Privacy Policy
Version 1.2.0 · Effective 29 August 2026
This Privacy Policy describes how AnnFar Global (Pvt) Ltd, a company incorporated in Sri Lanka and trading as “Unisay” (“Unisay”, “we”, “our”), collects, uses, shares, and protects personal data in connection with the Unisay platform and related services (the “Service”). It is written to align with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as modified by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (the “PDPA”). The substantive controller and processor obligations and the Authority’s penalty powers under Parts I, II, III and VII of the PDPA are not yet operative as of the effective date of this version; the Amendment Act removed the previously-gazetted commencement date and gave the Minister discretion to bring those Parts into force by future gazette order. We have written this Policy to be compliance-ready for the substantive provisions when they commence.
1. Who we are
Unisay is a software-as-a-service platform that helps small and medium businesses in Sri Lanka (“Vendors”) operate Meta-channel commerce: order taking, customer management, inventory, invoicing, courier coordination, and AI-assisted replies across WhatsApp Business, Instagram Direct, and Facebook Messenger.
- Controller: AnnFar Global (Pvt) Ltd (trading as Unisay), 22/4, Peterson Tower, Havelock City, Havelock Road, Colombo 05, Sri Lanka.
- Data Protection Officer (DPO): dpo@unisay.ai.
Where Unisay processes personal data on behalf of a Vendor (for example, a Vendor’s end-customer’s phone number, Instagram-Scoped ID, or order history), we act as a Processor under the PDPA and the Vendor is the Controller. Where Unisay processes personal data for our own purposes (Vendor account management, billing, security, product improvement, and Service operation including automatic refresh of the Vendor’s Meta access tokens), we act as a Controller. We do not repurpose end-customer message content for our own marketing, training of our own AI models, or product analytics that are not instructed by the Vendor.
2. Definitions
- Vendor: a business that has registered an account with Unisay.
- Vendor staff: a natural person authorised by the Vendor to access Unisay (Owner, Admin, Manager, Staff, or Viewer roles).
- Customer: the Vendor’s end-customer — a natural person who interacts with the Vendor’s business through WhatsApp Business, Instagram Direct, Facebook Messenger, or other Unisay-managed channels.
- Channel-Scoped Identifier: an opaque identifier that Meta issues per-channel for a Customer. Includes the WhatsApp E.164 phone number, the Instagram-Scoped User ID (“IGSID”), and the Page-Scoped User ID (“PSID”) for Facebook Messenger. PSIDs and IGSIDs are not globally unique: the same Customer can have different identifiers on different Vendor pages.
- Personal data: any information relating to an identified or identifiable natural person, as defined in PDPA s.2.
3. Information we collect
3.1 Vendor account data
When you register a Vendor account or are invited to join one, we collect: your business name, owner name, owner phone number, owner email (optional), business district, business type, business registration number (if provided), VAT number (if provided), preferred language, and the password you choose. Passwords are stored as bcrypt hashes (cost factor 12) — never in plaintext. JWTs issued at sign-in carry a unique jti claim and are revocable per-token via our denylist or in-bulk via the “sign me out everywhere” flow.
3.2 Customer data processed on a Vendor’s behalf
As Vendors operate their business through Unisay, our systems store data about their Customers: name (where shared), phone number in E.164 format (for WhatsApp Customers), WhatsApp profile id (wa_id), Instagram-Scoped ID (igsid) for Instagram Direct Customers, Page-Scoped ID (fbPsid) for Facebook Messenger Customers, email (where the Customer provided it), delivery and billing addresses, district, postal code, customer segmentation tags assigned by the Vendor, source channel, preferred language, order history (totals, averages, last-order date), credit account state, notes the Vendor adds, and Vendor-applied tags. We also store an authoritative channel identity row linking a single Customer record to each of their channel-scoped identifiers and the Vendor asset (Page, Instagram Business account, or WhatsApp Business Account) that received the conversation. Cross-channel identity merge — recognising the same Customer across two different channels — is only performed by explicit Vendor staff action; we never infer it automatically. We process this data as Processor under the Data Processing Agreement; the Vendor is the Controller of this data and is responsible for the lawful basis on which it was collected from the Customer.
3.3 Conversation content
Inbound and outbound messages exchanged between a Vendor and their Customers are delivered to us through Meta’s WhatsApp Business Platform webhook, the Instagram Platform webhook, and the Messenger Platform webhook (depending on the channel) and stored in our database. Messages may contain Customer phone numbers, names, free-text content (which the Customer chose to send), media (images, audio, video, documents, stickers), location coordinates (when shared), reactions, and quoted-reply context. Each conversation is assigned a per-channel thread record with its own messaging-window timer (24 hours for WhatsApp and Instagram Direct; 24 hours base extending to 7 days under the HUMAN_AGENT tag for Facebook Messenger). Outbound free-text replies are blocked when the window has lapsed; only Meta-approved templates may re-open a channel after that point.
