PRIVACY POLICY

Updated: 02/10/2023 Introduction Welcome to HitFlix from SLT-MOBITEL This Privacy Policy explains the collection, use, sharing, and processing of personal information by SLT-MOBITEL, the owner of the Hitflix streaming platform ("we," "us," or "our"), regarding individuals ("you") who interact with our Offerings ("Information"). You can learn more about affiliated companies by visiting our website: https://sltmobitel.lk
SLT-Mobitel consists of several legal entities and business units. In this Privacy Policy, the Controller or Controllers ("Controller") of your Information refers to the company that determines the purposes and methods of its processing. The Controller for the processing of your Information will depend on which Offering you are using; often, it will be the company responsible for providing that Offering, as stated in our terms and conditions.
In some countries outside Sri Lanka, such as the European Economic Area, we may require your consent for the processing of your Information as described in this Privacy Policy. Unless you indicate otherwise, such as opting out or not opting in if asked, and where permitted by law, by providing Information or interacting with our Offerings, you consent to our use of Information in accordance with this Privacy Policy. TABLE OF CONTENTS SCOPE OF THIS PRIVACY POLICY  THE INFORMATION WE COLLECT  HOW WE USE THE INFORMATION  INFORMATION SHARING AND DISCLOSURE  DATA RETENTION  INDIVIDUAL RIGHTS REQUESTS  COOKIES AND OTHER TECHNICAL INFORMATION  INTERNATIONAL TRANSFER  NOTIFICATION REGARDING UPDATES  HOW TO CONTACT US 
SCOPE OF THIS PRIVACY POLICY Please read this policy carefully as it outlines the types of Information we may collect about you, the purposes and methods of collection, the lawful basis for such collection (where applicable), data retention information, details about your rights, and how to contact us. This Privacy Policy applies to both our online and offline data processing activities, encompassing Information collected through various Offerings. Please note that we may combine Information collected from one source (e.g. a website) with Information obtained from another source (e.g., a mobile app), including Information possibly collected by SLT-Mobitel (as further described below).
THE INFORMATION WE COLLECT
We collect, use, share, and otherwise process the following categories of Information: 1) Information we may collect from you: - Registration, account, and sign-up Information, including details such as your name, username, password, email address, contact information, date of birth or age, and your interests in our content when you register or sign up for one of our Offerings. We may not allow children to register, without their parents’ consent as per the international standards. - Information about your purchase of an Offering, which may include relevant payment information like credit card details. Additionally, we may process Information related to trial periods, redemptions of rewards or promotions, periods without an active subscription, payment history, and any missed payments. - Information about your use of, or participation in an Offering, including interactions with our Digital Services, such as whether you have opened an email we sent you, the content you have viewed or posted, your interactions with advertisements, and your preferences and interests in various features, programs, services, and content available on a Digital Service. This may also include demographic information, both at an individual and household level. - Information provided by you when participating in consumer surveys, including online or written replies, where applicable. - Information about your location, derived from device information like IP address or country code, your device's interactions with our Digital Services, or, with your consent, precise geolocation information from mobile devices. - Technical/usage Information from your device, including the type of device, unique device identifier, operating system, mobile device identifier, and application attributes and settings. - Information about your customer queries, such as when you contact us through customer helpdesks, email addresses, forms or ticketing systems, where information may be recorded.
2) Information we may collect about you from other sources. Please note that we strive to handle your Information responsibly and protect your privacy. If you have any questions or concerns, please do not hesitate to contact us.
HOW WE USE THE INFORMATION We may use Information for the purposes described in this Privacy Policy. Below, we explain our various purposes, any processing activities that we believe may need further explanation, and, where necessary, the ‘lawful basis’ on which we rely to process your Information. Please note that while Information may be processed for more than one purpose (e.g. Information we obtain when Providing Our Offering may also be used for Improving and Developing Our Offering and/or for Marketing and Personalized Advertising), not all of the purposes or processing activities below will necessarily apply in every case. Our particular use of your Information will depend on the Offering you engage with and the manner in which you interact with us, including the permissions you give us (e.g. whether or not you consent to certain uses, such as direct marketing) and other controls you exercise regarding our processing of your Information (e.g. whether or not you choose to opt-out, where this is offered).
