Last updated: 14 August 2026
Who is responsible for your data
Subuddhi Ayurveda Medical Center, P. Don Paul Mawatha, Kuda Payagala 12050, Sri Lanka, is the controller of the personal data described here. Contact us at athukoralakaweesha@gmail.com or +94 78 122 1166.
What we collect and why
- Mobile number: to send and verify a one-time password, identify your booking account, and send transactional appointment confirmations, changes and reminders. We do not use it for advertising or promotional messages.
- Identity and contact details: name, age, city, sex and optional email, to identify you safely and manage your appointment and patient record.
- Health information: symptoms, consultation notes, diagnoses and prescriptions, so an authorised Ayurvedic medical professional can provide care and keep an accurate clinical history for future treatment.
- Security records: hashed request information, OTP attempts, consent time, and limited message-delivery logs to prevent abuse and operate the service.
Providing a mobile number is optional, but online booking cannot work without it. You may contact the medical center to ask about another booking method.
Legal basis
We process the mobile number for OTP and appointment messages with your consent. We process booking and identity data as necessary to take steps you request and provide the appointment service. Health data is a special category of personal data; it is processed for medical diagnosis, care or treatment by a health professional licensed or authorised under Sri Lankan law. Where another purpose requires consent, we will ask separately.
Who receives data
We do not sell, rent, or disclose personal data for advertising. Access inside the medical center is limited to authorised staff who need it for booking or care. Notify.lk receives the recipient mobile number and the transactional SMS content needed to deliver an OTP or reservation update. Reservation messages may contain the appointment date, time, booking reference and clinic location. Notify.lk does not receive the patient's name, age, city, sex, email, symptoms, prescriptions, consultation notes or medical history. Records are hosted separately on Supabase infrastructure. Mailtrap receives the email address and appointment details needed to deliver configured booking notifications. We may disclose information where Sri Lankan law or a valid court or regulatory order requires it.
How we protect data
Data is sent over encrypted HTTPS/TLS connections. The hosted database and backups are encrypted at rest using AES-256. OTP values are stored as keyed hashes rather than readable codes. Patient sessions use protected cookies, database tables use access controls, and clinical and administrative records are available only through approved administrator accounts. SMS messages contain no identity fields or clinical information. No online system can promise zero risk, so we review access and safeguards as the service changes.
How long we keep data
OTP codes expire after five minutes. Consent and delivery records are kept only while needed to demonstrate consent, secure the service and resolve delivery issues. Appointment, identity and clinical records are kept while needed for continuing care and for any period required by applicable professional or written law, then securely deleted or anonymised. We review retention instead of keeping records merely because storage is available.
Your choices and rights
You may ask us in writing to access, correct or complete your data, withdraw phone-message consent, object where applicable, or request erasure where the law permits. Withdrawing consent does not make earlier lawful use invalid, but it will prevent further OTP and reservation messages and therefore disables online booking. A parent or legal guardian may exercise these rights for a child. Contact us using the details above. You may also contact the Data Protection Authority of Sri Lanka at info@dpa.gov.lk.
Sri Lankan legal framework
Sections 6 to 12 of the Personal Data Protection Act, No. 9 of 2022 address specified purposes, proportionate collection, accuracy, retention limits, security, transparency and accountability. Sections 21 and 22 address safeguards and written terms for processors; sections 23 to 25 address breaches and risk assessment; and section 26 addresses transfers outside Sri Lanka. Schedule II permits necessary health-data processing for diagnosis, care or treatment by an authorised health professional. Schedule III requires consent to be demonstrable, clear and withdrawable, while Schedule V lists the information a privacy notice must provide. This notice also refers to the Personal Data Protection (Amendment) Act, No. 22 of 2025 and Gazette Extraordinary No. 2498/16 of 22 July 2026. We will update it as applicable provisions, rules and official guidance take effect.
