Last Updated: April 27, 2026

SCOPE OF THIS POLICY:  This Privacy Policy applies exclusively to the DocSync public-facing website (the “Website”) operated by Axon Systems (Pvt) Ltd. It does not apply to data processed within the DocSync EMR platform or any data submitted by healthcare practitioners or their patients through the platform, which is governed by a separate Data Processing Agreement.

  1. About Us & Our Commitment to Privacy

Axon Systems (Pvt) Ltd (“Axon Systems”, “we”, “us”, or “our”) is the company behind DocSync, a cloud-based Electronic Medical Records (EMR) and practice management platform built for healthcare practitioners in Sri Lanka. Our registered place of business is in Sri Lanka.

We are committed to protecting and respecting the privacy of every person who visits our Website. This Privacy Policy explains what personal information we collect when you visit [www.docsync.lk] (the “Website”), how we use it, who we share it with, and what rights you have in relation to it.

Please read this Policy carefully. By continuing to use the Website, you confirm that you have read and understood this Policy. If you do not agree with the practices described here, please discontinue use of the Website.

 

  1. Data Controller

For the purposes of applicable Sri Lankan data protection law, including the Personal Data Protection Act No. 9 of 2022 (“PDPA”), the data controller for personal information collected through this Website is:

Axon Systems (Pvt) Ltd

No.22, Kirimandala Mawatha, Nawala, Rajagiriya, Sri Lanka

Email: privacy@docsync.lk

Website: www.docsync.lk

 

  1. Information We Collect

3.1  Information You Provide Directly

When you interact with certain features of the Website, you may voluntarily provide us with personal information, including:

  • Contact form submissions: your name, email address, phone number, and the content of your message
  • Demo request forms: your name, email address, practice name, and the nature of your enquiry
  • Newsletter or update sign-up: your name and email address

You are not required to provide this information to browse the Website. We only collect what you choose to give us.

3.2  Information Collected Automatically

When you visit the Website, certain information is collected automatically through cookies and similar technologies. This includes:

  • Your IP address (anonymised where possible)
  • Browser type, version, and operating system
  • Pages visited, time spent on pages, and navigation paths
  • Referring URL (the page you came from before visiting our Website)
  • Device type and screen resolution
  • Date and time of your visit

This information is collected through WordPress (our website platform) and Google Analytics. It is used in aggregate form to understand how visitors use our Website and to improve our content and user experience.

  1. How We Use Your Information

We use the personal information we collect for the following purposes:

  • To respond to your enquiries, demo requests, or contact form submissions
  • To send you information about DocSync products and services where you have requested this
  • To analyse Website traffic and usage patterns in order to improve the Website and our content
  • To ensure the security and technical operation of the Website
  • To comply with our legal and regulatory obligations
  • To enforce our Website Terms of Use and protect our rights

We will only use your personal information for the purposes for which it was collected, unless we reasonably consider that we need to use it for another reason compatible with the original purpose, and that reason is permitted under applicable law.

  1. Legal Basis for Processing

Under the Personal Data Protection Act No. 9 of 2022, we are required to have a lawful basis for processing your personal data. Our lawful bases are:

  • Consent: where you have given us clear consent to process your data for a specific purpose (e.g. subscribing to updates or enabling analytics cookies)
  • Legitimate interests: where processing is necessary for our legitimate business interests, such as analysing website traffic to improve our services, provided those interests are not overridden by your rights
  • Contractual necessity: where processing is necessary to take steps at your request prior to entering a contract, such as responding to a product enquiry
  • Legal obligation: where processing is necessary to comply with a legal or regulatory obligation
  1. Cookies & Tracking Technologies

6.1  What Are Cookies?

Cookies are small text files placed on your device by a website when you visit it. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to website operators. Cookies do not contain executable code and cannot access information stored elsewhere on your device.

6.2  Categories of Cookies We Use

We use the following categories of cookies on our Website:

  • Necessary cookies: essential for the Website to function correctly. The Website cannot operate without these cookies and they cannot be disabled.
  • Functional cookies: enhance your experience by remembering your preferences and choices (e.g. pre-filling your name in comment forms).
  • Analytics cookies: help us understand how visitors interact with the Website by collecting information in an anonymous, aggregated form. We use Google Analytics for this purpose.

6.3  Cookie Inventory

The table below describes the specific cookies set by the Website:

Cookie Name Provider Purpose Type Duration
wordpress_logged_in_{hash} WordPress Authenticates logged-in users and maintains their login session Necessary Session
wordpress_sec_{hash} WordPress Stores login credentials securely during session (admin area) Necessary Session
wp-settings-{user} WordPress Personalises the WordPress admin interface for individual users Functional 1 year
wp-settings-time-{user} WordPress Records time-stamped session for admin settings cookie Functional 1 year
comment_author_{hash} WordPress Saves visitor name/email to pre-fill comment forms on return visits Functional 347 days
comment_author_email_{hash} WordPress Saves visitor email to pre-fill comment forms on return visits Functional 347 days
_ga Google Analytics Distinguishes unique users by assigning a random ID for traffic analysis Analytics 2 years
_ga_{container} Google Analytics Stores and counts page views for Google Analytics 4 sessions Analytics 2 years
_gid Google Analytics Distinguishes users; stores and counts page views for 24-hour sessions Analytics 24 hours
_gat / _gat_{container} Google Analytics Throttles request rate to limit data collection on high-traffic sites Analytics 1 minute

 

6.4  Google Analytics

We use Google Analytics, a web analytics service provided by Google LLC. Google Analytics collects information about your use of the Website (such as pages visited and time spent) through cookies and transmits this data to Google servers, which may be located outside Sri Lanka.

