Legal
Privacy Policy
This policy explains what personal data AbroadMaster collects, why, who we share it with, how long we keep it, and the rights you have over it. It is written to meet both the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA) and the EU General Data Protection Regulation (GDPR).
Last updated 14 September 2026 · Applies to abroadmaster.com
On this page▾
- 1. Who we are
- 2. Data we collect
- 3. Why we use it
- 4. Lawful basis (GDPR)
- 5. Sensitive data (PDPA)
- 6. Automated decision-making
- 7. Who we share it with
- 8. International transfers
- 9. Cookies & advertising
- 10. Security
- 11. Breach notification
- 12. How long we keep it
- 13. Your rights (EU/EEA)
- 14. Your rights (Sri Lanka)
- 15. Making a request
- 16. Complaints
- 17. Children
- 18. Changes
- 19. Contact
At a glance
A plain summary. The full text below is what actually applies.
- Who holds your data
- J.R.L Weerasingha, an individual in Godakawela, Ratnapura, Sri Lanka. No company, no investors, no parent organisation.
- What we never collect
- Passport or NIC numbers, biometric data, health data, religious or political affiliation, and your full card number.
- Whether we sell it
- No. It goes only to the processors that run the service, listed by name in section 7.
- How long we keep it
- Account data until you delete it, then 30 days. Payment records 7 years, because tax law requires it. Full table in section 12.
- Your rights
- Access, correction, deletion, portability and objection, under both the PDPA and the GDPR. Use the data request form and we respond within 30 days.
- Automated decisions
- Eligibility results are calculated automatically and are indicative only. You can always ask a person to re-examine one.
Nothing here is a substitute for reading the sections that affect you. If you only read one, make it section 12, how long we keep your data.
1. Who we are (data controller)
AbroadMaster is an independent project built and operated by J.R.L Weerasingha, an individual based in Godakawela, Ratnapura, Sri Lanka. For the purposes of the GDPR and the PDPA, that person is the data controller for personal data processed through this website. There is no company, parent organisation or investor behind AbroadMaster.
Privacy contact: privacy@abroadmaster.com. Email reaches the controller directly. A full postal address is provided to any supervisory authority, and to any data subject who asks for it in connection with a request or complaint.
Data Protection Officer
None appointed. AbroadMaster is not a public authority, does not carry out large-scale systematic monitoring, and does not process special-category data at scale, so a DPO is not required under GDPR Art. 37 or the comparable PDPA threshold. Privacy matters are handled personally by the controller at privacy@abroadmaster.com.
EU representative
AbroadMaster is operated from Sri Lanka and is aimed at people in Sri Lanka planning to move abroad; it is not targeted at the EU market, is not offered in any EU language other than English, and takes no payment in euro. On that basis we rely on the derogation in GDPR Art. 27(2)(a) and have not appointed an EU representative. If the service is later marketed to EU residents, a representative will be appointed and named here before that happens. EU users retain the full set of rights described in section 13 either way, and can reach the controller directly at the address above.
2. The data we collect
Account data
- Email address, and a display name if you set one
- Authentication data handled by Supabase Auth; we never see or store your raw password
- Sign-in metadata: timestamps, IP address, browser and device type, used for security and abuse prevention
Data we receive from Google Sign-In
Signing in with Continue with Google is optional. An email address and password does the same job, and nothing on AbroadMaster requires a Google account. If you do choose it, Google sends us three pieces of information about your Google account, and only these three:
- Your name, as it appears on your Google account
- Your email address, and whether Google has verified it
- Your profile picture and your Google account identifier, which is what lets us recognise you as the same person next time
We use them for one purpose: to create your AbroadMaster account, identify you when you sign in again, and contact you about the service. They are stored with the rest of your account data in Supabase, kept for as long as your account exists (see section 12), and covered by every right in sections 13 and 14, including deletion. We never sell them, never use them to build an advertising profile, and never share them with anyone beyond the processors listed in section 7.
What Continue with Google does not give us
We ask Google for the three basic sign-in permissions only, the ones Google names “openid”, “email” and “profile”. That is the minimum needed to sign somebody in, and it is all we have ever requested.
It means we cannot read your Gmail, your Google Contacts, your Calendar, your Drive files, your photos or your location, and we cannot send, post or change anything in your Google account. You can withdraw our access at any time from your Google account permissions page. Doing that stops future Google sign-ins but does not delete your AbroadMaster account or the data already held; for that, see section 15.