3.4 Technical data
When Vendor staff use the Unisay web application, we automatically collect: IP address, User-Agent string, device information, session metadata, login timestamps, and JWT identifiers. When Customers interact via a Meta channel, we record the channel-native message identifier (WhatsApp wamid, Messenger mid, Instagram mid) and timestamps. For ad-driven conversations across all three channels we capture the referral object Meta delivers on the first inbound message, with channel-specific attribution identifiers: the ctwa_clid on Click-to-WhatsApp; the ref + source: 'ig.me' payload on Instagram-ad-to-DM (e.g. ig.me/m/<vendor-username>); and the ref + source: 'm.me' payload on Messenger-ad-to-DM. We use these identifiers to associate the resulting conversation with the originating ad in your Ads-Manager attribution. We also store the Vendor’s asset identifiers (WhatsApp Business Account ID, phone-number ID, Facebook Page ID, Instagram Business Account ID) and per-Page access tokens issued by Meta during OAuth, all encrypted at rest under AES-256-GCM with the version prefix v1:.
3.5 AI-generated artifacts
When the AI Agent feature is enabled by a Vendor, Customer messages are sent to one or more AI providers (Anthropic, OpenAI, Google Gemini, or Groq — see Sub-Processors) for processing; the AI’s outputs (drafts, intent classifications, suggested orders) are stored in our database and tagged as AI-generated. Product names and descriptions are converted to numerical vector embeddings (768-dimensional) for semantic search; embeddings are derived data, not original content. Each upstream AI provider operates under contractual zero-retention or no-training terms (see Sub-Processors for the per-provider position).
3.6 Consequences of not providing personal data
- At Vendor signup: business name, owner name, owner phone, password, and your acceptance of these Terms are contractual requirements; you cannot register a Vendor account without them.
- For Customer interactions: a Customer’s channel-scoped identifier (E.164 phone number, IGSID, or PSID) is required to receive messages — this is a technical requirement of Meta’s platforms, not a Unisay choice. Without it, the channel cannot operate.
- Optional fields: email, business registration number, VAT number, Customer email, customer notes — declining to provide these does not prevent use of the Service but may limit certain features (for example, password reset by email is unavailable without an email on file).
3.7 Special categories of personal data
The Service is not designed to process “special categories of personal data” as defined in the PDPA — racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data, health data, sex life or sexual orientation data, criminal offence data, or data relating to children. We ask Vendors not to deliberately store such data through the Service.
However, conversation content (§3.3) and customer notes (§3.2) are free-text fields, and a Customer may voluntarily include such information in a message. Where this occurs, the Vendor is the controller and must ensure an additional lawful basis under the PDPA (typically the Customer’s explicit consent or vital-interests basis) before further processing.
4. Sources of data
- Directly from Vendor staff during signup and use of the Service.
- Directly from Customers via inbound webhooks delivered by Meta’s WhatsApp Business Platform, Instagram Platform, and Messenger Platform.
- From Meta’s Graph API (
/me/accounts,/{page-id},/me/businesses) when a Vendor connects their Meta Business through the Connect-Meta OAuth flow — used to enumerate and verify the Pages, Catalogs, WhatsApp Business Accounts, and Instagram Business accounts the Vendor authorised Unisay to act upon. - From third-party platforms when a Vendor connects their account (Meta Business Suite, courier APIs).
- Generated automatically by our systems (audit logs, AI usage metrics, embeddings, messaging-window timers).
5. Lawful basis for processing
Our lawful basis under PDPA s.5 varies by data category:
- Vendor account data: performance of the contract (Terms of Service) between Unisay and the Vendor.
- Customer data processed on Vendor’s behalf: the Vendor’s legitimate interest as a controller (operating their business). The Vendor remains responsible for the lawful basis under which they collected the data from the Customer.
- Conversation content: performance of the Service contract with the Vendor and the Vendor’s legitimate interest in operating their commerce channel.
- Meta access tokens (including the per-Page token map and the WhatsApp accessToken): performance of the Service contract — the Vendor explicitly authorises Unisay, as a Meta Tech Provider, to receive, hold, and automatically re-extend their long-lived tokens via the
fb_exchange_tokengrant; without auto-refresh the Vendor’s connection would lapse every ~60 days. - Technical data: our legitimate interest in security, fraud prevention, debugging, and service quality.
- AI processing: performance of the contract — the AI Agent is an opt-in feature explicitly enabled by the Vendor and can be disabled at any time.
6. How we use your data
- To provide, operate, and maintain the Service.
- To authenticate Vendor staff and prevent unauthorised access.
- To send transactional emails (welcome, password reset, billing, Meta-token-expiring warnings, breach notifications).
