Legal

Privacy Policy

How ORIGEN collects, uses, discloses, stores, protects and retains personal data across our products and business operations.

Last updated — 6 September 2026

01

Introduction

ORIGEN Holdings (Pvt).Ltd ("ORIGEN", "we", "us", or "our) respects your privacy and is committed to protecting the personal data entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store, protect, retain and otherwise process personal data when you:

  • visit or interact with our websites;
  • use our mobile applications;
  • use our web applications, software platforms or SaaS products;
  • create or use an account with us;
  • purchase products through an ORIGEN-operated online store;
  • make or attempt to make a payment;
  • communicate with us;
  • contact us regarding a product, service, partnership or project;
  • engage ORIGEN for software, web, mobile or e-commerce development services;
  • participate in surveys, promotions, competitions or other activities operated by us;
  • interact with our advertisements, marketing communications or social-media presence; or
  • otherwise interact with ORIGEN or services operated by ORIGEN.

This Policy applies across our digital products and business activities unless a particular product, application, website, service or transaction provides a separate privacy notice that expressly replaces or supplements this Policy.

Our business includes the development and operation of mobile applications, web applications, software platforms, online stores and related digital services. We may therefore process personal data in different capacities depending on the service involved.

Where ORIGEN determines why and how personal data is processed, we may act as a data controller. Where we process personal data on behalf of a business customer under that customer's instructions, we may act as a data processor or equivalent service provider. The applicable role depends on the circumstances and nature of the processing.

02

Who We Are

The entity responsible for this Privacy Policy is:

ORIGEN Holdings (Pvt).Ltd No. 387, Akkuregoda Road, Thalangama South, Battaramulla, Sri Lanka.

Email: hello@origen.lk

Telephone: +94 76 906 5806

ORIGEN operates digital products and online commerce businesses and provides technology services including web development, software development, mobile application development and e-commerce development.

03

Scope of This Privacy Policy

This Policy applies to personal data processed by ORIGEN through or in connection with:

3.1 ORIGEN Websites

Including origen.lk and other websites, domains, landing pages and digital properties operated by ORIGEN.

3.2 Mobile Applications

Applications developed, published, owned or operated by ORIGEN, including applications made available through platforms such as Apple App Store and Google Play.

3.3 Web Applications and Software

Including SaaS products, web-based applications, dashboards, platforms, customer portals, internal tools and other software services operated by ORIGEN.

3.4 Online Stores

Online stores owned or operated by ORIGEN, including associated product catalogues, shopping carts, checkout systems, order management, delivery and fulfilment processes.

3.5 Technology and Development Services

Information supplied to ORIGEN by customers or prospective customers in connection with website, software, mobile application, e-commerce, consulting, integration, hosting, maintenance or other technology services.

3.6 Communications

Emails, telephone calls, contact forms, support requests, messages, social-media interactions and other communications with ORIGEN.

04

Personal Data We May Collect

The information we collect depends on how you interact with us.

We do not seek to collect more personal data than reasonably necessary for the relevant purpose.

4.1 Identity and Contact Information

We may collect:

  • full name;
  • preferred name;
  • email address;
  • telephone number;
  • postal or delivery address;
  • billing address;
  • shipping address;
  • company or organisation name;
  • job title or professional information;
  • account identifiers; and
  • other information you voluntarily provide.

4.2 Account Information

Where a product or service requires an account, we may collect:

  • username;
  • email address;
  • phone number;
  • password credentials in appropriately protected form;
  • profile information;
  • account preferences;
  • authentication information;
  • account status;
  • subscription information;
  • security and login information; and
  • information associated with your use of the account.

We do not intend to store passwords in plain text.

Where authentication is provided through a third-party identity provider, certain authentication information may be received from that provider in accordance with its own privacy policy and your settings.