Eligibility profile data
Supplied by you, and used to calculate which countries and visa types you may qualify for:
- Age or date of birth
- Highest education level and field of study
- Years and type of work experience, and occupation
- Language test type and scores (e.g. IELTS)
- Approximate funds available for the move, a financial indicator
- Marital status and whether dependants would travel with you
- Destination and goal preferences (work, PR, study, family)
What we deliberately do not collect
Community content
- Posts, comments, questions and agent reviews you publish
- Reports and flags you submit about other content
AI Assistant data
- The messages and document briefs you send to the assistant, and the responses generated
- Monthly usage counters for messages and document generations, needed to enforce fair-use caps
Payment data
- Your checkout name, account email, phone number, bank transaction reference, amount, status, and the pass duration and expiry date
- We do not collect card or online-banking credentials. Your banking app processes the QR transfer. The receipt screenshot is sent by you through WhatsApp and is used only to verify the payment.
Messages you send us
When you use the form on the Contact page or the Data Subject Request page, the submission is stored so it cannot be lost, and a copy is emailed to the relevant mailbox. We keep:
- The name and email address you enter, the topic you choose, and the message itself
- A reference number, and for data requests the statutory response deadline
- Your browser's user agent, and a salted one-way hash of your IP address rather than the address itself, used only to detect a flood of automated submissions
Submissions are also checked by Cloudflare Turnstile, an anti-bot challenge that sets no advertising or tracking cookie. See section 7 for the processors involved.
Usage and technical data
- Pages viewed, features used, referring page, approximate region
- Device, browser and operating system information
- Server and security logs
- Cookie and similar identifiers, only in the categories you have consented to (see section 9)
3. Why we use your data
- Eligibility matching engine: comparing your profile against published visa criteria to produce match scores, points estimates and gap analysis
- AI Assistant: retrieving relevant verified content and generating grounded answers and draft documents
- Running your account: authentication, including the name, email address and profile picture received from Google Sign-In where you use it; saved profiles, bookmarks, comparisons, and transactional email (OTP, confirmation, password reset) sent from noreply@abroadmaster.com
- Payments and access: processing your prepaid pass and tracking its expiry
- Community moderation: investigating reports, removing fake reviews and preventing scams
- Service improvement: understanding, in aggregate, which countries and features people need most
- Advertising: showing ads, personalised only where you have consented
- Security, fraud prevention and legal compliance
4. Lawful basis for processing (GDPR Art. 6)
| Processing activity | Lawful basis |
|---|---|
| Creating and running your account | Contract necessity, Art. 6(1)(b) |
| Eligibility profile data and match scoring | Consent, Art. 6(1)(a); withdrawable at any time |
| AI Assistant messages and generated documents | Contract necessity, Art. 6(1)(b) |
| Payment processing and pass expiry tracking | Contract necessity, Art. 6(1)(b); legal obligation for financial records, Art. 6(1)(c) |
| Transactional email (OTP, password reset, receipts) | Contract necessity, Art. 6(1)(b) |
| Community posts and agent reviews | Consent, Art. 6(1)(a), by choosing to publish |
| Analytics cookies | Consent, Art. 6(1)(a) |
| Advertising and ad-personalisation cookies | Consent, Art. 6(1)(a) |
| Security logs, abuse and fraud prevention | Legitimate interests, Art. 6(1)(f) |
| Aggregated, non-identifying service improvement | Legitimate interests, Art. 6(1)(f) |
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent for eligibility data means we can no longer calculate match scores for you.
5. Sensitive personal data (PDPA)
Some of the eligibility profile fields, in particular funds available, marital status, dependants and education history, are financial or family-life information that can be treated as sensitive under Sri Lanka's PDPA and adjacent frameworks. We apply additional safeguards to these fields:
- They are collected only with your explicit, separate consent at the point you build your profile, and every field is optional
- They are used solely for eligibility calculation and never for advertising, ad targeting or profiling for marketing purposes
- They are never shared with agencies, consultants, advertisers or any other third party
- Access is restricted to your own account through Supabase Row Level Security, enforced at the database layer rather than in application code
- They are stored as ranges or bands wherever a precise figure is not required
6. Automated decision-making and profiling (GDPR Art. 22)
The Eligibility Checker, points calculators and AI-assisted matching produce results automatically, by comparing the profile you submit against published visa criteria. You should understand three things about this:
- What it does. It produces an indicative match percentage and a gap analysis per country and visa type, based on criteria such as age, education, experience, language score and funds.