1) Providing Our Offerings: We may use your Information for the purpose of setting up your account with us, registering you for an Offering, enabling you to pay for it, providing the Offering, maintaining the Offering, and resolving any issues. This may include enforcing applicable terms and conditions (e.g. for our subscription services, limitations on the number of devices, and displaying the right content based on location) and optimizing the delivery of the Offering to each specific device used to access it, as well as providing the "continue watching" feature on our subscription services.
When processing Information according to a lawful basis, we rely upon the following:
- Much of our processing, such as providing and maintaining our Offerings, is necessary for entering into, or the performance of, the contract we have with you, including enabling new customers to sign up or register with us and existing customers to log in to our Digital Services. - Other types of processing are necessary for our ‘legitimate interests’ (and those of others), including: - Running our business, providing our Offerings, and serving our customers. - Contacting customers with important notices or updates. - Contacting customers about their transactions, purchases, and competition wins. - Personalizing content and making recommendations for other content. - Exercising and/or enforcing the rights granted to us under the terms and conditions of the Offering. - Facilitating payment for our Offerings. - For other types of processing, we may rely on your consent (where given).
2) Improving and Developing Our Offerings: We may use your Information for the purpose of analyzing, improving, personalizing, and evaluating our Offerings and your use of them, as well as to develop new Offerings. This may include analyzing your responses to consumer surveys.
When processing Information according to a lawful basis, we rely upon the following: - Some types of processing are necessary for our ‘legitimate interests’ (and those of others), including: - Creating efficiencies in our business. - Understanding consumer trends and interests, including through customer insights, market research, and content performance measurement. - Compiling statistics about the use of our Offerings. - For other types of processing, we may rely on your consent (where given).
3) Providing Customer Services: We may use your Information for the purpose of providing Customer Services, including dealing with your queries and complaints (including troubleshooting), whether you contact us by email, chat boxes, forms or ticketing services, letter, website, or via a Social Media Site.
When processing Information according to a lawful basis, we rely upon the following: - Some types of processing activities will be necessary for us to perform our contract with you to provide an Offering. - Some types of processing activities will be necessary to comply with our legal obligations. - Some types of processing will be necessary for our legitimate interests (or those of others), including: - Responding to our customer queries and complaints. - Tracking the progress and effectiveness of our response. - Improving our Customer Services.
4) Detecting, Preventing, and Investigating Criminal and Other Illegal Activities: We may use your Information for the purpose of detecting, preventing, or investigating criminal activities (including fraud and copyright infringement), protecting user safety, and enforcing our civil rights in the courts. For example, where necessary, we may share your Information with law enforcement bodies or use it to take legal action against you to enforce our rights.
When processing Information according to a lawful basis, we rely upon the following: - Some types of processing activities will be necessary to comply with our legal obligations. - Some types of processing will be necessary for our legitimate interests (or those of others), including: - Protecting our business interests and rights, privacy, safety, and property, or that of our customers and users. - Establishing, exercising, or defending legal claims. - Sharing your Information with third parties to pursue available remedies or limit damage that we may sustain. 5) Compliance with Legal Obligations: We may use your Information for the purpose of complying with our legal obligations, including accounting rules, responding to Individual Rights Requests, and responding to requests from regulators, judicial authorities, and law enforcement or governmental bodies.
INFORMATION SHARING AND DISCLOSURE We share Information with and disclose it to the following parties, for the purposes set out below: Within our companies: We are part of a group of companies, and our companies support and interact with each other to run their businesses. As a result, we may receive your Information to process for the purposes set out in this Privacy Policy, where there is a legal basis for them to do so and consistent with any permissions you have given (e.g., whether or not you wish to receive marketing communications) and any other controls you exercise regarding our processing of your Information (e.g., where you have chosen to opt-out of certain processing).
