Back to Home
Security & Trust

Privacy Policy

Effective: September 8, 2026 · Last Updated: September 8, 2026

Correct.lk - Learning designed with children's privacy in mind.

Child Privacy Promise

Correct.lk is available only to children aged 8 or older. A child under 13 may use Correct.lk only after we obtain verifiable consent from a parent or legal guardian. We collect only the information reasonably necessary to provide learning, safety, support, and required administration.

1. About this Policy

This Privacy Policy explains how Correct.lk ("Correct.lk", "we", "us" or "our") collects, uses, shares, stores and protects personal data when students, parents or guardians, teachers and other users access our website, applications, classes, assessments, support channels or related learning services (together, the "Services").

Correct.lk is operated by Web3 Genes (Pvt) Ltd of Level 13, MAGA ONE, No. 200, Nawala Road, Colombo 05. The entity is the controller of personal data described in this Policy unless we state otherwise.

This Policy is designed to support compliance with Sri Lanka's Personal Data Protection Act, No. 9 of 2022 ("Sri Lanka PDPA"), as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025, together with applicable commencement orders, regulations and guidance. Where the U.S. Children's Online Privacy Protection Act and Rule ("COPPA") apply, we also follow COPPA requirements for children under 13.

Important: A written policy supports compliance, but actual compliance also requires matching consent, security, retention, vendor-management and rights-handling procedures.

2. Age Rules and Eligibility

  • Minimum age: A child must be at least 8 years old to use Correct.lk.
  • Ages 8-12: The child may use Correct.lk only after a parent or legal guardian creates or approves the account and we obtain verifiable parental consent before collecting the child's personal information, except where law permits a limited collection without prior consent.
  • Age 13 and above: The learner may generally use the Services directly, subject to applicable law and any additional consent required by a school, parent, guardian or programme.
  • Under age 8: The child must not create or use an account. If we learn that we collected personal data from a child under 8, we will suspend the account and delete the data, unless retention is legally required or necessary to protect the child.

Users must provide an accurate date of birth or age information. We may apply proportionate age-assurance steps. We do not use age assurance to create advertising profiles.

3. Parent or Guardian Consent for Children Under 13

Before collecting personal information online from a child under 13, Correct.lk will provide the parent or guardian with a direct notice explaining what we intend to collect, how we will use it, whether it will be disclosed, and how the parent can exercise control. We will then obtain verifiable parental consent using a method reasonably calculated to confirm that the person giving consent is the child's parent or legal guardian.

Depending on the information and activity involved, verification may include a parent account, confirmation link or one-time code sent to the parent, a signed consent form, a verified payment method, live or video confirmation, government-issued identification checked only for verification and promptly deleted, or another legally accepted method. We will not ask the child to provide the parent's sensitive identity documents.

Where consent obtained through email or a similar lightweight method is legally sufficient only for internal use, we will use a stronger method before disclosing a child's personal information to third parties, unless the disclosure is integral to the Service and the law permits the chosen method. We will obtain separate parental opt-in consent for third-party disclosure that is not integral to delivering the requested learning service, including targeted advertising. Correct.lk's policy is not to use children's personal data for targeted advertising.

A parent or guardian may refuse consent. The child may then be unable to use features that genuinely require the information, but we will not collect more data than reasonably necessary as a condition of participation.

4. Information We Collect

We apply data minimisation: we seek only information that is adequate, relevant and reasonably necessary for the stated purpose. The exact fields may differ by programme and user role.

Category

Student identity and eligibility

Examples

Name or preferred name, date of birth or age band, grade, language, student ID

Why it may be needed

Create the correct learner account, apply age rules and provide suitable content

Category

Parent or guardian details

Examples

Name, relationship to child, email address, mobile number, consent record

Why it may be needed

Verify and manage consent, communicate about the child and protect the account

Category

Account and enrolment

Examples

Username, securely protected password, selected courses, batch, class and subscription status

Why it may be needed

Operate the account and deliver enrolled Services

Category

Learning and assessment

Examples

Attendance, lesson activity, answers, scores, progress, teacher feedback and assignment submissions

Why it may be needed

Provide teaching, assessments, progress reports and academic support

Category

Class and support content

Examples

Questions, messages, support requests and, where clearly notified, audio/video or class recordings

Why it may be needed

Conduct classes, answer requests, maintain quality and safety

Category

Transaction records

Examples

Parent or payer name, amount, date, invoice and payment status

Why it may be needed

Process enrolments, refunds, accounting and fraud prevention. Full card data is normally handled by the payment provider

