| Legal entity | Infinite Global Solutions (Private) Limited (“IGS”, “we”, “us”, “our”) |
| Company number | PV 00269216 |
| Registered office | No. 358/A/1/1, Negombo Road, Welisara, Ragama 11010, Sri Lanka |
| Website | https://www.igsolutions.lk |
| Privacy contact | igs.edu.lk@gmail.com (mark “Data Protection”) |
| Effective date | 21 August 2026 · Version 1.0 |
| Governing law | Personal Data Protection Act, No. 9 of 2022 & laws of Sri Lanka |
1. Who is responsible
Infinite Global Solutions (Private) Limited (Company No. PV 00269216), of No. 358/A/1/1, Negombo Road, Welisara, Ragama 11010, Sri Lanka, is the controller of personal data described in this Policy. Data-protection questions: igs.edu.lk@gmail.com (please mark the subject “Data Protection”).
Where we process data only on a client’s instructions (for example, hosting a client’s customer database), we act as a processor for that client and the client’s own privacy notice also applies.
2. What we collect
The categories we collect depend on how you deal with us.
| Context | Typical data |
|---|---|
| Website and enquiries | Name, phone, e-mail, message content, pages viewed, device/browser data, IP address, cookies. |
| Visa and travel support | Identity details, passport and NIC information, photos, education and employment history, financial evidence, travel history, family details, health or police certificates you choose to supply, and application status. |
| Software, apps and accounts | Account credentials, profile information you choose to publish, usage logs, device identifiers, support tickets, and in-app content you upload. |
| Payments | Invoice details, amount, currency, PayHere order/payment ID, payment status, and last four digits / method type only. We do not receive full card numbers, CVV or PINs. |
| Project clients | Business contact details, billing information, project files and access credentials you provide. |
| Automatically generated | Log files, approximate location from IP, cookie identifiers, and security/audit records. |
We collect data directly from you, from people you authorise (for example a parent or employer), and from third parties you ask us to deal with (universities, medical centres, payment gateways). We do not buy marketing lists.
3. Why we use it and on what legal basis
The Personal Data Protection Act, No. 9 of 2022 requires a lawful basis. We rely on the following.
| Purpose | Lawful basis |
|---|---|
| Respond to enquiries and provide a requested service | Performance of a contract, or steps you ask us to take before a contract. |
| Create and manage accounts, deliver digital features, provide support | Performance of a contract. |
| Process payments, invoices, refunds and accounting | Contract, and legal obligation (tax and financial records). |
| Prepare and submit visa or education applications you have instructed | Contract, and your consent where a special category of data is involved. |
| Security, fraud prevention, abuse investigation | Legitimate interests, balanced against your rights. |
| Improve our website and products (aggregated or de-identified where possible) | Legitimate interests. |
| Send service messages (receipts, appointment reminders, policy updates) | Contract or legitimate interests. |
| Send marketing only if you have opted in | Consent, which you may withdraw at any time. |
| Comply with law, regulators, courts or a lawful request | Legal obligation. |
Where we rely on consent, you may refuse or withdraw it without affecting services that do not depend on that consent. Withdrawal does not undo processing already lawfully carried out.
4. Sensitive data
Visa files sometimes include health information, police clearances or similar. We process that data only because you have asked us to handle the application, and only for that purpose. We do not use it for marketing. If you prefer not to supply a document through us, you may send it directly to the relevant authority where that authority allows.
5. Who we share data with
We share personal data only as needed:
- PayHere and banks — to take or refund a payment;
- Hosting, e-mail, SMS and support tools — to run our website, products and communications;
- Universities, colleges, immigration authorities, medical centres, insurers, couriers and airlines — where you have asked us to submit or support an application;
- Professional advisers (accountants, auditors, lawyers) under confidentiality;
- Regulators, the Data Protection Authority, law enforcement or courts — where the law requires or permits;
- A successor if our business is reorganised, subject to equivalent protections.
We do not sell personal data. We do not allow third parties to use your data for their own marketing.
6. Transfers outside Sri Lanka
Some processing happens outside Sri Lanka. Typical examples: a visa or education file sent to an institution in Malaysia, Singapore or another destination you have chosen; cloud hosting or e-mail infrastructure; or a payment message routed by an international card network.