Outside our companies: Third-Party Partners: We sometimes offer Digital Services and Offline Services that are sponsored by or co-branded with identified third parties. Due to these relationships, the third parties may collect or obtain personal information from you during the activity. We do not control these third parties' use of personal information. We encourage you to read their privacy policies to learn about their data practices. Other Third Parties: In the event of a likely change of control of the business (or a part of the business), such as a sale, merger, acquisition, or any transaction or reorganization, we may share your Information with interested parties, including as part of any due diligence process with new or prospective business owners and their respective professional advisers. Law Enforcement Bodies, Authorities, and Courts: We disclose Information where necessary for the prevention, investigation, or prosecution of criminal activities and in response to legal process, such as a court order or subpoena, or in response to a regulator, government authority, or law enforcement body's request. DATA RETENTION
In broad terms, we will only retain your Information for as long as necessary for the purposes described in this Privacy Policy. This means that retention periods will vary according to the type of Information and the reason we collected the Information in the first place. For example, some Information related to providing our Offerings to you will be kept for a number of years to comply with various finance and tax-related legal obligations. We have detailed internal retention policies that set out the various retention periods for different categories of Information, depending on our legal obligations and whether there is a commercial need to retain the Information. After a retention period has lapsed, the Information is securely deleted, unless it is necessary for the establishment, exercise, or defense of legal claims. For further information regarding applicable retention periods, you should contact us using the contact methods set out below.
INDIVIDUAL RIGHTS REQUESTS
Under certain conditions, you have the right to ask us to fulfill one or more of the following requests. We may ask you for proof of identity or other additional information before doing so:
1. Right to access and rectification: You can request details of the Information we hold, along with a copy of your Information, and the correction of any errors in your Information.
2. Right to erasure ("right to be forgotten"): The right, in certain circumstances, to ask for your Information to be deleted. However, there may be specific cases where we are unable to delete certain types of Information due to legal obligations (e.g., regulatory reporting purposes) or where retaining the Information is necessary for the provision of an Offering you have requested.
3. Marketing communications and sharing with third parties: We provide you with an opportunity to express your preferences regarding receiving certain marketing communications from us and our sharing of Information with trusted partners for their direct marketing purposes. Please refer to the "Ad Choices" section below for more information.
4. Right to object: You have the right to object (based on grounds relating to your particular situation) to the processing of your Information based on our legitimate interests, including for direct marketing purposes.
5. Right to withdraw consent: You can withdraw your consent at any time in respect of any processing of Information that is based upon consent.
We will assess any request to exercise these rights on a case-by-case basis. Some circumstances may allow us not to legally comply with a request due to relevant exemptions provided for in applicable data protection legislation. In such instances, this may mean that we can retain your Information even if you withdraw your consent.
Marketing communications:
We provide you with an opportunity to express your preferences regarding receiving certain marketing communications from us. If you would like to update these preferences, you can log in to an account you may have created with us to adjust your settings (where the feature is available), or you can follow the 'unsubscribe' instructions provided in any marketing email you receive. You may have more options depending on your mobile device and operating system. For example, most device operating systems (e.g., iOS for Apple phones, Android for Android devices, and Windows for Microsoft devices) provide their own instructions on how to limit or prevent the delivery of tailored in-application advertisements. You may review the support materials and/or the privacy settings for the respective operating systems to learn more about these features and how they apply to tailored in-app advertisements. Precise location information: To enable or disable the collection of precise location information from your Apple TV, Roku TV, and Fire TV, mobile device through our mobile apps, you can access your device settings and choose to limit that collection. You may also limit the collection of precise location information from websites through browser settings. However, this may restrict some services.
INTERNATIONAL TRANSFER
We operate internationally, and some processes involved in our use of your Information may require it to be stored or processed in countries outside the country where you are located. These countries may have different levels of legal protection for your Information, and you may have fewer legal rights in relation to it. Your Information may be transferred to and processed in countries such as Sri Lanka (our home country) and India (where some of our systems are located). However, whenever we transfer your Information outside of a country or region, such as the European Economic Area, we will ensure that we take the necessary steps to comply with applicable legal requirements. We will implement appropriate safeguards, such as using appropriate contractual mechanisms like the EU Standard Contractual Clauses, or relying on service providers participating in approved international data transfer mechanisms, including the adoption of Binding Corporate Rules. These measures are put in place to protect your Information when it is transferred outside of your country or region. For further information about the documents we use to safeguard your Information during international transfers, please feel free to contact us using the contact methods provided below.
NOTIFICATION REGARDING UPDATES
From time to time, we may update this Privacy Policy. We will notify you about any material changes by placing a notice on our sites, and applications. We encourage you to periodically check back and review this policy to ensure you are up to date.
HOW TO CONTACT US
If you have any questions about this Privacy Policy, you can contact us and our Data Protection Officer at "Sri Lanka Telecom PLC."