4.3 Transaction and Order Information

If you purchase products or services from us, we may collect:

  • order number;
  • products purchased;
  • quantity;
  • price;
  • discounts;
  • delivery information;
  • billing information;
  • transaction status;
  • refund information;
  • payment confirmation;
  • invoice information;
  • tax-related information where required; and
  • communications relating to the transaction.

Payment card information may be processed by third-party payment processors.

Unless expressly stated otherwise for a particular service, ORIGEN does not intend to store complete payment-card numbers, CVV/security codes or equivalent sensitive payment credentials on its own systems.

Our Terms & Conditions similarly state that payments are processed through third-party payment providers and that ORIGEN does not store full card details on its own systems.

05

Information Collected Automatically

When you visit our websites, use our applications or interact with our digital services, certain technical information may be collected automatically.

This may include:

  • IP address;
  • browser type and version;
  • operating system;
  • device type;
  • device model;
  • language and regional settings;
  • approximate location derived from technical information;
  • screen resolution;
  • referring website;
  • pages or screens viewed;
  • links and buttons interacted with;
  • date and time of access;
  • session information;
  • application version;
  • crash information;
  • performance information;
  • network information;
  • diagnostic information;
  • security logs; and
  • other technical information necessary to operate and secure our services.

Where technically feasible and appropriate, we may use identifiers that are reasonably necessary to distinguish sessions, devices or accounts.

06

Cookies and Similar Technologies

Our websites and applications may use cookies, software development kits ("SDKs"), pixels, local storage, web beacons, device identifiers and similar technologies.

These technologies may be used for purposes including:

  • keeping websites and applications functioning;
  • maintaining sessions;
  • authentication;
  • remembering preferences;
  • security;
  • fraud prevention;
  • measuring website and application performance;
  • understanding how users interact with our services;
  • analytics;
  • improving products;
  • advertising and campaign measurement; and
  • understanding the effectiveness of our marketing.

6.1 Categories of Cookies

Depending on the service, we may use:

Strictly Necessary Technologies

Required for basic functionality, security, authentication, checkout or other essential functions.

Preference Technologies

Used to remember settings such as language, preferences or other choices.

Analytics Technologies

Used to understand how visitors use our websites and applications and to improve our products.

Marketing Technologies

Where implemented, these may be used to measure advertising campaigns, understand conversions or deliver more relevant advertising.

We will provide appropriate controls where applicable and where required by law.

You may also be able to control cookies through your browser or device settings. Disabling certain technologies may affect the availability or functionality of some services.

07

Information From Third Parties

We may receive personal data from third parties where legally permitted and reasonably necessary.

Examples include:

  • payment processors;
  • delivery and logistics providers;
  • authentication providers;
  • analytics providers;
  • advertising platforms;
  • app stores;
  • cloud infrastructure providers;
  • technology providers;
  • fraud-prevention providers;
  • business partners;
  • suppliers;
  • customer organisations;
  • publicly available sources; and
  • other service providers.

Where a third party provides personal data to us, we expect that third party to have an appropriate legal basis and authority to provide the information.

08

Information Provided by Business Customers

When ORIGEN provides software development, web development, mobile application, e-commerce or related technology services to a customer, that customer may provide ORIGEN with personal data relating to its users, employees, customers, suppliers or other individuals.

In these circumstances, ORIGEN may process such information solely to provide the contracted service and in accordance with the customer's documented instructions and applicable law.

Depending on the project, ORIGEN may act as a processor/service provider rather than as the controller of that information.

The relevant customer may remain responsible for:

  • determining the purposes of processing;
  • providing appropriate privacy notices;
  • obtaining required consents;
  • establishing an appropriate lawful basis;
  • responding to data-subject requests where required;
  • determining retention requirements; and
  • ensuring its instructions to ORIGEN are lawful.

Where appropriate, our contracts with business customers will contain data-processing, confidentiality, security and data-protection provisions.