- What it is not. It is not a decision by any immigration authority, not a prediction of your application outcome, and it produces no legal effect on you. Only the relevant government can decide a visa application.
- Your right to challenge it. You may contest any result, ask for human review, and express your point of view. Email privacy@abroadmaster.com with the country and visa type concerned; a person will re-examine the inputs and the criteria applied and respond, normally within 30 days.
7. Who we share data with
We do not sell personal data. We share it only with the processors needed to operate the service:
| Recipient | Purpose | What is shared |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, profile, community and payment-record data |
| Cloudflare | Hosting, CDN, DDoS and abuse protection, and the Turnstile anti-bot check on our forms | Technical request data including IP address |
| Resend | Sending transactional email: form acknowledgements, and the notification that reaches our own mailbox | Your email address, your name if given, and the content of the message you submitted |
| Anthropic (Claude API) | Generating AI Assistant answers and documents | Your message content and the retrieved site context; no account identifiers are sent |
| Meta (WhatsApp) | Receiving bank-transfer verification messages | The name, email, phone number, payment request details and bank receipt screenshot you choose to send through WhatsApp |
| Google AdSense | Displaying advertising | Cookie and device identifiers; personalised only with your advertising consent |
| Google (Sign in with Google) | Verifying who you are, if you choose to sign in with a Google account rather than an email address | Nothing about you is sent to Google beyond the sign-in request itself. The data moves the other way: Google sends us your name, email address and profile picture. See section 2 |
We may also disclose data where legally required, for example a valid order from a Sri Lankan court or regulator, or to establish, exercise or defend legal claims.
8. International data transfers
AbroadMaster is operated from Sri Lanka, and several of our processors store or process data outside Sri Lanka and outside the EU/EEA, including in the United States and the European Union, depending on the provider and region.
For EU/EEA users: transfers out of the EEA are made under the European Commission's Standard Contractual Clauses (SCCs), supplemented where necessary by additional technical and organisational measures such as encryption in transit and at rest. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that certification. You may request a copy of the relevant transfer safeguards from privacy@abroadmaster.com.
For Sri Lankan users: cross-border processing is carried out in line with the PDPA's conditions for transfers outside Sri Lanka: the recipient must provide an adequate level of protection through contractual commitments equivalent to the protections in this policy, and we assess each processor before onboarding it.
9. Cookies and advertising
We use strictly necessary cookies to keep you signed in and to remember your cookie choices. Analytics and advertising cookies, including cookies set by Google and its advertising partners, load only after you opt in.
Google and its partners may use cookies to serve ads based on your prior visits to this and other sites. You can control ad personalisation independently of us at Google My Ad Center and Google Ads Settings. Full detail, including the categories and how to change your mind, is in the Cookie Policy.
10. How we protect your data
- TLS encryption for all data in transit; encryption at rest
- Row Level Security policies on every database table, so a record is only readable by the account that owns it
- Passwords hashed and managed by Supabase Auth; never stored in plain text and never visible to us
- Secrets and API keys held in environment configuration, never in the database or in source control
- Administrative access to the production database is held by the operator alone; no employees, contractors or third parties have standing access to your data
- Rate limiting and abuse detection on authentication and AI endpoints
No system is perfectly secure. We cannot guarantee absolute security, but we do commit to the measures above and to telling you promptly if something goes wrong.
11. Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, in line with GDPR Art. 33. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do. The Data Protection Authority of Sri Lanka will be notified in accordance with PDPA requirements.
