a transaction, completing the transaction, delivering the Product, providing support and administering the contractual relationship between the Company and the Customer.
6.3 Legitimate business interests. The Company may process Personal Information where such processing is reasonably required for the Company to operate a lawful online business, protect its systems, prevent fraud, maintain records, manage customer relationships, improve services, enforce its terms, handle disputes and communicate with Customers about purchased Products or Services, provided that such processing is carried out in a proportionate manner.
6.4 Legal compliance. The Company may process and retain Personal Information where such processing or retention is reasonably necessary for compliance with applicable legal, accounting, tax, consumer, administrative, evidential, regulatory or dispute-related obligations.
6.5 Withdrawal of consent. Where any processing activity is based solely upon consent, the Customer may request withdrawal of such consent by contacting the Company, provided that withdrawal shall not affect processing already carried out lawfully prior to the withdrawal and shall not prevent the Company from retaining information where retention is required for contractual, legal, accounting, security, dispute or legitimate business purposes.
7. ACCOUNT CREATION, EMAIL VERIFICATION AND IDENTITY CONFIRMATION
7.1 Mandatory email verification. The Customer may be required to provide a valid email address and to complete the email verification process before the Company activates the account, processes the order, attaches a subscription to the account, provides downloadable invoices or enables full customer dashboard access, and any delay or failure in completing such verification may result in delay, suspension or non-completion of the requested service.
7.2 WhatsApp and phone confirmation. The Company may request a WhatsApp number or telephone number for the purpose of order confirmation, delivery coordination, subscription clarification, support communication, invoice identification, fraud prevention or customer verification, and the Customer acknowledges that inaccurate or inaccessible contact details may materially affect the ability of the Company to provide timely service.
7.3 Profile changes. Where the Customer changes profile details, including name, email address, WhatsApp number, billing information or subscription-related contact details, the Company may process and store both current and previous information to the extent necessary to preserve order history, prevent unauthorized changes, maintain invoice accuracy, protect account security and verify support or warranty requests.
7.4 Verification limits. Email, WhatsApp or identity verification procedures are administrative security measures intended to reduce errors and misuse, and the Company does not represent that such procedures will prevent every unauthorized action, fraudulent attempt, mistaken order, inaccurate submission or third-party misuse of customer credentials.
8. PAYMENT, INVOICE, QUOTATION AND TRANSACTION RECORDS
8.1 Payment records. The Company may process payment-related information to confirm that the Customer has paid the correct amount for the selected Product, subscription period, package or service, and such information may include payment slip images, transaction reference numbers, payment date, payer name, bank information visible on the payment proof and any other details reasonably required to match the payment to the corresponding order.
8.2 Invoice information. The Company may generate and retain invoices containing customer information, Product information, subscription duration, warranty period, invoice number, payment amount, payment status, delivery date and related transaction details, and such invoices may be made available within the Customer dashboard for viewing, downloading, printing or business record purposes.
8.3 Quotation information. Where the Customer requests a quotation, the Company may process the Customer name, contact details, requested Products, subscription terms, quantity, validity period, discount eligibility, business or institutional details and any other details necessary to prepare, issue, revise, store or later convert such quotation into an order.
8.4 Record retention for disputes. Payment, quotation and invoice records may be retained for a reasonable period after the completion, cancellation, refund, expiry or termination of the relevant order where such retention is reasonably necessary for accounting, taxation, customer service, fraud prevention, chargeback defense, warranty verification or dispute resolution purposes.
9. CUSTOMER DASHBOARD, PROFILE DETAILS AND SUBSCRIPTION RECORDS
9.1 Dashboard records. The Customer dashboard may display, store or make available Personal Information and order-related information including profile details, Product names, packages, subscription periods, order dates, expiry dates, warranty status, invoice downloads, quotation downloads, payment status, support history and other information which the Company considers useful for transparent customer account administration.
9.2 Customer responsibility for dashboard accuracy. The Customer shall be responsible for reviewing dashboard information and promptly notifying the Company of any error, omission, outdated information, unauthorized change or suspected misuse, and failure to notify the Company within a reasonable time may limit the ability of the Company to correct historical records, revise invoices or investigate account activity.
9.3 Administrative changes. The Company may update dashboard records when necessary to correct errors, reflect payment verification, record subscription changes, update warranty status, attach invoices, remove duplicated entries, close expired subscriptions or maintain the functional integrity of the Website and account management system.