09

How We Use Personal Data

We may process personal data for purposes including:

9.1 Providing Our Products and Services

To:

  • create and maintain accounts;
  • provide access to applications;
  • operate web applications;
  • provide software functionality;
  • process orders;
  • provide products and services;
  • deliver purchases;
  • provide customer support;
  • process subscriptions;
  • manage memberships;
  • provide requested information; and
  • perform contractual obligations.

9.2 Payments and Transactions

We may use information to:

  • process purchases;
  • verify transactions;
  • confirm payments;
  • issue invoices;
  • process refunds;
  • detect potentially fraudulent transactions;
  • reconcile payments;
  • manage chargebacks; and
  • maintain appropriate financial records.

9.3 Security and Fraud Prevention

We may process information to:

  • protect accounts;
  • detect unauthorised access;
  • investigate suspicious activity;
  • prevent fraud;
  • prevent abuse;
  • protect our systems;
  • enforce our terms;
  • investigate security incidents; and
  • protect users, employees, customers and third parties.

9.4 Product Development and Improvement

We may use information to:

  • understand how products are used;
  • identify technical problems;
  • improve functionality;
  • develop new products;
  • conduct product research;
  • improve user experience;
  • test features;
  • analyse performance; and
  • develop internal analytics.

Where practical, we may use aggregated, statistical or de-identified information for these purposes.

9.5 Communications

We may use your information to:

  • respond to enquiries;
  • provide support;
  • send transactional communications;
  • provide service announcements;
  • notify you about changes;
  • send security notifications;
  • respond to requests; and
  • communicate about an existing relationship.

9.6 Marketing

Where permitted by applicable law, we may use contact information for:

  • product announcements;
  • promotional communications;
  • offers;
  • newsletters;
  • events;
  • surveys;
  • business updates; and
  • other marketing communications.

Where consent is required, we will obtain consent before sending the relevant marketing communications.

You may unsubscribe from marketing communications at any time using the unsubscribe mechanism provided or by contacting us.

Unsubscribing from marketing communications does not prevent us from sending essential transactional, security or service-related communications.

11

Sensitive and Special Categories of Personal Data

Certain types of information may receive enhanced protection under applicable law.

Depending on the product or service, such information may include data relating to:

  • health;
  • biometric information;
  • financial information;
  • precise location;
  • identification information;
  • children's information;
  • authentication credentials; or
  • other categories recognised as sensitive or specially protected under applicable law.

We do not intentionally collect sensitive personal data unless there is a legitimate and lawful reason to do so.

Where sensitive or specially protected personal data is required for a particular service, we will process it only where permitted by applicable law and with appropriate safeguards.

12

Children's Privacy

Our services are generally intended for adults and persons who are legally permitted to use the relevant service.

We do not knowingly collect personal data from children in circumstances where applicable law requires parental or guardian authorisation without obtaining the required authorisation.

Where a particular product is designed for children, students or minors, additional privacy notices, parental controls, consent mechanisms and safeguards may apply.

If you believe that a child has provided personal data to us in circumstances where such collection was not appropriate or authorised, please contact us at:

hello@origen.lk

We will investigate and take appropriate action where required.

13

Disclosure of Personal Data

We may disclose personal data where reasonably necessary for the purposes described in this Policy.

Recipients may include:

Service Providers

Such as:

  • cloud hosting providers;
  • database providers;
  • email providers;
  • analytics providers;
  • customer-support systems;
  • payment processors;
  • fraud-prevention providers;
  • delivery and logistics companies;
  • communications providers;
  • authentication providers;
  • infrastructure providers;
  • software providers; and
  • professional advisers.

Business Partners

Where necessary to provide a product, service, promotion or transaction.

App Stores

Including Apple and Google where necessary to distribute and operate applications.

Advertising and Analytics Providers

Where applicable and permitted by law.

Professional Advisers

Including lawyers, accountants, auditors, consultants and other professional advisers who are subject to appropriate confidentiality obligations.