12. How long we keep your data
| Data | Retention period |
|---|---|
| Account and eligibility profile data, including anything received from Google Sign-In | For as long as your account is active. Deleted within 30 days of a verified deletion request. |
| Inactive accounts (no sign-in) | Deleted after 24 months of inactivity, after an email warning sent at least 30 days beforehand. |
| AI Assistant conversation history | 12 months from the message date, or immediately on request. Usage counters are kept for the current cap period only. |
| Community posts, comments and reviews | Retained while published. On account deletion, content is either removed or permanently anonymised, at your choice. |
| Payment and transaction records | 7 years, as required by Sri Lankan tax and accounting law. This is a legal obligation and survives account deletion. |
| Contact form messages | 24 months from the date you sent them, so we can see the history of an ongoing issue, then deleted. |
| Data subject request records | 6 years from completion. We are required to be able to demonstrate that a request was handled correctly and within the deadline, which means keeping the record of it after acting on it. |
| Server, security and access logs | 90 days, then automatically purged. |
| Moderation and abuse records | 24 months, to detect repeat offenders and scams. |
| Cookie consent record | 12 months, after which you are asked again. |
| Backups | Rolling 35-day cycle. Deleted data disappears from backups within that window. |
13. Your rights if you are in the EU or EEA
The table below is the short version, for both regimes at once. The GDPR detail follows here; the PDPA detail is in section 14.
| Right | EU/EEA (GDPR) | Sri Lanka (PDPA) |
|---|---|---|
| Access a copy of your data | Yes (Art. 15) | Yes |
| Correct inaccurate data | Yes (Art. 16) | Yes |
| Delete your data | Yes (Art. 17) | Yes |
| Restrict processing during a dispute | Yes (Art. 18) | Not named as a separate right; we honour it anyway |
| Export in a machine-readable format | Yes (Art. 20) | Not named as a separate right; we honour it anyway |
| Object to processing and to direct marketing | Yes (Art. 21) | Yes |
| Withdraw consent | Yes (Art. 7(3)) | Yes |
| Human review of an automated result | Yes (Art. 22) | Not named as a separate right; we honour it anyway |
| Complain to a regulator | Your local supervisory authority (Art. 77) | Data Protection Authority of Sri Lanka |
| Our response deadline | 30 days, extendable by two months for complex requests | 30 days, extendable by two months for complex requests |
Under the GDPR you have the right to:
- Access: obtain a copy of the personal data we hold about you (Art. 15)
- Rectification: have inaccurate or incomplete data corrected (Art. 16)
- Erasure: have your data deleted, subject to legal retention obligations (Art. 17)
- Restriction: have processing limited while a dispute about accuracy or lawfulness is resolved (Art. 18)
- Data portability: receive your data in a structured, machine-readable format, or have it sent to another controller (Art. 20)
- Objection: object to processing based on legitimate interests, and to direct marketing at any time (Art. 21)
- Not to be subject to automated decisions producing legal or similarly significant effects, and to obtain human intervention (Art. 22; see section 6)
- Withdraw consent at any time, without affecting processing already carried out (Art. 7(3))
- Lodge a complaint with a supervisory authority (Art. 77; see section 16)
14. Your rights if you are in Sri Lanka
Under the Personal Data Protection Act No. 9 of 2022, you have the right to be informed about processing, to access your data, to have inaccurate data rectified, to request erasure, to withdraw consent, to object to processing including for direct marketing, and to complain to the Data Protection Authority of Sri Lanka. We handle Sri Lankan and EU requests through the same process and to the same standard.
15. How to make a request
Use the Data Subject Request page, or email privacy@abroadmaster.com from the address registered to your account.
- We respond within 30 days. Complex requests may be extended by up to two further months, and we will tell you within the first 30 days if that happens.
- Requests are free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
- We may ask you to verify your identity before acting, so that we do not disclose your data to someone else.
16. Complaints
Please contact us first at privacy@abroadmaster.com. Most issues are resolved quickly. If you are not satisfied:
- Sri Lanka: complain to the Data Protection Authority of Sri Lanka.
- EU/EEA: you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred. A list of authorities is published by the European Data Protection Board.
17. Children's privacy
AbroadMaster is intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data promptly. If you believe a minor has given us data, contact privacy@abroadmaster.com.
18. Changes to this policy
We will update this page when our practices change, and update the “last updated” date at the top. Where a change materially affects your rights, we will notify registered users by email before it takes effect, and where the change requires it, ask for fresh consent.
19. Contact
- Privacy and data requests: privacy@abroadmaster.com
- General support: support@abroadmaster.com
- Billing and payments: billing@abroadmaster.com
- Controller: J.R.L Weerasingha, Godakawela, Ratnapura, Sri Lanka; full postal address on request