MITHRU Privacy Policy
Replaces all prior versions
Mithru Pvt Ltd. ("Mithru", "we", "us", or "our") is a technology-enabled companion care platform connecting families with trusted and qualified companions and support providers for elder care, companionship, daily assistance, and non-medical support services. We are committed to protecting the privacy and personal data of all users in accordance with the Personal Data Protection Act No. 09 of 2022 (Sri Lanka) and internationally recognised best practices including the EU General Data Protection Regulation (GDPR) principles.
This Privacy Policy describes how we collect, use, share, and protect your personal information, and explains your rights regarding that information. By accessing or using the Mithru platform (website, mobile application, or any related service), you agree to the terms of this Privacy Policy.
Article 1 - Purpose of Processing Personal Information
Mithru collects and processes personal information solely for the following purposes. We will not use your data beyond these stated purposes. Where a new purpose arises, we will obtain your separate consent or notify you as required by law.
1.1 Membership Registration & Account Management
- Verify your identity and eligibility to use the platform
- Create and maintain your Mithru account
- Prevent fraud, misuse, and unauthorised access
- Send service-related notices, alerts, and updates
1.2 Service Delivery
- Match care-seekers (Elders or their Guardians) with appropriate caregivers (Mithru Companions)
- Process bookings, payments, and service scheduling
- Provide personalised content, recommendations, and in-app features
- Enable real-time location sharing during active care sessions (Mithru Companion and care-seeker only)
1.3 Safety & Background Screening
- Conduct background checks on Mithru Companion applicants (criminal record, employment history, qualifications)
- Perform facial verification to prevent fraudulent or duplicate accounts
- Monitor for safety incidents and investigate complaints
1.4 Complaints & Dispute Resolution
- Verify identity and investigate reported concerns
- Mediate disputes between care-seekers and Mithru Companions
- Notify parties of investigation outcomes
1.5 Analytics & Service Improvement
- Analyse usage patterns to improve app features and user experience
- Conduct internal research and aggregate statistical analysis
- Monitor platform performance and resolve technical issues
1.6 Marketing & Communications (with consent)
- Send promotional offers, newsletters, and service updates where you have opted in
- Serve relevant advertisements based on preferences (you may opt out at any time)
1.7 Legal & Regulatory Compliance
- Comply with applicable laws, regulations, court orders, and government requests
- Enforce our Terms of Service and protect the rights of Mithru and its users
Article 2 - Retention and Use Period of Personal Information
We retain your personal data only for as long as necessary for the stated purpose or as required by law. When data is no longer needed, it is securely deleted or anonymised.
2.1 Standard Retention Periods
| Data Type | Retention Period |
|---|---|
| Account/membership data | 3 months after account deletion |
| Active investigation data | Until investigation is closed |
| Data subject to financial obligations | Until full settlement |
| Account recovery window | Up to 5 days post-deletion |
| Service provision data | Until service completion |
| Complaint & dispute records | 3 years from resolution |
| Contract & cancellation records | 5 years |
| Payment & supply records | 5 years |
| Access logs/server logs | 3 months |
| Partnership inquiry data | 6 months |
| Marketing consent records | Until consent is withdrawn + 1 year |
| Biometric/facial verification data | Deleted immediately after verification |
Article 3 - Legal Basis for Processing
Mithru processes personal data only where a valid legal basis exists. Depending on the type of data and purpose, we rely on one or more of the following grounds:
- Contractual necessity - processing required to perform our service agreement with you
- Legal obligation - compliance with applicable laws and regulatory requirements
- Legitimate interests - improving our services, preventing fraud, and ensuring platform safety, balanced against your rights
- Consent - where required (e.g., marketing communications, optional data collection); you may withdraw consent at any time
- Vital interests - in emergency situations where processing is necessary to protect life
Article 4 - Provision to Third Parties
Mithru does not sell, rent, or trade your personal data. We share data with third parties only in the following circumstances:
4.1 With Your Consent
We share data with third parties where you have given explicit, informed consent
4.2 Service Providers (Data Processors)
We engage trusted service providers who process data only on our instructions:
- Cloud infrastructure: Google Cloud Platform, Amazon Web Services (AWS)
- Payment processing: Stripe, Google Pay, Apple Pay, local payment gateways
- Identity verification & background checks: licensed third-party screening providers
- Customer communications: SMS/email notification providers
- Analytics: Google Analytics (anonymised/aggregated only)
4.3 Legal & Regulatory Disclosure
- Where required by law, court order, or government authority
- To enforce our Terms of Service or protect legal rights
- In connection with a merger, acquisition, or corporate restructuring (you will be notified)
4.4 Safety Emergencies
Where disclosure is necessary to prevent imminent harm to a person's life or safety.
