Privacy & Data Protection

Privacy Policy

This policy explains how Finnect Digital (Pvt) Ltd handles information through our website and our employee cash-collection mobile applications.

Last updated: 27 July 2026

1. Scope and Applications

This Privacy Policy explains how Finnect Digital (Pvt) Ltd (“Finnect Digital”, “we”, “us” or “our”) processes information when you use this website or either of the following Android applications:

  • Finnect Digital (package name: com.finnect.digital), provided for authorized employees of Peoples Credit Solutions (PCS).
  • Finnect CDFF Mobile APP (package name: lk.finnect.cdff), provided for authorized employees of Ceylon Development Funding Force (CDFF).

These are business applications for authorized employees of our client organizations. Finnect Digital hosts and processes application data to provide the service to PCS and CDFF. The relevant employer also determines how its business and customer records are used. Applicable client agreements, employment policies or additional privacy notices may also apply.

2. How the Mobile Apps Work

The mobile applications support cash collection for microfinance operations. An authorized collection officer can:

  • select a branch and a center or route;
  • view loans assigned to that center or route;
  • record payments received from clients and view the related receipt details;
  • view total collections in the cash summary or cashbook; and
  • record bank-deposit details so the cash summary can be updated.

The mobile apps communicate with Finnect Digital’s application programming interfaces (APIs) to retrieve and update the information required for these functions.

3. Information We Process

Employee authentication information

  • User ID and password used to authenticate an authorized employee.
  • The employee account and access permissions assigned by the relevant client organization.

Client, loan, payment and deposit information

Through our APIs, the apps access and process business records needed for cash collection, including:

  • client names;
  • loan numbers, balances, branch and center or route details;
  • payment amounts, dates and receipt details;
  • cash-summary or cashbook totals; and
  • bank-deposit information entered by the collection officer.

This information relates to the relevant financial institution’s operations and its clients. Employees should access and use it only for authorized work purposes.

4. How We Use Information

  • Authenticate authorized employees and apply their assigned access permissions.
  • Display assigned branches, centers or routes, loans and balances.
  • Record loan payments, generate or display receipt details and maintain cash summaries.
  • Record bank-deposit details and update the related cashbook information.
  • Operate, support, secure and maintain the applications, APIs and ERP services.
  • Prevent unauthorized access, investigate security incidents and comply with legal or contractual obligations.

We do not sell information processed through the mobile apps, use it for advertising or use it for purposes unrelated to providing and protecting the contracted ERP and cash-collection services.

5. Device Permissions and Data Not Collected

The current versions of these apps do not require or collect the following data for their cash-collection functions:

  • precise or approximate device location;
  • camera images, photos or files;
  • contacts, SMS messages or notification content; or
  • advertising identifiers, other device identifiers, analytics, diagnostics or app-usage data.

If a future version introduces a new permission or collection practice, we will update this policy and make any disclosure or obtain any consent required by applicable law and Google Play policy.

6. Disclosure and Service Providers

Application information is available to authorized personnel of the relevant client organization—PCS or CDFF—as required for its operations. We may also provide limited access to authorized Finnect Digital personnel who need it to host, maintain, secure or support the service.

We may use contracted infrastructure or technical service providers where necessary to operate and protect the applications and servers. Such providers are expected to process information only for the contracted service and protect it appropriately.

We may disclose information when required by applicable law, a court or regulatory authority, or when reasonably necessary to protect the rights, safety or security of Finnect Digital, our clients or others. We do not share app information with third parties for their own advertising or marketing.

7. Storage and International Processing

Information processed through the mobile applications is stored on servers operated or managed by Finnect Digital. If a contracted hosting or infrastructure provider processes information outside Sri Lanka, we will use appropriate contractual, organizational or technical safeguards where required by applicable law.

8. Data Retention

We retain employee account information and financial transaction records for as long as necessary to provide the service, follow the relevant client organization’s instructions, maintain accurate business and financial records, resolve disputes, protect the service, and meet contractual, regulatory or legal requirements.

Because payment, receipt and bank-deposit records may form part of the relevant financial institution’s official records, deactivating an employee’s access does not automatically delete those transaction records. When information is no longer required, it is deleted, anonymized or securely archived as appropriate.

9. Data Security

Finnect Digital uses reasonable administrative, technical and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration or disclosure. Access is limited according to assigned user permissions.

Employees are responsible for keeping their User ID and password confidential and must promptly report suspected unauthorized access to their employer. No internet transmission or storage system is completely secure.

10. Employee Accounts, Access Removal and Data Requests

App accounts are issued and administered for employees by PCS or CDFF; employees do not create personal consumer accounts within the apps. When an employee leaves the organization or no longer requires access, the employer’s authorized department, such as Human Resources or system administration, can block or deactivate the employee’s access.

An employee who wants to request correction or deletion of employee account information should first contact the relevant employer. The employee may also email info@finnectdigital.lk and identify the applicable app and employer. Finnect Digital will coordinate the request with the relevant client organization and may need to verify the requester’s identity and authority.

Access deactivation is separate from deletion of business transaction records. Loan payments, receipts, cashbook entries and bank-deposit records may be retained where needed for the client organization’s financial records or to satisfy contractual, fraud-prevention, regulatory or legal requirements.

11. Your Privacy Rights

Subject to applicable law, you may have rights to:

  • Request access to personal information held about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion or restriction of processing in applicable circumstances.
  • Object to certain processing or withdraw consent where processing is based on consent.

We may need to verify your identity and consult the relevant client organization before responding. These rights may be limited where law, regulation, contract or legitimate record-keeping requirements require continued retention or processing.

12. Website Information and Cookies

When you contact us through this website or otherwise communicate with us, we may receive your name, company name, email address, telephone number, enquiry details and any other information you choose to provide. Basic technical information may also appear in website security or hosting logs, such as an IP address, browser type, device type and requested page.

This website currently uses browser local storage to remember your light or dark theme and whether you accepted or declined the cookie notice. We do not currently enable analytics or advertising cookies. Browser preferences remain on your device until you clear them.

13. Children’s Privacy

The mobile applications are restricted business tools for authorized employees and are not intended for children. Our website is also not directed to children, and we do not knowingly request personal information from them.

14. Policy Updates

We may update this policy when our applications, website, services, data practices or legal obligations change. The revised version will be published on this page with a new “Last updated” date.

15. Contact Us

To ask a privacy question, report a concern or submit an account-data request for either mobile app, email info@finnectdigital.lk or use our Contact page.

Please state whether your request relates to Finnect Digital (PCS) or Finnect CDFF Mobile APP (CDFF), and include enough information for us to identify the relevant employee account. Do not send your password or sensitive identification documents by email.