Sri Lanka PDPA Compliant · Legal & Compliance

Privacy Policy & Guest Data Charter

Our uncompromising standard of hospitality extends to the integrity, sovereignty, and protection of your personal information across all SkyNest properties.

Effective Date: 1 January 2026 · Version 2.4 · Sri Lanka PDPA No. 9 (2022) Alignment

1. Our Privacy Commitment & Charter

At SkyNest Hotel Reservation & Guest Services Management System (“SkyNest”, “we”, “our”), safeguarding your personal confidentiality and travel identity is foundational to our philosophy of unhurried luxury.

This Privacy Charter governs all personal information gathered through our central reservation platform (skynesthotels.com), guest self-service portals, front-desk registers across our three Sri Lankan sanctuaries (Colombo, Kandy, and Galle), and ancillary dining and spa usage logs.

2. Information We Collect & Relational Model

In accordance with our system architecture and Sri Lanka statutory hotel registration requirements (Rule B6), we collect and securely store the following data points within our central PostgreSQL audit engine:

  • Guest Identity & Profile: Full name, national identity card (NIC) number, foreign passport number, nationality, and digital residency records.
  • Contact Coordinates: Verified email address, telephone contact lines, and postal billing addresses.
  • Stay & Reservation Metadata: Scheduled check-in/out intervals, assigned suite categories, frozen booking rates (Rule B8), and accompanying guest declarations.
  • Ancillary Consumption Logs: Itemized charges incurred during residency, including culinary dining plans (RO, BB, HB, FB), wellness therapies, and airport transfers.
  • Financial Audit Trail: Immutable folio invoices, statutory indirect tax remittances (SC, TDL, SSCL, VAT), transaction reference numbers, and encrypted settlement tokens.

3. Legal Basis & Sri Lankan Statutory Compliance

Our data processing strictly complies with the Personal Data Protection Act (PDPA) No. 9 of 2022 of the Democratic Socialist Republic of Sri Lanka, as well as hospitality guidelines mandated by the Sri Lanka Tourism Development Authority (SLTDA).

Statutory Lodging Requirements (Rule B6): The Sri Lanka Tourist Board mandates identity verification (NIC/Passport match) for all adult occupants prior to key hand-off.

Tax Audit Retention (Rule B13 & B17): Finalized invoices and tax cascade breakdowns must be retained for financial auditing under the Inland Revenue Act No. 24 of 2017.

4. Cryptographic Security & Zero-Leakage Architecture

SkyNest employs enterprise-tier cryptographic protocols across every tier of our software pipeline:

  • Stateless RBAC & JWT: User accounts utilize cryptographically signed JSON Web Tokens with strict role isolation (Guest, Receptionist, Manager, Administrator).
  • Password Hashing: Staff and guest credentials are salted and hashed utilizing the bcrypt algorithm (minimum factor 10).
  • Zero ORM Parameterized SQL: Database interactions use 100% parameterized SQL prepared statements to eliminate SQL injection vectors.
  • Transport Layer Security: All client-to-cloud communications are enforced over TLS 1.3 encryption.

5. Your Rights as a SkyNest Resident

Under statutory privacy protections and SkyNest policy, you maintain sovereign rights regarding your data:

  • Right of Rectification: Update contact coordinates, dining preferences, or emergency contacts via the guest portal or front-desk concierge.
  • Right of Access: Request a complete export of your stay history and itemized invoice records at any juncture.
  • Right to Deletion: Request erasure of non-statutory personal data upon departure, subject to mandatory tax retention periods.

6. Privacy Officer & Data Inquiries

For questions, data access requests, or regulatory communications regarding our data protection standards, please address our dedicated Data Protection Officer:

Data Protection & Compliance Officer

SkyNest Hotels (Pvt) Ltd

45 Galle Face Centre Road, Colombo 03, Sri Lanka

Email: privacy@skynesthotels.com

Hotline: +94 11 234 5600 (Extension: Legal & Compliance)