Privacy Policy
Last updated: 17 July 2026
This document explains how Ants Creation (PVT) Ltd (“we”, “us”, “our”) collects, uses, protects, and retains personal information when you contact us through our website, Facebook, Instagram, WhatsApp, phone, email, walk-in visits, or other business channels.
We use a secure CRM platform to manage sales enquiries, follow-ups, quotations, orders, and customer support. Protecting your information is part of how we run our business - not an afterthought.
1. Who This Policy Applies To
This policy applies to:
- Customers and prospects who contact us or submit enquiries
- People who complete Facebook or Instagram lead forms linked to our business
- People who message us on WhatsApp
- Website visitors who submit contact or enquiry forms
- Our authorised staff who use our internal CRM
This policy does not cover third-party platforms such as facebook.com or instagram.com. Those services have their own privacy policies.
2. Information We Collect
Information you give us directly
- Name
- Phone number
- Email address
- Company name
- City or address (when needed for quotations, delivery, or invoicing)
- Enquiry details, notes, or messages
Information from Facebook and Instagram
If you submit a lead form on Facebook or Instagram connected to our business, we receive the details you entered in that form (for example name, phone, email, and any custom questions). We may also receive a lead reference ID from Meta to match your enquiry correctly.
We do not receive your social media password, and we do not access your private profile beyond what you submit through an approved lead form or business messaging channel.
Information from WhatsApp
If you message our business WhatsApp number, we may receive and store:
- Your WhatsApp phone number or WhatsApp ID
- Message content
- Media you send (images, documents, voice notes, where applicable)
- Delivery or read status where provided by the WhatsApp Business platform
Other channels
We may also receive enquiries through our website, email, phone, walk-ins, LinkedIn, TikTok, or other channels you use to reach us.
Technical information
We may collect limited technical data such as IP address, browser/device type, submission time, and system logs used for security and troubleshooting.
For staff CRM login, we use secure session cookies to keep authorised users signed in.
3. How We Use Your Information
We use personal information to:
- Respond to enquiries and provide customer support
- Manage leads and customer records
- Assign enquiries to the correct branch or staff member
- Prepare quotations, orders, invoices, and payment records
- Follow up on active sales or service requests
- Maintain accurate customer history and reduce duplicate records
- Produce internal business reports and branch performance summaries
- Protect our systems from fraud, abuse, and unauthorised access
- Meet legal, tax, and regulatory obligations
We do not sell your personal information.
We do not use Facebook Lead Ads data for unrelated advertising profiling.
4. Legal Basis For Processing
Depending on your location and how you contact us, we process data based on:
- Your consent (for example when you submit a form or message us)
- Steps before or under a contract (for example preparing a quotation or fulfilling an order)
- Legitimate business interests (for example managing enquiries and improving service)
- Legal obligations (for example tax and invoice record keeping)
You may withdraw consent where consent applies, but we may not be able to continue assisting with an active enquiry or order.
5. How We Share Information
We share information only when necessary:
Meta platforms
We use Meta business tools such as Facebook Lead Ads, Instagram lead forms, and WhatsApp Business Platform to receive and reply to customer enquiries. Data you submit through Meta is transmitted to our CRM under Meta’s platform rules and our integration settings.
Service providers
We may use hosting, email, backup, and maintenance providers who process data on our behalf under confidentiality and security obligations.
Internal staff
Authorised employees may access information only when needed for their role, such as sales follow-up, quotation preparation, or order fulfilment.
Legal requirements
We may disclose information if required by law, court order, or to protect our rights, customers, staff, or systems.
We do not share your data with unrelated marketers for their own purposes.
6. Data Retention
We keep personal information only as long as needed:
- Active enquiries: while follow-up is ongoing
- Customer records: for ongoing service and business relationship needs
- Invoice and payment records: as required by applicable tax and accounting laws
- Communication logs: for customer history and dispute resolution
- Integration and webhook logs: for a limited period for troubleshooting and audit purposes
When data is no longer needed, we delete or anonymise it using reasonable measures.
7. Your Rights
Depending on applicable law, you may have the right to:
- Request access to your personal information
- Request correction of inaccurate information
- Request deletion, subject to legal or business record requirements
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
To make a request, email support@ants.lk with your name and the phone or email you used to contact us. We will respond within a reasonable time.
If you no longer want WhatsApp messages from us, tell us in chat or use WhatsApp’s block/report options.
8. Security & Compliance
This section explains how we protect personal information and the security standards we follow in our CRM operations.