Authorities and Regulators

We may disclose personal data where reasonably necessary to:

  • comply with applicable law;
  • comply with a lawful request;
  • respond to legal proceedings;
  • enforce our legal rights;
  • investigate fraud or unlawful activity;
  • protect the safety of individuals; or
  • protect our systems and property.
14

Corporate Transactions

If ORIGEN is involved in:

  • a merger;
  • acquisition;
  • restructuring;
  • investment;
  • financing;
  • sale of assets;
  • transfer of business operations; or
  • similar corporate transaction,

personal data may be transferred as part of that transaction where permitted by applicable law.

Any recipient will be expected to handle personal data consistently with applicable privacy obligations.

15

International Data Transfers

ORIGEN may use service providers and infrastructure located outside Sri Lanka.

As a result, personal data may be transferred to, stored in, or accessed from jurisdictions other than the jurisdiction in which you reside.

Where personal data is transferred outside Sri Lanka, ORIGEN will take reasonable steps to ensure that the transfer is conducted in accordance with applicable data-protection requirements and any applicable restrictions or safeguards governing cross-border transfers.

Depending on the circumstances, safeguards may include:

  • contractual protections;
  • appropriate data-processing agreements;
  • recognised transfer mechanisms;
  • contractual confidentiality obligations;
  • technical safeguards;
  • encryption;
  • access controls;
  • assessments of the relevant recipient or jurisdiction; and
  • other safeguards required or permitted by applicable law.

Because our technology stack may change over time, the countries and jurisdictions in which data may be processed may also change.

16

Data Security

We implement reasonable technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure;
  • misuse;
  • unlawful processing; and
  • other security threats.

Depending on the nature of the information and service, safeguards may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • access controls;
  • authentication mechanisms;
  • role-based permissions;
  • secure development practices;
  • logging and monitoring;
  • backups;
  • infrastructure security controls;
  • vulnerability management;
  • security testing;
  • incident response procedures; and
  • employee confidentiality obligations.

No internet-based system can be guaranteed to be completely secure.

Accordingly, while we take reasonable measures to protect personal data, we cannot guarantee absolute security.

17

Data Breaches and Security Incidents

If ORIGEN becomes aware of a personal-data breach or security incident involving personal data, we will assess and respond to it in accordance with applicable law and our internal incident-response procedures.

Where notification to a regulator, affected individuals, customers or other parties is legally required, we will make such notifications within the applicable timeframes.

Where ORIGEN processes personal data on behalf of a customer, we may notify the relevant customer in accordance with the applicable contractual and legal requirements.

18

Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by law.

Retention periods may depend on:

  • the purpose for which information was collected;
  • the nature of the relationship;
  • contractual requirements;
  • legal requirements;
  • accounting and tax requirements;
  • dispute-resolution requirements;
  • security requirements;
  • fraud-prevention requirements;
  • backup systems; and
  • legitimate business requirements.

Examples include:

Account Data

Generally retained while an account remains active and for a reasonable period afterwards where necessary for legal, security or operational purposes.

Transaction Data

May be retained for periods required for accounting, taxation, audit, fraud prevention, dispute resolution and legal compliance.

Support Communications

May be retained for a reasonable period to manage support history, quality, security and legal requirements.

Marketing Data

Generally retained until you unsubscribe, withdraw consent where applicable, or the information is otherwise no longer required.

Technical and Security Logs

May be retained for periods reasonably necessary for security, troubleshooting, fraud prevention and system integrity.

When personal data is no longer required, we may securely delete it, anonymise it, aggregate it, or otherwise dispose of it in accordance with applicable requirements.

19

Your Privacy Rights

Subject to applicable law, you may have rights relating to your personal data.

These may include the right to:

  • know whether we process your personal data;
  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion or erasure where legally available;
  • request restriction or cessation of certain processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request information about processing activities;
  • request information regarding disclosures to third parties where applicable;
  • request information concerning cross-border processing where applicable;
  • request portability of personal data where legally available;
  • object to certain forms of direct marketing;
  • lodge a complaint with the relevant data-protection authority; and
  • exercise other rights provided under applicable law.