Category

Technical and security data

Examples

IP address, device/browser type, login time, diagnostic logs and cookie identifiers

Why it may be needed

Secure the Service, troubleshoot, prevent abuse and maintain reliability

5. Information We Do Not Ask Children to Provide

Unless a specific feature genuinely requires it, it is lawful, and we give clear notice and obtain any required consent, Correct.lk does not ask children to provide:

  • national identity card, passport, birth-certificate or other government identification numbers;
  • precise geolocation, contacts/address-book data, biometric identifiers, health information or financial account details;
  • information about race, ethnicity, religion, political opinions, sexual life or other sensitive matters;
  • public profile content, unnecessary photographs, or unrestricted free-text information unrelated to learning.

Children should not upload or type unnecessary personal information into answers, chat, assignments or support messages. Where practical, we use structured fields, age bands, internal student IDs and other privacy-preserving alternatives.

6. How We Collect Information

  • Directly from a parent, guardian, or student.
  • Automatically when the Services are used, through essential cookies, logs and similar technologies.
  • From service providers that support payments, communications, video classes, hosting, analytics or authentication, in accordance with their roles and our instructions.
  • From a school or educational organisation where it has authority to enrol or manage the student and provide us with the data.

7. How and Why We Use Personal Data

We use personal data only for clear and lawful purposes, including to:

  • create and administer accounts; verify age, parent/guardian authority and consent;
  • deliver live or recorded classes, learning materials, assessments, certificates and progress reporting;
  • personalise learning within the Service without building advertising profiles;
  • communicate service notices, class updates, safety information and parent-approved educational messages;
  • process payments, refunds and financial records through appropriate providers;
  • provide technical support, maintain service quality and troubleshoot errors;
  • protect children and other users, secure accounts, prevent fraud and investigate misuse;
  • meet legal, regulatory, tax, audit and dispute-resolution duties; and
  • improve the Services using aggregated or de-identified information where reasonably possible.

Under the Sri Lanka PDPA, our processing may rely on consent, performance of a contract or pre-contractual steps, compliance with law, protection of vital interests, public-interest grounds where applicable, or another lawful basis recognised by the Act. We will identify and document the appropriate basis for each material processing activity. Where we rely on consent, it must be freely given, specific, informed and unambiguous, and may be withdrawn subject to lawful limitations.

8. Cookies, Analytics and Advertising

We may use cookies or similar technologies that are necessary for login, security, language preferences, session continuity and core operation. Any non-essential analytics will be configured to minimise data and used only with any consent required by law.

  • We do not sell or rent children's personal information.
  • We do not use children's personal information for behavioural or targeted advertising.
  • We do not knowingly permit third-party advertising technologies to track children across unrelated websites or services.

If Correct.lk introduces a materially different advertising or analytics practice, we will update this Policy and obtain any fresh or separate consent required before applying it to a child.

9. When We Share Personal Data

We share personal data only when necessary for the described purposes, with appropriate safeguards, and never merely because it may be commercially valuable. Recipients may include:

  • a parent or guardian linked to the child's account;
  • authorised teachers, tutors and staff who need the information to teach or support the learner;
  • a school or educational organisation responsible for the relevant class or programme;
  • carefully selected processors supporting hosting, cloud storage, live-class/video services, email/SMS, customer support, authentication, security, payment processing and learning operations;
  • professional advisers, auditors, insurers and regulators where reasonably necessary; and
  • law-enforcement or other authorities where disclosure is required or permitted by law, or necessary to protect a child or another person from serious harm.

Service providers must process data only for authorised purposes, protect it appropriately, and retain it only as necessary. A current list or category-level description of providers that process children's information may be requested through the contact details below. We will identify operators collecting or maintaining children's personal information where COPPA requires this in the online notice.

10. International and Cross-Border Data Transfers

Some providers may process or store data outside Sri Lanka. For cross-border data flows, we will apply the Sri Lanka PDPA requirements then in force, including appropriate contractual or other instruments specified by the Data Protection Authority, enforceable safeguards, and any applicable exception or explicit informed consent. We will also assess provider security and limit the data transferred.

