Last Updated: April 27, 2026
SCOPE OF THIS POLICY: This Privacy Policy applies exclusively to the DocSync public-facing website (the “Website”) operated by Axon Systems (Pvt) Ltd. It does not apply to data processed within the DocSync EMR platform or any data submitted by healthcare practitioners or their patients through the platform, which is governed by a separate Data Processing Agreement.
- About Us & Our Commitment to Privacy
Axon Systems (Pvt) Ltd (“Axon Systems”, “we”, “us”, or “our”) is the company behind DocSync, a cloud-based Electronic Medical Records (EMR) and practice management platform built for healthcare practitioners in Sri Lanka. Our registered place of business is in Sri Lanka.
We are committed to protecting and respecting the privacy of every person who visits our Website. This Privacy Policy explains what personal information we collect when you visit [www.docsync.lk] (the “Website”), how we use it, who we share it with, and what rights you have in relation to it.
Please read this Policy carefully. By continuing to use the Website, you confirm that you have read and understood this Policy. If you do not agree with the practices described here, please discontinue use of the Website.
- Data Controller
For the purposes of applicable Sri Lankan data protection law, including the Personal Data Protection Act No. 9 of 2022 (“PDPA”), the data controller for personal information collected through this Website is:
Axon Systems (Pvt) Ltd
No.22, Kirimandala Mawatha, Nawala, Rajagiriya, Sri Lanka
Email: privacy@docsync.lk
Website: www.docsync.lk
- Information We Collect
3.1 Information You Provide Directly
When you interact with certain features of the Website, you may voluntarily provide us with personal information, including:
- Contact form submissions: your name, email address, phone number, and the content of your message
- Demo request forms: your name, email address, practice name, and the nature of your enquiry
- Newsletter or update sign-up: your name and email address
You are not required to provide this information to browse the Website. We only collect what you choose to give us.
3.2 Information Collected Automatically
When you visit the Website, certain information is collected automatically through cookies and similar technologies. This includes:
- Your IP address (anonymised where possible)
- Browser type, version, and operating system
- Pages visited, time spent on pages, and navigation paths
- Referring URL (the page you came from before visiting our Website)
- Device type and screen resolution
- Date and time of your visit
This information is collected through WordPress (our website platform) and Google Analytics. It is used in aggregate form to understand how visitors use our Website and to improve our content and user experience.
- How We Use Your Information
We use the personal information we collect for the following purposes:
- To respond to your enquiries, demo requests, or contact form submissions
- To send you information about DocSync products and services where you have requested this
- To analyse Website traffic and usage patterns in order to improve the Website and our content
- To ensure the security and technical operation of the Website
- To comply with our legal and regulatory obligations
- To enforce our Website Terms of Use and protect our rights
We will only use your personal information for the purposes for which it was collected, unless we reasonably consider that we need to use it for another reason compatible with the original purpose, and that reason is permitted under applicable law.
- Legal Basis for Processing
Under the Personal Data Protection Act No. 9 of 2022, we are required to have a lawful basis for processing your personal data. Our lawful bases are:
- Consent: where you have given us clear consent to process your data for a specific purpose (e.g. subscribing to updates or enabling analytics cookies)
- Legitimate interests: where processing is necessary for our legitimate business interests, such as analysing website traffic to improve our services, provided those interests are not overridden by your rights
- Contractual necessity: where processing is necessary to take steps at your request prior to entering a contract, such as responding to a product enquiry
- Legal obligation: where processing is necessary to comply with a legal or regulatory obligation
- Cookies & Tracking Technologies
6.1 What Are Cookies?
Cookies are small text files placed on your device by a website when you visit it. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to website operators. Cookies do not contain executable code and cannot access information stored elsewhere on your device.
6.2 Categories of Cookies We Use
We use the following categories of cookies on our Website:
- Necessary cookies: essential for the Website to function correctly. The Website cannot operate without these cookies and they cannot be disabled.
- Functional cookies: enhance your experience by remembering your preferences and choices (e.g. pre-filling your name in comment forms).
- Analytics cookies: help us understand how visitors interact with the Website by collecting information in an anonymous, aggregated form. We use Google Analytics for this purpose.
6.3 Cookie Inventory
The table below describes the specific cookies set by the Website:
| Cookie Name | Provider | Purpose | Type | Duration |
| wordpress_logged_in_{hash} | WordPress | Authenticates logged-in users and maintains their login session | Necessary | Session |
| wordpress_sec_{hash} | WordPress | Stores login credentials securely during session (admin area) | Necessary | Session |
| wp-settings-{user} | WordPress | Personalises the WordPress admin interface for individual users | Functional | 1 year |
| wp-settings-time-{user} | WordPress | Records time-stamped session for admin settings cookie | Functional | 1 year |
| comment_author_{hash} | WordPress | Saves visitor name/email to pre-fill comment forms on return visits | Functional | 347 days |
| comment_author_email_{hash} | WordPress | Saves visitor email to pre-fill comment forms on return visits | Functional | 347 days |
| _ga | Google Analytics | Distinguishes unique users by assigning a random ID for traffic analysis | Analytics | 2 years |
| _ga_{container} | Google Analytics | Stores and counts page views for Google Analytics 4 sessions | Analytics | 2 years |
| _gid | Google Analytics | Distinguishes users; stores and counts page views for 24-hour sessions | Analytics | 24 hours |
| _gat / _gat_{container} | Google Analytics | Throttles request rate to limit data collection on high-traffic sites | Analytics | 1 minute |
6.4 Google Analytics
We use Google Analytics, a web analytics service provided by Google LLC. Google Analytics collects information about your use of the Website (such as pages visited and time spent) through cookies and transmits this data to Google servers, which may be located outside Sri Lanka.