These rights are not absolute and may be subject to legal exceptions, limitations, verification requirements and other applicable conditions.

20

How to Exercise Your Rights

To submit a privacy request, contact:

Email: hello@origen.lk

Please include enough information for us to understand your request.

We may request reasonable information to verify your identity before processing certain requests. This is intended to prevent unauthorised access to personal data.

We will respond to valid requests within the period required by applicable law.

Where permitted by law, we may charge a reasonable fee for requests that are manifestly unfounded, excessive or repetitive, or we may refuse to act on such requests.

If we cannot fulfil your request, we will explain the reason where legally permitted.

21

Complaints

If you believe that ORIGEN has processed your personal data unlawfully or has not adequately addressed your privacy request, you may contact us first so that we can investigate and attempt to resolve the matter.

Privacy Contact: ORIGEN Holdings (Pvt).Ltd Email: hello@origen.lk Telephone: +94 76 906 5806

Nothing in this Policy prevents you from exercising any statutory right to lodge a complaint with the relevant data-protection authority or pursue any other remedy available under applicable law.

22

Third-Party Services

Our services may use or link to third-party products and services.

These may include:

  • payment processors;
  • hosting providers;
  • cloud infrastructure;
  • analytics services;
  • advertising platforms;
  • authentication providers;
  • app stores;
  • mapping services;
  • communications platforms;
  • delivery providers;
  • social-media platforms;
  • customer-support platforms; and
  • other technology providers.

Third parties may process information under their own privacy policies and terms.

ORIGEN does not control the privacy practices of third parties and is not responsible for their independent processing activities.

You should review the privacy policies of relevant third-party providers where appropriate.

23

Payment Processing

Payments made through our online stores or paid products may be processed by third-party payment providers.

Depending on the payment method, information may be provided directly to the relevant payment provider.

Payment providers may collect and process information including:

  • card information;
  • bank information;
  • payment identifiers;
  • billing information;
  • transaction information;
  • device information;
  • fraud-prevention information; and
  • other information necessary to process and secure the transaction.

ORIGEN generally does not store complete payment-card details on its own systems.

The payment provider's own terms and privacy policy apply to its processing of payment information.

24

E-Commerce and Delivery Data

When purchasing products from an ORIGEN-operated store, we may process information necessary to fulfil the order.

This may include:

  • customer name;
  • telephone number;
  • email;
  • delivery address;
  • order information;
  • payment status;
  • delivery instructions;
  • order history;
  • returns and refund information; and
  • communications regarding the order.

We may provide relevant information to delivery partners and fulfilment providers where necessary to deliver an order.

25

Mobile Applications

Our mobile applications may collect information necessary for their operation.

Depending on the specific application, this may include:

  • account information;
  • device information;
  • application usage information;
  • crash and diagnostic data;
  • push-notification tokens;
  • approximate or precise location where specifically required and authorised;
  • camera or photo data where a feature requires it;
  • contacts or other device information only where the application specifically requires and obtains appropriate permission;
  • authentication information; and
  • information generated through your use of the application.

The exact permissions required by each application will depend on its functionality.

Mobile operating systems provide permission controls that allow you to manage certain access.

You may withdraw permissions through your device settings, although doing so may prevent some application features from functioning.

26

Push Notifications

Where an application supports push notifications, we may process device or notification identifiers necessary to send those notifications.

Push notifications may be used for:

  • security alerts;
  • account notifications;
  • transactions;
  • reminders;
  • service updates;
  • product notifications; and
  • marketing communications where permitted.

You can generally control push-notification permissions through your device settings.

27

Location Information

Certain products or features may require location information.

Where location information is required, we will use it only for purposes reasonably connected to the relevant functionality or other lawful purposes described in this Policy.

Location permissions are generally controlled through your device or browser.

You may disable location access, although doing so may affect features that depend on location.