9.4 Visibility limitation. Dashboard information is provided for customer convenience and administrative transparency, and the Company may restrict, suspend, hide, correct, archive or remove dashboard features where required for system maintenance, account security, legal compliance, suspected misuse, platform changes or business operational reasons.
10. COMMUNICATIONS THROUGH EMAIL, WHATSAPP AND OTHER CHANNELS
10.1 Order communications. The Company may use the Customer email address, WhatsApp number or other contact details to send order confirmations, payment verification messages, delivery instructions, activation guidance, invoice notifications, quotation responses, warranty messages, renewal reminders, account security alerts and other communications directly related to Products or Services requested or purchased by the Customer.
10.2 Support communications. Support communications may be stored and reviewed for the purpose of resolving the relevant issue, training support personnel, maintaining service quality, verifying warranty eligibility, preventing repeated errors, investigating complaints and documenting the assistance provided to the Customer.
10.3 Communication channel risks. The Customer acknowledges that communication through email, WhatsApp, social media platforms, messaging applications or other third-party communication channels may be subject to security limitations, service interruptions, platform policies and privacy practices outside the direct control of the Company, and the Customer should avoid sending unnecessary sensitive information through such channels unless it is required for the specific support or order issue.
10.4 Customer instructions by message. Where the Customer provides instructions, approvals, profile changes, order confirmations, refund requests, support authorizations or other directions through WhatsApp, email or similar communication methods, the Company may retain such communications as evidence of the instruction and may rely upon them where it reasonably believes the instruction was sent by the Customer or an authorized representative.
11. COOKIES, WEBSITE LOGS AND SIMILAR TECHNOLOGIES
11.1 Cookies and technical identifiers. The Website may use cookies, local storage, session identifiers, analytics tags, security tokens or similar technologies for purposes including maintaining login sessions, remembering user preferences, improving website performance, securing account access, measuring traffic, diagnosing errors and enabling features such as shopping cart functionality, order forms and dashboard access.
11.2 Analytics and performance records. The Company may process aggregated or individual technical information concerning page visits, device characteristics, referral sources, browser information, approximate access times and website interactions in order to understand how the Website is used, identify technical issues, improve customer experience and protect the Website from abuse.
11.3 Cookie controls. The Customer may be able to manage or disable certain cookies through browser settings, device settings or Website options, provided that disabling essential cookies may impair account login, order submission, invoice download, dashboard display, security verification or other necessary Website functions.
11.4 Third-party tools. Where analytics, security, payment, email or communication tools provided by third parties are used in connection with the Website, those tools may place or read cookies or similar identifiers in accordance with their own technical configurations, and the Company shall take reasonable steps to use such tools for legitimate business purposes associated with Website functionality, security and service delivery.
12. TECHNICAL SUPPORT, REMOTE ASSISTANCE AND INSTALLATION HELP
12.1 Support data collection. When the Customer requests installation assistance, activation guidance, update help, warranty support, troubleshooting or similar technical support, the Company may process information concerning the Customer device, software environment, operating system, error messages, screenshots, Product version, Autodesk account status or other technical details which the Customer provides or which becomes visible during the support interaction.
12.2 Remote assistance. Where the Customer voluntarily permits remote assistance through AnyDesk or any other remote support tool, the Customer remains responsible for ensuring that private files, passwords, financial documents, personal documents and unrelated sensitive information are closed, hidden or removed from view before granting access, and the Company shall use such access only for the purpose of providing the requested technical assistance unless otherwise expressly authorized by the Customer.
12.3 Support records. The Company may record notes concerning support actions taken, issue descriptions, troubleshooting steps, customer confirmations, activation outcomes and warranty decisions so that the Company can maintain continuity of service, respond to follow-up issues, verify whether assistance was provided and protect both parties in the event of later disagreement.
12.4 No unnecessary access. The Customer should not provide unnecessary passwords, unrelated personal files or confidential third-party information to the Company, and where such information is incidentally disclosed during support, the Company may disregard, delete or avoid recording such information where practical and not necessary for the support purpose.
13. DISCLOSURE OF INFORMATION TO THIRD PARTIES
13.1 Operational service providers. The Company may disclose Personal Information to hosting providers, payment processors, banks, email delivery services, communication platforms, analytics providers, fraud prevention tools, cloud storage providers, accounting advisers, technical support providers and other operational service providers to the extent reasonably necessary for the Company to provide the Website, process orders, verify payments, issue invoices, deliver Products, maintain customer accounts or provide support.
