Law Enforcement & Government Data Requests
How we handle requests from law enforcement and public authorities for user data.
Last updated September 2, 2026
Law Enforcement & Government Data Requests
This page explains how DTK Holdings (Pvt) Ltd responds when law enforcement, a court, a regulator, or any other public authority asks us for data about someone who uses EventCraft. It is written for those authorities, and published so that our users can see the standard we hold ourselves to.
We take these requests seriously in both directions: we will not obstruct a lawful investigation, and we will not hand over our users' personal data without a legal basis that we have checked ourselves.
1. How to send a request
Send requests to info@dtkholdings.com with the subject line Data request — [authority name], or by post to DTK Holdings (Pvt) Ltd, 166/B, Kommala, Bentota, 80500, Sri Lanka.
A request must be made in writing on official letterhead and must state:
- the authority making the request and a named, contactable officer,
- the legal provision that authorises it,
- the specific account, event, or record concerned — an email address, username, or event link,
- the precise categories of data sought and the time period they cover,
- the deadline, and whether the matter is an emergency.
We do not accept requests made by telephone, social media, or messaging apps, and we cannot act on a request that does not identify a specific account.
2. What we require before we disclose anything
We disclose personal data to an authority only where we are satisfied that the request is lawful and binding on us. In practice that means valid legal process under the law of Sri Lanka — a court order, warrant, or a written demand issued under a statutory power that actually applies to us.
Authorities outside Sri Lanka should proceed through mutual legal assistance or a Sri Lankan court. We are not obliged to act on foreign legal process served directly on us, and generally will not.
3. How we review each request
Every request is reviewed before any data leaves our systems. That review checks that the requesting authority has the power it claims, that the legal process is valid and correctly served, that it actually covers the data being asked for, and that the scope is proportionate to the matter described.
No disclosure is made on the strength of a request alone. Our privacy contact reviews it, and a director of DTK Holdings (Pvt) Ltd approves any decision to disclose.
We push back where we should. Where a request is unlawful, defective, overbroad, vague, or seeks data we consider it has no right to, we say so and ask for it to be narrowed or withdrawn — and we will challenge it, including in court where appropriate, rather than comply with a request we believe to be unlawful. Where a defect is procedural, we tell the authority what would need to be corrected.
4. We disclose the minimum
When we do respond, we produce only the specific records the legal process actually compels, for the period it covers, and nothing more. We do not send an account's full history because it is easier than filtering it.
We do not give any authority direct, standing, or bulk access to our systems, our database, or our administrative tools. We do not build tools to make surveillance easier, and we do not respond to fishing requests that name no account.
5. We keep a record of every request
We log every request we receive, whether or not we comply: who asked, when, the legal basis claimed, the data sought, who reviewed it, the reasoning behind our decision, exactly what we disclosed or why we refused, and any challenge we brought. These records are retained for at least five years and are held securely with restricted access.
6. Telling the affected user
Our default is to notify a user whose data has been requested, with enough information to seek their own legal advice, before we disclose anything. We will not notify where the law or a court order forbids it, or where there is a genuine emergency involving a risk to life. Where a non-disclosure obligation is time-limited, we notify the user once it expires.
7. Emergencies
Where an authority tells us in good faith that there is an imminent risk of death or serious physical harm, we may disclose the limited data needed to address that specific risk without waiting for legal process. Emergency requests must explain the nature of the danger, why the data is needed to prevent it, and why there is no time for normal process. Every emergency disclosure is logged and reviewed afterwards in the same way as any other.
8. Preservation requests
On a written request from an authority we can preserve a snapshot of an identified account's existing data for up to 90 days while valid legal process is obtained. Preservation is not disclosure — nothing is handed over unless and until a lawful request arrives and passes the review described above.
9. What data we hold
What we hold about a user is set out in our Privacy Policy. In short: account details, the events, guests, tasks and budgets they have created, billing records, and limited technical logs. We do not hold users' passwords in readable form, and we cannot recover them. Data is deleted in the ordinary course as described in our Data Deletion policy, and we do not retain data solely in anticipation of a request.
10. Costs and contact
We do not charge authorities for responding to valid legal process. For questions about this page, email info@dtkholdings.com.