We have enabled IP anonymisation in Google Analytics, meaning your IP address is truncated before it is stored by Google. The data collected is used solely to generate aggregate reports on Website activity and is not used to identify you personally.

You can opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on, available at: tools.google.com/dlpage/gaoptout

For more information on how Google uses data collected via our Website, please visit: policies.google.com/technologies/partner-sites

6.5  Managing Cookies

Most web browsers allow you to control cookies through their settings preferences. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of the Website may not function as intended.

You can manage your cookie preferences at any time through your browser settings. Common browser guides:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Manage Website Data
  • Microsoft Edge: Settings > Cookies and site permissions
  1. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your information in the following limited circumstances:

  • Service providers: we share data with trusted third-party service providers who assist us in operating the Website (e.g. web hosting, email delivery). These providers are authorised to use your information only as necessary to provide services to us and are bound by appropriate data protection obligations.
  • Google LLC: as described in Section 6, Website analytics data is processed by Google Analytics.
  • WordPress (Automattic Inc.): our Website is built on WordPress. Automattic may process certain technical data as part of providing the WordPress platform. For details, see Automattic’s Privacy Policy at automattic.com/privacy.
  • Legal requirements: we may disclose your information where required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights or the safety of any person.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to the same privacy protections described in this Policy.
  1. International Data Transfers

Some of our third-party service providers, including Google LLC (Google Analytics) and Automattic Inc. (WordPress), are based outside Sri Lanka and may process your data in countries whose data protection laws differ from those of Sri Lanka.

Where your data is transferred outside Sri Lanka, we take reasonable steps to ensure that appropriate safeguards are in place to protect your information in accordance with this Policy and applicable law. Google Analytics data is transferred subject to Google’s data processing terms and standard contractual commitments.

  1. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

  • Contact form and enquiry data: retained for up to 2 years from the date of your last interaction with us
  • Analytics data: retained in Google Analytics for up to 14 months (as configured in our account), after which it is automatically deleted
  • Session cookies: deleted when you close your browser
  • Persistent cookies: retained for the duration specified in the cookie inventory in Section 6.3

When your data is no longer required, we will securely delete or anonymise it in accordance with our data retention practices.

  1. Your Privacy Rights

Under the Personal Data Protection Act No. 9 of 2022, you have the following rights in relation to the personal data we hold about you:

  • Right of access: you have the right to request a copy of the personal data we hold about you and information about how we process it.
  • Right to rectification: you have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  • Right to erasure: in certain circumstances, you have the right to request that we delete your personal data.
  • Right to restrict processing: you have the right to request that we restrict how we process your personal data in certain circumstances.
  • Right to data portability: you have the right to receive your personal data in a structured, commonly used, machine-readable format in certain circumstances.
  • Right to object: you have the right to object to processing of your personal data where we are relying on legitimate interests as the legal basis for processing.
  • Right to withdraw consent: where we process your data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at privacy@docsync.lk. We will respond to your request within 30 days of receipt. We may need to verify your identity before processing your request.

  1. Children’s Privacy

The Website is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without verifiable parental consent, we will take steps to delete that information as soon as practicable.

If you believe we may have inadvertently collected information from a child, please contact us immediately at privacy@docsync.lk.

  1. Data Security

We implement appropriate technical and organisational security measures to protect your personal information against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access. These measures include SSL/TLS encryption for data in transit, access controls, and regular security reviews of our Website infrastructure.

However, please be aware that no method of transmission over the internet and no method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

  1. Third-Party Websites

The Website may contain links to third-party websites, plug-ins, or applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy policies or practices.

We encourage you to read the privacy policy of every website you visit when you leave the DocSync Website.

  1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the Effective Date at the top of this Policy and, where appropriate, notify you by posting a notice on the Website.

Your continued use of the Website after any changes to this Policy constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

  1. How to Make a Complaint

If you have any concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue directly:

Email: privacy@docsync.lk

You also have the right to lodge a complaint with the Data Protection Authority of Sri Lanka, once formally established under the Personal Data Protection Act No. 9 of 2022, or with any other competent supervisory authority.

 

  1. Contact Us

If you have any questions, concerns, or feedback regarding these Terms or the Services, please contact us:

Axon Systems (Pvt) Ltd

Email: info@healthsync.lk

Customer Support: info@healthsync.lk

We will respond to your inquiries within a reasonable timeframe. For urgent matters, please mark your communication as “URGENT” in the subject line.