All third-party providers are bound by data processing agreements requiring appropriate security standards and data protection compliance.
Article 5 - Outsourcing of Personal Data Processing
When Mithru outsources data processing activities, we ensure all processors comply with applicable data protection laws through binding contractual obligations. Current sub-processors include:
| Provider | Tasks | Retention |
|---|---|---|
| Google Cloud / AWS | Cloud hosting, storage, infrastructure | As per service agreement |
| Stripe / Payment Gateways | Payment processing, transaction records | 5 years (legal requirement). |
| Google Pay / Apple Pay | Mobile payment processing | Per their privacy policies |
| SMS/Email Providers | Notifications, OTPs, alerts | 90 days |
| Background Check Providers | Mithru Companion screening & verification | Duration of engagement + 1 year |
| Google Analytics | Anonymised usage analytics | 14 months (autodeleted) |
Article 6 - Your Rights and How to Exercise Them
As a user of the Mithru platform, you have the following rights regarding your personal data:
6.1 Rights Available to All Users
- Right to Access - request a copy of the personal data we hold about you
- Right to Rectification - request correction of inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten") - request deletion of your data, subject to legal retention requirements
- Right to Restrict Processing - request that we limit how we use your data in certain circumstances
- Right to Data Portability - receive your data in a structured, machine-readable format
- Right to Object - object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent - withdraw any previously given consent at any time, without affecting prior processing
- Right not to be subject to Automated Decision-Making - where decisions have significant effects on you
6.2 How to Exercise Your Rights
Requests may be submitted through any of the following channels:
- In-app: Settings > Privacy > Data Request
- Email: mithru.team@gmail.com (subject line: "Privacy Rights Request")
- Written request to the Data Protection Officer (address in Article 11)
We will respond within 30 days of receipt. Identity verification may be required before processing your request. Certain rights may be subject to restrictions under applicable law.
Article 7 - Types of Personal Information Collected
The table below sets out the categories of personal data Mithru collects and the specific data types within each category:
| Data Category | Data Types Collected |
|---|---|
| a. Account Information (Collected at registration/update) |
Full name, email address, phone number Profile photo Login credentials (hashed password) Home address Banking/payment details Government-issued ID numbers Tax details (where applicable) Accessibility settings & preferences Loyalty program information |
| b. Background Check Information (Mithru Companions only) |
Criminal record (where permitted by law) Current and prior residential addresses Caregiver/employment history Known aliases Professional qualification & certification status |
| c. Demographic Data (Where required for service features) |
Age or date of birth (eligibility verification) Gender (for Mithru Companion matching preferences) |
| d. Identity Verification & Biometric Data |
Government-issued IDs (passport, driver's license) User-submitted selfies and profile photos Facial verification data (used only for fraud prevention; not stored beyond verification) |
| e. User-Generated Content |
Ratings and feedback on Mithru Companions Survey responses Photos, audio, and video recordings (uploaded or in-app, for safety purposes) |
| f. Location Data |
Approximate location (general area) Precise location (while app is active, for service delivery) |
| g. Service & Transaction Data |
Earnings and payment records Services booked, completed, or cancelled Service dates, times, and ratings Acceptance and cancellation rates |
| h. Usage Data |
App features or pages viewed Access dates and times App crash and system activity logs Browser type and session data |
| i. Device Data |
Device model and unique identifiers IP address Operating system and version Mobile network information Advertising identifiers |
| j. Communications Data |
Preferred language settings Chat logs between users and Mithru Companions (end-to-end encrypted) Customer support correspondence Phone call recordings (only where users are notified in advance) Call transcripts Communication type (voice or text) and timestamps |
| k. Mithru Companion Health & Safety Data (New - required for vulnerable user protection) |
Vaccination status (where legally required) First Aid / CPR certification Medical fitness declaration |
| l. Emergency Contact Information (New - for user safety) |
Name and relationship of emergency contact Emergency contact phone number |
- Camera access is used in-app for profile photos and identity verification only. Images are not permanently stored on Mithru servers beyond their immediate processing purpose.
- In-app chat messages between users and Mithru Companions are end-to-end encrypted and are not shared with third parties except where required by law.
- Biometric data (facial verification) is processed solely to prevent account fraud and is deleted immediately upon completion of the verification process.
- Location data is collected only when the app is actively in use during a care session, unless you have separately consented to background location tracking.
Article 8 - Destruction of Personal Information
Mithru applies the following data destruction procedures when personal data is no longer needed:
8.1 Deletion Triggers
- Retention period has expired
- User submits a verified erasure request and no legal obligation requires retention
- Purpose for which data was collected has been fulfilled
8.2 Destruction Methods
- Electronic data: cryptographic erasure (key destruction) followed by secure deletion using industry-standard overwriting
- Paper documents: cross-cut shredding or secure incineration by certified document destruction providers
- Backup copies: scheduled for deletion at next backup cycle, with confirmation log maintained
Where data must be retained beyond the deletion trigger due to a legal obligation, it is isolated in a separate, access-restricted environment until the legal retention period expires.
