Privacy Policy

Last updated: September 9, 2025

Overview

COSMOPOLITAN Sri Lanka (“we,” “our,” or “us”) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

This policy complies with the Sri Lankan Personal Data Protection Act No. 9 of 2022 (PDPA) and the European Union General Data Protection Regulation (GDPR) to ensure comprehensive protection of your personal data.

Information We Collect

Personal Information You Provide

  • Contact Information: Name, email address, phone number when you subscribe to our newsletter or contact us
  • Account Information: Username, password, and profile information when you create an account
  • Communication Data: Messages, comments, and feedback you provide

Information Automatically Collected

  • Usage Data: Pages visited, time spent, click patterns, referring websites
  • Device Information: IP address, browser type, operating system, device identifiers
  • Cookies and Tracking: See our Cookie Policy for detailed information

How We Use Your Information

We process your personal information for the following legitimate purposes:

  • Service Provision: To provide, maintain, and improve our content and services
  • Communication: To send newsletters, updates, and respond to inquiries
  • Analytics: To understand user behavior and improve website performance
  • Legal Compliance: To comply with applicable laws and regulations
  • Security: To protect against fraud, abuse, and security threats

Legal Basis for Processing

Under GDPR and Sri Lankan PDPA, we process your personal data based on:

  • Consent: When you voluntarily provide information or agree to cookies
  • Legitimate Interest: For analytics, security, and website improvement
  • Legal Obligation: To comply with applicable laws and regulations
  • Contract Performance: To provide services you have requested

Lawful Bases and Retention Schedule

We match each purpose to a lawful basis and retention period under GDPR/PDPA:

Newsletters & Accounts

  • Lawful basis: Consent (marketing opt‑in) or Contract (account servicing)
  • Retention: Until unsubscribe or account deletion; backups per legal requirements

Analytics & Security

  • Lawful basis: Legitimate Interests (site performance, fraud prevention)
  • Retention: Up to 26 months (aggregated thereafter)

Advertising & Affiliates

  • Lawful basis: Consent (marketing cookies) and Legitimate Interests (brand safety, measurement)
  • Retention: Up to 24 months depending on partner

Customer Support & Legal

  • Lawful basis: Legitimate Interests and Legal Obligation
  • Retention: 3 years from last contact or longer where law requires

Your Rights

Under GDPR and Sri Lankan PDPA, you have the following rights:

Right to Access

Request copies of your personal data

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data

Right to Object

Object to processing of your data

Right to Portability

Transfer your data to another service

Right to Withdraw Consent

Withdraw consent at any time

Data Security

We implement appropriate technical and organizational security measures to protect your personal information:

  • Encryption of data in transit and at rest
  • Regular security assessments and monitoring
  • Access controls and staff training
  • Incident response procedures

Data Retention

We retain personal information only as long as necessary for the purposes outlined in this policy:

  • Newsletter subscriptions: Until you unsubscribe
  • Analytics data: 26 months from collection
  • Contact inquiries: 3 years from last contact
  • Legal compliance: As required by applicable law

Third-Party Sharing

We may share your information with trusted third parties in the following circumstances:

  • Service Providers: Analytics, hosting, and marketing platforms
  • Legal Requirements: When required by law or legal process
  • Business Transfers: In connection with mergers or acquisitions
  • Hearst Media: We may share data with Hearst Magazine Media, Inc., our parent company, for business operations and content development
  • Consent: When you have given explicit consent

Advertising, Sponsored Content, and Affiliate Links

Some pages contain affiliate links and/or sponsored content. If you purchase through these links, we may earn a commission at no extra cost to you. Such content is labeled and separated from editorial. Any tracking associated with advertising/affiliates relies on Marketing cookies and will only run with your consent. Measurement and brand‑safety processing follow our legitimate interests where permitted.

Data Transferability

In certain circumstances, your personal data may be transferred to:

  • Hearst Magazine Media, Inc.: Our parent company may access your data for business operations, content development, and legal compliance
  • Future Licensees: In the event of a business transfer, merger, or change in ownership, your data may be transferred to the new entity with appropriate safeguards
  • Service Providers: Trusted third-party service providers who assist in our operations under strict data protection agreements

All data transfers are conducted with appropriate legal safeguards and in compliance with applicable data protection laws.

PDPA Alignment, Cross‑Border Transfers and DSAR Instructions

We align with the Sri Lankan Personal Data Protection Act No. 9 of 2022 (PDPA). Where we transfer personal data outside Sri Lanka or the EU/UK, we implement appropriate safeguards such as contractual clauses and strict access controls. You may request details of the transfer mechanisms by contacting our Data Protection Officer.

How to Exercise Your Rights (DSAR)

  1. Submit your request via our dedicated portal: /user-rights.
  2. We acknowledge within 72 hours and respond within 30 days (extendable where permitted by law).
  3. We verify identity, process your request, and deliver securely. Deletions include a 30‑day grace period to reverse if requested.

Complaints & Supervisory Authorities

You have the right to lodge a complaint with the Data Protection Authority of Sri Lanka. If you are in the EU/UK, you may also complain to your local supervisory authority. We encourage contacting us first so we can resolve your concerns quickly.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Data Protection Officer

Email: privacy@cosmopolitanlk.com

Editorial Office:

TRIBAL LANKA PRIVATE LIMITED bearing registration No. PV131904, a limited liability company incorporated under the Companies Act No 07 of 2007 and having its registered office at 32A, First Lane Jambugasmulla Road, Nugegoda.

This publication is operated by Tribal Lanka Private Limited by Permission of Hearst Magazine Media, Inc., New York, NY, United States of America.