1. Who we are
Headrest Technologies operates the Headrest website and software platform. For privacy questions, requests or complaints, contact headrest.lk@gmail.com.
2. When Headrest is a controller and when it acts for a Merchant
For website inquiries, subscription administration, account security, billing records and Headrest’s own business operations, Headrest decides why and how personal data is used and therefore acts in a controller-like capacity.
For customer and vehicle data that a service or repair centre enters into Headrest to manage a service session, the Merchant generally decides why that information is collected and how it is used. Headrest processes that information to provide the platform on the Merchant’s instructions. Customers should contact the relevant Merchant first for questions about the underlying vehicle-service record.
3. Personal data we may collect
Merchant and account data
- Name, business name, email address, mobile number and business contact details.
- Account credentials, role, login activity and security logs.
- Subscription plan, trial status, billing and transaction records where applicable.
- Support requests, correspondence and onboarding information.
Customer and service-session data
- Customer name, mobile number and other contact details provided by the Merchant.
- Vehicle registration/number plate, vehicle type, make/model, year and service details.
- Service stages, technician assignment, inspection findings, quotations, approvals, rejections or requests for changes.
- Images, documents, notes and other information uploaded or created in connection with a service session.
- Customer-link or QR access events, status updates and related technical logs where needed to operate or secure the Service.
Website and device data
- IP address, browser/device information, timestamps, error logs and basic security telemetry.
- Inquiry-form content and any information voluntarily submitted through the website.
4. Where the data comes from
Personal data may come directly from Merchants, from customers interacting with a Merchant’s Headrest link, from authorised Merchant staff, from technical systems needed to operate the platform, and from service providers that support hosting, messaging, email delivery, security or related infrastructure.
5. How we use personal data
- To create and administer Merchant accounts and trials.
- To create service sessions and provide QR or link-based customer views.
- To display service stages, findings, quotations and customer approval/rejection responses.
- To send transactional SMS or other service communications where enabled.
- To provide support, onboarding and onsite training.
- To secure accounts, detect misuse, investigate incidents and maintain audit or operational logs.
- To process billing and subscription administration.
- To troubleshoot, maintain and improve reliability and usability.
- To comply with applicable law, lawful requests and dispute-resolution obligations.
We do not sell personal data to advertisers.
6. Legal bases and purpose limitation
Depending on the context, processing may be based on performance of a contract, steps taken at a user’s request, consent where required, compliance with legal obligations, or legitimate business purposes that are compatible with applicable law and the rights of individuals.
Headrest aims to collect data for specified, explicit and legitimate purposes and to keep the data adequate, relevant and proportionate to those purposes. The Sri Lankan PDPA contains requirements relating to lawful processing, purpose limitation, data minimisation, accuracy, retention, integrity, confidentiality and transparency.
8. SMS and customer notifications
Where a Merchant uses SMS features, Headrest may process the customer’s mobile number, the type of service event, message content or template, delivery status, timestamps and provider response data. The Merchant is responsible for ensuring it has the authority to provide the mobile number and initiate the message.
Transactional service notifications are separate from marketing. Headrest does not treat a vehicle-service notification as permission to send unrelated promotional messages.
9. Storage, access and security
Headrest uses reasonable technical and organisational safeguards appropriate to the nature of the Service. These may include access controls, authentication, scoped links, server protections, logging, backups and measures intended to prevent unauthorised access, alteration, loss or disclosure.
Customer service records and uploaded files are not intentionally placed in unrestricted public storage. Customer-facing information may be accessible through a temporary or scoped link associated with a QR code. A person who receives or obtains a valid link may be able to access the information presented through it, so such links should be treated as confidential.
No online system can guarantee absolute security. Merchants should use strong credentials, limit staff access and promptly report suspected compromise.
10. Retention, deletion and uploaded content
Headrest keeps personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide the Service, maintain security and business records, resolve disputes and meet legal obligations.
When a Merchant requests deletion, deletes a service record through available tools, or closes an account, Headrest will delete or anonymise personal data that is no longer reasonably required, subject to legitimate legal, accounting, security, fraud-prevention, backup and dispute-resolution needs.
Uploaded images, documents and service-session content are included in this deletion approach. Protected backup copies may persist for a limited period until overwritten through the ordinary backup cycle and are not intended for active use except recovery or security purposes.
11. Privacy rights and requests
Subject to applicable law and the status of the relevant provisions, individuals may have rights to request access to personal data, correction of inaccurate data, withdrawal of consent where processing is based on consent, objection or restriction in applicable circumstances, and other remedies provided by Sri Lankan data-protection law.
If the data relates to a vehicle service session created by a Merchant, Headrest may need to coordinate the request with that Merchant. Requests can be sent to headrest.lk@gmail.com. We may need to verify identity before fulfilling a request.
Individuals may also have the right to raise a complaint with the Data Protection Authority of Sri Lanka where applicable.
12. Cookies, local storage and analytics
The public Headrest website may use strictly necessary browser storage or cookies where required for security or site functionality. If non-essential analytics, advertising or tracking technologies are introduced, Headrest will provide appropriate notice and choices where required.
Headrest does not currently describe the website as using behavioural advertising cookies, and this Policy should be updated before such tracking is introduced.
13. Artificial intelligence and automated decision-making
Headrest does not currently use generative AI or automated decision-making to determine repair outcomes, quotation acceptance, customer eligibility, pricing, creditworthiness or similar consequential decisions.
Headrest may use ordinary software automation to update service states, deliver notifications, maintain security and operate the platform. If material AI-assisted functionality is introduced later, Headrest will assess the privacy impact, disclose relevant processing and update this Policy or provide an additional notice as required.
14. Children
Headrest is a business service for vehicle service and repair operations and is not directed to children. Merchants should not intentionally submit a child’s personal data unless it is genuinely necessary for a lawful service purpose and all required authority has been obtained.
15. Cross-border processing
Some technology providers may operate infrastructure or support functions outside Sri Lanka. Where personal data is transferred or made accessible across borders, Headrest will seek to use appropriate contractual, organisational and technical measures and will comply with applicable Sri Lankan requirements governing cross-border data flows.
16. Changes to this Policy
Headrest may update this Policy when the product, service providers, legal requirements or processing activities change. The “Last updated” date will be revised. Material changes may also be communicated through the Service, email or another reasonable channel.
17. Contact and complaints
Privacy requests, deletion requests, corrections, questions or complaints:
headrest.lk@gmail.com