8.1 Our security approach
We use a defence-in-depth approach: multiple layers of protection so that no single failure exposes customer data. Our CRM is designed for branch-based sales operations, which means access, visibility, and accountability are built into the system from the start.
8.2 Access control
- Authentication required: Staff must sign in to access the CRM.
- Role-based permissions: Users only receive access based on their job role (for example admin, manager, agent).
- Branch-based visibility: Non-admin staff generally see only data relevant to their branch and assigned work.
- Active account enforcement: Deactivated staff accounts are blocked from further access.
- API protection: Mobile and API access uses token-based authentication with active-user checks.
8.3 Data protection in the system
- Password protection: Staff passwords are stored using industry-standard one-way hashing, not plain text.
- Encrypted integration secrets: Sensitive integration settings such as API keys and app secrets are encrypted at rest in the application database.
- Authorised file access: WhatsApp media and email attachments are served through protected application routes, not open public links.
- Soft deletion: Important business records support controlled deletion workflows rather than careless permanent removal.
- Duplicate review: The system supports duplicate detection so customer records stay accurate and reduce data handling errors.
8.4 Communication and integration security
- Webhook verification: Inbound data from Facebook, Instagram, WhatsApp, and website integrations is validated using cryptographic signature checks before processing.
- Rate limiting: Login, API, and webhook endpoints use request throttling to reduce abuse and brute-force attempts.
- CSRF protection: Web forms in the CRM use cross-site request forgery protections.
- Transport security: We use encrypted connections (HTTPS/TLS) for web access and encrypted email transport (TLS/SSL) where configured.
- Security headers: The application applies browser security headers including Content Security Policy, frame protection, and MIME-type protection.
8.5 Monitoring, logging, and accountability
- Activity logging: Critical changes to leads, contacts, quotations, orders, invoices, and branches are recorded for traceability.
- Integration logging: Inbound webhook payloads and processing results are logged to support troubleshooting, audit review, and incident investigation.
- Need-to-know principle: Staff access is limited to what is required to perform legitimate business tasks.
8.6 Organisational safeguards
- Staff access is granted only to authorised personnel.
- Administrative settings, integrations, and user management are restricted to authorised roles.
- We review access and system configuration as part of normal business operations.
- We take reasonable steps to ensure staff handle customer data responsibly and only for business purposes.
8.7 Payment information
Our system supports finance-lite payment tracking such as cash, bank transfer, cheque, card, or online payment references.
We do not store full credit or debit card numbers, CVV codes, or full payment card credentials on our CRM servers.
If card payments are accepted, processing is handled through appropriate external payment channels or manual business processes, not by storing sensitive card data in our application.
8.8 Compliance alignment
We design and operate our CRM with privacy and security principles aligned with commonly accepted standards and legal expectations, including:
- Meta Platform Terms and Developer Policies for Facebook, Instagram, and WhatsApp integrations
- WhatsApp Business Messaging Policy for business communication through WhatsApp
- General data protection principles such as purpose limitation, data minimisation, access control, and retention limits
- Applicable local privacy and business record-keeping laws in Sri Lanka
We do not claim formal certification (such as ISO 27001 or SOC 2) unless explicitly stated by us in writing. Instead, we follow practical, documented security controls appropriate to the size and nature of our operations.
8.9 Incident response
If we become aware of a security incident that affects personal information, we will:
- Investigate and contain the issue as quickly as reasonably possible
- Assess the scope and impact
- Take corrective action to reduce further risk
- Notify affected individuals or authorities where required by applicable law
To report a security concern, email support@ants.lk
8.10 Limitations
No online system can guarantee 100% security. While we use reasonable technical and organisational measures to protect personal information, we cannot guarantee absolute security against all possible threats.
9. International Data Transfers
Our systems or service providers may be located outside your country. Where data is transferred internationally, we take reasonable steps to ensure appropriate protection consistent with applicable privacy requirements.
10. Children’s Privacy
Our services are intended for business and customer enquiries and are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to remove it.
11. Third-Party Links
Our website or messages may contain links to third-party websites. We are not responsible for the privacy or security practices of those sites.
12. Changes To This Policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top. If changes are significant, we may also post a notice on our website.
13. Contact Us
For privacy, security, or data deletion requests:
Ants Creation (PVT) Ltd
Email: support@ants.lk
Phone: +94 77 282 0543
Address: No 12 Rest house rd, Gampaha