We understand that your personal data is important to you. Guided by our corporate values, we are committed to protecting your privacy and handling your information responsibly.
PRIVACY NOTICE
Updates and Amendments to our Privacy Notice
This Privacy Notice outlines the commitment of Mabroc Teas (Pvt) Ltd to the secure and transparent management of personal data. We operate in accordance with the Personal Data Protection Act No. 9 of 2022 of Sri Lanka (“PDPA”) and relevant international standards such as the European Union’s General Data Protection Regulation (GDPR), ensuring accountability across all our touchpoints.
This notice applies to Mabroc Teas (Pvt) Ltd and its business operations. When we say “Mabroc Teas,” “we,” or “us,” we refer to the company you are interacting with.
For the purposes of this notice, “Personal Data,” “Data Controller,” and “Data Processor” shall have the meanings assigned to them under the PDPA.
Who Collects Your Personal Data
Mabroc Teas acts as a Data Controller and may appoint trusted third-party service providers as Data Processors acting on our written instructions. Depending on the service you use, we are responsible for the processing of your information.
What Personal Data We Collect
We limit data collection to the information necessary for our business operations, including:
- Information you provide: Name, email, phone number, shipping and billing addresses, payment details for online orders, subscription preferences and account information.
- Information collected automatically: IP address, browser type, device identifiers, website usage data (such as pages visited, time spent, and order history).
All Personal Data collected is relevant, limited, and used only for its intended purpose.
How We Collect It
- Directly when you place an order, sign up for newsletters, or contact us.
- Automatically through cookies and tracking tools that remember your preferences.
- Occasionally from trusted partners or public sources (for example, if you interact with us through social media).
Why We Use Your Personal Data
We process your Personal Data based on consent, contractual necessity, legal obligation, or legitimate interests, as permitted under the PDPA.
Primary purposes include:
- Order and Service Fulfillment: Processing online orders, deliveries, and payments.
- Communication: Sending order updates, promotional offers, newsletters, and responding to inquiries.
- Website and Experience Improvement: Analyzing website traffic and usage to enhance our services.
- Compliance and Security: Preventing fraud, ensuring cybersecurity, and meeting legal obligations.
- Legal or Legitimate Interests: Processing where required under law or to protect life, health, or safety.
Special Categories of Personal Data and Children
We only collect sensitive personal data (e.g., health or biometric data) if necessary and with explicit consent.
Our website and services are not intended for children under 16. If we discover such data without parental consent, we will delete it immediately. Parents or guardians may contact our Data Protection Officer to request deletion.
Sharing Your Personal Data
We do not sell or rent your Personal Data. Sharing occurs only for necessary purposes:
- Within Mabroc Teas for seamless service and support.
- With trusted third-party service providers (e.g., payment gateways, delivery partners, cloud services) under strict confidentiality agreements.
- For legal or legitimate reasons – if required by law, court order, or to protect interests.
All service providers process Personal Data only under our instructions and are contractually obligated to maintain confidentiality and security.
Your Rights
Under the PDPA, you have the right to:
| Your Right | What It Means |
|---|---|
| Access & Correction | Request a copy or correct inaccuracies. |
| Erasure (“Be Forgotten”) | Request deletion when no longer needed. |
| Restrict or Object | Limit or object to specific processing. |
| Data Portability | Request data in a transferable format. |
| Withdraw Consent | Withdraw consent for specific uses at any time. |
| Automated Decisions Review | Request information about automated logic and human review. |
Rights may be exercised by authorized representatives or heirs within ten years of an individual’s passing.
To exercise your rights, email: mabroc@mabrocteas.com. We will respond within 21 working days.
If unsatisfied, you may raise a complaint with the Data Protection Authority of Sri Lanka.
How We Keep Your Personal Data Safe
We maintain a robust security framework including encryption, firewalls, and internal access controls. We conduct regular risk assessments and maintain incident response procedures for potential breaches.
All third-party service providers comply with strict security and confidentiality agreements.
Data Retention
We retain Personal Data according to legal, contractual, and operational requirements. Internal retention schedules ensure data is not kept longer than necessary.
Cross-Border Data Transfers
Cross-border processing is safeguarded through adequacy assessments and binding agreements to ensure protection consistent with Sri Lankan law and international standards.
Cookies and Tracking
We use cookies to enhance your website experience. You can manage or disable cookies via your browser, though some features may not function fully.
Updates to this Notice
This notice is periodically reviewed to maintain compliance with regulations and operational standards. The latest version is available on our website.
Contact Our Data Protection Officer
Data Protection Officer
Mabroc Teas (Pvt) Ltd
Address – 57, 3 Hunupitiya Rd, Kiribathgoda 11600
Email: mabroc@mabrocteas.com
Your trust matters deeply to us. Protecting your privacy reflects our commitment as a responsible brand.
Last Updated: March 2026