Where we transfer personal data out of Sri Lanka we do so in line with the cross-border rules of the PDPA, and only to recipients who need the data for the purpose you have requested or who are bound by contractual or legal obligations offering a comparable level of protection.
7. Cookies and similar technology
Our website may use essential cookies to keep a session secure and remember form progress, and limited analytics cookies to understand how the site is used. You can block non-essential cookies in your browser. Blocking essential cookies may stop parts of the site from working. We do not use cookies to display third-party advertising on our site.
8. How long we keep data
| Record type | Typical retention |
|---|---|
| Enquiry that does not become a client | Up to 24 months after last contact. |
| Visa / project client file | Duration of the engagement plus 7 years, or longer if a related claim remains open. |
| Account and product usage data | While the account is active and up to 24 months after closure, unless a longer legal period applies. |
| Payment, invoice and refund records | Not less than 5 years from the end of the relevant financial year (Inland Revenue Act, No. 24 of 2017). |
| CCTV or access logs (if any at our office) | As needed for security, normally up to 90 days. |
| Marketing consents and withdrawals | For as long as we need to demonstrate compliance. |
When a period ends we delete or irreversibly anonymise the data, unless the law requires us to keep it. Deleting an app account removes profile content as described at the time of deletion, but financial records must still be kept for the statutory period.
9. Security
We apply reasonable technical and organisational measures: access control, encryption in transit where appropriate, staff need-to-know rules, and a procedure for personal-data breaches. No method of transmission or storage is completely secure. Full payment-card data is handled by PayHere on PCI-DSS infrastructure and is not stored on our systems.
If a breach is likely to result in a risk to your rights, we will notify the Data Protection Authority and, where the Act requires, affected individuals.
10. Children
Our website and digital products are directed at adults. We do not knowingly create product accounts for children under 18. Visa services for a minor are provided only through a parent or guardian. If you believe we hold a child’s data without proper authority, contact us and we will delete or restrict it unless we must keep it by law.
11. Your rights under the PDPA
Subject to the conditions and exceptions in the Act, you may:
- access the personal data we hold about you and learn how it is processed;
- rectify data that is inaccurate, incomplete, misleading or out of date;
- request erasure where we no longer have a lawful ground to keep it;
- withdraw consent where processing is based on consent;
- object to processing in the circumstances the Act allows;
- request restriction of processing in the circumstances the Act allows.
Write to igs.edu.lk@gmail.com. We may need to verify your identity. We aim to respond within fourteen (14) days and in any event within the period the Act requires. These requests are free of charge unless they are manifestly unfounded or excessive.
We may refuse erasure of billing or visa-file records that we are legally required to retain. In that case we will tell you what we are keeping and why, and we will limit use to that purpose.
12. Automated decisions
We do not make legally significant decisions about you solely by automated means without human review. Matching, ranking or recommendation features inside a digital product, if any, are tools for users and do not replace a human decision about a visa file, a refund or an account ban.
13. Complaints
Please raise a concern with us first at igs.edu.lk@gmail.com so we can try to put it right. You also have the right to complain to the Data Protection Authority of Sri Lanka, established under the Personal Data Protection Act, No. 9 of 2022.
14. Changes
We may update this Policy. The current version will be published on our website. Material changes will be notified on the website or by e-mail at least fourteen (14) days in advance where practicable.
15. Contact
Infinite Global Solutions (Private) Limited
No. 358/A/1/1, Negombo Road, Welisara, Ragama 11010, Sri Lanka
Privacy / data protection: igs.edu.lk@gmail.com
Telephone: +94 11 295 0550
https://www.igsolutions.lk
Infinite Global Solutions (Private) Limited
Company No. PV 00269216
No. 358/A/1/1, Negombo Road, Welisara, Ragama 11010, Sri Lanka
Telephone: +94 11 295 0550 · WhatsApp: +94 71 394 9308
E-mail: igs.edu.lk@gmail.com
Version 1.0 · Effective 21 August 2026 · Last reviewed 21 August 2026. Published in English. If a Sinhala or Tamil translation is later provided, the English text prevails if there is any inconsistency.