භාෂාව තෝරන්න · மொழியைத் தெரிவு செய்க · Choose your language

Privacy policy

Last updated: 27 September 2026

PublicWatch lets you report misuse of duty time by government dental surgeons without revealing who you are. This page explains what information we collect, how we use it, and how we protect you.

1. Who is responsible for your data

  • PublicWatch is responsible (the “controller”) for the information you send, under Sri Lanka's Personal Data Protection Act, No. 9 of 2022 (as amended in 2025).
  • Questions about your data go to our data protection contact, shown at the end of this page.

2. What we collect

  • The report: the hospital, the concern, the date and time, the dental surgeon's name or description, and what you tell us.
  • Evidence you choose to add: photos, documents and voice messages.
  • Contact details, only if you choose to give them.

3. What we do not collect

  • We do not ask for your name or an account.
  • We do not store your IP address. It is used for a few minutes only, to block spam, and then forgotten.
  • We remove the location (GPS), phone model and owner details from photos. We keep only the time the photo was taken, because it is evidence.
  • We do not use advertising or tracking cookies, or analytics services.

4. How we use your report

  • Trained reviewers read every report to check whether it is credible.
  • If a report is verified, we send a formal petition to the hospital and the responsible health authorities (for example the RDHS, the Provincial Director of Health Services, the Ministry of Health and the Presidential Secretariat). The petition includes the report details and may include your photos and documents. It never includes your name or contact details. Voice messages are not sent.
  • We publish only anonymised totals (for example, the number of verified reports by district). We never publish doctors' names.

5. Why we may use this information

  • We use report information to pass possible misconduct by public officers to the authorities responsible for them, which is in the public interest.
  • Reports contain allegations about a named person, which the law treats as sensitive. We limit who can see them, keep them only as long as needed, and never publish them.

6. Keeping your identity confidential

  • We never reveal who made a report: not to the dental surgeon, and not to the authorities we petition.
  • If a person named in a report asks for their data, we will not disclose the source where that would reveal you or defeat the purpose of the report, as the law allows.
  • Petitions are marked confidential. If an authority is asked to release a petition under the Right to Information Act, we will ask it to withhold personal and confidential information.

7. Who can see your information

  • Only authorised reviewers can see reports, evidence and contact details. They sign in with a password, and every action is recorded.
  • We do not sell or share your information with anyone else, except where the law requires it.

8. Where your data is stored

  • Reports are stored on secure servers. If they are stored outside Sri Lanka, we use the safeguards the law requires for transfers abroad.

9. Information kept on your phone

  • To help you, the app stores a few things on your phone: an unfinished report, reports waiting to be sent while you are offline, and the tracking codes of reports you sent. You can remove saved codes on the Track page. Anyone who uses your phone may be able to see them.
  • Cookies: we store your language choice. Reviewers also get a sign-in cookie. We use no other cookies.

10. Protecting yourself

  • Check that your photos do not show your face, your reflection or anything else that identifies you, and avoid photographing patients.
  • If you are worried about being identified, leave out details that only you could know.

11. How long we keep information

  • We keep reports and evidence only as long as needed to review them and follow up with the authorities, and then delete or anonymise them.
  • To ask for your contact details or a report to be removed, add a message on your tracking page. Because we do not know who you are, the tracking code is the only way to link you to a report.

12. Your rights

  • Sri Lanka's Personal Data Protection Act (No. 9 of 2022) gives you rights over your personal data, including the right to access it, correct it and ask for it to be deleted. Use your tracking page to contact us.

13. If you are named in a report

  • Dental surgeons named in a report also have rights under the law. They can contact our data protection contact. We will respond fairly while protecting the identity of the person who reported.

14. Changes to this policy

  • If we change this policy, we will update this page and the date above.

Data protection contact: [email protected]