Privacy Policy
Detailed overview of personal data collection, processing operations, multi-tenant controller/processor responsibilities, retention practices, and data subject rights under Sri Lankan data protection law.
1. Introduction & Multi-Tenant Data Controller Model
WSNexa ("we", "us", or "our") respects the privacy and confidentiality of all individuals who interact with our hospitality software platform. This Privacy Policy details how we process, store, and safeguard personal information in connection with our services.
Legal Framework: WSNexa is designed to support applicable data protection obligations under the Personal Data Protection Act No. 9 of 2022 (PDPA) and the Personal Data Protection (Amendment) Act No. 22 of 2025 of Sri Lanka (operational from 18 March 2025).
Crucial Distinction: Data Controller vs. Data Processor:
- WSNexa as Data Controller: We act as the Data Controller for direct account registration details, business owner profiles, billing accounts, technical server access logs, and communications directed to WSNexa Support.
- Hospitality Venue as Data Controller (WSNexa as Data Processor): When a hospitality venue (restaurant, hotel, cafe) operates WSNexa to manage customer dining, table reservations, QR orders, guest phone numbers, loyalty points, or kitchen orders, the individual venue is the primary Data Controller. WSNexa acts as a SaaS Data Processor providing the digital infrastructure on behalf of the venue.
2. Categories of Personal Data Collected
We collect only the minimum personal information necessary to deliver, secure, and operate the platform:
- Business & Owner Information: Full name, business email address, contact phone number, registered venue name, physical address, operating currency, and timezone.
- Staff Member Information: Name, work email, contact phone, branch assignment, system role (Owner, Manager, Cashier, Kitchen, Waiter), and operational action timestamps.
- Dining Guest / Customer Information: Optional guest name, phone number (for SMS/order status updates or loyalty programs), table seating association, ordered items, dietary notes, and payment preference.
- Operational & Transactional Data: Live order tickets, item modifiers, kitchen preparation timestamps, cashier settlements, payment transaction identifiers, and inventory stock usage.
- Technical & Session Information: Strictly necessary authentication tokens, active business/branch selector cookies, IP addresses recorded in server traffic logs, and browser user-agent headers for session security.
3. Legal Basis for Processing
Under the Sri Lanka Personal Data Protection Act No. 9 of 2022, we process personal data under the following lawful bases:
- Performance of a Contract: Processing is required to deliver SaaS capabilities, fulfill order lifecycles, and process subscription transactions.
- Legitimate Operational Interests: Maintaining platform security, preventing dining fraud, enforcing tenant isolation, and debugging system errors.
- Statutory & Legal Obligations: Maintaining financial and tax audit records as required under Sri Lankan revenue and commercial laws.
- Consent: Where a dining guest voluntarily joins a venue loyalty reward program or opts into promotional SMS communications.
4. Data Access Controls & Tenant Isolation
Multi-Tenant Row-Level Security (RLS): All customer and operational data is strictly segregated at the database layer using PostgreSQL Row-Level Security. No hospitality venue or authorized user can access, query, or view data belonging to another tenant.
Role-Based Authorization: Inside each tenant workspace, access to sensitive features (such as financial settlement, cashier balances, staff invitations, and raw audit logs) is strictly restricted based on verified system roles.
5. Subprocessors & Third-Party Integrations
We do not sell, rent, or monetize personal data to third parties. We engage only reputable infrastructure subprocessors necessary for operational delivery:
- Cloud Database & Auth Infrastructure: Supabase (managed PostgreSQL database, secure user authentication, and encrypted file storage).
- Direct Billing & Settlement Processing: During the current pre-commercial phase, subscription and pilot transactions are processed directly without an active third-party payment gateway. Technical integrations with Sri Lankan payment service providers remain in development for future activation, at which point applicable processing terms will be updated.
- No Advertising Trackers: WSNexa does NOT embed advertising pixels, social media trackers, or third-party behavioral analytics scripts.
6. Data Retention & Erasure Principles
Data Minimization: We retain personal information only for as long as is necessary to fulfill operational, contractual, and statutory accounting purposes.
Account Data: Retained while the business subscription remains active. Account owners may request permanent deletion as described in our Data & Account Deletion Policy.
Guest Dining Data: Temporary QR guest session tokens expire automatically. Completed order history and settlement logs are retained in accordance with the venue’s operational policies and statutory tax audit obligations.
7. Data Subject Rights Under Sri Lankan Law
Under Part II of the Sri Lanka Personal Data Protection Act No. 9 of 2022, data subjects possess the following statutory rights:
- Right of Access: You have the right to request confirmation and a summary of personal data held about you.
- Right to Rectification: You may request the correction of inaccurate or incomplete personal information.
- Right to Erasure / Deletion: You may request the deletion of personal data subject to legal, tax, or fraud-prevention retention exceptions.
- Right to Withdraw Consent: Where processing relies on consent, you may withdraw your consent at any time without affecting prior lawful processing.
- Exercising Rights: Direct your request to wsnexaofficial@gmail.com with your name, account details, and the nature of your request.
8. Privacy Inquiries & Contact
For privacy questions, data subject access requests, or regulatory communications regarding our data handling practices, please contact:
WSNexa Privacy & Data Protection Desk: wsnexaofficial@gmail.com | Phone: 0761434289 | Address: Panawewa, Bingiriya, Sri Lanka.

