Privacy Policy
Last updated: September 9, 2025
Overview
COSMOPOLITAN Sri Lanka (“we,” “our,” or “us”) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
This policy complies with the Sri Lankan Personal Data Protection Act No. 9 of 2022 (PDPA) and the European Union General Data Protection Regulation (GDPR) to ensure comprehensive protection of your personal data.
Information We Collect
Personal Information You Provide
- Contact Information: Name, email address, phone number when you subscribe to our newsletter or contact us
- Account Information: Username, password, and profile information when you create an account
- Communication Data: Messages, comments, and feedback you provide
Information Automatically Collected
- Usage Data: Pages visited, time spent, click patterns, referring websites
- Device Information: IP address, browser type, operating system, device identifiers
- Cookies and Tracking: See our Cookie Policy for detailed information
How We Use Your Information
We process your personal information for the following legitimate purposes:
- Service Provision: To provide, maintain, and improve our content and services
- Communication: To send newsletters, updates, and respond to inquiries
- Analytics: To understand user behavior and improve website performance
- Legal Compliance: To comply with applicable laws and regulations
- Security: To protect against fraud, abuse, and security threats
Legal Basis for Processing
Under GDPR and Sri Lankan PDPA, we process your personal data based on:
- Consent: When you voluntarily provide information or agree to cookies
- Legitimate Interest: For analytics, security, and website improvement
- Legal Obligation: To comply with applicable laws and regulations
- Contract Performance: To provide services you have requested
Lawful Bases and Retention Schedule
We match each purpose to a lawful basis and retention period under GDPR/PDPA:
Newsletters & Accounts
- Lawful basis: Consent (marketing opt‑in) or Contract (account servicing)
- Retention: Until unsubscribe or account deletion; backups per legal requirements
Analytics & Security
- Lawful basis: Legitimate Interests (site performance, fraud prevention)
- Retention: Up to 26 months (aggregated thereafter)
Advertising & Affiliates
- Lawful basis: Consent (marketing cookies) and Legitimate Interests (brand safety, measurement)
- Retention: Up to 24 months depending on partner
Customer Support & Legal
- Lawful basis: Legitimate Interests and Legal Obligation
- Retention: 3 years from last contact or longer where law requires
Your Rights
Under GDPR and Sri Lankan PDPA, you have the following rights:
Right to Access
Request copies of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
Request deletion of your personal data
Right to Object
Object to processing of your data
Right to Portability
Transfer your data to another service
Right to Withdraw Consent
Withdraw consent at any time
Data Security
We implement appropriate technical and organizational security measures to protect your personal information:
- Encryption of data in transit and at rest
- Regular security assessments and monitoring
- Access controls and staff training
- Incident response procedures
Data Retention
We retain personal information only as long as necessary for the purposes outlined in this policy:
- Newsletter subscriptions: Until you unsubscribe
- Analytics data: 26 months from collection
- Contact inquiries: 3 years from last contact
- Legal compliance: As required by applicable law
Third-Party Sharing
We may share your information with trusted third parties in the following circumstances:
- Service Providers: Analytics, hosting, and marketing platforms
- Legal Requirements: When required by law or legal process
- Business Transfers: In connection with mergers or acquisitions
- Hearst Media: We may share data with Hearst Magazine Media, Inc., our parent company, for business operations and content development
- Consent: When you have given explicit consent
Advertising, Sponsored Content, and Affiliate Links
Some pages contain affiliate links and/or sponsored content. If you purchase through these links, we may earn a commission at no extra cost to you. Such content is labeled and separated from editorial. Any tracking associated with advertising/affiliates relies on Marketing cookies and will only run with your consent. Measurement and brand‑safety processing follow our legitimate interests where permitted.
Data Transferability
In certain circumstances, your personal data may be transferred to:
- Hearst Magazine Media, Inc.: Our parent company may access your data for business operations, content development, and legal compliance
- Future Licensees: In the event of a business transfer, merger, or change in ownership, your data may be transferred to the new entity with appropriate safeguards
- Service Providers: Trusted third-party service providers who assist in our operations under strict data protection agreements
All data transfers are conducted with appropriate legal safeguards and in compliance with applicable data protection laws.
PDPA Alignment, Cross‑Border Transfers and DSAR Instructions
We align with the Sri Lankan Personal Data Protection Act No. 9 of 2022 (PDPA). Where we transfer personal data outside Sri Lanka or the EU/UK, we implement appropriate safeguards such as contractual clauses and strict access controls. You may request details of the transfer mechanisms by contacting our Data Protection Officer.
How to Exercise Your Rights (DSAR)
- Submit your request via our dedicated portal: /user-rights.
- We acknowledge within 72 hours and respond within 30 days (extendable where permitted by law).
- We verify identity, process your request, and deliver securely. Deletions include a 30‑day grace period to reverse if requested.
Complaints & Supervisory Authorities
You have the right to lodge a complaint with the Data Protection Authority of Sri Lanka. If you are in the EU/UK, you may also complain to your local supervisory authority. We encourage contacting us first so we can resolve your concerns quickly.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Data Protection Officer
Email: privacy@cosmopolitanlk.com
Editorial Office:
TRIBAL LANKA PRIVATE LIMITED bearing registration No. PV131904, a limited liability company incorporated under the Companies Act No 07 of 2007 and having its registered office at 32A, First Lane Jambugasmulla Road, Nugegoda.
This publication is operated by Tribal Lanka Private Limited by Permission of Hearst Magazine Media, Inc., New York, NY, United States of America.