13.2 Software vendors and external platforms. Where delivery or activation of a Product requires interaction with Autodesk, software vendor accounts, license management systems, email invitation systems, cloud storage systems or other external platforms, the Company may process or transmit the minimum information reasonably necessary to enable such delivery, activation, subscription association, support or warranty administration.
13.3 Legal and protective disclosure. The Company may disclose Personal Information where reasonably necessary to comply with legal obligations, respond to lawful requests, enforce the Terms and Conditions, protect the rights and property of the Company, investigate suspected fraud, defend against chargebacks, resolve disputes, protect customers or prevent unauthorized use of the Website or Services.
13.4 No sale of customer information. The Company does not intend to sell Customer Personal Information as an independent commercial product, and any disclosure of information to service providers or third parties shall be made for operational, legal, support, transactional, security or business administration purposes rather than for the purpose of selling customer identity data to unrelated advertisers.
14. INTERNATIONAL TRANSFERS AND EXTERNAL PLATFORMS
14.1 Use of international services. Because many digital services, hosting systems, communication platforms, payment tools, software vendor systems and cloud-based business tools operate across multiple countries, Personal Information processed by or on behalf of the Company may be stored, accessed, routed, transmitted or otherwise processed outside Sri Lanka or outside the Customer country of residence.
14.2 Customer acknowledgement. By using the Website, creating an account, purchasing a Product, requesting support or communicating with the Company, the Customer acknowledges that such international transmission or storage may occur where reasonably necessary for order processing, product delivery, software activation, invoice administration, support, security, analytics or ordinary business operations.
14.3 Third-party platform terms. Where Personal Information is processed by a third-party platform, including payment, communication, email, hosting, software vendor, analytics or support platforms, the processing may be subject to the privacy notices, terms, security practices and data handling rules of that platform, and the Company shall not be responsible for matters outside its reasonable control.
14.4 Reasonable safeguards. The Company shall endeavor to use reputable service providers and reasonable administrative or technical safeguards suitable for the nature of the information and the commercial context, but the Customer acknowledges that no internet-based transmission, cloud service or electronic storage method can be guaranteed to be completely secure or uninterrupted.
15. DATA RETENTION AND DELETION
15.1 General retention principle. The Company shall retain Personal Information only for as long as it is reasonably necessary for the purposes for which it was collected, including account administration, order delivery, subscription management, invoice issuance, warranty support, customer service, accounting, taxation, fraud prevention, security, dispute handling, chargeback defense and legal compliance.
15.2 Account and subscription records. Account records, order histories, subscription periods, invoice details, warranty status and support notes may be retained after expiry of a subscription where such retention is reasonably necessary to prove the service provided, support a renewal, handle a complaint, verify warranty history, defend against a dispute or comply with accounting and administrative obligations.
15.3 Payment proof retention. Payment slips, payment confirmations and related transaction records may be retained for a reasonable business and legal retention period because such documents may be necessary to verify the identity of a transaction, investigate duplicate payments, respond to payment disputes, reconcile financial accounts or comply with tax and accounting requirements.
15.4 Deletion requests. Where the Customer requests deletion of Personal Information, the Company may delete, anonymize, restrict or archive the relevant information where reasonably possible, provided that the Company may refuse or delay deletion where retention is required or permitted for legal, contractual, accounting, taxation, security, warranty, support, fraud prevention or dispute resolution reasons.
16. SECURITY AND CONFIDENTIALITY MEASURES
16.1 Security measures. The Company shall use reasonable administrative, technical and organizational measures appropriate to the nature and scale of its business to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, including measures related to account credentials, administrative access, hosting environments, communication records and payment verification records.
16.2 Customer credential responsibility. The Customer shall be solely responsible for maintaining the confidentiality of account login details, email credentials, device access, WhatsApp account access and any other credentials used to interact with the Company, and the Company shall not be responsible for unauthorized access arising from the Customer failure to maintain such confidentiality or to secure the Customer own device or communication channels.
16.3 Limitations of security. While the Company intends to protect Personal Information through reasonable safeguards, the Customer acknowledges that electronic communications, internet transmissions, cloud storage, payment verification, remote assistance and online account systems involve inherent risks and that absolute security cannot be guaranteed by any commercial online service provider.
16.4 Restricted internal access. The Company shall endeavor to restrict access to Personal Information to those persons who require such access for order processing, customer support, payment verification, invoice administration, technical maintenance, management, legal compliance or other legitimate business purposes.