- To process payments and manage subscriptions.
- To detect and prevent fraud, abuse, and security incidents.
- To generate AI-assisted replies and product suggestions when the AI Agent is enabled.
- To call Meta’s Graph, Send, and Subscribed-Apps APIs on the Vendor’s behalf using their authorised access tokens, including automatic re-extension of long-lived tokens before expiry.
- To produce aggregated analytics that do not identify any individual.
- To comply with legal obligations, including responses to lawful requests from regulators or law enforcement, and to respond to user-data-deletion callbacks issued by Meta on behalf of a Customer (see §11).
We do not sell personal data and we do not use Customer data to train AI models without explicit Vendor consent. Each upstream AI provider operates under contractual zero-retention or no-training terms with us; the current provider-specific position is at /sub-processors.
7. Sharing and sub-processors
We share personal data only with sub-processors who help us deliver the Service, and only as needed for that purpose. The current list is at /sub-processors and is incorporated into this Policy by reference. We will provide at least 30 days’ advance notice via the Unisay dashboard before adding any new sub-processor that processes personal data.
We may also share personal data when legally compelled (court order, regulator demand) or when necessary to protect the rights, property, or safety of Unisay, our Vendors, their Customers, or the public.
8. International transfers
Personal data may be processed in: the United States (Anthropic, OpenAI, Google, Groq, Vercel, Render, Resend, AWS), the European Union / Ireland (Meta), and Singapore (Neon’s primary region for our deployment). The Sri Lanka Data Protection Authority has not yet designated any third country as having an adequate level of protection under PDPA s.26(2), and the Authority’s draft Directive on Cross-Border Transfers (issued for public consultation 2 October 2024) has not been finalised. Where we transfer personal data outside Sri Lanka we rely on one or more of the instruments contemplated by the Authority’s draft Directive, namely:
- binding corporate rules within a sub-processor’s corporate group;
- contractual agreements imposing binding and enforceable data-protection commitments on the recipient (our Data Processing Agreements with each sub-processor);
- industry codes of conduct subscribed to by the recipient;
- binding certification schemes adhered to by the recipient; and
- cross-border processing impact assessments where required.
We monitor sub-processor jurisdictions and reserve the right to relocate processing if local laws change in a way that materially undermines these safeguards.
9. Retention periods
| Data category | Retention period | Reason |
|---|---|---|
| Vendor account data | Lifetime of the account + 5 years | Inland Revenue Act No. 24 of 2017 §123 (5-year tax-record retention) and Companies Act No. 7 of 2007 record-keeping requirements |
| Customer data (on Vendor’s behalf) | Per Vendor’s instructions; default 5 years post-account-closure | VAT / income-tax record retention and the Vendor’s own books |
| Conversation content (WhatsApp, Instagram Direct, Facebook Messenger messages) | 24 months rolling; configurable per Vendor in Settings (default not yet implemented) | Operational utility balanced against data minimisation |
| Meta access tokens (encrypted at rest) | For the duration of the Vendor’s connection | Cleared on disconnect or account closure; never retained beyond the active connection |
| Audit log (non-financial mutations) | 90 days | Security and incident response |
| Audit log (financial mutations) | 5 years | Tax and accounting record-keeping under §123 of the Inland Revenue Act |
| AI usage daily aggregates (no PII) | 5 years | Billing reconciliation and capacity planning |
| Failed login attempts and security logs | 30 days | Brute-force detection |
| Backup snapshots | Up to 30 days, then expired by sub-processor rotation | Disaster recovery |
10. Your rights under PDPA
Subject to the conditions in the PDPA, you have the following rights with respect to personal data we hold about you:
- Right of access (s.13): obtain confirmation of whether we hold personal data about you and a copy of that data.
- Right to rectification (s.14): correct inaccurate or incomplete data.
- Right to erasure (s.15): have your data deleted, subject to legal retention obligations and our legitimate interests.
- Right to restrict processing (s.16): request that we limit processing while disputes about accuracy or basis are resolved.
- Right to object (s.17): object to processing based on legitimate interest, including objection to automated decisions.
- Right to data portability: receive a copy of your data in a structured, commonly used, machine-readable format (we provide JSON).
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawfulness.
- Right to lodge a complaint with the Sri Lanka Data Protection Authority (see §17).
11. How to exercise your rights
Vendors may export their Customer’s data via the Unisay dashboard (Customers → [Customer] → Export data) and may also export their own staff data via Settings → Account → Export my data.
Customers seeking to exercise rights with respect to their own data should first contact the Vendor through whom they transact, since the Vendor is the Controller of that data. If you are a Customer and the Vendor has not responded within the statutory timeframe, you may contact us directly at dpo@unisay.ai and we will assist.
