1. Who We Are
Mirissa Collective is a trading name of TP Development PvT Ltd, a company registered in Sri Lanka. TP Development PvT Ltd operates water-based activities — diving, snorkeling, whale watching, kayak, and fishing — in Mirissa and Nilaveli, Sri Lanka. For data protection purposes, TP Development PvT Ltd is the data controller.
For questions about how we handle your data:
Email: hello@mirissacollective.com
Website: www.mirissacollective.com
2. What Data We Collect
When you make a booking, we collect:
- Contact details: Full name, email address, phone number, country of residence
- Participant details: Names, dates of birth of all participants in your booking
- Booking data: Activity, date, time, number of participants, special requests
- Payment data: We do not store card details. Payments are processed by PayHere. We store transaction references and amounts.
- Health data (diving activities only): PADI Diver Medical Questionnaire responses. This data is treated as sensitive personal data and stored securely with access restricted to operational staff only.
- Uploaded files (PADI courses only): Certification card images and related documents, stored securely with access restricted to operational staff.
- Communication data: Emails and messages sent to hello@mirissacollective.com.
When you use our website, we may collect:
- Technical data: IP address, browser type, pages visited, time spent on site — via Google Analytics 4 and Microsoft Clarity, only if you give consent.
- Cookies: See our Cookie Policy.
3. How We Use Your Data
We use your data to:
- Process and manage your booking
- Send booking confirmations, reminders, and relevant pre-activity information
- Process refunds and rescheduling requests
- Comply with PADI requirements for dive course certification
- Improve our website and services via analytics (with your consent)
- Respond to your enquiries
We do not use your data for marketing without your explicit consent.
4. Legal Basis for Processing
We process your data on the following legal bases (GDPR Article 6):
- Contract performance: To fulfill the booking you have made with us
- Legal obligation: To comply with applicable laws and PADI requirements
- Legitimate interests: To manage our business, improve our services, and ensure safety
- Consent: For analytics cookies and any optional marketing communications
Health data from the PADI Medical Questionnaire is processed under GDPR Article 9(2)(a) — your explicit consent — and Article 9(2)(b) — for obligations in the field of occupational health and safety.
5. How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Booking and participant data | 5 years from activity date |
| Payment transaction references | 7 years (accounting requirements) |
| PADI Medical Questionnaire | 5 years from activity date |
| Uploaded certification files | 2 years from activity date |
| Email communications | 3 years |
| Analytics data | As per Google Analytics / Microsoft Clarity settings (maximum 14 months for GA4) |
After the retention period, your data is securely deleted.
6. Who We Share Your Data With
We share your data only where necessary. All data processor agreements are entered into by TP Development PvT Ltd:
- PayHere — payment processing
- Xero — accounting and invoicing
- Google — Analytics 4 (with your consent), Maps API (for tuk tuk distance calculation)
- Microsoft — Clarity analytics (with your consent)
- PADI — your name and course details are registered with PADI as part of certification
- Simply.com — email infrastructure
We display Google reviews on our website, including reviewer names and profile photos as provided by the Google Places API. These are publicly available reviews published by Google users.
We do not sell your data to third parties.
7. International Data Transfers
TP Development PvT Ltd operates in Sri Lanka. If you are based in the EU/EEA, your data is transferred to Sri Lanka and to the third-party processors listed above, some of which process data outside the EU/EEA. Where this occurs, we rely on Standard Contractual Clauses or the recipient's adequacy decision where applicable.
8. Your Rights
If you are an EU resident, you have the following rights under GDPR:
- Right of access: Request a copy of the data we hold about you
- Right to rectification: Ask us to correct inaccurate data
- Right to erasure: Ask us to delete your data, subject to legal retention requirements
- Right to restriction: Ask us to limit how we use your data
- Right to portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise your rights, email us at hello@mirissacollective.com. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
9. Security
We store your data securely using Supabase (PostgreSQL with encryption at rest and in transit). Access to sensitive data is restricted to authorised personnel only. We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.
10. Cookies
We use cookies to operate our website and, with your consent, for analytics. For full details, see our Cookie Policy.
11. Contact
For privacy-related enquiries or to exercise your rights:
Email: hello@mirissacollective.com