28

Analytics

We may use analytics technologies to understand:

  • how our websites and applications are used;
  • which features are popular;
  • where users encounter problems;
  • performance;
  • conversion and transaction activity;
  • marketing effectiveness; and
  • general usage trends.

Analytics information may include technical identifiers and usage information.

Where analytics providers process personal data on our behalf, their access will be governed by appropriate contractual and technical controls where required.

29

Advertising and Marketing Technologies

Where we use advertising platforms, pixels or similar technologies, those technologies may allow us and relevant providers to:

  • measure advertising performance;
  • identify conversions;
  • understand campaign effectiveness;
  • build audience segments;
  • limit repetitive advertising; and
  • deliver advertising that may be more relevant to users.

Where legally required, we will obtain consent before using non-essential marketing technologies.

You may also be able to control advertising preferences through the relevant platform or device.

30

Social Media

ORIGEN may maintain accounts or pages on third-party social-media platforms.

If you interact with us through those platforms, the relevant platform may independently collect and process your information.

Your interactions may therefore be governed by both this Policy and the privacy policy of the relevant platform.

31

Automated Decision-Making and Profiling

We may use automated systems for purposes such as:

  • fraud detection;
  • security;
  • abuse prevention;
  • service optimisation;
  • analytics;
  • recommendation or personalisation features; and
  • marketing measurement.

Where applicable law grants you rights concerning solely automated decision-making or profiling that produces legal or similarly significant effects, we will provide the safeguards and rights required by that law.

ORIGEN does not intend to make decisions producing significant legal effects about individuals solely through automated processing unless legally permitted and appropriate safeguards are in place.

32

De-Identified and Aggregated Information

We may create aggregated, statistical or de-identified information from personal data.

Where information has been appropriately de-identified so that it can no longer reasonably be associated with an identifiable individual, we may use it for purposes including:

  • analytics;
  • research;
  • product development;
  • benchmarking;
  • reporting;
  • business planning; and
  • improving our products and services.

We will not intentionally attempt to re-identify properly de-identified information except where legally permitted and necessary for legitimate purposes such as security or compliance.

33

Business Communications

If you communicate with us on behalf of a company or organisation, we may process:

  • your name;
  • business email;
  • job title;
  • company information;
  • telephone number;
  • project information;
  • correspondence;
  • proposals;
  • statements of work;
  • billing information; and
  • other business information.

We use this information to manage the business relationship, provide services, communicate with you and fulfil contractual and legal obligations.

34

Confidential Business and Project Information

If you provide ORIGEN with confidential information as part of a software, web, mobile or e-commerce project, we may process and store that information to provide the contracted services.

Project-specific confidentiality, security and data-processing obligations may also be governed by:

  • a contract;
  • statement of work;
  • non-disclosure agreement;
  • data-processing agreement;
  • service agreement; or
  • other written agreement.

Where a project involves personal data belonging to the customer's users or customers, the customer's privacy responsibilities and ORIGEN's processing responsibilities may be further defined in the applicable agreement.

35

Data Minimisation

ORIGEN aims to collect and process personal data that is relevant and reasonably necessary for the purpose for which it is processed.

We do not intentionally collect personal data merely because it may be useful in the future.

Where practical, we seek to:

  • minimise collection;
  • limit access;
  • avoid unnecessary duplication;
  • remove outdated information;
  • anonymise information where appropriate; and
  • restrict processing to legitimate purposes.
36

Accuracy of Personal Data

We take reasonable steps to maintain accurate and up-to-date personal data where necessary for the relevant processing purpose.

You may contact us to request correction of inaccurate or incomplete information.

You are responsible for providing accurate information where you create an account, place an order or otherwise provide information to us.

37

Data Access by ORIGEN Personnel

Access to personal data is restricted to personnel, contractors and service providers who reasonably require access for legitimate business or service purposes.

