Privacy Policy
Effective date: 15 August 2026
1. The short version
We are a Sri Lankan company that builds websites, software and marketing programmes for other businesses. To do that well we need to know some things about you — who you are, what your business needs, and how to reach you. We ask for exactly that and not more. We do not sell your data, we do not trade it, and we do not run advertising or analytics trackers on you unless you have said yes.
The rest of this page is the detail, written plainly. If anything here is unclear, please write to [email protected] and a person will answer you.
2. Who we are
Rukshimart (Private) Limited, doing business as Regalia Solutions ("we", "our", "us"), is the data controller for the personal data described here. We handle personal data in accordance with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka (the "PDPA").
Rukshimart (Private) Limited
No: 94/1/1, Artigala Mawatha, Kolomunna, Piliyandala, Colombo, Sri Lanka
[email protected]
+94 11 260 0063
3. What we collect, and when
3.1 When you browse regalia.lk
You can read every public page — our services, insights, portfolio and products — without telling us anything. Our servers keep short-lived technical logs (IP address, browser type, the page requested) which we use to keep the site running and to investigate abuse.
3.2 When you contact us or request a call
Our contact form and the Schedule a Call booking ask for your name, email address, phone number, company name, what you would like to talk about and your preferred date and time. We send a six-digit code to your email address to confirm it is really yours before we book anything.
3.3 When you use a proposal builder
The web development, software and digital marketing builders ask more, because a useful proposal needs a real picture of your business. Specifically we collect:
- your company name and contact details;
- your approximate staff size, annual turnover band and budget band — these are what let us tell whether our published SME pricing applies to you, or whether your requirement needs to be priced individually by our management;
- your answers to the service questions in the builder;
- any documents you choose to attach (briefs, brand guidelines, specifications, existing site details); and
- anything you write in the free-text box at the end.
Attaching a document is entirely optional. Please do not upload anything containing other people's personal data, payment card details or credentials — we do not need them, and we would rather you did not send them.
3.4 Your resumable link, and our follow-up emails
Filling in a detailed brief in one sitting is unrealistic, so once you have confirmed your email we give you a private link that keeps your answers for seven days. You can close the tab and come back to the same link without verifying again, and you will land where you left off.
Over those seven days we may send you up to seven reminder emails — the first about an hour after you stop, then roughly daily, and only between 8am and 8pm Sri Lanka time. Every one of them carries a one-click opt-out link. Use it and we stop immediately; we will not ask twice. When the seven days are up the link stops working.
3.5 If you are a client with a portal account
Clients and support partners get an account in our portal. That account holds your name, email address, contact details, an optional profile picture, and the records of our work together — projects, files, quotations, invoices, credit notes, subscriptions and helpdesk tickets. We also keep an audit log of significant actions taken in the portal, including the account involved, what changed, when, and the IP address it came from. That log exists to protect your data: it is how we can tell you what happened if something ever goes wrong.
4. Why we are allowed to use it (legal basis)
- To take steps at your request before a contract: preparing your proposal, responding to an enquiry, arranging a call.
- To perform our contract with you: delivering projects, invoicing, support.
- Your consent: analytics and marketing cookies, and marketing emails you have asked for. You can withdraw consent at any time, and withdrawing it is as easy as giving it.
- Our legitimate interests: keeping the site secure, preventing fraud and abuse, keeping backups, and following up on a brief you started — balanced against your rights, which is why every follow-up can be stopped in one click.
- Legal obligation: tax, accounting and other records we are required to keep.
5. Who else sees it
We do not sell, rent or trade personal data. We share it only with:
- Our own staff, and only those whose role requires it. Access in our portal is controlled by role-based permissions, and changes to those permissions are logged.
- Cloudflare, whose Turnstile service checks that logins and form submissions come from a person rather than a bot.
- Our email provider, which delivers verification codes, notifications and follow-ups.
- Google, where encrypted copies of our database backups may be stored in a Google Drive account we control. We request the narrowest available permission, which lets our software see only the files it created there — never the rest of the account.
- Google, Meta and LinkedIn analytics or advertising services — only if you consent. See our Cookie Policy.
- Legal and regulatory authorities, where the law requires it or where we need to establish or defend a legal claim.
6. Where your data goes
Some of the providers above process data outside Sri Lanka. Where personal data is transferred abroad we take steps to ensure it remains protected to a standard consistent with the PDPA, including contractual safeguards with the provider.
7. How long we keep it
- Unfinished proposal drafts: the resumable link expires after seven days.
- Submitted enquiries, briefs and bookings: kept as part of our client and prospect records so we can pick up the conversation where it stopped.
- Client records (projects, invoices, tickets): kept for the life of the relationship and afterwards for as long as tax, accounting and limitation periods require.
- Database backups: we retain a rolling set of the most recent archives — the last fourteen locally — so older copies are overwritten in the normal course.
- Audit and security logs: retained so we can investigate incidents.
When data is no longer needed for the purpose it was collected for, and we are not required to keep it, we delete it.
8. How we protect it
We take this seriously, and we would rather describe what we actually do than make a blanket promise:
- Signing in to our portal requires a one-time code sent to your email address, valid for two minutes, tied to that single login attempt. There is no password to steal or reuse.
- Session cookies are HTTP-only, restricted to our own site, and encrypted in transit.
- Documents and files you send us are not publicly downloadable. Reaching them requires a signed-in account with the right permission.
- Credentials for connected services are encrypted before they are stored.
- Who can see and do what is governed by roles, and changes to roles are recorded.
- Backups are taken on a schedule and stored separately from the live system.
No system connected to the internet can be guaranteed impenetrable, and we will not pretend otherwise. What we can commit to is that we design for it, review it, and tell you promptly if something affecting your data goes wrong.
9. Your rights under the PDPA
You have the right to:
- Access — ask what personal data we hold about you and get a copy;
- Correct — have inaccurate or incomplete data put right;
- Erase — ask us to delete your data, where we are not legally required to keep it;
- Object — object to processing based on our legitimate interests, including our follow-up emails;
- Withdraw consent — at any time, without affecting what we did lawfully before you withdrew it;
- Data portability — receive your data in a commonly used, machine-readable format.
Write to [email protected] and we will respond within the time the PDPA allows. We may need to confirm your identity first — that is to protect you, not to slow you down. If you are not satisfied with our response, you may complain to the Data Protection Authority of Sri Lanka.
10. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, tell us and we will delete it.
11. Changes to this policy
When our practices change, this page changes with them, and the effective date at the top moves. Where a change is significant we will make it visible rather than quietly republishing the page.
12. Contact us
Questions, requests or concerns about your data go to [email protected], or to the postal address in section 2. You are also welcome to just book a call and ask us directly.