17. CUSTOMER RIGHTS, ACCESS REQUESTS AND CORRECTIONS
17.1 Access and copy requests. Subject to reasonable verification of identity, applicable law, system limitations and the rights of other persons, the Customer may request access to Personal Information held by the Company, including account information, order records, invoice details and support records which relate to that Customer.
17.2 Correction and update requests. The Customer may request correction of inaccurate or outdated Personal Information, and the Company may require supporting information or verification before making changes to information that affects invoices, order history, warranty records, subscription ownership, account security or payment verification.
17.3 Restriction and objection requests. The Customer may request restriction of certain processing activities or object to certain non-essential uses of Personal Information, provided that the Company may continue processing where necessary for contract performance, legal compliance, fraud prevention, account security, dispute resolution, invoice administration, warranty support or other legitimate business purposes.
17.4 Response time and format. The Company shall endeavor to respond to reasonable privacy requests within a commercially reasonable period, and may provide the response by email, dashboard message, WhatsApp or any other method reasonably suited to the nature of the request and the identity verification procedure used by the Company.
18. MARKETING COMMUNICATIONS AND PROMOTIONAL MESSAGES
18.1 Transactional messages. Messages concerning orders, payments, invoices, quotations, delivery, activation, warranty, support, account security, subscription expiry and policy changes shall be treated as transactional or service-related communications and may be sent to the Customer even where the Customer has opted out of purely promotional marketing messages.
18.2 Promotional communications. The Company may send marketing communications concerning new Products, discounts, subscription renewals, software updates, bundle offers, educational offers, professional packages or other promotions where the Customer has consented, where the Customer has an existing business relationship with the Company or where such communication is otherwise permitted in the ordinary course of business.
18.3 Opt-out. The Customer may request to stop receiving non-essential promotional communications by contacting the Company or using any available unsubscribe or opt-out method, provided that such opt-out shall not prevent the Company from sending necessary service communications related to active orders, subscriptions, invoices, warranty matters or account security.
18.4 Marketing accuracy. The Customer acknowledges that promotional information, prices, discounts, product lists, delivery estimates and warranty offers may change from time to time and that the current offer published on the Website or expressly confirmed by the Company at the time of purchase shall prevail over older promotional messages to the extent of any inconsistency.
19. MINORS AND USE BY STUDENTS
19.1 Use by students and younger customers. The Company may supply Products to students or for educational purposes; however, where a Customer is below the age required to validly enter into a binding commercial transaction, the Customer must obtain the involvement and consent of a parent, guardian or legally responsible person before creating an account, placing an order, submitting payment details or providing Personal Information.
19.2 Parent or guardian responsibility. Where a parent, guardian, teacher, institution or other responsible person purchases a Product for a student, that person shall be responsible for ensuring that the information submitted to the Company is accurate, authorized and appropriate, and the Company may treat the purchasing or communicating adult as the authorized representative for that transaction.
19.3 No intentional collection from children without involvement. The Company does not intentionally seek to collect unnecessary Personal Information from children, and where the Company becomes aware that information has been provided by a minor without appropriate consent or authorization, the Company may delete, restrict, correct or otherwise handle such information in a manner that is reasonable in the circumstances.
19.4 Educational use limitations. Student or educational references provided to the Company may be used only for the purposes of determining eligibility for offers, communicating about the relevant purchase, providing support and maintaining transaction records, unless the Customer separately consents to another use.
20. AUTOMATED PROCESSING AND FRAUD PREVENTION
20.1 Fraud prevention checks. The Company may use manual or automated checks to identify payment irregularities, repeated failed orders, suspicious account activity, unusual dashboard access, duplicate invoice requests, refund abuse, payment slip mismatches or other patterns which may indicate mistake, unauthorized use, fraud or breach of the Company Terms and Conditions.
20.2 Administrative decisions. Decisions concerning account verification, order approval, payment verification, delivery timing, refund eligibility, warranty status or support eligibility may be made by reference to Personal Information, order history, payment records, support records and other relevant information held by the Company.
20.3 Customer review request. Where the Customer believes that an administrative decision has been made incorrectly, the Customer may contact the Company with supporting information, and the Company may review the matter in its discretion and correct any error that it reasonably determines to have occurred.
20.4 No guarantee of approval. The provision of Personal Information, completion of an online form, uploading of a payment slip or creation of an account shall not require the Company to approve every order, provide every service, issue every refund or complete every support request where the Company reasonably determines that further verification, correction, restriction or refusal is necessary.