Meta-initiated deletion. If you previously connected a Meta account (Facebook, Instagram, or WhatsApp Business) to Unisay through one of our Vendors and you subsequently revoke our app or request data deletion via Meta, Meta will issue a Data Deletion Callback to https://api.unisay.ai/api/legal/data-deletion-callback. You may also request deletion directly, or track the status of a previously-initiated request using the confirmation code Meta returns, at https://unisay.ai/legal/data-deletion.
Response timeline. We respond to verified rights requests without undue delay and in any event within one (1) month of receipt. Where the request is complex or we receive multiple related requests, we may extend the response period by a further two (2) months — totalling no more than three (3) months — and will notify you of the extension and reasons within the first month.
We do not charge a fee for routine rights requests but reserve the right to charge a reasonable administrative fee for manifestly unfounded or excessive repeat requests, or to refuse such requests, as permitted under the PDPA.
12. Automated decision-making (AI Agent)
Unisay’s AI Agent feature, when enabled by a Vendor, automatically generates draft replies to Customer messages and may classify Customer intents. The feature operates in one of three modes set per Vendor business and per Customer:
- OFF: the AI is silent; no drafts are generated.
- SUGGEST mode (default): the AI prepares a draft; a Vendor staff member reviews and explicitly approves or edits the draft before it is sent to the Customer. No AI decision is communicated to the Customer without human review.
- AUTO mode (opt-in by Vendor): the AI sends replies directly when an internal Haiku-as-judge composite quality score passes the Vendor’s configured threshold AND none of the safety gates trip (guarded-topic regex, tool-error count, customer-side
forceSuggestoverride). The Vendor has explicitly accepted responsibility for the AI’s outputs in AUTO mode; on any safety-gate trip the turn is silently demoted to SUGGEST.
No fully-automated decision producing legal or similarly significant effects on a Customer is taken without human review. Customers may request human review of any AI-generated decision by replying with the keyword “AGENT” in their conversation with the Vendor, by contacting the Vendor directly, or by emailing dpo@unisay.ai.
13. Security measures
- Encryption in transit (TLS 1.2+) for all API and web traffic.
- Application-layer encryption at rest (AES-256-GCM, version-prefixed
v1:) for all stored Meta access tokens, WhatsApp webhook verify tokens, per-Page access tokens, and Vendor courier API keys, on top of Neon’s database at-rest encryption. - HMAC-SHA256 signature verification of every inbound Meta webhook and outbound Graph API call (the latter via the
appsecret_proofparameter), so a stolen access token alone cannot be weaponised against a hardened Meta App. - Bcrypt password hashing (cost factor 12) and brute-force lockout (5 attempts, 15 minutes).
- JWT-based authentication with a per-token
jti, an LRU-cached denylist for per-token revocation, and a per-usertokensValidFromcutoff for sign-out-everywhere. - Multi-tenant data isolation enforced at every database query.
- Role-based access control (Owner, Admin, Manager, Staff, Viewer).
- Append-only audit logging of mutations to sensitive entities, with retention split between security (90 days) and financial (5 years) categories.
- Five offline breach detectors running every 10 minutes (failed-login spike, geo anomaly, export burst, webhook-signature-failure cluster, privilege escalation), feeding a managed BreachIncident lifecycle with PDPA s.24-shaped notification drafts.
- Regular dependency updates and security review.
14. Breach notification
Where we identify a personal data breach likely to result in risk to the rights and freedoms of natural persons, we will notify the Sri Lanka Data Protection Authority within 72 hours of becoming aware. Affected Vendors will be notified without undue delay and provided with the information needed to discharge their own notification obligations to data subjects, where applicable under PDPA. The Authority’s final breach-notification form has not yet been published; until it is, our notification is structured to satisfy every data field anticipated by the draft Rules on Personal Data Breach Notifications (issued for public consultation 1 October 2024).
15. Children’s data
The Unisay platform is not directed to individuals under 18, and Vendor staff accounts may only be created by adults. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact dpo@unisay.ai and we will delete it promptly.
16. Changes to this Policy
We may revise this Policy by posting an updated version at /privacy with a new version number and effective date. Material changes will require your re-acceptance via the click-through prompt at next login. Non-material changes (corrections, clarifications) take effect on posting.
Past versions of this Policy are accessible at /legal/history/privacy-policy. The English version is authoritative; translations into Sinhala or Tamil are provided for convenience only.
17. Complaints
If you believe we have not handled your personal data lawfully, please contact dpo@unisay.ai first so we can resolve the issue. You also have the right to lodge a complaint directly with the Data Protection Authority of Sri Lanka at https://www.dpa.gov.lk/.
18. Contact us
AnnFar Global (Pvt) Ltd (trading as Unisay)
22/4, Peterson Tower, Havelock City, Havelock Road, Colombo 05, Sri Lanka
Email: dpo@unisay.ai