Article 9 - Security Measures
Mithru employs a layered, defence-in-depth approach to data security, encompassing administrative, technical, and physical controls:
9.1 Administrative Controls
- Data protection policies reviewed annually and updated as required
- Mandatory privacy and security training for all staff handling personal data
- Data Protection Impact Assessments (DPIAs) for high-risk processing activities
- Access granted on a need-to-know, least-privilege basis
- Supplier due diligence and contractual data processing agreements
9.2 Technical Controls
- Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Multi-factor authentication (MFA) for all internal systems and administrator accounts
- Role-based access controls (RBAC) with comprehensive audit logging
- Automated intrusion detection and prevention systems
- Regular vulnerability assessments and penetration testing
- End-to-end encryption of in-app user communications
9.3 Physical Controls
- Data processed exclusively in ISO 27001-certified data centres
- Physical access restricted to authorised personnel only
- CCTV monitoring and visitor log requirements at all data processing facilities
9.4 Incident Response
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by law.
Article 10 - Cookies and Tracking Technologies
Mithru uses cookies and similar tracking technologies on its website and mobile application. The following table summarises the types of tracking used:
| Cookie Type | Purpose | Opt-Out Option |
|---|---|---|
| Essential | Authentication, security, session management | Cannot be disabled (required for service) |
| Functional | Language preferences, accessibility settings | Via browser settings |
| Analytics | Usage patterns, performance monitoring (Google Analytics - anonymised) | Opt-out via browser settings or analytics opt-out page |
| Marketing | Personalised ads and remarketing | Android/iOS ad settings; platform opt-out page |
A cookie consent banner is displayed on first use of the Mithru website. You may update your cookie preferences at any time via Settings > Privacy > Cookie Preferences.
Article 11 - Data Protection Officer
Mithru has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection laws.
- Name: Ayesha Weerasinghe
- Position: Data Protection Officer
- Email: mithru.team@gmail.com
- Response time: Within 30 business days of receipt
All privacy-related queries, data subject requests, and complaints should be directed to the DPO using the contact details above.
Article 12 - Remedies for Rights Infringement
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority. In Sri Lanka, you may contact:
- Personal Information Protection Commission (or equivalent regulatory body as established under the Personal Data Protection Act No. 09 of 2022)
- Personal Information Dispute Mediation Committee
- Cyber Crimes Investigation Division of the Sri Lanka Police (for data-related criminal offences)
We encourage users to contact our DPO first so we may address concerns directly. You also have the right to seek judicial remedies if you consider that your rights have been infringed.
Article 13 - Children's Privacy
The Mithru platform is not directed at, and does not knowingly collect personal data from, individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor without verified parental consent, we will take immediate steps to delete such data.
If you believe a minor's data has been submitted to the platform, please contact our DPO immediately at mithru.team@gmail.com.
Article 14 - International Data Transfers
Mithru's cloud infrastructure (Google Cloud, AWS) may result in your personal data being stored or processed in jurisdictions outside Sri Lanka, including within the European Economic Area and the United States. Where such transfers occur, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by relevant authorities
- Transfers only to jurisdictions with an adequate level of data protection, or
- Processor contracts requiring equivalent protections to those provided under Sri Lankan law
Article 15 - Scope of Policy
This Privacy Policy applies to all services provided by Mithru Pvt Ltd., including:
- The Mithru mobile application (iOS and Android)
- The Mithru website and web-based portal
- Customer support interactions
- All Mithru Companion and care-seeker interactions facilitated through the Mithru platform
This Policy does not apply to third-party websites, applications, or services that may be linked from the Mithru platform. We encourage you to review the privacy policies of any third-party services you access through links on our platform.
Article 16 - Changes to This Policy
Mithru reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. We will provide notice of material changes as follows:
- Minor updates: posted on the Mithru website and app with the updated effective date, with at least 7 days' notice
- Material changes (affecting your rights or how we use your data): additional notice via email or in-app notification at least 30 days prior to the change taking effect
- Changes requiring consent: we will seek your explicit consent before implementing such changes
Continued use of the Mithru platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the updated policy, you should discontinue use of the platform and may request deletion of your account.
The version history of this Privacy Policy is available upon request from our Data Protection Officer.
Questions about this Privacy Policy?
Contact our Data Protection Officer at mithru.team@gmail.com or visit Settings > Privacy within the Mithru app.
Mithru Pvt Ltd. | Privacy Policy Version 2.0 | Effective: May 17, 2026