21. DATA BREACH HANDLING AND NOTIFICATIONS
21.1 Incident assessment. If the Company becomes aware of a suspected or actual unauthorized access, disclosure, alteration, loss or destruction of Personal Information, the Company shall assess the nature of the incident, the type of information involved, the likely consequences, the affected systems and the reasonable steps available to contain, investigate and remediate the incident.
21.2 Customer notification. Where the Company reasonably determines that notification is necessary or appropriate having regard to the nature and seriousness of the incident, the Company may notify affected Customers by email, dashboard notice, WhatsApp message or any other reasonable method, and such notice may include recommended protective steps where applicable.
21.3 Cooperation. The Customer shall cooperate with reasonable security instructions issued by the Company following a suspected incident, including changing passwords, verifying account activity, reviewing dashboard records or confirming whether any communication was authorized.
21.4 Limitations. The Company shall not be responsible for security incidents caused by the Customer own negligence, compromised email accounts, shared passwords, insecure devices, phishing attacks not caused by the Company or unauthorized third-party access occurring outside systems reasonably controlled by the Company.
22. CHANGES TO THIS PRIVACY POLICY
22.1 Right to amend. The Company may amend, revise, replace, supplement or update this Privacy Policy from time to time in order to reflect changes in the Website, Products, Services, customer dashboard, payment methods, legal requirements, service providers, technical systems or business practices.
22.2 Publication of updated policy. An updated version of this Privacy Policy may be published on the Website or otherwise made available to Customers, and the updated version shall take effect from the date stated in the updated document unless a later effective date is expressly provided.
22.3 Continued use. Continued access to the Website, continued use of the customer dashboard, continued placing of orders, continued request for support or continued use of the Services after publication of an updated Privacy Policy shall be deemed acceptance of the updated policy to the extent permitted by applicable law.
22.4 Material changes. Where the Company makes a material change that substantially affects the way Customer Personal Information is processed, the Company may provide additional notice by email, dashboard message, WhatsApp, website banner or any other method that the Company considers reasonable in the circumstances.
23. CONTACT, COMPLAINTS AND PRIVACY REQUESTS
23.1 Contact details. All privacy-related requests, corrections, objections, deletion requests, access requests, complaints or questions concerning this Privacy Policy should be directed to the Company using the contact channels published on the Website or through the following general details: Website: www.procode.lk; WhatsApp: +94 720 151 935; Email: support@procode.lk.
23.2 Identity verification for requests. Before responding to a privacy request, the Company may request information reasonably necessary to verify the identity and authority of the person making the request, including order number, invoice number, registered email address, WhatsApp number, payment reference or other reasonable confirmation details.
23.3 Requests through representatives. Where a privacy request is submitted by a representative, the Company may request evidence of authority before disclosing, correcting, deleting or restricting information associated with the relevant Customer account or transaction.
23.4 Complaint handling. The Company shall endeavor to consider privacy complaints in good faith and to provide a reasonable response, but nothing in this Privacy Policy shall prevent the Company from defending its legal rights, preserving records required for disputes or declining requests that are excessive, unclear, unverified, unlawful or inconsistent with the Company legitimate obligations.
24. MISCELLANEOUS PRIVACY PROVISIONS
24.1 Severability. If any provision of this Privacy Policy is held to be invalid, unlawful or unenforceable, the remaining provisions shall remain in full force and effect to the maximum extent permitted by law, and the invalid provision shall be interpreted or replaced in a manner that most closely reflects the lawful commercial intention of the original provision.
24.2 No waiver. No delay, failure or omission by the Company in exercising any privacy-related administrative right, security measure or record retention right shall constitute a waiver of such right, and any waiver must be expressly made in writing by the Company.
24.3 Language and interpretation. This Privacy Policy is drafted in English for formal business use, and where any translation, summary, explanation or simplified version is provided for customer convenience, the English version shall prevail to the extent of any inconsistency unless the Company expressly states otherwise in writing.
24.4 Governing context. This Privacy Policy is intended to operate in connection with the Company business activities in Sri Lanka and online digital commerce generally, and shall be interpreted consistently with applicable laws of Democratic Socialist Republic of Sri Lanka to the extent such laws are applicable to the Company, the Customer and the relevant transaction.
Prepared for: Pro CODE Contact: support@procode.lk | +94 720 151 935 | www.procode.lk