11. Security

We use reasonable administrative, technical and physical safeguards proportionate to the nature of the data and the risk to children. These may include:

  • encryption in transit and appropriate encryption at rest;
  • role-based access, least-privilege permissions and multi-factor authentication for privileged access;
  • secure password hashing, access logging, monitoring and vulnerability management;
  • separation of child, parent and staff permissions; staff confidentiality and training;
  • vendor due diligence and written data-protection obligations; and
  • incident response, backup and recovery procedures.

No system is completely secure. If a personal data breach creates a risk requiring notice under applicable law, we will notify the relevant authority and affected individuals or parents/guardians as required.

12. How Long We Keep Information

We keep personal data only for as long as reasonably necessary for the purpose collected, and then securely delete or de-identify it, unless a longer period is required by law, needed to resolve a dispute, protect safety or establish legal claims. Our documented retention schedule will consider:

  • active-account and course duration;
  • the parent's consent and any withdrawal;
  • the time needed to provide progress history, certificates or support;
  • legal, financial, safeguarding and dispute-resolution obligations; and
  • the sensitivity of the data and risk of continued retention.

Children's information will not be retained indefinitely. Class recordings, raw support attachments and precise technical logs should have short, defined retention periods unless a documented need requires longer storage. Backups are deleted or overwritten according to controlled backup cycles.

13. Rights and Choices

Subject to applicable law and lawful exceptions, a user—or a parent/guardian acting for a child—may ask us to:

  • confirm whether we process personal data and provide access to it;
  • correct or complete inaccurate or incomplete data;
  • delete personal data;
  • withdraw consent and stop further collection or use based on consent;
  • object to or restrict certain processing where applicable;
  • request review of a decision based solely on automated processing where applicable; and
  • receive information about relevant recipients and make a complaint or appeal to the competent authority.

Parents of children under 13 may review the child's personal information, request deletion, refuse further collection or use, and permit collection and internal use while refusing non-integral disclosure to third parties. We may verify the requester's identity and relationship to the child before acting. We aim to respond without undue delay and within the time required by applicable law; under the amended Sri Lanka PDPA, this is generally within one month, subject to a permitted extension.

A child may also contact us with a privacy concern. We will explain the process in age-appropriate language and, where appropriate, involve the parent or guardian.

14. Automated Decisions and AI-Supported Features

Correct.lk may use automated tools to mark objective questions, recommend learning content, identify possible errors or help teachers review progress. We will not make a decision producing legal or similarly significant effects on a child solely through automated processing without the safeguards required by applicable law. Important academic or disciplinary decisions should include meaningful human review. We will not use children's personal information to train general-purpose external AI models unless clearly disclosed and lawfully authorised, with any required parental consent.

15. Children's Safety and Public Sharing

Student profiles are private by default. Children should not publicly disclose their contact details, location, school timetable, passwords or other sensitive information. If community, chat, competition, leaderboard or user-generated-content features are offered, we will use age-appropriate defaults and moderation, limit public identifiers, and provide reporting and blocking tools appropriate to the feature.

16. Schools, Teachers and Institutional Accounts

Where a school or organisation provides student information, it must have authority to do so and must give students and parents any notices or choices required by law. We will use the data only to provide the contracted educational service and related safety, support and administration. A school's authorisation will not replace verifiable parental consent where COPPA requires Correct.lk to obtain that consent directly or where the school's consent is not legally sufficient.

17. Changes to this Policy

We may update this Policy to reflect changes to the Services, law or our practices. We will post the revised Policy with a new effective date. For material changes affecting children's information, we will provide prominent notice to parents or guardians and obtain fresh verifiable consent where required before using previously collected information in a materially different way.

18. Contact Us

For privacy questions, parental requests, consent withdrawal, complaints or rights requests, contact:

Data Controller
Web3 Genes (Pvt) Ltd
Privacy contact / DPO
Data Protection Officer
Email
privacy@correct.lk
Postal address
Level 13, MAGA ONE, No. 200, Nawala Road, Colombo 05

If you are not satisfied with our response, you may have the right to complain or appeal to the Data Protection Authority of Sri Lanka or another competent regulator. U.S. users may also contact the U.S. Federal Trade Commission regarding COPPA matters.

19. Legal References

  • Sri Lanka: Personal Data Protection Act, No. 9 of 2022; Personal Data Protection (Amendment) Act, No. 22 of 2025.
  • United States: FTC Children's Online Privacy Protection Rule (COPPA) and FTC COPPA compliance guidance.

Have concerns about your personal data?

Request data updates or file erasure requests here.

privacy@correct.lk