Where appropriate, access may be controlled through:

  • role-based permissions;
  • authentication;
  • access logging;
  • confidentiality obligations; and
  • other security controls.
38

Data Processors and Service Providers

We may appoint third-party processors or service providers to process personal data on our behalf.

Where required, we will seek to impose appropriate contractual obligations relating to:

  • confidentiality;
  • security;
  • permitted processing;
  • data retention;
  • sub-processing;
  • breach notification;
  • deletion or return of information; and
  • compliance with applicable law.

Service providers may not necessarily be located in Sri Lanka.

39

Sub-Processors

Where our service providers use additional service providers to process personal data, those providers may act as sub-processors.

Depending on the applicable service and legal requirements, we may:

  • assess the provider;
  • contractually restrict its processing;
  • require appropriate security measures;
  • maintain records of relevant providers; and
  • provide information about material sub-processors where required.
40

Data Security Responsibilities of Users

You are responsible for taking reasonable steps to protect your account and information.

You should:

  • use a strong password;
  • avoid sharing passwords;
  • enable available security features;
  • keep devices and software updated;
  • avoid using unauthorised third-party applications;
  • log out of shared devices; and
  • notify us if you suspect unauthorised access.

ORIGEN will not normally ask you to disclose your account password through unsolicited communications.

41

Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be necessary because of:

  • changes to our products;
  • changes to our business;
  • changes to technology;
  • changes to third-party providers;
  • changes to applicable law;
  • regulatory guidance;
  • security improvements; or
  • changes in our data-processing practices.

The updated version will be published on the relevant website or application.

The "Last Updated" date at the top of this Policy indicates when it was most recently revised.

Where a material change is legally required to be brought to your attention, we will take reasonable steps to notify affected users.

42

Relationship With Other Policies

This Privacy Policy should be read together with applicable:

  • Terms & Conditions;
  • Refund Policy;
  • End User Licence Agreements;
  • Subscription Terms;
  • Store Terms;
  • Cookie notices;
  • Data Processing Agreements;
  • Statements of Work;
  • service agreements; and
  • other product-specific policies.

Where a specific product or service has a separate privacy notice, that notice may provide additional information specific to that product.

Where a conflict exists, the applicable product-specific notice or contractual data-processing terms will govern to the extent of the conflict, subject to applicable law.

44

Governing Law

This Privacy Policy is intended to operate primarily under the laws of Sri Lanka, including applicable data-protection legislation.

Nothing in this Policy prevents applicable mandatory privacy or consumer-protection laws from applying where they provide additional rights or protections.

Where a dispute or regulatory matter arises, the applicable jurisdiction and dispute-resolution rules will be determined in accordance with applicable law and any valid contractual provisions.

45

Contact Us

For questions, requests or complaints concerning privacy or personal data, contact:

ORIGEN Holdings (Pvt).Ltd

No. 387, Akkuregoda Road, Thalangama South, Battaramulla, Sri Lanka.

Email: hello@origen.lk Phone: +94 76 906 5806 Website: https://www.origen.lk

Please include "Privacy Request" in the subject line where appropriate.

46

Privacy Requests

For privacy-related requests, please provide:

  • your name;
  • email address associated with the relevant account, where applicable;
  • the nature of your request;
  • the relevant product, website, application or service; and
  • any other information reasonably necessary to identify the relevant data.

Please do not send passwords, payment-card numbers, authentication codes or other unnecessary sensitive information in a privacy request.

We may contact you if additional information is reasonably necessary to verify your identity or clarify your request.

47

Final Statement

ORIGEN is committed to building digital products and services in a manner that respects privacy, security and responsible data use.

As our products, applications, online stores and technology services evolve, our data-processing practices may also evolve. We will continue to review this Privacy Policy and our privacy practices to ensure that they remain appropriate for the products and services we operate and the legal requirements applicable to us.

© 2026 ORIGEN Holdings (Pvt).Ltd. All rights reserved.

Want to work with us?

A product idea, a partnership, or a build you want taken on. Let's have a conversation.

Contact us