We have enabled IP anonymisation in Google Analytics, meaning your IP address is truncated before it is stored by Google. The data collected is used solely to generate aggregate reports on Website activity and is not used to identify you personally.
You can opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on, available at: tools.google.com/dlpage/gaoptout
For more information on how Google uses data collected via our Website, please visit: policies.google.com/technologies/partner-sites
6.5 Managing Cookies
Most web browsers allow you to control cookies through their settings preferences. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of the Website may not function as intended.
You can manage your cookie preferences at any time through your browser settings. Common browser guides:
- Google Chrome: Settings > Privacy and Security > Cookies and other site data
- Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Microsoft Edge: Settings > Cookies and site permissions
- How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your information in the following limited circumstances:
- Service providers: we share data with trusted third-party service providers who assist us in operating the Website (e.g. web hosting, email delivery). These providers are authorised to use your information only as necessary to provide services to us and are bound by appropriate data protection obligations.
- Google LLC: as described in Section 6, Website analytics data is processed by Google Analytics.
- WordPress (Automattic Inc.): our Website is built on WordPress. Automattic may process certain technical data as part of providing the WordPress platform. For details, see Automattic’s Privacy Policy at automattic.com/privacy.
- Legal requirements: we may disclose your information where required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights or the safety of any person.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to the same privacy protections described in this Policy.
- International Data Transfers
Some of our third-party service providers, including Google LLC (Google Analytics) and Automattic Inc. (WordPress), are based outside Sri Lanka and may process your data in countries whose data protection laws differ from those of Sri Lanka.
Where your data is transferred outside Sri Lanka, we take reasonable steps to ensure that appropriate safeguards are in place to protect your information in accordance with this Policy and applicable law. Google Analytics data is transferred subject to Google’s data processing terms and standard contractual commitments.
- Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Contact form and enquiry data: retained for up to 2 years from the date of your last interaction with us
- Analytics data: retained in Google Analytics for up to 14 months (as configured in our account), after which it is automatically deleted
- Session cookies: deleted when you close your browser
- Persistent cookies: retained for the duration specified in the cookie inventory in Section 6.3
When your data is no longer required, we will securely delete or anonymise it in accordance with our data retention practices.
- Your Privacy Rights
Under the Personal Data Protection Act No. 9 of 2022, you have the following rights in relation to the personal data we hold about you:
- Right of access: you have the right to request a copy of the personal data we hold about you and information about how we process it.
- Right to rectification: you have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure: in certain circumstances, you have the right to request that we delete your personal data.
- Right to restrict processing: you have the right to request that we restrict how we process your personal data in certain circumstances.
- Right to data portability: you have the right to receive your personal data in a structured, commonly used, machine-readable format in certain circumstances.
- Right to object: you have the right to object to processing of your personal data where we are relying on legitimate interests as the legal basis for processing.
- Right to withdraw consent: where we process your data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us at privacy@docsync.lk. We will respond to your request within 30 days of receipt. We may need to verify your identity before processing your request.
- Children’s Privacy
The Website is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without verifiable parental consent, we will take steps to delete that information as soon as practicable.
If you believe we may have inadvertently collected information from a child, please contact us immediately at privacy@docsync.lk.
- Data Security
We implement appropriate technical and organisational security measures to protect your personal information against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access. These measures include SSL/TLS encryption for data in transit, access controls, and regular security reviews of our Website infrastructure.
However, please be aware that no method of transmission over the internet and no method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
- Third-Party Websites
The Website may contain links to third-party websites, plug-ins, or applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy policies or practices.
We encourage you to read the privacy policy of every website you visit when you leave the DocSync Website.
- Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the Effective Date at the top of this Policy and, where appropriate, notify you by posting a notice on the Website.
Your continued use of the Website after any changes to this Policy constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
- How to Make a Complaint
If you have any concerns about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue directly:
Email: privacy@docsync.lk
You also have the right to lodge a complaint with the Data Protection Authority of Sri Lanka, once formally established under the Personal Data Protection Act No. 9 of 2022, or with any other competent supervisory authority.
- Contact Us
If you have any questions, concerns, or feedback regarding these Terms or the Services, please contact us:
Axon Systems (Pvt) Ltd
Email: info@healthsync.lk
Customer Support: info@healthsync.lk
We will respond to your inquiries within a reasonable timeframe. For urgent matters, please mark your communication as “URGENT” in the subject line.